The Scoping Guide's CMMC Asset Categories section (citing 32 CFR § 170.19(c)(1) Table 3) is the canonical source.
The five categories at a glance
| Category | Definition | In SSP? | Inventory? | Network diagram? | Assessed against requirements? |
|---|---|---|---|---|---|
| CUI Asset | Processes, stores, or transmits CUI. | Yes (treatment) | Yes | Yes | Yes. All Level 2 security requirements. |
| Security Protection Asset | Provides security functions or capabilities to the assessment scope. Can be People, Technology, or Facilities. | Yes (treatment) | Yes | Yes | Yes. The practices relevant to the capabilities provided. |
| Contractor Risk Managed Asset | Can but is not intended to process CUI because of security policy in place. Not required to be separated from CUI Assets. | Yes (treatment) | Yes | Yes | Generally no, if sufficiently documented. Assessor may run a limited check if documentation raises questions; the limited check shall not materially increase assessment duration or cost. |
| Specialized Asset | Can process CUI but cannot be fully secured: GFE, IoT, IIoT, OT, Restricted Information Systems, Test Equipment. | Yes. Show managed under risk-based policies. | Yes | Yes | No. Review SSP only. |
| Out-of-Scope Asset | Cannot process CUI, does not provide security protections for CUI Assets, and is physically or logically separated from CUI Assets. | No | No documentation requirement | No | No. |
The categorization decision flow
- Does it process, store, or transmit CUI? If yes → CUI Asset.
- If no, does it provide security functions or capabilities to the CMMC Assessment Scope? (Authentication, monitoring, logging, threat protection, backup of CUI, privileged access to CUI Assets, security administration.) If yes → Security Protection Asset. People and Facilities count here, not just Technology.
- If no, is it capable of processing CUI but restricted from doing so by security policy? If yes → CRMA. CRMAs do not need to be separated from CUI Assets.
- If no, is it a Specialized Asset (GFE, IoT/IIoT, OT, Restricted Information System, Test Equipment)? If yes → Specialized Asset.
- If none of the above and the asset is technically incapable of touching CUI and is physically or logically separated → Out-of-Scope.
Key nuances
- CRMA limited-check rule. The Scoping Guide states explicitly: "If sufficiently documented, do not assess against other CMMC security requirements, except as noted." A limited check is allowed when documentation raises questions, but it "shall not materially increase the assessment duration nor the assessment cost."
- Specialized Assets at Level 3. CRMAs and Specialized Assets not assessed to Level 3 scoping requirements by a C3PAO during the Level 2 certification assessment will undergo limited checks for compliance with Level 2 security requirements during the subsequent DCMA DIBCAC Level 3 certification assessment.
- Out-of-Scope means architectural separation. The guide defines separation as logical or physical isolation, such as firewall rules, VLANs, subnetworks, or physical air gaps. Policy alone is not separation.
Sources
Ask an assessor about your asset categories.
Wrightbrained Security reviews asset inventories against the L2 Scoping Guide before assessments, so you know each asset is in the right category before a C3PAO does it for you.
Ask an assessor