CMMC ANSWER ENGINE

Are my developers' laptops in scope if they don't handle CUI directly?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

Developer environments are scope-sensitive because development workflows routinely touch artifacts that are CUI (technical data, source code marked CDI, customer exports). The right question isn't whether developers "work on CUI" — it's whether the laptop fits any in-scope category from the Scoping Guide.

The two main paths to in-scope

  1. CUI Asset. The laptop processes, stores, or transmits CUI. Examples: cloning a repository containing CUI-marked technical data; downloading a contract artifact; debugging against a CUI export pulled from production; attaching a CUI document to a ticket.
  2. Security Protection Asset. The laptop provides security functions to the assessment scope — typically because the developer holds privileged credentials into CUI Assets or SPAs (SSH/RDP to a CUI server, kubectl into a CUI cluster, admin console access to an SPA). The workstation that holds those credentials provides security capabilities to the scope.

The VDI / thin-client out-of-scope pattern

The Scoping Guide gives one explicit affirmative pattern for keeping a workstation out-of-scope:

"An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset."

The conditions are strict:

  • The endpoint hosts a VDI client (not a full local development environment).
  • The VDI client is configured to prevent any CUI processing, storage, or transmission on the endpoint — clipboard, file transfer, screen capture, USB redirection, printer redirection all locked down.
  • Only keyboard, video, and mouse traffic flows to and from the VDI client.

If those conditions are met, the endpoint is Out-of-Scope. This is the cleanest pattern for organizations that don't want to baseline every developer laptop to 800-171.

If you're not using VDI

For organizations giving developers full local workstations with access into the assessment scope, the practical choices are:

  • Treat developer laptops as CUI Assets or SPAs and baseline them to 800-171 (Intune or equivalent MDM, EDR, configuration baseline, audit logging, MFA).
  • Treat them as CRMAs if a clear policy prevents CUI from landing on the workstation and the policy is enforced. CRMAs are still in scope for documentation, asset inventory, and network diagram, but receive a documentation-based assessment treatment.

Common scoping mistakes

  • Declaring developer laptops out-of-scope based on policy alone. Without VDI architecture or equivalent technical control, this isn't Out-of-Scope per the guide — at best it's a CRMA.
  • Forgetting the build pipeline. If the developer's CI/CD pulls CUI into build artifacts, the build runner and any cached artifact storage are CUI Assets even if the laptop isn't.
  • Treating admin tools as ordinary applications. An administrative console on the laptop that manages a CUI Asset makes the laptop an SPA.

Sources

  • CMMC Assessment Scope — Level 2 (v2.13) — CMMC Asset Categories; Out-of-Scope Assets (VDI example) — link
  • NIST SP 800-171 Rev 2 — 3.1.1, 3.1.2, 3.13.1 — link
  • 32 CFR Part 170 — § 170.19(c)(1) Table 3 — link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170); CMMC Assessment Scope — Level 2 v2.13
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.