The Scoping Guide defines a Security Protection Asset in the Security Protection Assets/Security Protection Data section: any asset that "provides security functions or capabilities within the OSA's CMMC Assessment Scope." The category is broader than most contractors assume — it includes People and Facilities, not just Technology.
Examples from Table 2 of the Scoping Guide
| Asset Type | Examples |
|---|---|
| People | Consultants who provide cybersecurity service; managed service provider personnel who implement system maintenance; enterprise network administrators. |
| Technology | Cloud-based security solutions; hosted Virtual Private Network (VPN) services; SIEM solutions. |
| Facilities | Co-located data centers; Security Operations Centers (SOCs); OSA office buildings. |
What "assessed against relevant requirements" means
The Scoping Guide is specific: SPAs are assessed against "Level 2 security requirements that are relevant to the capabilities provided." In practice that means the assessor evaluates the SPA's role in protecting the assessment scope — an SIEM's logging configuration, an identity provider's authentication controls, an administrator's privileged access management. An SPA's own access controls, configuration management, and audit posture are evaluated against the practices that map to its security function.
Security Protection Data (SPD)
The guide also defines Security Protection Data — data stored or processed by SPAs that protects the assessed environment. SPD includes:
- configuration data required to operate a Security Protection Asset,
- log files generated by or ingested by an SPA,
- data related to the configuration or vulnerability status of in-scope assets, and
- passwords that grant access to the in-scope environment.
SPD is treated as security-relevant; its disclosure could aid an attacker in compromising the assessment scope. The systems and services holding SPD are themselves SPAs.
SIEM example from the guide
The Scoping Guide explicitly addresses SIEM: "If the SIEM and/or associated log data is hosted or maintained by an ESP, then the portion of the ESP that is used to provide the SIEM service or log storage is part of the OSA's assessment scope." Both hot and cold log storage are in the assessment scope.
OSA documentation requirements for SPAs
- Document each SPA in the asset inventory.
- Document the asset's treatment in the SSP.
- Include the asset on the network diagram of the CMMC Assessment Scope.
Where SPAs are most often missed
- People-as-SPA. Consultants, MSP staff, and internal administrators with privileged access into the assessment scope are SPAs. Many SSPs omit them entirely.
- Facilities-as-SPA. An OSA office building where in-scope work happens is itself an SPA, which means physical security practices (PE family) apply to that facility.
- The log archive. Cold log storage hosted by an ESP is in scope, not just the SIEM itself.