Free lead magnet · 7 minutes

    CUI Scope & Contract-Risk Check

    Answer 7 questions. Get your likely CMMC path, readiness band, SPRS estimate, top contract risks, and the next deliverable to buy.

    See the full deliverable ladder →

    Tell us about your environment

    No account needed. We compute the result locally in your browser.

    Categorize every asset — the step that decides your scope

    The wizard above gives you your likely CMMC path. This inventory turns that into a defensible boundary: five asset categories from the CMMC Level 2 Scoping Guide, what each one means for an assessment, and your reasoning for why an asset sits inside or outside the boundary. Nothing is uploaded and no CUI is collected.

    Asset inventory by scoping category

    Scope decides everything downstream: what gets assessed, how many objectives you must evidence, and how large your SSP is. Categorize every asset once, in general terms. Do not upload documents or enter CUI here — describe asset groups, not systems.

    0 of 5 categories described
    CUI assets

    Assets that process, store, or transmit CUI.

    In an assessment: Assessed against all applicable Level 2 requirements.

    Document: Document in the asset inventory, SSP, and network diagram.

    Security protection assets

    Assets that provide security functions or capabilities to the CUI environment, even if they never touch CUI themselves.

    In an assessment: Assessed against the requirements relevant to the security capability they provide.

    Document: Document in the asset inventory, SSP, and network diagram.

    Contractor risk managed assets

    Assets that can, but are not intended to, process/store/transmit CUI because they are managed with your risk-based policies and practices.

    In an assessment: Not assessed against Level 2 requirements, but the assessor may review your risk-based documentation and may spot-check if the documentation is insufficient.

    Document: Document in the asset inventory, SSP, network diagram, and your risk-based policies.

    Specialized assets

    Government property, IoT/IIoT, operational technology, restricted information systems, and test equipment.

    In an assessment: Not assessed against Level 2 requirements; must be documented and managed using your risk-based approach.

    Document: Document in the asset inventory, SSP, and network diagram.

    Out-of-scope assets

    Assets that cannot process, store, or transmit CUI and are physically or logically separated from the CUI environment.

    In an assessment: Not part of the assessment scope.

    Document: Show the separation. If separation cannot be demonstrated, the asset is in scope.

    Sanitized example

    Fictional contractor "Northgate Precision LLC". No real system names, hostnames, IPs, or findings — deliberately generic so it is safe to share.

    Northgate Precision records 24 CUI assets (engineering laptops and one file share), 4 security protection assets (identity provider, endpoint manager, log collector, VPN), 30 contractor risk managed assets (front-office laptops with the same baseline but no CUI routing), 3 specialized assets (two CNC controllers and one government-furnished test rig), and 60 out-of-scope assets on a separate VLAN with deny-all rules. Their boundary reasoning for out-of-scope: "distinct VLAN, no shared credentials, no route to the CUI file share, verified in the firewall rule export."

    One path forward

    Free result → $129 CMMC Survival Report → Athena workspace

    1. Free, right now: keep the result and downloads from this tool. No account, no e-mail required.
    2. $129 CMMC Survival Report: an objective-level readiness snapshot with your weakest practices, prioritized remediation order, and an assessor-facing narrative.
    3. Athena workspace / evidence sprint: continuous objective-level tracking, evidence defensibility scoring, and assessor-ready artifacts.

    Athena works at the assessment-objective level, keeps a provenance trail for every artifact, and scores how defensible your evidence is. We do not guarantee a certification outcome — no tool or consultant can.

    The other free CMMC tools

    Score all 110 requirements with official weighted deductions.
    Met / Not Met / N/A across 110 requirements with a gap report.
    Every NIST SP 800-171A Rev. 2 objective with evidence planning.
    Build a DoD-oriented POA&M with eligibility warnings.
    Day-one evidence list, mock intake, and readiness verdict.

    Educational readiness aid. This is not legal advice, not an official assessment, not a certification, and not a submitted SPRS score. Your assessment results and any affirmation remain your organization's responsibility.