
For a small defense contractor, CMMC scope is not automatically the entire company. At Level 1, the core boundary is the contractor information systems that process, store, or transmit Federal Contract Information (FCI). At Level 2, the boundary centers on Controlled Unclassified Information (CUI), but it also reaches security systems, certain connected assets, specialized equipment, and service providers that support or protect the CUI environment.
Your best first move is not buying software. Take one defense contract and trace its information from receipt to deletion: email, file storage, endpoints, engineering tools, backups, logs, identity systems, vendors, printers, and people. The main decision hinge is whether the work involves FCI only or CUI.
There is also an important 2026 wrinkle. As of September 2026, the Department has suspended the planned CMMC Phase II transition that had been scheduled for November 10, 2026. Phase I self-assessment requirements remain in place. That pause does not erase existing contractual duties to protect defense information, so scope still matters now.
Table of Contents

Start With the Contract, Not the Network
The fastest way to create an oversized CMMC project is to begin with a spreadsheet of every laptop, switch, SaaS application, and employee in the company. That inventory may become useful later, but it does not tell you why an asset belongs in the assessment boundary.
Start instead with the information requirement. Ask what information the contract, subcontract, purchase order, statement of work, or prime contractor will actually provide or require you to create.
- FCI only: Level 1 may be the relevant CMMC requirement.
- CUI: Level 2 becomes the key scoping model.
- No FCI or CUI on contractor systems: do not assume a CMMC environment exists merely because your customer is part of the defense supply chain.
FCI is not simply “anything related to a federal contract,” and CUI is not a label contractors should invent for information that merely feels sensitive. Review the solicitation and contract clauses, CUI markings, data-delivery instructions, and guidance from the contracting activity or prime contractor.
The current DFARS CMMC contract clause ties CMMC status to contractor information systems used in contract performance that process, store, or transmit FCI or CUI. That makes the information flow, rather than company headcount, the natural starting point for scope.
Level 1 and Level 2 Have Different Scoping Logic
Level 1 scope is comparatively direct: identify information systems that process, store, or transmit FCI. Level 2 is more demanding because an asset can be relevant even when it does not itself hold a CUI document.
| Situation | Likely Scoping Question | What to Verify |
|---|---|---|
| FCI only | Which systems process, store, or transmit FCI? | Level 1 assessment boundary |
| CUI present | Where can CUI travel, reside, or be processed? | Level 2 CUI assets and connected categories |
| Security service protects CUI systems | Does it handle security functions or security protection data? | Security Protection Asset or ESP treatment |
| General corporate asset cannot reach CUI | Is the separation technically defensible? | Potential out-of-scope treatment |
| Asset could handle CUI but policy says it should not | Is it truly separated, or merely restricted by policy? | Possible Contractor Risk Managed Asset |
For small contractors, that distinction is financially significant. A ten-person company can create an expensive assessment boundary if CUI is allowed to wander through normal email, shared drives, personal workstations, backup services, and administrative tools. A larger company can sometimes maintain a much smaller CUI boundary through disciplined architecture.
How Level 2 Classifies Assets
The Level 2 rule does not reduce everything to “in scope” and “out of scope.” It uses several asset categories, and confusing them is one of the easiest ways to build a misleading scope.
The Department’s current Level 2 scoping guidance is the document to keep beside your working asset inventory.
CUI Assets
These assets process, store, or transmit CUI. For a small engineering contractor, examples might include a workstation used to open controlled drawings, a file repository containing CUI, or a server that processes controlled technical data.
CUI assets belong in the Level 2 assessment scope and should appear in the asset inventory, System Security Plan (SSP), and network diagram. They are assessed against applicable Level 2 security requirements.
Security Protection Assets
A Security Protection Asset provides security functions or capabilities to the CMMC assessment scope. This category matters because a system does not need to contain the engineering drawing itself to become relevant.
Depending on the architecture, identity systems, centralized logging, security monitoring, endpoint management, authentication infrastructure, or other protective services may qualify. These assets are assessed against the Level 2 requirements relevant to the security capabilities they provide.
