Scoping a CMMC Assessment: CUI Assets Versus Security Protection Assets
Scope is the single decision that sets the cost, duration and outcome of a CMMC Level 2 assessment, and it is decided before a single control is tested. Get the boundary wrong and you either pay to assess systems that never needed to be in scope, or you leave a security tool outside the boundary that an assessor will pull back in.
In This Article
The distinction that causes the most confusion is between a CUI Asset and a Security Protection Asset. They are treated differently, they are documented differently, and they carry different amounts of assessment work. Below is how the categories are defined in the CMMC Program rule at 32 CFR Part 170, and how to apply them without guessing.
What the Phase 2 Suspension Changed About Scoping
In a memorandum dated July 13, 2026, the Department suspended CMMC Phase II requirements. Reporting from counsel and assessment firms indicates that the third party certification gate for Level 2 has been paused in new solicitations, while the underlying contractual security obligations were not repealed. We are not going to characterize what comes next or when, because that is not settled, and anyone telling you a firm date is speculating.
What is settled is this: DFARS 252.204-7012 still requires adequate security for covered defense information and still requires implementation of NIST SP 800-171. DFARS 252.204-7019 and 252.204-7020 self assessment and SPRS reporting obligations are a separate mechanism from the CMMC certification gate. Scoping work is the least perishable thing you can do right now, because the asset boundary you define serves your SPRS score, your SSP, your DFARS 7012 posture and any future assessment, in that order.
If your program stalled when the news broke, restart it at scoping. It is the work that holds its value regardless of what the Department does with Phase II.
What Counts as a CUI Asset?
A CUI Asset is any asset that processes, stores or transmits Controlled Unclassified Information. Processing means CUI is in use on the asset, storage means CUI is at rest on it, and transmission means CUI transits it.
CUI Assets are assessed against all applicable Level 2 security requirements. That is the full weight of the 110 requirements in NIST SP 800-171 Rev. 2 as incorporated by the CMMC rule, including AC.L2-3.1.1 for authorized access, AC.L2-3.1.3 for controlling the flow of CUI, IA.L2-3.5.3 for multifactor authentication, AU.L2-3.3.1 for audit records, MP.L2-3.8.3 for media sanitization and SC.L2-3.13.16 for protecting CUI at rest.
Two practical points. First, a laptop that a user occasionally opens a CUI attachment on is a CUI Asset, whether or not anyone intended it to be. Second, this category is the reason enclaves exist. Many contractors deliberately constrain CUI to a defined enclave so that the population of CUI Assets is small, well understood and separable from the rest of the corporate network. That is a legitimate architecture, but the separation has to be real and demonstrable, backed by boundary protection under SC.L2-3.13.1 and flow enforcement under AC.L2-3.1.3.
What Is a Security Protection Asset, and Why Do People Get It Wrong?
A Security Protection Asset (SPA) is an asset that provides security functions or capabilities to your CMMC Assessment Scope, regardless of whether it processes, stores or transmits CUI. That last clause is the part people miss.
Typical SPAs include a SIEM or log aggregation platform, a vulnerability scanner, a privileged access management tool, an enterprise identity provider, a VPN concentrator, endpoint detection and response consoles, a jump host used for administration, and the infrastructure a managed service provider uses to administer your CUI environment.
SPAs are assessed against the Level 2 requirements that are relevant to the capabilities they provide. This is a narrower assessment than a CUI Asset receives, but it is not zero. If your SIEM is the mechanism you rely on for AU.L2-3.3.1 and AU.L2-3.3.5, the assessor will look at the SIEM. If your identity provider is how you satisfy IA.L2-3.5.3, the assessor will look at the identity provider. The logic is simple: if you point at a tool as evidence a control is met, that tool is inside your scope.
The common failure mode is a contractor who builds a tight CUI enclave and then administers it with tooling that lives outside the enclave, on the general corporate network, unhardened and unmonitored. The enclave boundary does not protect you when the administrative path into it is outside the boundary. Inventory your security tooling and your administrative paths first, then decide where the boundary actually sits.
Where Contractor Risk Managed Assets and Specialized Assets Fit
The Level 2 scoping model in 32 CFR 170.19 defines five categories. Two more matter after CUI Assets and SPAs.
Contractor Risk Managed Assets (CRMAs) are assets that are capable of processing, storing or transmitting CUI but are not intended to, and that you manage using your own risk based security policies, procedures and practices. CRMAs must be documented in the asset inventory, described in the System Security Plan under CA.L2-3.12.4, and shown on the network diagram of the assessment scope. They are not assessed against the other Level 2 requirements by default. The catch: if the assessor concludes that an asset is not in fact being managed according to your documented risk based policies, that asset can be reclassified as a CUI Asset and assessed against all applicable requirements. CRMA is not a place to hide systems you do not want to fix.
Specialized Assets include Government Furnished Equipment, Internet of Things and Industrial IoT devices, operational technology, Restricted Information Systems and test equipment. At Level 2 these are documented in the asset inventory, the SSP and the network diagram, but are not assessed against the other Level 2 security requirements. Document how each one is managed. Do not treat "specialized" as an exemption from thinking about it.
Out of Scope Assets are assets that cannot process, store or transmit CUI and that provide no security protection to the scope. They must be physically or logically separated from CUI Assets, and the burden of demonstrating that separation is yours.
How External Service Providers and Cloud Services Change the Boundary
Almost every contractor has some part of the CUI environment operated by someone else, whether that is a managed service provider, a hosted virtual desktop, a cloud email tenant or an outsourced security operations center.
