The four asset categories
- CUI Assets. Process, store, or transmit CUI. Fully in scope; all 110 controls apply.
- Security Protection Assets (SPAs). Provide security functions for CUI Assets — your SIEM, EDR, identity provider, vulnerability scanner. Fully in scope.
- Contractor Risk Managed Assets (CRMAs). Can access CUI but are not designed to. Documented and managed but not fully assessed.
- Out-of-Scope Assets. Physically or logically isolated from CUI. Not assessed — but you must prove the isolation.
The enclave strategy
Most defense contractors should not assess their whole company. They should carve out a CUI enclave — a defined set of systems, identities, and physical spaces where CUI is processed — and assess that. The rest of the business stays out of scope, with documented logical and physical boundaries between the two. The enclave is usually Microsoft GCC High or AWS GovCloud plus a small set of endpoints. The corporate network stays commercial. Done well, this reduces the in-scope user count by 80% or more, which collapses tooling, licensing, and assessment cost.
Common scoping mistakes that fail assessments
- Shared Active Directory. If your corporate AD federates with the enclave, both fall in scope. Either fully isolate the enclave AD or accept the broader boundary.
- BYOD email touching CUI. Personal phones that sync work email containing CUI pull the device into scope.
- Unmanaged SaaS. Any SaaS that processes CUI is in scope. Discover your shadow IT before the C3PAO does.
- "Out of scope by policy, not by control." Telling people not to put CUI somewhere does not put it out of scope. The C3PAO will ask how the control prevents it.
- Network shares with mixed CUI/non-CUI. If one folder contains CUI, the file server is in scope.
Documenting your boundary
The scope documentation a C3PAO expects: a system boundary diagram, the asset inventory mapped to the four categories, the data-flow diagram showing where CUI enters and exits the enclave, and the shared responsibility matrix that splits control ownership between you, your cloud provider, and any managed-service partners. All four become part of the SSP. Athena generates them from the live environment rather than from a Visio file that aged out two quarters ago.