Summary
Scoping sets the foundation for CMMC by defining which assets fall inside your compliance boundary. Classify assets accurately, minimize CUI exposure, document all decisions, and use segmentation to avoid risky CRMAs. Apply appropriate controls, justify classifications, and maintain clear evidence. Strong documentation makes assessments smoother and reduces cost and complexity.
Scoping is an early step, but it’s far from an easy one. Not only is scoping high stakes in determining compliance method and cost, but it is also complex in touching every corner of your environment: people, processes, machines, cloud tools, legacy systems, and more. Here’s what every organization should understand before jumping into scoping.
Start with Asset Types
When you look at your environment, you’ll see all kinds of assets: Enterprise Resource Planning (ERP) systems, laptops, Computer Numerical Control (CNC) machines, mobile devices, firewalls, Software as a Service (SaaS) tools, and the list goes on. The challenge is putting everything into the right category so you can keep your boundary tight and avoid unnecessary cost or complexity.
Let’s break the challenge down by asset type.
CUI Assets
This is where everyone starts, and for good reason. These are assets that store, process, or transmit Controlled Unclassified Information (CUI). Laptops often fall here, but what surprises most people is that people, and the tech that they use indirectly, count too.
The harder part is figuring out what CUI actually is.
Here’s a common question: “If the document feels sensitive, isn’t it automatically CUI?”
Not necessarily. Ideally, a law, regulation, or government-wide policy should justify CUI markings. Even so, many subcontractors and primes mark items as CUI simply because someone told them to. When in doubt, it’s always best to revisit your contract or ask the contracting officer directly.
Once a CUI asset is identified, the rules are clear:
- Apply all 110 controls
- Document everything in the System Security Plan (SSP)
- Include it in the network diagram
- Ensure any cloud system handling CUI is Federal Risk and Authorization Management Program (FedRAMP) Moderate or equivalent
The smaller the CUI boundary, the easier life becomes.
Security Protection Assets
Security Protection Assets are the ones that actually secure your environment. They encompass firewalls, endpoint protection, identity providers, monitoring tools, and so on.
Document them, include them in the SSP and network diagram, and then apply relevant controls, not all 110.
Overhardening security tools can break your environment, so focus on what is truly applicable, then collect evidence: screenshots, logs, policies, procedures. Clear documentation like this is what makes assessments go smoother.
Contractor Risk Managed Assets
Contractor Risk Managed Assets (CRMAs) are a bit of a problem child. CRMAs are assets located inside the same environment as CUI systems but are not intended to store, process, or transmit CUI. Because they sit alongside CUI, CRMAs carry significant assessment risk.
For example, a receptionist’s workstation on the same flat network as engineering can be classified as CRMA. In practice, CRMAs should be used sparingly.
Why to Avoid CRMAs
If you classify an asset as a CRMA, you must prove beyond doubt that CUI cannot end up on that device. During an assessment, an assessor can spot-check any CRMA; if they challenge it and you can’t justify it, you may be forced to reclassify the asset on the spot, which risks failing the assessment.
CRMAs also disappear completely at Level 3, and Revision 3 tightens rules even more, so I generally encourage organizations to avoid CRMA when possible.
How to Avoid CRMAs
Avoid CRMAs whenever possible. Use network segmentation and boundary design so assets fall cleanly into either CUI Assets or Out‑of‑Scope Assets. CRMAs should only exist when a device is physically or logically near CUI, but strong controls prevent CUI interaction.
When using CRMAs is unavoidable, treat them like CUI Assets from a controls standpoint and be prepared to defend their classification.
Specialized Assets
These are the manufacturing machines, research equipment, and legacy systems you simply cannot modernize to meet Cybersecurity Maturity Model Certification (CMMC) technical controls. And honestly, this category feels like a lifeline for many environments.
You still need documented policies, physical protections, logical access controls, and clear inventory tracking, but you’re not expected to apply all 110 controls to a Microsoft Disk Operating System (MS-DOS)-era machine.
I love that this category exists because upgrading some manufacturing lines would cost millions. It’s practical and realistic.
Out-of-Scope Assets and VDI
Out-of-scope is exactly what it sounds like: the asset is not part of the boundary and requires no CMMC controls, no documentation, and/or no assessment.
One special case is physical devices used only as a gateway into a tightly controlled Virtual Desktop Infrastructure (VDI) environment, where all redirection features – printers, USBs, screenshots, file transfers – are disabled.
The local device can be out of scope, but I still build out strong acceptable use and remote work policies. People always introduce risk, even when the endpoints aren’t technically in scope.
Assessors can question anything in your documentation, so clarity and justification matter here, too.
Final Thoughts
After walking through all of this, the biggest takeaway is simple: document everything. Assessors rely heavily on evidence, diagrams, inventories, and justifications from your documentation.
If you still have questions about compliance, reach out a Summit 7 expert.


