
How to Scope Your CMMC Assessment: A Defense Contractor’s Guide to CUI Boundaries and Enclaves
Introduction
If you’re a Defense Industrial Base contractor working toward CMMC Level 2 certification, there’s a question that will shape every decision you make — and every dollar you spend — long before an assessor ever walks through your door: What’s actually in scope?
Get the answer right, and you’re looking at a manageable, cost-effective path to certification. Get it wrong, and you’ll spend months remediating systems that never needed to be in scope to begin with — or worse, you’ll miss assets that should have been included and face a failed assessment.
Scoping your CMMC assessment isn’t a paperwork formality. It’s a strategic discipline. This guide breaks down the core concepts — CUI boundaries, asset categories, and the enclave strategy — in plain English, so your team can walk into your assessment with confidence.
What “Scope” Actually Means in a CMMC Assessment
In CMMC terms, your assessment scope is the complete set of assets in your environment that will be evaluated against CMMC security requirements. That includes the systems, people, and processes that touch Controlled Unclassified Information (CUI) — directly or indirectly.
The formal definition under 32 CFR § 170.19 breaks assets into four categories:
CUI Assets are the core of your scope. These are any systems that process, store, or transmit CUI. Every asset in this category must be fully documented in your System Security Plan (SSP) and assessed against all applicable CMMC Level 2 security requirements.
Security Protection Assets (SPAs) are systems that don’t handle CUI directly but provide security functions that protect the environment — your SIEM, your endpoint detection platform, your log management infrastructure. These are absolutely in scope, even if CUI never touches them.
Contractor Risk Managed Assets (CRMAs) are systems that can access CUI environments but aren’t intended to process or store it. Think of a general-purpose laptop on the same network as a CUI workstation. CRMAs don’t need to meet all Level 2 requirements but must be documented and managed under a risk-based policy.
Specialized Assets — IoT devices, operational technology (OT), government-furnished equipment (GFE) — are handled differently. They’re documented and reviewed, but the assessment methodology accounts for their unique limitations.
Understanding these distinctions isn’t academic. It’s the foundation for making smart architecture and investment decisions before your C3PAO ever submits their assessment report.
The CUI Boundary: Your Most Important Line in the Sand
Before you can build or document a scope, you need to know where CUI lives. This is harder than it sounds.
CUI has a way of spreading through an organization organically — in email attachments, shared drives, collaboration tools, and project management platforms. Most contractors discover during scoping that CUI has drifted far beyond where they thought it was contained. That sprawl is costly, because every system where CUI lives becomes a CUI Asset subject to full CMMC requirements.
The first step is a CUI data flow analysis. Walk every path that CUI takes through your organization: where it enters, where it’s stored, who accesses it, where it goes when it’s shared with teammates or subcontractors. Document it in your SSP with enough specificity that an assessor can follow the same trail.
A few practical rules of thumb:
- Encrypted CUI is still CUI. Encryption reduces risk, but it does not remove CUI from scope.
- If a cloud service stores, processes, or transmits CUI, it must meet FedRAMP Moderate baseline requirements (per DFARS clause 252.204-7012). Platforms like Azure Government (GCC/GCC-High) and AWS GovCloud are purpose-built to meet this requirement — general-purpose commercial cloud platforms are not.
- External Service Providers (ESPs) — including managed service partners — that handle CUI or Security Protection Data are part of your scope and need to be documented accordingly.
The narrower and more intentional your CUI boundary, the smaller your assessment scope — and the lower your compliance overhead.

Using Enclaves to Shrink Your Scope (Without Shrinking Your Business)
One of the most powerful — and underutilized — strategies in CMMC scoping is the enclave approach. An enclave is a logically or physically segmented environment specifically designed to contain CUI and the systems that support it. It sits within your broader enterprise network but is treated as a distinct CMMC Assessment Scope.
The logic is straightforward: instead of bringing your entire IT environment into scope — every device, every user, every server — you architect a tightly controlled environment where CUI lives, then keep everything else out of it.
Done correctly, an enclave strategy can dramatically reduce the number of assets in your assessment scope, shrink the cost and duration of your C3PAO assessment, and give your security team a defensible, auditable boundary to manage over time.
Cloud platforms are particularly well-suited for this approach. Azure Government (GCC-High) and AWS GovCloud are FedRAMP-authorized environments purpose-built for handling CUI at the federal and DoD level. When you stand up a CUI enclave in one of these platforms, you inherit a significant portion of the underlying infrastructure controls — reducing what you need to independently implement and demonstrate.
A few important considerations when designing an enclave:
- Logical separation alone isn’t always sufficient. Your assessor will evaluate whether the separation is meaningful and effective. Encryption can help manage transmission risk, but it doesn’t automatically move a networking component out of scope if that component provides essential connectivity for your CUI environment.
- Enterprise IT functions that support the enclave — centralized patch management, identity systems, authentication infrastructure — may be pulled into scope even if they live outside the enclave boundary. Document the inheritance and responsibilities clearly in your SSP.
- The enclave approach works at both Level 2 and Level 3. For Level 3 (DCMA DIBCAC), your enclave must be a subset of the Level 2 scope, and all Level 2 POA&M items must be closed before the Level 3 assessment begins.
