CMMC ANSWER ENGINE

How do I determine if a system is in scope for CMMC?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-16
Quick answer. Scoping work must be grounded in the CMMC Assessment Scope, Level 2 (v2.13). Every asset maps to one of five categories. Four are in scope (CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets); the fifth (Out-of-Scope Assets) requires architectural separation. Document every in-scope asset in the inventory (at minimum, identified and categorized), treat it in the SSP, and show it on the network diagram. CM.L2-3.4.1 requires the baseline inventory to cover hardware, software, firmware, and documentation.

Scoping work must be grounded in the CMMC Assessment Scope, Level 2 (v2.13). Together with 32 CFR § 170.19(c)(1) Table 3, the L2 Scoping Guide is the canonical reference for asset categorization. Every scoping decision the OSA makes should be defensible against it. Scoping is a categorization exercise: you sort every asset in your environment into exactly one of five categories.

The five asset categories

CategoryDefinitionIn scope?
CUI AssetProcesses, stores, or transmits CUI.Yes. Assessed against all Level 2 security requirements.
Security Protection Asset (SPA)Provides security functions or capabilities to the OSA's CMMC Assessment Scope.Yes. Assessed against Level 2 security requirements relevant to the capabilities provided.
Contractor Risk Managed Asset (CRMA)Can, but is not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place. Not required to be separated from CUI Assets.Yes, but generally not assessed against requirements if sufficiently documented in the SSP. An assessor may conduct a limited check if documentation raises questions.
Specialized AssetCan process, store, or transmit CUI but is unable to be fully secured: Government Furnished Equipment (GFE), IoT, IIoT, Operational Technology (OT), Restricted Information Systems, and Test Equipment.Yes. Documented and managed per the OSA's risk-based policies. Not assessed against other CMMC requirements.
Out-of-Scope AssetCannot process CUI, does not provide security protections for CUI Assets, and is physically or logically separated from CUI Assets.No.

What the OSA must produce for in-scope assets

For CUI Assets, SPAs, CRMAs, and Specialized Assets, the OSA must:

  • document each asset in the asset inventory. Under CM.L2-3.4.1, baseline inventories must cover hardware, software, firmware, and documentation. At minimum, each entry should identify the asset and its category (CUI Asset, SPA, CRMA, or Specialized);
  • document the asset's treatment in the SSP;
  • include the asset on the network diagram of the CMMC Assessment Scope used in pre-assessment scoping discussions.

What qualifies an asset as Out-of-Scope

The Scoping Guide is explicit: an asset that falls into any in-scope category cannot be claimed as Out-of-Scope. The guide also provides a concrete affirmative example. "An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard, Video, Mouse sent to the VDI client is considered an Out-of-Scope Asset." Well-architected thin-client patterns are recognized.

Common categorization errors

  • Not listing every in-scope asset in the inventory. The asset inventory is a complete list of in-scope assets, not a representative sample. Missing assets are missing controls, and the assessor will notice the gap when the inventory does not match the network diagram or the SSP.
  • Inventory missing required information. Each asset entry should at minimum identify the asset (name or identifier) and its category (CUI Asset, SPA, CRMA, or Specialized). An entry that only lists a name without identifying its category does not satisfy the L2 Scoping Guide's documentation expectation.
  • Inventory limited to hardware only. CM.L2-3.4.1 requires the baseline inventory to cover hardware, software, firmware, and documentation. An inventory that only lists servers and laptops, with no software, firmware, or supporting documentation, is incomplete.
  • Skipping categorization entirely. Some OSAs document an inventory but never categorize the assets. The categorization is what the assessor uses to scope the assessment and to determine assessment treatment per category. An uncategorized inventory is half an answer.
  • Categorizing only CUI Assets. Listing every asset that processes CUI but not the SPAs, CRMAs, or Specialized Assets is a partial scope determination. All four in-scope categories must be addressed. Missing the SPAs (identity provider, EDR management server, log aggregation tier, backup system) is the most common version of this error.
  • Skipping Specialized Assets. GFE and test equipment in particular get overlooked because they often live with engineering rather than IT.
  • Claiming Out-of-Scope without separation evidence. The Scoping Guide treats separation as architectural (logical or physical), not procedural. If you cannot show the firewall rule, the VLAN, or the air gap, the asset is not Out-of-Scope.
  • Treating CRMAs as Out-of-Scope. CRMAs are in scope; they just receive a documentation-based assessment treatment rather than full evaluation, provided the SSP documentation is sufficient.
  • Treating an identity provider as out-of-scope when it issues authentication tokens used to access in-scope assets. Identity providers serving the assessment scope are Security Protection Assets regardless of platform.

Sources

  • CMMC Assessment Scope, Level 2 (v2.13). CMMC Asset Categories; Table 1; Defining the CMMC Assessment Scope. link
  • 32 CFR Part 170, CMMC Program (Final Rule). § 170.19(c)(1) Table 3. link
  • NIST SP 800-171 Rev 2. Chapter 1, Scoping discussion. link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170, effective 2024-12-16); CMMC Assessment Scope, Level 2 v2.13 (Sept 2024)

Get a Lead Assessor scoping review.

Wrightbrained Security offers Lead Assessor scoping consultations: independent review of your asset categorization and assessment scope before a C3PAO does it for you.

Talk with a Lead Assessor
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.