CMMC & Compliance

CUI Scoping: The Decision That Determines Your Entire CMMC Budget

Most CMMC conversations start in the wrong place.

They start with controls. MFA, logging, encryption, the 110 requirements in NIST SP 800-171. Those matter, of course. But they are the second question.

The first question is where does this apply. And the answer to that question will swing your cost, your timeline and your ongoing burden by an order of magnitude, on the same contract, against the same standard.

Scoping is the highest-leverage decision in CMMC. It is also the one most likely to be made by accident.

Why the boundary is worth more than the controls

Every control you implement gets multiplied by the number of systems you implement it on.

Consider two shops holding the identical contract with the identical CUI.

The first has decided, deliberately, that CUI lives in one place: a segmented enclave with controlled access. Fourteen systems in scope. Every control applies fourteen times.

The second never decided anything. CUI arrived by email, got saved to the shared drive, ended up on three laptops, and someone put a copy in a personal cloud folder to work on it at home. Now the boundary is the whole company. A hundred and forty systems in scope. Every control applies a hundred and forty times.

Same standard. Same contract. Roughly ten times the work, ten times the tooling spend, and ten times the ongoing evidence burden — forever, not once.

Nobody chose the second outcome. That is exactly the problem. Scope sprawl is what happens when nobody draws the line, so the line draws itself around everything.

The five asset categories, and what each one costs you

CMMC scoping is not one bucket. It is five, and knowing which is which is where the savings live.

CUI Assets — systems that process, store or transmit CUI. These get the full treatment: all 110 requirements, asset inventory, System Security Plan, network diagram with CUI flow labelled. This is the expensive category. Everything you keep out of it is money.

Security Protection Assets — the things that protect the CUI environment. SIEM, firewalls, MDM, your identity provider. Assessed against the requirements relevant to their security function. You cannot avoid these; they are the cost of having a defensible boundary.

Contractor Risk Managed Assets — systems that could access CUI but are not intended to, because policy, segmentation or access control prevents it. These may avoid full assessment if you have documented them properly. That conditional is doing enormous work in that sentence. Documented, they are cheap. Undocumented, an assessor will simply treat them as CUI assets and you have bought nothing.

Specialized Assets — OT, ICS, test equipment, government-furnished equipment, IoT. Things that may touch CUI and cannot be secured conventionally. Reviewed in your SSP and data flow diagram, not assessed against the requirements. For a machine shop with CNC equipment, this category is the difference between a manageable project and an impossible one.

Out-of-Scope Assets — no interaction with CUI, the CUI environment, or security protection data. No assessment, no documentation. The goal of good scoping is to move as much as legitimately belongs here, here.

Notice the pattern: three of the five categories are cheaper than the first, and reaching them is a documentation and architecture exercise, not a security-spend exercise.

The enclave decision

For most small contractors the highest-value architectural move is an enclave — a deliberately isolated segment where CUI lives, works and stays.

The appeal is arithmetic. Instead of raising the whole company to Level 2, you raise one bounded environment and keep everything else out of scope. Assessment boundary shrinks. Tooling spend shrinks. Evidence burden shrinks. Onboarding a new employee stops being a compliance event.

The cost is discipline. An enclave only works if CUI actually stays in it. One person emailing a drawing to their own address to print at home has, technically, just expanded your assessment boundary to include their home computer.

So the enclave is half technical and half cultural. The technical half is a weekend. The cultural half is why it fails.

Why your consultant may not push back on sprawl

I will say the uncomfortable part plainly.

Most CMMC consulting is priced by effort. More systems in scope means more controls to implement, more documentation to write, more evidence to collect, more hours to bill. A consultant who helps you scope tightly is deliberately shrinking their own engagement.

I am not suggesting bad faith is common. I am suggesting that when the incentive points one direction and nobody is actively pushing the other way, sprawl is the default outcome. Nobody has to do anything wrong for you to end up over-scoped.

Ask your consultant directly: what did you take out of scope, and why? If they cannot answer with specifics, they scoped by including rather than by deciding.

The six ways scope quietly sprawls

  • Email. The single most common. CUI arrives as an attachment and your mail system is now in scope.
  • Convenience copies. Someone puts a file somewhere easier to reach. That somewhere is now assessed.
  • Assuming specialized assets are automatically excluded. They are not — they are excluded when documented. No documentation, no exclusion.
  • Unverified cloud providers. External providers handling CUI generally need FedRAMP Moderate or equivalent. Discovering yours does not, late, is expensive.
  • Flat networks. Without segmentation, nothing can legitimately be risk-managed or out of scope. Everything connects to everything.
  • Scoping once. Scope is not a document you write. It is a boundary you maintain through new contracts, new hires, new systems.

What to actually do

Draw the data flow first. Where does CUI enter, where does it rest, where does it go, who touches it. On paper, before you buy anything.

Then decide where you want it to live — rather than accepting where it currently lives.

Then move it there and close the other doors.

Then categorise every asset into the five buckets, and write down your justification for each. That written justification is the saving.

Then, and only then, start implementing controls — against the reduced boundary you just built.

Doing these in this order is, in my experience, the single largest cost difference between two otherwise identical small contractors.

This work survives the reform

Phase II third-party assessment was suspended in July 2026 and the reform task force reports in September. Plenty of contractors are using that as a reason to pause.

Scoping is the wrong thing to pause on. Every plausible outcome of the review — expanded self-assessment, risk-tiered assessment, reduced documentation — still requires you to know which systems handle CUI. There is no version of this where the boundary stops mattering, because the boundary is not a CMMC artefact. It is how you actually protect the information.

Do this now, while nobody is at the door.

Where to start

The CMMC readiness quiz takes two minutes and will tell you roughly where your boundary sits today.

The CMMC guide walks the full path for small defense contractors, scoping included.

And if you are FCI-only and Level 1 is your ceiling, the Level 1 packet is free — take it and do it yourself.

I’m Ken Haynes. I run CyberCloudAI — CMMC readiness, fractional CISO leadership, and AI tooling for defense contractors. General information, not legal advice; scoping decisions should be documented and defensible against your own contracts.


Discover more from CyberCloudAI.tech

Subscribe to get the latest posts sent to your email.

Scroll to Top