GovCon Cybersecurity | | 26 min read
CMMC Scoping Guide for Contractors and Subcontractors
Key Takeaways
A defensible CMMC boundary follows data and protection
Four Level 2 categories remain in scope
CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets receive different documentation and assessment treatment.
SIEM and logging score 94
Security services lead the GS discovery model because they combine protective function, persistent records, administrative reach, and evidence dependency.
Test every claimed boundary
Export, local storage, clipboard, print, support, recovery, provider, and subcontractor scenarios reveal scope that a diagram can hide.
CMMC scope follows information and security function. It does not follow the company org chart or the tool list someone remembered during a meeting.
Most scope errors begin with a neat box. A team draws the enclave, lists the obvious laptops and servers, and calls everything else out of scope. Then the real workflow appears. FCI moves through email. CUI lands in a backup. A provider administers identity. A SIEM protects the enclave. A printer makes paper. A subcontractor receives a file. The box was never the boundary.
A defensible scope starts with the governing contract and the information needed for performance. It traces processing, storage, transmission, security functions, people, facilities, and provider duties. It applies the official asset categories. Then it tests the technical and operating paths that could prove the drawing wrong.
This CMMC scoping guide covers both contractors and subcontractors. It connects to the CMMC Compliance hub, the CMMC Level 1 requirements guide, the CMMC enclave architecture guide, the CUI data flow map guide, and GS Consulting services for secure AI automation.
Draw the boundary from the work.
GS Consulting helps contractors trace FCI and CUI, classify assets, map provider duties, test separation, and prepare a scope that matches the operating environment.
Plan the Scoping WorkshopCMMC Scoping Guide: The Short Answer
Build scope in this order:
- Read the solicitation, contract, subcontract, clauses, data terms, deliverables, and customer direction.
- Identify the FCI and CUI needed for performance. Record the source, owner, recipient, and approved use.
- Trace where the information is processed, stored, transmitted, printed, backed up, recovered, and shared.
- Add systems, people, facilities, and providers that supply security functions or administration.
- Apply the Level 1 scope rule or the five Level 2 asset categories.
- Document the inventory, system security plan treatment, network diagram, provider responsibilities, and subcontractor decisions required for the selected level.
- Test the boundary against export, local storage, clipboard, print, support, logging, backup, recovery, and lower tier scenarios.
- Put scope review into change control.
The sequence matters. Starting with a product list misses data paths. Starting with a network diagram misses paper and people. Starting with a provider contract misses customer configuration and local administration. Start with the award and information. Then build outward.
As of August 19, 2026, the official CMMC resources page says Phase II is suspended while Phase I self assessment requirements remain in place. Scope preparation still matters because current awards, self assessment duties, and supply chain decisions depend on the actual contract and information. Verify current Government direction for each acquisition.
Contract Terms and Information Create the First Boundary
The contract tells the organization what work it must perform and which clauses govern. The information register tells the organization what must move through the system to perform that work. Both are required. A clause list without data analysis is incomplete. A data map without the award cannot settle the required CMMC status or assessment type.
Collect the solicitation, award, task order, modifications, security classification guidance, CUI notices, data descriptions, statements of work, deliverable lists, attachments, prime instructions, and subcontracts. Identify the required CMMC level and assessment type. Then ask the program owner to name the information actually used during performance.
For each information set, record:
- The contract, task, clause, and source organization.
- Whether the information is public, simple transactional information, FCI, CUI, or unresolved.
- The owner and authorized users.
- The business action that needs the information.
- The systems and providers approved to process, store, or transmit it.
- The recipients, including lower tier suppliers.
- The marking, handling, retention, and destruction rules.
- The decision date, decision maker, and source evidence.
Do not ask the security team to invent the data category. Escalate unclear contract language or information status to the appropriate contracts, legal, Government, program, and information owner channels. Strong preparation is decisive. Legal conclusions still need authorized judgment.
Level 1 and Level 2 Use Different Scope Structures
Level 1: The DoD Level 1 Scoping Guide places contractor information systems that process, store, or transmit FCI in scope. Systems that do not are out of scope. A restricted virtual desktop client can remain out of scope when it permits no FCI processing, storage, or transmission beyond keyboard, video, and mouse interaction.