This is where supposedly tiny enclaves sometimes grow tentacles. A two-laptop CUI environment can still depend on a company-wide identity platform, administrative service, log repository, or managed security provider.
Contractor Risk Managed Assets
Contractor Risk Managed Assets can process, store, or transmit CUI technically, but are not intended to do so because the contractor has policies, procedures, and security practices designed to prevent that use.
This is different from being out of scope. A normal corporate workstation does not become out of scope merely because a policy document says, “Do not put CUI here.” If it remains capable of interacting with the CUI environment and lacks a defensible separation boundary, its proper classification may require closer analysis.
These assets must be documented in the inventory, SSP, and network diagram. When the risk-based treatment is sufficiently documented, they are not routinely assessed like ordinary CUI assets, although an assessor may perform limited checks if the documentation or observed environment raises questions.
Specialized Assets
Specialized Assets include certain systems that can process, store, or transmit CUI but cannot be fully secured in the same way as conventional IT. The regulation identifies categories such as operational technology, IoT and IIoT devices, government-furnished equipment, restricted information systems, and test equipment.
At Level 2, these assets still require documentation and risk-based treatment. They are not simply an escape hatch for old equipment.
Out-of-Scope Assets
An out-of-scope asset must be unable to process, store, or transmit CUI and must not provide security protection for CUI assets. Physical or logical separation can support that conclusion.
The key word is unable, not merely “not supposed to.” If an ordinary laptop can sign into the same CUI file service, download a controlled attachment, or access a shared location containing CUI, calling it out of scope becomes difficult to defend.

Use Two Maps: the CUI Path and the Security Path
A useful small-business scoping method is to build two simple maps instead of one giant network diagram.
Map 1: Follow the CUI
- Where does CUI enter the company?
- Who can open or modify it?
- Which endpoints process it?
- Where is it stored?
- How is it transmitted?
- Where is it backed up?
- Can it reach email, chat, ticketing, printing, scanning, or collaboration systems?
- How is it archived or deleted?
Do not stop at the obvious file server. A drawing downloaded from a protected repository can create copies in browser caches, synchronization folders, temporary storage, backups, print queues, or user-created exports.
Map 2: Follow the Security Dependency
- What authenticates users?
- What controls privileged administration?
- What collects security logs?
- What manages endpoints?
- What detects malware or suspicious activity?
- What provides backup or recovery?
- What external provider receives CUI or security protection data?
The first map finds CUI assets. The second often reveals Security Protection Assets and External Service Providers. Overlay them and your real CMMC boundary begins to emerge.
External Service Providers Can Quietly Expand the Boundary
Small contractors often outsource more IT than large contractors, so External Service Provider scoping deserves disproportionate attention. The trap is assuming that outsourcing a function also outsources the CMMC responsibility.
At Level 2, a service provider can become relevant when CUI or Security Protection Data resides on its assets. Security Protection Data can include information such as security logs and configuration data used to protect the assessed environment.
Potential examples include a managed IT provider, managed SOC, cloud service, security monitoring service, backup platform, or other provider whose systems actually handle relevant CUI or security data. A provider that processes neither CUI nor Security Protection Data does not become a CMMC ESP merely because your company pays it an IT invoice.
For an in-scope ESP, document the relationship in the SSP and obtain a clear service description and customer responsibility matrix. The practical question is: which security requirement objectives belong to you, and which belong to the provider?
Do not accept “we support CMMC customers” as evidence of what the service actually does. Ask for documentation showing the service boundary, data handling, security responsibilities, administrative access, and any inherited capabilities you plan to rely on.
How to Reduce Scope Without Creating a Paper Fiction
Legitimate scope reduction comes from architecture and data discipline. It does not come from renaming assets in a spreadsheet the week before an assessment.
- Limit where CUI can enter. Use defined channels rather than allowing controlled files to arrive anywhere employees happen to work.
- Limit who can access CUI. A smaller authorized user population usually creates a cleaner boundary.
