Developer environments are scope-sensitive because development workflows routinely touch artifacts that are CUI (technical data, source code marked CDI, customer exports). The right question isn't whether developers "work on CUI" — it's whether the laptop fits any in-scope category from the Scoping Guide.
The two main paths to in-scope
- CUI Asset. The laptop processes, stores, or transmits CUI. Examples: cloning a repository containing CUI-marked technical data; downloading a contract artifact; debugging against a CUI export pulled from production; attaching a CUI document to a ticket.
- Security Protection Asset. The laptop provides security functions to the assessment scope — typically because the developer holds privileged credentials into CUI Assets or SPAs (SSH/RDP to a CUI server, kubectl into a CUI cluster, admin console access to an SPA). The workstation that holds those credentials provides security capabilities to the scope.
The VDI / thin-client out-of-scope pattern
The Scoping Guide gives one explicit affirmative pattern for keeping a workstation out-of-scope:
"An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset."
The conditions are strict:
- The endpoint hosts a VDI client (not a full local development environment).
- The VDI client is configured to prevent any CUI processing, storage, or transmission on the endpoint — clipboard, file transfer, screen capture, USB redirection, printer redirection all locked down.
- Only keyboard, video, and mouse traffic flows to and from the VDI client.
If those conditions are met, the endpoint is Out-of-Scope. This is the cleanest pattern for organizations that don't want to baseline every developer laptop to 800-171.
If you're not using VDI
For organizations giving developers full local workstations with access into the assessment scope, the practical choices are:
- Treat developer laptops as CUI Assets or SPAs and baseline them to 800-171 (Intune or equivalent MDM, EDR, configuration baseline, audit logging, MFA).
- Treat them as CRMAs if a clear policy prevents CUI from landing on the workstation and the policy is enforced. CRMAs are still in scope for documentation, asset inventory, and network diagram, but receive a documentation-based assessment treatment.
Common scoping mistakes
- Declaring developer laptops out-of-scope based on policy alone. Without VDI architecture or equivalent technical control, this isn't Out-of-Scope per the guide — at best it's a CRMA.
- Forgetting the build pipeline. If the developer's CI/CD pulls CUI into build artifacts, the build runner and any cached artifact storage are CUI Assets even if the laptop isn't.
- Treating admin tools as ordinary applications. An administrative console on the laptop that manages a CUI Asset makes the laptop an SPA.