Two rules to anchor on. First, if a cloud service provider processes, stores or transmits CUI on your behalf, DFARS 252.204-7012(b)(2)(ii)(D) requires that the CSP meet the FedRAMP Moderate baseline or equivalent, plus the cyber incident reporting and related flow down requirements. Second, an external service provider that does not handle CUI but does handle security protection data, such as your MSP's RMM platform or your outsourced SOC's tooling, is in scope as a Security Protection Asset and its relevant capabilities are evaluated as part of your assessment.
The final rule did not create a requirement that every ESP hold its own certification. It made the ESP's relevant services part of your scope. Practically, that means you need a service description, a responsibility matrix showing which requirements the provider performs and which you perform, and evidence you can actually produce at assessment time. A shared responsibility matrix that exists only as a sales slide is not evidence.
Is Level 1 Scoping Different?
Yes, and it is much simpler. Level 1 concerns Federal Contract Information, not CUI. The scope is the assets that process, store or transmit FCI. There is no CUI Asset category, no Security Protection Asset category and no CRMA category to sort through, and specialized assets are not part of the Level 1 scope.
What you still owe is a defensible statement of which systems handle FCI and evidence for the 15 Level 1 requirements, including AC.L1-3.1.1, AC.L1-3.1.20 for connections to external systems, SC.L1-3.13.1 for boundary protection and SC.L1-3.13.5 for separating publicly accessible components. Level 1 is a self assessment with an annual affirmation, so the honesty of your scope statement is on you.
How to Run the Scoping Exercise
A workable sequence, in order:
- Find the CUI. Trace it by contract and by data flow, not by asking people where they think it lives. Start with the contracts that carry DFARS 252.204-7012 and the CUI categories and markings that came with them.
- Map the flow. Where does CUI enter, where is it stored, who touches it, where does it leave, and what does it transit on the way.
- Classify every asset. CUI Asset, SPA, CRMA, Specialized, or Out of Scope. Every asset gets exactly one label and a written justification.
- Inventory the security tooling and administrative paths separately. This is where SPAs surface. Assume anything you would cite as evidence is in scope.
- List every external service provider touching CUI or providing security capability, and get a responsibility matrix for each.
- Draw the network diagram and write the SSP scope section. CA.L2-3.12.4 requires the SSP to describe system boundaries, environments of operation, relationships with other systems and how requirements are implemented.
- Test the separation claims you are relying on to keep assets out of scope.
Then stop and ask the architecture question: is the current boundary the one you want to defend for years, or would a smaller, deliberately designed enclave be cheaper to build and cheaper to sustain? That question is much easier to answer before you have implemented 110 requirements across an accidental boundary.
Free Resource
Get a Second Set of Eyes on Your Scope
Scope is the one decision every other CMMC dollar depends on. Before you build to a boundary, get an honest read on which assets belong inside it and which controls apply. Start with our free NIST 800-171 guide to see where the gaps usually hide before an assessor does the checking for you.
Get the Free NIST 800-171 GuideFrequently Asked Questions
What is the difference between a CUI Asset and a Security Protection Asset?
A CUI Asset processes, stores or transmits Controlled Unclassified Information and is assessed against all applicable CMMC Level 2 security requirements. A Security Protection Asset provides security functions or capabilities to the assessment scope regardless of whether it touches CUI, and is assessed only against the requirements relevant to the capabilities it provides. A SIEM that never stores CUI is still in scope as an SPA.
Can an asset be both a CUI Asset and a Security Protection Asset?
Yes. A jump host that stores CUI while also serving as the administrative path into the CUI environment meets both definitions. When an asset meets the CUI Asset definition, treat it as a CUI Asset and assess it against all applicable Level 2 requirements, since that is the more demanding treatment.
Do Contractor Risk Managed Assets get assessed?
CRMAs are documented in the asset inventory, the System Security Plan and the network diagram, and are not assessed against the other Level 2 requirements by default. However, under 32 CFR 170.19, if an assessor determines the asset is not being managed according to the organization's documented risk based policies, it can be reclassified as a CUI Asset and assessed in full. CRMA status is conditional, not permanent.
Does the CMMC Phase II suspension mean I can stop scoping?
No. The July 13, 2026 memorandum suspended CMMC Phase II requirements, but DFARS 252.204-7012 and the NIST SP 800-171 implementation obligations it carries were not withdrawn, and self assessment and SPRS reporting obligations sit in separate clauses. What happens next with Phase II is not settled, and we are not going to predict a date. Scoping is the work that retains its value in every scenario.
Does my managed service provider need its own CMMC certification?
The CMMC Program rule does not impose a blanket certification requirement on every external service provider. Instead, an ESP that provides security capabilities to your scope is treated as a Security Protection Asset and its relevant services are evaluated as part of your assessment. If the provider is a cloud service provider that processes, stores or transmits CUI, DFARS 252.204-7012(b)(2)(ii)(D) requires FedRAMP Moderate baseline or equivalence.
Do I need a network diagram for scoping?
Yes. The Level 2 scoping requirements in 32 CFR 170.19 call for the asset inventory, the System Security Plan and a network diagram of the CMMC Assessment Scope to reflect each in scope asset category. CA.L2-3.12.4 separately requires the SSP to describe system boundaries and environments of operation.
Sources
- 32 CFR Part 170, CMMC Program final rule, including the Level 1 and Level 2 scoping provisions at 170.19
- NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019 and 252.204-7020, NIST SP 800-171 DoD Assessment Requirements
- CMMC Assessment Scope guidance documents for Level 1 and Level 2, published by the Department
- CMMC Reform Memorandum, July 13, 2026 (dowcio.war.gov)
- Latham & Watkins, "What Defense Contractors Should Know About DoD Suspension of CMMC Phase 2" (lw.com)
