Contractor Risk Managed Assets: The CMMC Category Contractors Get Wrong
Contractor Risk Managed Assets are not a shortcut, and treating them as one is how a clean scope turns into a failed assessment. The category exists for assets that are capable of handling CUI but are deliberately prevented from doing so by your own policy and configuration, and the burden of proving that intent sits entirely with you.
In This Article
- What Exactly Is a Contractor Risk Managed Asset
- How a CRMA Differs from Out of Scope and Specialized Assets
- What You Actually Have to Produce for a CRMA
- Why Assessors Reclassify a CRMA as a CUI Asset
- Which Controls Make the Not Intended Claim Credible
- Should You Use the Category, and the November Talk
- Frequently Asked Questions
Several vendor guides published in the last week frame CMMC around two things: a dollar range for a Level 2 assessment and a certification deadline. Both are downstream of scoping. The size of your assessment, and therefore its cost, is set by how many assets land in each category, which is why the category most people fudge deserves a post of its own.

What Exactly Is a Contractor Risk Managed Asset?
Per the CMMC Assessment Scope Level 2 guidance, now carried into the CMMC Program rule at 32 CFR Part 170, a Contractor Risk Managed Asset (CRMA) is an asset that can, but is not intended to, process, store, or transmit CUI because of the security policy, procedures, and practices in place. Read that definition twice. Two conditions have to be true at the same time:
- The asset is technically capable of touching CUI. It is a general purpose endpoint, server, or system on your network.
- Something you actually implemented stops it. Not a hope, not a habit, not an unwritten expectation. A policy, a procedure, and a practice.
One more detail that surprises people: CRMA are not required to be physically or logically separated from CUI assets. That is what distinguishes them from out of scope assets, and it is also exactly why assessors look at them closely. You are asserting that an asset sitting inside or adjacent to your CUI environment does not receive CUI, and you are asserting it on the strength of your controls rather than on the strength of a boundary.
Note that CRMA is a Level 2 concept. The Level 1 scope model works in terms of FCI assets, Specialized Assets, and out of scope assets, and there is no CRMA category and no SSP requirement at Level 1.
How Is a CRMA Different from an Out of Scope Asset or a Specialized Asset?
This is where most scoping documents fall apart. Three categories, three different tests.
- Out of scope assets cannot process, store, or transmit CUI. The test is capability, not intent. You need to be able to demonstrate that the asset is incapable, which in practice means physical or logical separation. If someone could plausibly copy a CUI file onto it tomorrow, it is not out of scope.
- Specialized Assets are defined by what the asset is, not by how you manage it. The category covers government furnished equipment, IoT and IIoT devices, operational technology, restricted information systems, and test equipment. A laptop is not a Specialized Asset because it is old, unusual, or inconvenient to patch.
- Contractor Risk Managed Assets are defined by intent plus enforcement. Capable, but prevented, by controls you can show.
The failure mode is predictable. A contractor has forty machines they do not want to bring into a full Level 2 assessment, cannot separate them, and cannot call them Specialized, so everything gets swept into CRMA. That is not risk management. That is a category being used as a container for whatever is left over, and an assessor reading your SSP will recognize it immediately. If you have not settled the difference between CUI assets and Security Protection Assets first, start with our guide to scoping CUI assets versus Security Protection Assets.
What Do You Actually Have to Produce for a CRMA?
Three artifacts, and all three are required. Missing one is a real finding, not a paperwork nit.
- Asset inventory. The asset is enumerated. This overlaps directly with CM.L2-3.4.1, which requires you to establish and maintain baseline configurations and inventories of organizational systems.
- System security plan. The SSP must show the asset is managed using your risk based security policies, procedures, and practices. This is CA.L2-3.12.4 doing real work rather than sitting in a binder.
- Network diagram. The asset appears in the network diagram of the CMMC Assessment Scope. This is the one most often skipped, and it is the one that makes an assessor start asking follow up questions, because a category that depends on the asset position relative to your CUI boundary is meaningless without a diagram showing that position.
The assessor reviews these documents to confirm the assets are managed under your stated risk based approach. CRMA are not assessed line by line against the full set of Level 2 requirements in the way CUI assets are. That is the concession the category grants. It is a narrow one.
Why Do Assessors Reclassify a CRMA as a CUI Asset?
Because the category comes with a check, and contractors forget it. If deficiencies or inconsistencies turn up during the assessment, the assessor may perform a limited check on CRMA to determine whether the asset is being managed the way the SSP claims. The guidance is explicit that this limited check is not meant to materially increase the duration or cost of the assessment, so it is not a second full assessment. But if that check shows the asset is in fact processing, storing, or transmitting CUI, the asset is no longer a CRMA. It is a CUI asset, and it gets assessed against all applicable Level 2 requirements.
Consider what that means mid assessment. An asset you never hardened, never brought into your logging pipeline under AU.L2-3.3.1, and never covered with FIPS validated cryptography for CUI at rest and in transit is suddenly in scope. Every requirement it fails becomes a NOT MET.
That has direct scoring consequences. Under 32 CFR Part 170, a Conditional CMMC Status requires a score of at least 88 out of 110 with the remaining gaps on a POA&M closed out within 180 days, and certain high weight requirements cannot be placed on a POA&M at all. A handful of reclassified assets can take a passing posture below that line. This is the single most expensive scoping mistake in the model, and it happens after the assessment has already started.
