CMMC ANSWER ENGINE

What's the difference between CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

The Scoping Guide's CMMC Asset Categories section (citing 32 CFR § 170.19(c)(1) Table 3) is the canonical source.

The five categories at a glance

CategoryDefinitionIn SSP?Inventory?Network diagram?Assessed against requirements?
CUI AssetProcesses, stores, or transmits CUI.Yes (treatment)YesYesYes. All Level 2 security requirements.
Security Protection AssetProvides security functions or capabilities to the assessment scope. Can be People, Technology, or Facilities.Yes (treatment)YesYesYes. The practices relevant to the capabilities provided.
Contractor Risk Managed AssetCan but is not intended to process CUI because of security policy in place. Not required to be separated from CUI Assets.Yes (treatment)YesYesGenerally no, if sufficiently documented. Assessor may run a limited check if documentation raises questions; the limited check shall not materially increase assessment duration or cost.
Specialized AssetCan process CUI but cannot be fully secured: GFE, IoT, IIoT, OT, Restricted Information Systems, Test Equipment.Yes. Show managed under risk-based policies.YesYesNo. Review SSP only.
Out-of-Scope AssetCannot process CUI, does not provide security protections for CUI Assets, and is physically or logically separated from CUI Assets.NoNo documentation requirementNoNo.

The categorization decision flow

  1. Does it process, store, or transmit CUI? If yes → CUI Asset.
  2. If no, does it provide security functions or capabilities to the CMMC Assessment Scope? (Authentication, monitoring, logging, threat protection, backup of CUI, privileged access to CUI Assets, security administration.) If yes → Security Protection Asset. People and Facilities count here, not just Technology.
  3. If no, is it capable of processing CUI but restricted from doing so by security policy? If yes → CRMA. CRMAs do not need to be separated from CUI Assets.
  4. If no, is it a Specialized Asset (GFE, IoT/IIoT, OT, Restricted Information System, Test Equipment)? If yes → Specialized Asset.
  5. If none of the above and the asset is technically incapable of touching CUI and is physically or logically separated → Out-of-Scope.

Key nuances

  • CRMA limited-check rule. The Scoping Guide states explicitly: "If sufficiently documented, do not assess against other CMMC security requirements, except as noted." A limited check is allowed when documentation raises questions, but it "shall not materially increase the assessment duration nor the assessment cost."
  • Specialized Assets at Level 3. CRMAs and Specialized Assets not assessed to Level 3 scoping requirements by a C3PAO during the Level 2 certification assessment will undergo limited checks for compliance with Level 2 security requirements during the subsequent DCMA DIBCAC Level 3 certification assessment.
  • Out-of-Scope means architectural separation. The guide defines separation as logical or physical isolation, such as firewall rules, VLANs, subnetworks, or physical air gaps. Policy alone is not separation.

Sources

  • CMMC Assessment Scope, Level 2 (v2.13). CMMC Asset Categories; Table 1. link
  • 32 CFR Part 170, § 170.19(c)(1) Table 3. link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170); CMMC Assessment Scope, Level 2 v2.13

Ask an assessor about your asset categories.

Wrightbrained Security reviews asset inventories against the L2 Scoping Guide before assessments, so you know each asset is in the right category before a C3PAO does it for you.

Ask an assessor
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.