The Level 1 rule also provides limited treatment for specialized assets that cannot be fully secured. People, technology, facilities, and external service providers should be considered.
Level 2: The DoD Level 2 Scoping Guide assigns assets to five official categories. CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets are part of the Level 2 assessment scope. Out of Scope Assets are not. Each in scope category has its own documentation and assessment treatment.
Level 2 also makes Security Protection Data important. Configuration data, logs, vulnerability status, and credentials used to protect the assessed environment can matter even when the service does not store CUI. A SIEM that receives only security records may still be a Security Protection Asset because it supports CMMC requirements.
Do not transfer a Level 2 category label into Level 1 without checking the Level 1 rule. Do not use the simpler Level 1 asset split to scope Level 2. The information trigger, required status, and official category structure must stay aligned.
Original Research: The GS CMMC Scope Discovery Priority Index
Direct data systems are obvious. Security services are where scope analysis often breaks.
GS Consulting scored 12 common system paths across five factors. Information contact carries 30 percent. Persistence and copy potential and security function reach each carry 20 percent. Provider or administrative reach and evidence dependency each carry 15 percent. Each input receives a GS rating from one to five. The result is a zero to 100 discovery priority score.
SIEM and centralized logging score 94.0. A cloud application that handles contract data scores 92.0. Backup and archive services score 89.0. Shared email and collaboration score 85.0. These paths combine persistent records, broad reach, provider or administrator access, and evidence that other controls depend on.
The restricted virtual desktop client scores 23.0 under the stated assumptions because the modeled configuration permits only keyboard, video, and mouse interaction and offers little persistence or administrative reach. That low score depends on a real restriction. Enable local download, clipboard transfer, print, browser storage, file redirection, or support capture and the inputs change.
A sensitivity test moves five percentage points from information contact to persistence. Every score changes by no more than one point, and the leading three remain the same. The conclusion is stable: trace both information paths and security functions before drawing the boundary.
The model is a discovery tool, not an official scope algorithm. The official categories still control. The full source register, assumptions, ratings, formulas, sensitivity results, figure data, and caveats are preserved in the repository research workbook and companion CSV package.
Apply the Five Level 2 Asset Categories Precisely
CUI Assets
CUI Assets process, store, or transmit CUI. Document each asset in the inventory, describe treatment in the system security plan, include it in the network diagram, and prepare it for assessment against all Level 2 requirements. Processing includes access, entry, editing, generation, manipulation, and printing. Storage includes memory and paper. Transmission includes digital and physical movement.
Security Protection Assets
Security Protection Assets provide security functions or capabilities to the assessment scope. Document them in the inventory, system security plan, and network diagram. Assess them against the Level 2 requirements relevant to the capabilities they provide. Identity services, SIEM, endpoint security, vulnerability platforms, firewalls, virtual private network services, and security operations can fit this category depending on the actual role.
Contractor Risk Managed Assets
These assets can process, store, or transmit CUI but are not intended to because policies, procedures, and practices prevent that path. They do not have to be physically or logically separated from CUI Assets. They remain in scope.
Document each asset, its treatment, and its location in the scope diagram. If the system security plan is sufficient, the assessor generally reviews that treatment. Questions or weak documentation can lead to a limited check.
Specialized Assets
Specialized Assets can process, store, or transmit CUI but cannot be fully secured using ordinary treatment. The category can include certain Internet of Things devices, industrial systems, operational technology, Government furnished equipment, restricted systems, and test equipment. Keep them in the inventory, system security plan, and network diagram. Explain how risk based policies, procedures, and practices manage them. The assessor reviews that treatment.
Out of Scope Assets
An Out of Scope Asset cannot process, store, or transmit CUI, does not provide security protection for CUI Assets, and is physically or logically separated from CUI Assets. Any asset that fits an in scope category cannot be relabeled out of scope.
The Level 2 guide says there are no documentation requirements for Out of Scope Assets. The organization should still preserve enough decision evidence to justify the exclusion and test the separation.
