CUI Scoping

    CUI Scoping for CMMC: How to Draw a Defensible Boundary

    CUI scoping for CMMC is the decision that drives every other cost on your program. Get the boundary wrong and the whole company falls into scope; get it right and you assess an enclave a fraction the size. This guide covers the four asset categories under 32 CFR Part 170, the enclave strategy most contractors should use, common mistakes that fail assessments, and how to document a boundary a C3PAO will accept.

    The four asset categories

    • CUI Assets. Process, store, or transmit CUI. Fully in scope; all 110 controls apply.
    • Security Protection Assets (SPAs). Provide security functions for CUI Assets — your SIEM, EDR, identity provider, vulnerability scanner. Fully in scope.
    • Contractor Risk Managed Assets (CRMAs). Can access CUI but are not designed to. Documented and managed but not fully assessed.
    • Out-of-Scope Assets. Physically or logically isolated from CUI. Not assessed — but you must prove the isolation.

    The enclave strategy

    Most defense contractors should not assess their whole company. They should carve out a CUI enclave — a defined set of systems, identities, and physical spaces where CUI is processed — and assess that. The rest of the business stays out of scope, with documented logical and physical boundaries between the two. The enclave is usually Microsoft GCC High or AWS GovCloud plus a small set of endpoints. The corporate network stays commercial. Done well, this reduces the in-scope user count by 80% or more, which collapses tooling, licensing, and assessment cost.

    Common scoping mistakes that fail assessments

    • Shared Active Directory. If your corporate AD federates with the enclave, both fall in scope. Either fully isolate the enclave AD or accept the broader boundary.
    • BYOD email touching CUI. Personal phones that sync work email containing CUI pull the device into scope.
    • Unmanaged SaaS. Any SaaS that processes CUI is in scope. Discover your shadow IT before the C3PAO does.
    • "Out of scope by policy, not by control." Telling people not to put CUI somewhere does not put it out of scope. The C3PAO will ask how the control prevents it.
    • Network shares with mixed CUI/non-CUI. If one folder contains CUI, the file server is in scope.

    Documenting your boundary

    The scope documentation a C3PAO expects: a system boundary diagram, the asset inventory mapped to the four categories, the data-flow diagram showing where CUI enters and exits the enclave, and the shared responsibility matrix that splits control ownership between you, your cloud provider, and any managed-service partners. All four become part of the SSP. Athena generates them from the live environment rather than from a Visio file that aged out two quarters ago.

    Frequently asked questions

    Does my whole company need CMMC?

    Almost never. Most defense contractors scope to a CUI enclave — typically a GCC High tenant plus a small set of managed endpoints — and put the rest of the business out of scope. The enclave strategy is the single biggest cost lever in a CMMC program.

    What is a Security Protection Asset?

    Any asset that provides security functions for CUI Assets — SIEM, EDR, identity provider, vulnerability scanner, MFA system, log aggregator. SPAs are fully in scope for CMMC even though they do not process CUI themselves, because they protect what does.

    Can I scope out my corporate network?

    Yes, if you can prove logical and physical isolation between the corporate network and the CUI enclave. That means separate identity, separate network, separate endpoints, no federation, and no shared file systems. Documented and demonstrated, not just asserted.

    Does GCC High automatically shrink my scope?

    GCC High provides a FedRAMP-equivalent baseline for the cloud portion of your environment. It does not shrink scope by itself — you still need to define the boundary, document the SRM, and prove that CUI never leaves the enclave. GCC High is an enabler, not a solution.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.