- Use dedicated CUI endpoints where practical. This can prevent ordinary corporate devices from becoming CUI-capable.
- Separate CUI storage from general collaboration. Uncontrolled synchronization can turn one repository into dozens of copies.
- Control printing and removable media. Scope does not stop at the Ethernet cable.
- Separate administrative paths thoughtfully. Security systems protecting the enclave may themselves become part of scope.
- Review backups and logs. A tightly segmented production environment can still depend on broadly shared backup or monitoring services.
The official guidance also recognizes a narrowly configured VDI case: an endpoint hosting a VDI client that does not process, store, or transmit CUI beyond keyboard, video, and mouse interaction can be treated as out of scope. That does not mean every remote-desktop architecture automatically qualifies. Clipboard transfer, local drive mapping, downloads, printing, synchronization, or other data paths can change the conclusion.
Scope reduction can materially affect implementation and assessment spending. If you are estimating the broader financial impact after defining the boundary, use the CMMC compliance cost guide to separate scoping decisions from remediation, tooling, internal labor, and assessment costs.
What Evidence Makes a Scope Defensible?
A useful scope is not merely accurate in the IT manager’s head. Another person should be able to understand why each important asset is inside or outside the boundary.
| Evidence | What It Should Explain | Common Failure |
|---|---|---|
| Data-flow description | How FCI or CUI enters, moves, and leaves | Only documenting storage |
| Asset inventory | Asset category and treatment | Listing hardware without scope rationale |
| Network diagram | Boundary, connectivity, segmentation, services | Diagram does not match production |
| System Security Plan | Environment and security implementation | Generic template with no architecture detail |
| ESP service description | What the provider actually performs | Marketing page used as technical evidence |
| Customer responsibility matrix | Provider versus contractor responsibilities | Control ownership left ambiguous |
| Out-of-scope justification | Why an asset cannot handle CUI | Relying only on policy language |
The objective is not documentation volume. A thirty-page diagram set that hides one uncontrolled file-sharing path is worse than a simple architecture that accurately explains the boundary.
Your 15-Minute CMMC Scope Check
Before hiring a consultant or buying a compliance platform, perform this short test using one real contract.
- Find the information requirement. Determine whether the work involves FCI, CUI, both, or neither.
- Choose one representative CUI or FCI item. A drawing, specification, technical file, contract document, or other actual artifact is more useful than discussing data abstractly.
- Trace it from entry to deletion. Write down every system and provider it touches.
- Identify every security dependency. Add identity, endpoint management, logging, monitoring, backup, and administrative services protecting those systems.
- Mark the uncertain assets. For each one, ask whether it can process, store, or transmit CUI or protects a CUI asset.
- Challenge every “out of scope” label. Ask what technical fact makes CUI handling impossible.
- List every external provider holding CUI or security data. Request the relevant service description and responsibility matrix.
If this exercise produces a clear, narrow flow, your next job is documentation and control verification. If arrows explode across normal email, shared corporate SaaS, personal endpoints, MSP systems, and multiple business units, you have found the real problem before paying someone to assess it.
When DIY Scoping Is Enough and When Professional Help Is Worth Paying For
A small contractor does not automatically need a consultant to draw its CMMC boundary. The unresolved complexity should justify the expense.
DIY can be reasonable when
- the FCI or CUI requirement is unambiguous;
- only a small number of systems handle the information;
- the company has a clearly separated environment;
- the internal administrator understands the actual data paths;
- few external providers are involved; and
- the current requirement is a Level 1 or Level 2 self-assessment.
Software becomes useful when
- asset and evidence tracking has become difficult to maintain manually;
- multiple owners must continually update evidence;
- control mapping and recurring attestations need repeatable workflows; or
- several contracts share the same assessed environment.
A compliance platform can organize evidence. It cannot decide a disputed CUI boundary for you, repair a poor architecture by itself, or turn an unsupported policy statement into a technical separation.