Managed Services providers with enclave design experience can significantly accelerate this process — both in standing up the environment and in maintaining the ongoing compliance posture it requires.
Documenting Your Scope: What the Assessor Actually Needs
The CMMC assessment scope isn’t a verbal description — it’s a documented artifact that your C3PAO or DCMA DIBCAC assessor will use as the foundation for their work. Your documentation package needs to hold up under scrutiny.
At minimum, your scoping documentation should include:
A comprehensive asset inventory that lists every in-scope asset by category (CUI Asset, SPA, CRMA, Specialized Asset), with each asset’s role, data handling classification, and treatment documented in the SSP.
A network boundary diagram that visually represents the CMMC Assessment Scope, shows how CUI flows between assets, and clearly delineates what is inside and outside the boundary. Assessors use this diagram to verify that the scope matches the technical reality of your environment.
An SSP that reflects the current state — not the ideal state. The SSP is a living document, and it must accurately describe how each of the 110 NIST SP 800-171 controls is implemented, inherited, or addressed via a Plan of Action and Milestones (POA&M). Gaps are expected; misrepresentation is not.
ESP documentation for every third-party provider that handles CUI or Security Protection Data on your behalf. This includes reviewing their customer responsibility matrices (CRMs), understanding which controls they own versus which you own, and documenting that relationship in your SSP.
For Defense Industrial Base contractors managing complex environments, a qualified Managed Services partner with CMMC experience can be invaluable in building and maintaining this documentation stack — not just for the initial assessment, but for the annual affirmations and triennial recertification cycles that follow.
Conclusion
Scoping is the phase of CMMC preparation that pays the biggest dividends — and causes the most avoidable problems when it’s rushed. A well-defined CUI boundary, a deliberate enclave architecture, and documentation that accurately reflects your environment set the conditions for a clean assessment and a sustainable compliance posture.
The contractors who navigate CMMC most effectively aren’t necessarily the ones with the largest security budgets. They’re the ones who did the foundational scoping work right — and partnered with people who know this terrain.
Ready to Define Your CMMC Assessment Scope?
VSO is a CMMC Level 2 certified, veteran-led Managed Services provider specializing in DIB compliance, secure enclave design, and cloud environments including Azure Government and AWS GovCloud. Our team has the technical depth and compliance expertise to help you define your scope, build your SSP, and prepare for your C3PAO assessment — without overcomplicating the process.
Call us: (888) 805-0510 Email: sales@vso-inc.com Learn more: vso-inc.com
Frequently Asked Questions
How do I know if my company needs a CMMC Level 2 certification assessment or a self-assessment?
If your contracts require you to handle Controlled Unclassified Information (CUI), you will generally need a Level 2 certification assessment conducted by a third-party C3PAO. If your contracts only involve Federal Contract Information (FCI) and not CUI, a Level 1 self-assessment is sufficient. When in doubt, review your contract language for references to DFARS clause 252.204-7012 and consult with a CMMC advisor.
Can we limit our CMMC scope to just one part of the company?
Yes — and this is exactly the intent behind the enclave strategy. You are not required to bring your entire enterprise IT environment into scope. If you can logically or physically isolate the systems that handle CUI into a defined enclave, only that enclave (and the security infrastructure that supports it) needs to be in scope for assessment. Your C3PAO will evaluate whether the separation is technically sufficient.
Does using a cloud provider like Azure Government or AWS GovCloud automatically satisfy CMMC requirements?
Not automatically, but it helps significantly. FedRAMP-authorized cloud platforms like Azure Government (GCC-High) and AWS GovCloud allow you to inherit a substantial number of underlying infrastructure controls, reducing your independent implementation burden. However, the 110 NIST SP 800-171 requirements still apply to your environment — including the 24 enhanced requirements at Level 3 — and you must demonstrate compliance for everything your CSP doesn’t directly cover.
What happens if our Managed Services provider handles CUI on our behalf?
Your MSP would be classified as an External Service Provider (ESP) and may be in scope for your assessment. You need to document the relationship in your SSP, review the provider’s customer responsibility matrix (CRM), and confirm they meet applicable security requirements. If your MSP stores, processes, or transmits CUI on a cloud platform, that platform must meet FedRAMP Moderate requirements.
How often do we need to re-assess, and does our scope change at renewal?
CMMC Level 2 certification assessments are required every three years, with annual affirmations of continued compliance in the interim. If you make significant architectural changes to your environment — such as expanding your network boundary, adding new cloud environments, or undergoing a merger or acquisition — a new assessment may be required before the three-year mark. Routine operational changes within the existing scope do not trigger a new assessment.
What is a POA&M, and can we still pass our assessment if we have open items?
A Plan of Action and Milestones (POA&M) documents security requirements that are not yet fully met, along with your plan and timeline for remediation. For Level 2 certification assessments, a limited number of POA&M items are permitted — resulting in a Conditional CMMC Status rather than Final status. However, high-weighted requirements cannot remain open, and all POA&M items must be closed within 180 days to achieve Final status. For Level 3, all Level 2 POA&Ms must be closed before the DCMA DIBCAC assessment can begin.





