Skip to Content

How to Scope Your CMMC Level 2 Assessment Boundary

Scoping is the decision that shapes the cost, duration, and outcome of a CMMC Level 2 assessment. Get it wrong and no configuration change can save you.
June 2, 2026 by
How to Scope Your CMMC Level 2 Assessment Boundary
William Yeack (YGI Solutions)

Most teams approach Cybersecurity Maturity Model Certification (CMMC) Level 2 as a list of 110 controls to satisfy. That framing is correct but incomplete. Before any control applies, you have to decide where it applies. That decision is your assessment scope, and it is the most consequential and most frequently mishandled part of the entire effort.

Over-scope and you pay to secure systems that never touch sensitive data. Under-scope and an assessor finds Controlled Unclassified Information (CUI) on a system you excluded, which can end an assessment before it finishes. This guide explains how to draw the boundary deliberately.

Start with the Data (not the Network)

CMMC Level 2 protects Controlled Unclassified Information (CUI). Level 1, by contrast, protects only Federal Contract Information (FCI) and carries fifteen basic safeguarding requirements. Level 2 aligns fully with NIST SP 800-171 and its 110 requirements across 14 control families. The first scoping question is therefore not architectural. It is informational: where does CUI actually live, move, and rest in your organization?

  • Identify every contract and data flow that introduces CUI.
  • Trace each flow through email, file storage, collaboration tools, endpoints, and any printed output.
  • Note where CUI is created, where it is received, and where it is transmitted onward to subcontractors.

Sort Assets into CMMC Categories

The program defines several asset categories, and each is treated differently in an assessment. The practical goal is to keep the set of assets that store, process, or transmit CUI as small and as clearly bounded as is realistic, while honestly accounting for the systems that protect or connect to that boundary.

  • CUI Assets
    Anything that stores, processes, or transmits Controlled Unclassified Information. These are fully in scope.

  • Security Protection Assets
    Providers of security functions to the boundary, such as identity providers and logging systems.

  • Contractor Risk Managed Assets
    Assets that can access the environment but are governed by policy rather than full assessment.

  • Out-of-Scope Assets
    Assets that are physically or logically separated and never handle CUI.

Write your System Security Plan (SSP)

Both self-assessments and third-party assessments require a System Security Plan that describes the assessment scope, the major system components, and how each control is implemented. The plan has to describe the environment that actually exists. A common and expensive failure is a plan that describes intended practices that are not consistently performed. Documented practices that the environment does not actually follow do not survive an assessor's scrutiny.

Need help writing your CMMC assessment boundary?

YGI has helped hundreds of companies achieve compliance.

Book a Call

Pressure-test the Boundary

A gap assessment is not a formal step in certification, but it is the most useful first move available to you. It is a point-in-time review of your current program against the requirements, and it surfaces scoping errors while they are still inexpensive to fix. Many organizations conduct gap, readiness, and mock assessments at different stages. Treating the readiness review as a separate workstream, rather than a footnote inside remediation, is one of the clearest markers of teams that pass cleanly.

110

NIST SP 800-171 Requirements at CMMC Level 2

14

Control Families

180 Days

Maximum window to Close a POA&M Item

Scoping with YGI

A configuration change cannot fix a scoping error. By the time an under-scoped boundary is discovered, the cost is measured in re-assessment fees and lost contract time. Scoping rewards judgment built from many engagements: knowing which assets a particular assessor will challenge, where CUI tends to leak across boundaries, and how to keep an enclave small without leaving a gap. That judgment is the core of what YGI Solutions brings to a Level 2 program, and it is the hardest part to build from scratch under contract pressure.