Scoping work must be grounded in the CMMC Assessment Scope, Level 2 (v2.13). Together with 32 CFR § 170.19(c)(1) Table 3, the L2 Scoping Guide is the canonical reference for asset categorization. Every scoping decision the OSA makes should be defensible against it. Scoping is a categorization exercise: you sort every asset in your environment into exactly one of five categories.
The five asset categories
| Category | Definition | In scope? |
|---|---|---|
| CUI Asset | Processes, stores, or transmits CUI. | Yes. Assessed against all Level 2 security requirements. |
| Security Protection Asset (SPA) | Provides security functions or capabilities to the OSA's CMMC Assessment Scope. | Yes. Assessed against Level 2 security requirements relevant to the capabilities provided. |
| Contractor Risk Managed Asset (CRMA) | Can, but is not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place. Not required to be separated from CUI Assets. | Yes, but generally not assessed against requirements if sufficiently documented in the SSP. An assessor may conduct a limited check if documentation raises questions. |
| Specialized Asset | Can process, store, or transmit CUI but is unable to be fully secured: Government Furnished Equipment (GFE), IoT, IIoT, Operational Technology (OT), Restricted Information Systems, and Test Equipment. | Yes. Documented and managed per the OSA's risk-based policies. Not assessed against other CMMC requirements. |
| Out-of-Scope Asset | Cannot process CUI, does not provide security protections for CUI Assets, and is physically or logically separated from CUI Assets. | No. |
What the OSA must produce for in-scope assets
For CUI Assets, SPAs, CRMAs, and Specialized Assets, the OSA must:
- document each asset in the asset inventory. Under CM.L2-3.4.1, baseline inventories must cover hardware, software, firmware, and documentation. At minimum, each entry should identify the asset and its category (CUI Asset, SPA, CRMA, or Specialized);
- document the asset's treatment in the SSP;
- include the asset on the network diagram of the CMMC Assessment Scope used in pre-assessment scoping discussions.
What qualifies an asset as Out-of-Scope
The Scoping Guide is explicit: an asset that falls into any in-scope category cannot be claimed as Out-of-Scope. The guide also provides a concrete affirmative example. "An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard, Video, Mouse sent to the VDI client is considered an Out-of-Scope Asset." Well-architected thin-client patterns are recognized.
Common categorization errors
- Not listing every in-scope asset in the inventory. The asset inventory is a complete list of in-scope assets, not a representative sample. Missing assets are missing controls, and the assessor will notice the gap when the inventory does not match the network diagram or the SSP.
- Inventory missing required information. Each asset entry should at minimum identify the asset (name or identifier) and its category (CUI Asset, SPA, CRMA, or Specialized). An entry that only lists a name without identifying its category does not satisfy the L2 Scoping Guide's documentation expectation.
- Inventory limited to hardware only. CM.L2-3.4.1 requires the baseline inventory to cover hardware, software, firmware, and documentation. An inventory that only lists servers and laptops, with no software, firmware, or supporting documentation, is incomplete.
- Skipping categorization entirely. Some OSAs document an inventory but never categorize the assets. The categorization is what the assessor uses to scope the assessment and to determine assessment treatment per category. An uncategorized inventory is half an answer.
- Categorizing only CUI Assets. Listing every asset that processes CUI but not the SPAs, CRMAs, or Specialized Assets is a partial scope determination. All four in-scope categories must be addressed. Missing the SPAs (identity provider, EDR management server, log aggregation tier, backup system) is the most common version of this error.
- Skipping Specialized Assets. GFE and test equipment in particular get overlooked because they often live with engineering rather than IT.
- Claiming Out-of-Scope without separation evidence. The Scoping Guide treats separation as architectural (logical or physical), not procedural. If you cannot show the firewall rule, the VLAN, or the air gap, the asset is not Out-of-Scope.
- Treating CRMAs as Out-of-Scope. CRMAs are in scope; they just receive a documentation-based assessment treatment rather than full evaluation, provided the SSP documentation is sufficient.
- Treating an identity provider as out-of-scope when it issues authentication tokens used to access in-scope assets. Identity providers serving the assessment scope are Security Protection Assets regardless of platform.
Sources
Get a Lead Assessor scoping review.
Wrightbrained Security offers Lead Assessor scoping consultations: independent review of your asset categorization and assessment scope before a C3PAO does it for you.
Talk with a Lead Assessor