Most teams approach Cybersecurity Maturity Model Certification (CMMC) Level 2 as a list of 110 controls to satisfy. That framing is correct but incomplete. Before any control applies, you have to decide where it applies. That decision is your assessment scope, and it is the most consequential and most frequently mishandled part of the entire effort.
Over-scope and you pay to secure systems that never touch sensitive data. Under-scope and an assessor finds Controlled Unclassified Information (CUI) on a system you excluded, which can end an assessment before it finishes. This guide explains how to draw the boundary deliberately.
Start with the Data (not the Network)
CMMC Level 2 protects Controlled Unclassified Information (CUI). Level 1, by contrast, protects only Federal Contract Information (FCI) and carries fifteen basic safeguarding requirements. Level 2 aligns fully with NIST SP 800-171 and its 110 requirements across 14 control families. The first scoping question is therefore not architectural. It is informational: where does CUI actually live, move, and rest in your organization?
- Identify every contract and data flow that introduces CUI.
- Trace each flow through email, file storage, collaboration tools, endpoints, and any printed output.
- Note where CUI is created, where it is received, and where it is transmitted onward to subcontractors.
The question that reframes every engagement
A team will report that all CUI is in the cloud, and then an assessor asks whether anything is ever printed. The moment the answer is yes, physical facilities, devices, and personnel re-enter scope. Scope is defined by where CUI exists, not by where you would prefer it to exist.
Sort Assets into CMMC Categories
The program defines several asset categories, and each is treated differently in an assessment. The practical goal is to keep the set of assets that store, process, or transmit CUI as small and as clearly bounded as is realistic, while honestly accounting for the systems that protect or connect to that boundary.
CUI Assets
Anything that stores, processes, or transmits Controlled Unclassified Information. These are fully in scope.Security Protection Assets
Providers of security functions to the boundary, such as identity providers and logging systems.Contractor Risk Managed Assets
Assets that can access the environment but are governed by policy rather than full assessment.Out-of-Scope Assets
Assets that are physically or logically separated and never handle CUI.
Write your System Security Plan (SSP)
Both self-assessments and third-party assessments require a System Security Plan that describes the assessment scope, the major system components, and how each control is implemented. The plan has to describe the environment that actually exists. A common and expensive failure is a plan that describes intended practices that are not consistently performed. Documented practices that the environment does not actually follow do not survive an assessor's scrutiny.
Need help writing your CMMC assessment boundary?
YGI has helped hundreds of companies achieve compliance.
Book a CallPressure-test the Boundary
A gap assessment is not a formal step in certification, but it is the most useful first move available to you. It is a point-in-time review of your current program against the requirements, and it surfaces scoping errors while they are still inexpensive to fix. Many organizations conduct gap, readiness, and mock assessments at different stages. Treating the readiness review as a separate workstream, rather than a footnote inside remediation, is one of the clearest markers of teams that pass cleanly.
110
NIST SP 800-171 Requirements at CMMC Level 2
14
Control Families
180 Days
Maximum window to Close a POA&M Item
Scoping with YGI
A configuration change cannot fix a scoping error. By the time an under-scoped boundary is discovered, the cost is measured in re-assessment fees and lost contract time. Scoping rewards judgment built from many engagements: knowing which assets a particular assessor will challenge, where CUI tends to leak across boundaries, and how to keep an enclave small without leaving a gap. That judgment is the core of what YGI Solutions brings to a Level 2 program, and it is the hardest part to build from scratch under contract pressure.