Scoping a CMMC Level 2 assessment

Editor's note, 2026-07-14: The Department of War suspended CMMC Phase 2 on 2026-07-13, pending a 60-day review. During the suspension Level 2 is self-assessed, and select government-led assessments still apply. The program is suspended, not cancelled. The scoping in this post still governs: the CUI boundary decides what a Level 2 self-assessment covers, and the 110 NIST 800-171 practices are unchanged. Source: DoW memo 26-P-1023.

The first decision in a CMMC Level 2 effort is where the boundary sits. Scope decides which systems hold controlled unclassified information, which systems touch it, and which systems can be kept out of assessment entirely. Draw it too wide and you pay to secure systems that never see CUI. Draw it too narrow and you fail an assessment against the 110 NIST 800-171 practices when an assessor finds CUI outside the line you drew.

Good scoping starts from the data, not the org chart. You follow where CUI enters, where it is processed, where it is stored, and where it leaves, and you draw the boundary around that flow.

The asset categories that set your scope

The scoping guidance for a Level 2 assessment sorts every asset into a category, and the category decides how much of the practice set applies. You do not assign categories by preference. The data flow decides, and the assessor checks your categories against how CUI moves.

CUI assets process, store, or transmit CUI. A workstation where someone opens a controlled document, a file share that holds one, an application that sends one to a partner: each is in scope in full, and the practices apply to it directly. This is the category to keep small, because every asset in it carries the whole weight of the assessment.

Security protection assets provide a security function to the CUI assets even when they never hold CUI themselves. A logging pipeline, an identity provider, a vulnerability scanner, a firewall management console: none of these handle CUI, but the protection they provide is part of how you meet the practices. They are in scope, and the assessor examines them for the security capability they contribute rather than for data they do not hold.

Out-of-scope assets neither handle CUI nor protect the assets that do, and they are separated from the CUI environment. A guest network, a public marketing site, a developer laptop that only touches open-source code: these can sit outside the boundary. The category is not free. You have to show the separation. An asset is only out of scope if you can demonstrate that it cannot reach the CUI assets, and that demonstration is itself an assessment artifact.

Between these sit two more categories the guidance names. Contractor risk managed assets can access CUI but are not intended to, and you handle them through policy and your risk process rather than the full practice set. Specialized assets, such as some operational technology and connected devices, are in scope but assessed against your documented risk approach. For a first boundary, the three primary categories usually carry the work. The intermediate ones start to matter once the environment holds equipment that resists a clean in-or-out call.

Separation that holds up under assessment

The word that carries the weight in scoping is separation. Calling an asset out of scope is a claim, and the assessor tests the claim. Weak separation is the most common reason a boundary that looked clean on paper falls apart in the assessment room.

Separation that holds up is enforced, not asserted. A handful of techniques carry real weight:

  • Network segmentation with enforced controls. A VLAN on its own is an organizing convenience, not a boundary. What the assessor wants to see is a firewall or access control list that denies traffic between the CUI enclave and everything else by default, with the allowed paths written down and justified.
  • Identity separation. If one directory, one set of accounts, and one group of administrators span the CUI systems and the out-of-scope systems, an assessor can argue the two are a single environment. Distinct administrative accounts and a scoped identity plane keep the line real.
  • Physical and logical isolation for the assets that warrant it. A locked room, a dedicated device, or a virtual desktop that keeps CUI off the endpoint each shrink the in-scope set, because the data never lands where you would otherwise have to defend it.
  • Data flow controls that stop CUI from spreading. Blocking removable media, restricting where a controlled document can be saved, and preventing forwarding to an out-of-scope mailbox all keep the in-scope set from quietly growing after you drew the line.

Whatever technique you choose, document it and be ready to show it working. A diagram states the intent. A firewall rule set, a directory export, and a configuration screen show that the intent is enforced. Assessors trust what they can observe over what they are told, so the artifact that proves separation is worth as much as the separation itself.

From boundary to enclave

The boundary is not the end of scoping. It is the input to the design. Once you know which assets hold CUI and which security protection assets serve them, you know the shape of the enclave you have to build and defend.

A well-drawn boundary produces an enclave you can reason about. The CUI assets sit inside it. The security protection assets either sit inside or connect through a controlled, documented path. Everything else stays out, held there by the separation you can demonstrate. Each of the 110 practices then has a clear place to land, because you know exactly which systems it governs and which it does not.

This is why the effort you spend on the boundary pays back across the whole engagement. A tight enclave means fewer systems inheriting the full practice set, fewer configurations to keep current, and fewer places for evidence to drift between assessments. A sprawling boundary means the opposite. Every extra in-scope system is another set of controls to implement, monitor, and prove, year after year.

A boundary holds up when each asset's category matches how CUI moves through your systems, and when the separation is enforced by controls an assessor can watch work. Get that right and the same boundary carries you through the assessment and the ones after it.

Scoping a CMMC Level 2 assessment · TRGR