How to Properly Scope CUI for CMMC Level 2
Preparing for CMMC Level 2 starts with understanding your environment. For organizations that handle Controlled Unclassified Information (CUI), one of the most important early steps is determining where that information is processed, stored, and transmitted—and which assets are part of the CMMC assessment scope.
Proper scoping gives your organization a clearer picture of the systems, users, applications, and external providers that matter. It can also help prevent unnecessary complexity by identifying what actually needs to be protected before you begin making major technology or architecture decisions.
In this article, we'll walk through the key concepts behind CMMC Level 2 scoping, the asset categories identified in the official CMMC Level 2 Scoping Guide, and practical questions organizations can ask when evaluating their CUI environment.
What CUI Scoping Means and Why It Matters
CUI scoping is the process of establishing the boundaries of the environment relevant to your CMMC assessment. A major part of that process is identifying the assets that process, store, or transmit CUI, along with other assets that provide security functions or may otherwise fall within the assessment scope.
Why does this matter? It’s about protecting the parts that actually touch CUI. If you scope too broadly, you waste resources securing systems that don’t need it. If you scope too narrowly, you risk missing critical areas, which can lead to compliance failures or security gaps.
Proper scoping helps you:
Focus your security controls on relevant assets
Reduce the cost and complexity of compliance
Understand your risk exposure better
Prepare for assessments with clear boundaries
How to Identify Where CUI Is Stored, Processed, and Transmitted
The first step in scoping is to find all the places where CUI lives or moves through your environment. This includes:
Storage locations: Servers, databases, file shares, laptops, removable media, cloud storage
Processing systems: Applications, workstations, servers that handle or manipulate CUI
Transmission paths: Email systems, network connections, APIs, cloud services, external transfers
To identify these, start by asking:
What contracts or projects involve CUI?
Which employees handle CUI in their daily work?
What systems do those employees use?
Where is CUI saved or backed up?
How does CUI move between systems or to external partners?
Mapping this out can be done through interviews, reviewing documentation, and scanning your IT environment. The goal is to create a clear picture of your CUI data flow.

Asset Categories to Consider for CMMC Level 2 Assessment Scope
The CMMC Level 2 Scoping Guide identifies five asset categories organizations should consider when determining their assessment scope:
CUI Assets: Assets that process, store, or transmit CUI. These assets are part of the CMMC assessment scope.
Security Protection Assets: Assets that provide security functions or capabilities to the CMMC assessment scope. These can be important even when they do not directly process, store, or transmit CUI.
Contractor Risk Managed Assets: Assets that can, but are not intended to, process, store, or transmit CUI because the organization has security policies, procedures, and practices in place to manage that risk.
Specialized Assets: Certain assets that may be capable of processing, storing, or transmitting CUI but cannot be fully secured using conventional methods. Examples identified in the guidance include IoT and IIoT devices, operational technology, government property, restricted information systems, and test equipment.
Out-of-Scope Assets: Assets that cannot process, store, or transmit CUI and do not provide security protections for CUI assets. The official guidance establishes specific conditions for assets to be considered out of scope.
Correctly categorizing assets is important because the documentation and assessment requirements differ depending on the category. Organizations should use the current official CMMC Level 2 Scoping Guide when making these determinations.
How External Connections, Service Providers, and Cloud Platforms Can Affect Scope
Your CUI environment doesn’t exist in isolation. External connections and third-party services can expand your scope or introduce risks.
Your CUI environment may extend beyond systems your organization directly owns or operates. Cloud platforms, Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), and other External Service Providers (ESPs) may support systems or security functions relevant to your CUI environment.
When evaluating these relationships, determine what services the provider performs, whether CUI is processed, stored, or transmitted through the service, and whether the provider supplies security functions or capabilities to your CMMC assessment scope.
Don't assume that a third-party service is automatically inside—or outside—your scope simply because it is externally hosted. Understanding exactly how the service interacts with your environment is an important part of determining the appropriate treatment under the CMMC scoping guidance.
Understanding these external touch-points is crucial. It helps you avoid surprises during assessments and ensures your CUI stays protected across all environments.
Why Understanding Your CUI Data Flow Matters Before Choosing Security Technology
Before you pick security tools or technologies, you need a clear understanding of your CUI data flow and environment. Why?
Targeted Protection: Knowing where CUI lives and moves lets you apply controls where they’re needed most.
Avoid Over-Engineering: Without scoping, you might deploy expensive or complex solutions that don’t add value.
Simplify Compliance: Clear boundaries make it easier to document and prove compliance during audits.
Identify Gaps: Mapping data flow reveals weak points or unprotected paths that need attention.
Before deciding whether your organization needs GCC High, VDI, a secure enclave, a segmented environment, an on-premise solution, or another architecture, first understand where CUI actually flows and which systems and providers support that environment.

Common Scoping Mistakes and Considerations to Watch For
Many organizations struggle with scoping. Here are some common mistakes to avoid:
Missing CUI flows: Focusing only on primary servers or applications while overlooking where CUI is transmitted, printed, backed up, or shared.
Overlooking security assets: Forgetting about tools and services that provide security capabilities to the CMMC assessment scope.
Overlooking external providers: Not evaluating MSPs, cloud platforms, and other providers that interact with or protect the environment.
Assuming connectivity determines scope: Asset categorization requires more analysis than simply determining whether something is connected to the network.
Poor documentation: Failing to maintain the asset inventory, System Security Plan (SSP), network diagram, and other documentation applicable to the assessment scope.
Allowing the scope to become outdated: Changes to systems, providers, users, or CUI flows can affect the environment and should be evaluated.
To avoid these, regularly review your CUI environment, involve multiple teams (IT, security, legal), and document everything clearly.
How Accurate Scoping Helps You Understand What Needs Protection and Assessment
When you get scoping right, you gain a clear view of your CUI environment. This clarity helps you:
Prioritize security investments
Focus training and awareness on relevant staff
Prepare for CMMC assessments with confidence
Reduce audit surprises and remediation work
Build a security program that fits your actual risk
Accurate scoping is the foundation for effective CMMC Level 2 compliance. It’s not just a checkbox; it’s a strategic step that shapes your entire security approach.

If you're unsure about your CUI scope, Hire A Cyber Pro can help you understand where CUI moves through your business, identify the systems and external providers that matter, and review potential gaps in your current environment.
From there, we can help develop a practical future-state plan based on your actual needs—whether that involves GCC High, VDI, a secure enclave, hybrid infrastructure, on-premise systems, or a segmented architecture.
Does your team know how to properly scope CUI in your environment?
Contact Hire A Cyber Pro to discuss your CUI environment and get expert guidance on CMMC preparation.
Disclaimer: This article provides general educational information based on CMMC scoping guidance and is not a guarantee of CMMC compliance or certification. CMMC requirements and implementation guidance can change. Organizations should consult current official government documentation when making CMMC scoping and compliance decisions.




Comments