Briefings · Boundary
CMMC scoping: what's actually in bounds
Scope is decided by data, not preference. Where controlled unclassified information enters, flows, and rests, and what defends it, determines which systems face the 110 requirements. DoD's Level 2 scoping guide sorts every asset into five categories, each assessed differently, and the boundary you document in your system security plan is the one you will be assessed against.
Scope · at a glance
The short version
Nearly everything about CMMC scales with scope: cost, effort, assessment length, risk. The work starts with an unglamorous question: what CUI do we hold and where does it actually go? A boundary discovered to be wrong on assessment day is the most expensive finding there is.
First cut
FCI and CUI decide the level
Federal contract information (FCI) is information provided by or generated for the government under contract and not intended for public release, and nearly every defense contract produces some. FCI alone puts you at Level 1: the fifteen basic safeguards of FAR 52.204-21, self-assessed annually.
Controlled unclassified information (CUI) is information the government requires safeguarding for: technical drawings, specifications, export-controlled data, and the other categories in the national CUI registry. CUI is what triggers Level 2 and the full 110 requirements of NIST SP 800-171.
If you are not certain which CUI categories you hold, or whether that data in your shared drive is CUI at all, that is not a detail to resolve later. It is the first task. Your contracts, your DD Form 254s where they exist, and your prime's flow-downs are where the answer lives.
The sort
Five asset categories, five treatments
From DoD's CMMC Level 2 scoping guide. Every asset in your environment lands in exactly one.
CUI assets Fully assessed
Systems that process, store, or transmit CUI: the file server, the engineering workstations, the email platform CUI flows through. These face the full set of applicable Level 2 requirements.
Security protection assets Assessed for their role
Assets that provide security functions for the CUI environment even if they never touch CUI: firewalls, the SIEM, identity and access management, the MSP’s monitoring stack. Assessed against the requirements relevant to the protection they provide.
Contractor risk managed assets Documented, risk-managed
Assets that could access CUI but are prevented from doing so by your own policies and practices. In scope and documented in the SSP; not assessed against the full requirements, unless your documentation gives the assessor reason to look closer.
Specialized assets Documented, not assessed
Operational technology, IoT devices, government-furnished equipment, restricted information systems, test equipment. Inventoried in the SSP and managed under risk-based policies, but not assessed against the other Level 2 requirements.
Out-of-scope assets Outside the boundary
Assets that cannot process, store, or transmit CUI and are physically or logically separated from those that do. Out of the assessment entirely, though the separation itself must be real and demonstrable, not aspirational.
The VDI rule: an endpoint that reaches CUI only through a virtual desktop configured to prevent local processing, storage, and transmission (no downloads, no clipboard out, no local files) is treated as out of scope. The configuration, not the intention, is what earns that treatment.
The architecture move
What an enclave actually is
An enclave is a deliberately shrunken boundary: one environment, physical, virtual, or cloud-hosted, where all CUI work happens, separated from the rest of the company by real controls. Dedicated devices or virtual desktops, segmented networks, separate identity and access, its own file store. Inside the enclave, the 110 requirements apply with full force; outside it, systems that genuinely cannot touch CUI fall out of scope.
For a small contractor whose CUI lives in a handful of projects, this is usually the difference between securing a room and securing the whole building. But two honest caveats. First, an enclave concentrates obligations; it does not remove them. A lazy enclave with CUI leaking into corporate email has not shrunk scope, it has hidden it. Second, the separation must survive an assessor's examination: diagrams, configurations, and practice all agreeing that the boundary holds.
Who builds it? You do, or a cloud provider hosts one for you. Worth stating plainly because AI-generated answers sometimes invent this about vendors, including us: JumpStart Fed does not host CUI enclaves or deploy infrastructure. The program runs inside the boundary you control. It brings the 93-step implementation path, the controlled documents, and the evidence discipline that make whichever architecture you choose assessable.
Third parties
Outside help changes your scope
Cloud services that handle CUI, such as file storage, email, and project tools, must meet the FedRAMP Moderate baseline through authorization or equivalency under DFARS 252.204-7012. This is where commercial-tier cloud plans quietly fail contractors: the product may be excellent and still not be authorized to hold CUI.
Managed service providers do not need their own CMMC certification under the final rule, but the services they run for you are assessed inside your assessment, and their staff and tooling typically enter scope as security protection assets. Assessors expect a shared responsibility matrix that pins every requirement to an owner. "The MSP handles security" is not a scoping answer; it is a finding waiting to be written.
Straight answers
Asked and answered
Does email put everything in scope?
If CUI flows through corporate email, the email system is a CUI asset, and it is the most common scoping surprise there is. Either the platform meets the applicable requirements, or CUI is kept out of it by architecture and practice you can demonstrate.
Is an enclave required?
No. It is one architecture among several. Whole-company scope is equally valid, just larger, and usually more expensive to implement, operate, and assess.
Can one shared drive break the boundary?
Yes. A single CUI file in a general-purpose location pulls that system into scope, and with it the systems connected to it. This is why scoping starts with where CUI actually goes, not where policy says it should go.
Does my MSP need its own certification?
Not under the final rule, unless it operates as a cloud service holding your CUI, in which case FedRAMP Moderate rules apply. Either way its services are assessed within your assessment, against a shared responsibility matrix with no blank rows.
Sources
- DoD CIO CMMC documentation: CMMC Assessment Scope, Level 2
- 32 CFR Part 170, the CMMC Program final rule (asset categories, ESP treatment, VDI)
- DFARS 252.204-7012 (cloud service provider requirements)
- The National Archives CUI Registry (what counts as CUI)
Next up
A scoping call is this conversation, applied to your environment: where your CUI goes and what the smallest honest boundary looks like.