External Service Providers Can Enter Scope Two Ways
A provider enters the analysis when it handles FCI or CUI, or when it supplies a security function to the assessed environment. Those are different paths and may create different assessment treatment. A cloud application may process CUI. A managed service provider may administer the system. A SIEM provider may process Security Protection Data. An identity provider may control access without storing contract content.
For each provider, document:
- The service and the information it receives, creates, stores, or transmits.
- The security capability it provides to the assessment scope.
- The provider platform, region, tenant, support model, and relevant authorization or assessment status.
- The company configuration and administration duties.
- The evidence the provider supplies and the evidence the company must create.
- Incident, access, change, recovery, retention, and termination duties.
- The owner, contract, review date, and unresolved dependency.
A provider attestation does not prove the customer configuration. A responsibility matrix does not prove the responsibility is performed. Trace each requirement to the provider duty, company duty, actual setting, current record, and test.
Cloud services that process covered defense information also require careful review under DFARS 252.204-7012 and related contract terms. This guide does not replace an authorized contract, legal, cloud, or CUI determination.
Subcontractor Scope Follows the Information Shared
32 CFR 170.23 sets the minimum subcontractor treatment. FCI only requires Level 1 under the stated rule. CUI requires at least Level 2 Self. When the associated prime contract requires Level 2 C3PAO, that is the minimum for a subcontractor that handles CUI.
When the prime contract requires Level 3, Level 2 C3PAO is the stated minimum for a subcontractor that handles CUI, subject to specific Government direction.
The prime should not begin with a generic demand that every supplier obtain the highest status. Begin with the work. What information does the lower tier truly need? Can the prime provide a restricted access path instead of transferring a copy? Can the deliverable be produced without FCI or CUI? Information minimization reduces scope and risk when it still permits performance.
If information must flow, record the subcontract clause, information category, approved transfer, required status and assessment type, CMMC unique identifier when applicable, CAGE codes, covered systems, lower tier rights, evidence exchange, incident notice, change notice, and verification date. DFARS 252.204-7021, when included, addresses current status and award conditions. Read the executed subcontract and current policy.
Use the CMMC small business and subcontractor guide for a broader supplier operating plan. Scope is the connection between the flow clause and the real lower tier system.
Enclaves and Virtual Desktops Reduce Scope Only When Paths Are Controlled
An enclave can concentrate contract information, security controls, provider duties, and evidence. It does not remove every shared dependency. Identity, logging, endpoint protection, remote administration, backup, support, and facilities can still enter the assessment scope through data handling or a security function.
A virtual desktop can support a narrower endpoint treatment when the client permits only keyboard, video, and mouse interaction. Test the actual configuration. Check local drive mapping, clipboard, print, screenshots, browser cache, file transfer, offline mode, session logs, support capture, crash dumps, tokens, and recovery. Document exceptions by user, device group, application, and support role.
Use the CMMC enclave architecture guide to compare design patterns. The architecture decision should follow user tasks and information paths. A clean drawing without a tested transfer model is not scope reduction.
Run the Scoping Workshop in Eight Decisions
Decision 1: governing requirement. Record the award, clause, required CMMC status, assessment type, CAGE codes, unique identifiers, program owner, and current implementation direction.
Decision 2: information set. Identify each FCI and CUI set, owner, source, recipient, use, marking, retention, and destruction requirement.
Decision 3: workflow. Trace entry, user action, processing, storage, transfer, print, backup, recovery, support, and exit. Include physical and digital paths.
Decision 4: protection. Add identity, network, endpoint, logging, vulnerability, monitoring, administration, incident, and recovery services that protect the environment.
Decision 5: asset category. Assign the official category and record the basis. Do not use a category as a desired future state. Classify the current system.
Decision 6: provider and lower tier duty. Map each external service and subcontractor to information handling, protection, contract, evidence, incident, and change responsibilities.
Decision 7: documentation. Reconcile the inventory, system security plan, network diagram, data flow, provider matrix, subcontractor record, and assessment boundary. Names and counts should agree.
Decision 8: boundary proof. Run scenarios that could move information or security function outside the proposed boundary. Fix or reclassify the result.