Which Controls Make the Not Intended Claim Credible?
CRMA are not assessed against the full Level 2 set, but your justification for calling them CRMA is built out of controls you already owe elsewhere. If these are weak, the category collapses.
- AC.L2-3.1.3, control the flow of CUI in accordance with approved authorizations. This is the load bearing one. If you cannot describe how CUI is prevented from flowing to the asset, you cannot claim it is not intended to receive CUI.
- SC.L2-3.13.1, monitor and control communications at external boundaries and key internal boundaries. Key internal boundaries is the operative phrase for a CRMA sitting inside your network.
- CM.L2-3.4.2, establish and enforce security configuration settings, plus CM.L2-3.4.6 least functionality, CM.L2-3.4.7 restriction of nonessential programs, ports, and services, and CM.L2-3.4.9 control of user installed software. These turn we told people not to into an enforced configuration.
- MP.L2-3.8.7, control the use of removable media, and AC.L2-3.1.21, limit the use of portable storage devices on external systems. Removable media is the most common way a CRMA quietly becomes a CUI asset.
- AC.L2-3.1.1 and AC.L2-3.1.2, limiting system access to authorized users and to permitted transactions and functions.
- AT.L2-3.2.1 and AT.L2-3.2.2, so the people using the asset understand that putting CUI on it is a violation, not an inconvenience.
If you write your CRMA justification and find yourself unable to point at a specific implemented control for each claim, you have found your answer. It is not a CRMA yet.
Should You Use the Category at All, and What About the November Talk?
Yes, use it, but use it deliberately and sparingly. CRMA exists for a genuine situation: shared infrastructure you cannot cleanly separate, managed under real controls, where separation would cost more than it returns. Used that way, it is a defensible engineering decision.
On timelines, be careful with what you are reading right now. Vendor content circulating this week states flatly that every company with a DoD contract needs certification by a specific month, and quotes assessment cost ranges as though they were established figures. The phased rollout beyond the initial phase is not settled, and we do not state certification deadlines as fact while Phase 2 remains suspended. What is settled is that your requirement level and your assessment obligations come from the clauses in your specific contracts, not from a blog headline.
The cost figures deserve the same skepticism. Published ranges vary enormously because the assessments behind them vary enormously, and the variable doing most of the work is scope. Every asset you legitimately keep out of the CUI asset category reduces assessment effort. Every asset you illegitimately keep out of it raises your risk of a mid assessment reclassification that costs far more than the enclave you avoided building. Do the scoping first. Everything else is downstream.
Not Sure Your CRMA Column Will Survive a Limited Check?
Book a free 30-minute call with Rick and get an honest read on which assets belong in each category before an assessor decides for you, with no sales pitch. We never touch your CUI.
Book a Free Call with RickFrequently Asked Questions
What is a Contractor Risk Managed Asset in CMMC?
A Contractor Risk Managed Asset is an asset that can, but is not intended to, process, store, or transmit CUI because of the security policy, procedures, and practices the contractor has in place. It applies at CMMC Level 2 and is one of five asset categories in the Level 2 assessment scope, alongside CUI assets, Security Protection Assets, Specialized Assets, and out of scope assets. CRMA are not required to be physically or logically separated from CUI assets.
Do Contractor Risk Managed Assets get assessed?
Not against the full set of Level 2 requirements the way CUI assets are. The assessor reviews your documentation to confirm the assets are managed under your risk based policies, procedures, and practices. However, if deficiencies surface, the assessor may perform a limited check, and if that check shows the asset actually handles CUI, it is reclassified as a CUI asset and assessed against all applicable Level 2 requirements.
What is the difference between a CRMA and an out of scope asset?
Capability. An out of scope asset cannot process, store, or transmit CUI, and you must be able to demonstrate that, which generally requires physical or logical separation. A CRMA is fully capable of handling CUI and is prevented from doing so by your controls and policy rather than by a boundary. If you cannot prove incapability, the asset is not out of scope.
What documentation is required for Contractor Risk Managed Assets?
Three things: the asset must appear in your asset inventory, it must be documented in your system security plan showing it is managed under your risk based security policies and procedures (CA.L2-3.12.4), and it must appear in the network diagram for your CMMC Assessment Scope. Omitting the network diagram is a common and avoidable finding.
Are Contractor Risk Managed Assets the same as Specialized Assets?
No. Specialized Assets are defined by asset type: government furnished equipment, IoT and IIoT, operational technology, restricted information systems, and test equipment. CRMA are defined by intent and enforcement, not by what kind of device it is. An ordinary laptop or file server can be a CRMA. It cannot be a Specialized Asset.
Does CRMA apply at CMMC Level 1?
No. The Level 1 scope model deals with FCI assets, Specialized Assets, and out of scope assets. There is no Contractor Risk Managed Asset category at Level 1, and Level 1 does not carry a system security plan requirement, so the documentation path described here is a Level 2 concern.
Sources
- CMMC Assessment Scope, Level 2, DoD CIO CMMC documentation library (dodcio.defense.gov)
- CMMC Program final rule, 32 CFR Part 170, including the Level 2 scoping provisions and the Conditional CMMC Status and POA&M closeout provisions (ecfr.gov)
- NIST SP 800-171 Revision 2, the security requirement set CMMC Level 2 is built on (csrc.nist.gov)
- CMMC Assessment Scope, Level 1, DoD CIO CMMC documentation library
