What's in the CUI boundary.
Any asset that processes, stores, or transmits CUI is in scope.
Viewing counts as processing. From there, how an asset is treated in a CMMC Level 2 assessment depends on which of five categories it falls into. Scope is the biggest lever on what an assessment costs — so it's worth getting exactly right.
Assessed against the requirements.
These sit at the core of the boundary. They're checked directly in the assessment.
Assets that process, store, or transmit CUI.
Provide security functions to the boundary — even though they hold no CUI.
Inside the boundary, on the record.
In the asset inventory, the SSP, and the network diagram — but not assessed against the requirements, provided they're sufficiently documented.
Can, but are not intended to, handle CUI — kept out by policy and practice.
Can handle CUI but can't be fully secured — managed by risk-based policy.
Outside the boundary — and it has to be earned.
An asset is out of scope only if it cannot process, store, or transmit CUI, provides no security protection to CUI assets, and is physically or logically separated. Separation must be enforced, not asserted — a flat network shared with CUI is not out of scope.
Your security stack — firewall, SIEM, identity, MFA, MDM — is in scope and assessed, even though it never touches CUI. It protects the boundary, so it's part of it.
Where does one asset land?
Pick what an asset does. This is orientation, not a determination — your SSP and assessor decide.
The category and how it's treated in the assessment will show here.
Every claim on this page is citable.
A properly separated CUI enclave shrinks the assessment scope — fewer assets are assessed — but all 110 requirements still apply in full to the enclave. It reduces how many assets are assessed, not the controls.
CMMC Level 2 = NIST SP 800-171 Rev 2 (110 requirements). Current as of Sept 2026.
Not sure where your assets land?
A readiness check scopes your environment and tells you exactly what gets assessed — before the C3PAO does.