Who needs to be in the room
Include contracts, the program owner, information owner, security, information technology, system owners, cloud and provider owners, facilities, procurement, and a representative user. Add legal or Government clarification channels where the contract or information decision requires them.
Boundary Tests Find What Diagrams Miss
Test at least these scenarios before accepting an out of scope claim:
- Email: send, forward, reply, attachment preview, mobile access, retention, and archive.
- Endpoint: download, save as, clipboard, print, screenshot, temporary files, browser cache, and offline use.
- Identity: authentication, federation, privileged access, emergency access, termination, and recovery.
- Logging: event content, user names, file names, configuration, vulnerability data, retention, and provider access.
- Backup: protected content, keys, snapshots, replication, restore, support, and media disposal.
- Provider support: remote session, diagnostic bundle, ticket attachment, screen capture, memory dump, and administrator action.
- Physical handling: print, visitor, cleaning, storage, transport, reuse, and destruction.
- Subcontractor: portal, email, local copy, further sharing, return, retention, incident, and change notice.
Record the test setup, expected result, actual result, evidence, exception, owner, correction, and retest. If the result contradicts the category, change the control or change the scope. Do not change the test record.
Review scope whenever a contract, information type, provider, application, integration, identity path, facility, user group, backup, support model, or subcontractor changes. Put those events into normal change control. Scope drift is an operating problem, not an annual paperwork problem.
Minimum CMMC Scoping Evidence Packet
Keep eight controlled records: the contract requirement map, information register, data flow map, asset inventory, network diagram, provider responsibility map, subcontractor decision record, and boundary test record. Level 2 also requires the relevant system security plan treatment. Link the records so an asset name, category, system owner, provider, and boundary location remain consistent across every view.
Do not turn the packet into a static binder. Give each record an owner, source system, approval, review date, and change trigger. Preserve prior versions so the organization can explain why the boundary changed.
Sources, Method, and Caveats
The research package uses primary public sources: the DoD Level 1 and Level 2 Scoping Guides, 32 CFR Part 170, FAR 52.204-21, DFARS 252.204-7012, DFARS 252.204-7021, and the current CMMC resources page. Public observations and GS assumptions are separated in the workbook.
The GS CMMC Scope Discovery Priority Index is a derived planning tool. It does not assign an official asset category, decide contract applicability, replace an authorized legal or CUI determination, predict an assessment result, or establish compliance. The actual award, information, service, configuration, data flow, and current Government direction control.
Frequently Asked Questions About CMMC Scoping
What is included in CMMC scope?
Level 1 includes systems that process, store, or transmit FCI. Level 2 includes CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets, with different treatment. Out of Scope Assets must not handle CUI or protect CUI Assets and must be separated.
What documents are required for Level 2 scope?
The official guide calls for an inventory of in scope asset categories, treatment in the system security plan, and a network diagram. Add the data flow, provider responsibilities, subcontractor decisions, and test records needed to support those documents.
Are security tools in scope if they do not store CUI?
They can be. A tool that supplies a security capability can be a Security Protection Asset and face the Level 2 requirements relevant to that capability.
Can virtual desktop keep an endpoint out of scope?
A restricted client can support that decision when only keyboard, video, and mouse interaction is possible. Test local storage, clipboard, print, file transfer, browser, support, and recovery behavior before relying on the exclusion.
How does CMMC flow to subcontractors?
The minimum status follows the information and prime contract context. FCI only drives Level 1. CUI drives at least the applicable Level 2 status. Read the actual subcontract and current implementation direction.
How often should scope be reviewed?
Review it before the assessment and whenever contracts, data, tools, providers, integrations, locations, people, backup, support, or subcontractors change. Put those triggers into normal change control.
Keep the Boundary Honest
A narrow scope can reduce burden. An imaginary scope increases it. Start with the contract. Follow the information. Add the protection services. Apply the official categories. Test every claimed separation. Reopen the decision when the system changes.
The operating standard is direct: if the data or security function crosses the line, the scope decision must cross with it.
Build a scope that survives technical review.
GS Consulting can facilitate the workshop, reconcile the inventory and diagrams, classify provider dependencies, and test the boundary before assessment.
Discuss CMMC Scope