Professional scoping help is easier to justify when
- CUI identification is disputed or poorly documented;
- the environment spans multiple offices, business units, or networks;
- an MSP, MSSP, SOC, cloud provider, or shared corporate service complicates ownership;
- operational technology or specialized assets are involved;
- the company cannot explain why supposedly out-of-scope assets are unable to handle CUI; or
- a contract opportunity is large enough that an incorrect scope could jeopardize award eligibility.
Before paying, ask the provider what deliverable you will receive. A useful engagement should leave you with an understandable boundary, asset categorization logic, data-flow view, identified ESP dependencies, assumptions, and unresolved questions. “CMMC readiness support” without defined outputs is too foggy to price intelligently.
What the 2026 Phase II Suspension Changes
The current implementation schedule is unusually important because older CMMC articles may still tell contractors to prepare for an automatic Phase II start on November 10, 2026.
That is no longer the current implementation position. On July 13, 2026, the Department suspended Phase II requirements and paused progression beyond Phase I while reviewing the program. The official CMMC program page states that Phase I self-assessment requirements remain in place.
For a small contractor, the practical consequence is straightforward: do not purchase an expensive third-party certification engagement merely because an old calendar says Phase II automatically begins in November 2026. Verify the actual solicitation, contract requirement, and current Department guidance first.
At the same time, do not interpret the suspension as permission to ignore CUI protection. Existing DFARS safeguarding requirements remain relevant, and the Department has said it will continue using self-assessments and selected government-led assessments during the interim period.
There is another version trap. NIST has published SP 800-171 Revision 3, but the current CMMC Level 2 model in 32 CFR Part 170 incorporates the 110 requirements from Revision 2. Contractors therefore should not silently replace the CMMC assessment basis with Revision 3 simply because it is the newer NIST publication. For reference, NIST preserves the Revision 2 publication and status information.
This is a moving policy area. Before a bid, option exercise, or major compliance purchase, check the current solicitation and official program guidance rather than relying on a forecasted rollout date copied from a 2025 presentation.

Frequently Asked Questions
Can a very small contractor put only one or two systems in CMMC scope?
Potentially, yes. CMMC scope follows information processing and security dependencies rather than employee count. A very small enclave can work if CUI is genuinely confined to those systems and supporting security services are properly accounted for. The difficult part is proving that ordinary corporate assets cannot become alternate CUI paths.
Are HR, accounting, and payroll systems automatically in scope?
No. A system is not automatically part of the CMMC Level 2 scope merely because it belongs to the same company. Determine whether it can process, store, or transmit CUI or provides security protection to the CUI environment. A properly separated business system may remain outside the assessment boundary.
Does a policy saying “no CUI” make a laptop out of scope?
Not by itself. If the laptop remains technically capable of accessing or receiving CUI, you need to evaluate whether it fits another asset category, including Contractor Risk Managed Asset treatment. Out-of-scope classification requires a stronger boundary than employee intent.
Does the Phase II suspension mean Level 2 no longer matters?
No. The current pause stops the planned Phase II progression, but Phase I remains in effect, including Level 2 self-assessment requirements where applicable. Contractual protection requirements for CUI also remain relevant. Check the current solicitation rather than assuming either “certification is due now” or “CMMC is gone.”
Do subcontractors need CMMC too?
CMMC requirements can flow through the supply chain when subcontractors process, store, or transmit FCI or CUI for the covered work. Under 32 CFR Part 170, FCI-only subcontractors may require Level 1, while subcontractors handling CUI require at least the applicable Level 2 status. The precise assessment type should be checked against the prime contract, subcontract language, and current implementation policy.
Map Your Scope Before You Buy Anything
Take one real contract and one real piece of FCI or CUI. Draw its path on a single page. Add every endpoint, repository, backup, security service, administrator, and outside provider it touches. Then circle each asset you believe is out of scope and write one sentence explaining the technical fact that prevents it from handling CUI.
If you cannot write that sentence confidently, do not buy another security tool yet. Resolve the boundary first. In CMMC, a clean scope is not clerical housekeeping. It is the blueprint that determines what you must secure, document, assess, operate, and eventually pay for.
Last reviewed: 2026-10