Built by Velocity Technologies for defense contractors, manufacturers, and subcontractors.
(602) 425-5630
Velocity CMMC Resource Center

CMMC scoping and boundary FAQ: CUI, asset categories, enclaves, logical separation, and VDI

Use this guide to turn the official scoping rules into plain language, define the boundary, classify assets, and avoid common scoping mistakes that drive up cost.

Why scoping comes first

The official Level 2 Scoping Guide says the organization seeking assessment must define the CMMC Assessment Scope before the assessment. In plain English, that means you need to know which assets, systems, services, people, and connections are actually part of the environment being assessed.

This is the place where companies can save or waste the most money. A tight, justified scope can reduce remediation burden and make the assessment clearer. A sloppy scope can pull in unnecessary systems, vendors, and workflows.

The Level 2 asset categories

CMMC Level 2 asset categories
CategoryMeaningWhy it matters
CUI AssetsAssets that process, store, or transmit CUI.These are assessed against all applicable Level 2 requirements.
Security Protection AssetsAssets that provide security functions or capabilities for the environment.They are in scope and assessed against relevant Level 2 requirements.
Contractor Risk Managed AssetsAssets that are technically capable of handling CUI but are not intended to do so because of policy, procedure, and practice.They remain part of the Level 2 scope and must be treated carefully.
Specialized AssetsAssets like IoT, OT, restricted information systems, or test equipment that may not support full implementation in the usual way.They still require attention, documentation, and handling decisions.
Out-of-Scope AssetsAssets that cannot process, store, or transmit CUI and do not provide security protections for CUI assets, or are physically or logically separated.These are not assessed as part of the Level 2 scope.

The scoping guide also requires the asset categories to be documented in an asset inventory and supported with a network diagram.

Hard-copy CUI, logical separation, and encryption

DoD’s January 2026 FAQ added several very useful clarifications. If a company handles only hard-copy CUI and does not place it on an IT system, it does not need a CMMC assessment for that reason alone. The moment that information is entered into or stored on an IT system, the analysis changes.

The FAQ also says encryption alone does not create logical separation. That is a big one. Companies sometimes assume that because files are encrypted or a system uses encrypted storage, they can treat the system as outside the boundary. That is not the official position. The same FAQ also states that encrypted CUI remains CUI until it is formally decontrolled.

VDI and unmanaged endpoints

The official FAQ gives a specific path for when a VDI endpoint can remain out of scope. The endpoint has to be configured so it does not process, store, or transmit CUI beyond keyboard, video, and mouse functions, and a number of practical controls must be in place, including blocking copy/paste, file transfer, and printing in ways that would move CUI out of the controlled environment.

That does not mean every VDI design automatically keeps endpoints out of scope. It means the architecture and configuration have to support that conclusion.

What an enclave really is

An enclave is not a government-mandated buzzword. It is a practical way to define a smaller assessed boundary inside a larger company. The official scoping guidance allows the assessment scope to be the entire enterprise, a segment of the enterprise, or a specific enclave, as long as the scope is justified and documented correctly.

That is why enclave strategy should be framed as a scoping and architecture decision, not as a product purchase.

What a good scoping engagement should produce

  • A CUI and FCI discovery workshop.
  • A plain-language description of business workflows that create or receive CUI.
  • An asset inventory with the official asset categories applied.
  • A network diagram and data-flow diagram.
  • A list of external providers, cloud dependencies, and service responsibilities.
  • A written boundary statement that can be reused in the SSP and assessment preparation.

Frequently asked questions

What is the CMMC Assessment Scope?

The CMMC Assessment Scope is the set of all assets in the organization’s environment that are being assessed for the required CMMC status.

Do we have to document the scope?

Yes. The Level 2 Scoping Guide says the organization must document asset categories in an asset inventory and provide a network diagram.

Can we scope only a segment or enclave instead of the whole company?

Yes. The assessment can cover the full enterprise, a segment, or a specific enclave, as long as the scope is defined and justified correctly.

Does hard-copy-only CUI trigger an IT assessment?

No, not unless that hard-copy CUI is placed onto an IT system.

Does encryption alone make an asset out of scope?

No. DoD’s FAQ says encryption alone does not create logical separation.

Can encrypted CUI be treated as non-CUI?

No. The FAQ says encrypted CUI remains CUI until it is formally decontrolled.

Can VDI endpoints be out of scope?

Yes, but only if they are configured so that no CUI is processed, stored, or transmitted on the endpoint beyond keyboard, video, and mouse interaction and the required restrictions are in place.

Why do companies overspend on CMMC?

One major reason is poor scoping. They buy tools or redesign systems before they define the real CUI boundary and supporting assets.

Official sources reviewed

Use this guide to plan readiness and communicate clearly with buyers, primes, and internal stakeholders. Contract language, current regulations, and assessor guidance control.

Want help turning this into a real readiness plan?

Velocity CMMC can scope the environment, map CUI flows, organize the documentation package, support remediation, and help your team prepare for the right assessment path without pretending to be the certifier.