Readiness check
Compliance / CUI scoping

What's in the CUI boundary.

Any asset that processes, stores, or transmits CUI is in scope.

Viewing counts as processing. From there, how an asset is treated in a CMMC Level 2 assessment depends on which of five categories it falls into. Scope is the biggest lever on what an assessment costs — so it's worth getting exactly right.

Tier 1 · In scope — assessed

Assessed against the requirements.

These sit at the core of the boundary. They're checked directly in the assessment.

CUI Assets
ASSESSED vs ALL 110 REQUIREMENTS

Assets that process, store, or transmit CUI.

Laptop opening CUI drawings · file server / SharePoint holding CUI · a mailbox that sends or receives CUI · enclave virtual desktops
Security Protection Assets
ASSESSED vs RELEVANT REQUIREMENTS

Provide security functions to the boundary — even though they hold no CUI.

Firewall / VPN · SIEM & EDR consoles · identity provider + MFA · MSSP / SOC tooling
Tier 2 · In scope — documented, not assessed

Inside the boundary, on the record.

In the asset inventory, the SSP, and the network diagram — but not assessed against the requirements, provided they're sufficiently documented.

Contractor Risk-Managed Assets
DOCUMENTED · SSP REVIEWED

Can, but are not intended to, handle CUI — kept out by policy and practice.

Corporate workstation on a policy-barred segment · conference-room PC · internal app server barred from CUI
Specialized Assets
DOCUMENTED · SSP REVIEW ONLY

Can handle CUI but can't be fully secured — managed by risk-based policy.

Government-furnished equipment · OT (CNC / PLC) · IoT / IIoT sensors · test equipment
Tier 3 · Out of scope

Outside the boundary — and it has to be earned.

An asset is out of scope only if it cannot process, store, or transmit CUI, provides no security protection to CUI assets, and is physically or logically separated. Separation must be enforced, not asserted — a flat network shared with CUI is not out of scope.

Separated guest Wi-Fi · segregated HR / marketing network with no path to CUI · a personal device with no CUI access
The point most firms miss

Your security stack — firewall, SIEM, identity, MFA, MDM — is in scope and assessed, even though it never touches CUI. It protects the boundary, so it's part of it.

Try it

Where does one asset land?

Pick what an asset does. This is orientation, not a determination — your SSP and assessor decide.

This asset…
Select an option

The category and how it's treated in the assessment will show here.

Sources

Every claim on this page is citable.

A properly separated CUI enclave shrinks the assessment scope — fewer assets are assessed — but all 110 requirements still apply in full to the enclave. It reduces how many assets are assessed, not the controls.

CMMC Level 2 = NIST SP 800-171 Rev 2 (110 requirements). Current as of Sept 2026.

Not sure where your assets land?

A readiness check scopes your environment and tells you exactly what gets assessed — before the C3PAO does.