Built by Velocity Technologies for defense contractors, manufacturers, and subcontractors.
(602) 425-5630

CUI scoping, asset inventory, and boundary design

The fastest way to overspend on CMMC is to scope the environment poorly. We start here so you build smarter, spend less, and pass assessment with confidence.

Author: Velocity CMMC Team · Reviewer: Velocity CMMC Review Team · Last reviewed: July 21, 2026

Official sources reviewed

Contract language, current regulations, and official CMMC program guidance control scoping decisions.

Last reviewed July 21, 2026 for current CMMC program sources.

Start with the boundary, not the technology

Defense contractors often jump straight into technology purchases before they have defined what actually processes, stores, or transmits CUI, what systems protect those assets, and what can remain outside the assessment boundary entirely. That is the wrong order — and it is an expensive mistake.

A properly scoped CMMC environment is smaller, less costly to implement, and produces cleaner, more defensible evidence. The boundary you define today determines the cost of everything downstream: technology, remediation, documentation, and assessment prep.

What this service covers

  • CUI and FCI workflow discovery — trace how controlled information enters, moves through, and exits the environment
  • Asset inventory by category — categorize every system by its role: CUI-in-scope, security-relevant, or out-of-scope
  • System interconnections and external service review — identify cloud services, MSP connections, VPNs, and external systems that touch the boundary
  • Network diagram and data-flow diagram development — visual documentation of the environment as assessors expect to see it
  • Boundary reduction and separation strategy — identify legitimate scope-reduction options before you commit to an architecture

Asset categories CMMC uses

CMMC scoping guidance (derived from NIST 800-171 and DoD assessment guidance) organizes assets into categories that determine how they're treated:

  • CUI Assets — systems that process, store, or transmit CUI; fully in scope
  • Security Protection Assets — systems that protect CUI assets (firewalls, IAM, logging); still in scope
  • Contractor Risk Managed Assets — systems with network connectivity but no CUI interaction; managed separately
  • Specialized Assets — OT, IoT, and government-furnished equipment with specific handling rules
  • Out-of-Scope Assets — physically and logically separated from CUI; don't require full assessment coverage

Understanding which category each asset falls into is the core output of a scoping engagement — and the foundation for every SSP and POA&M decision that follows.

Common scope deliverables

  • Boundary definition memo
  • Asset inventory with category and treatment notes
  • Data-flow and network diagrams
  • External service provider (ESP/MSP) list
  • Scope reduction options analysis
  • SSP boundary section inputs

Timeline

  • Small environments: 2–3 weeks
  • Mid-size environments: 3–5 weeks
  • Complex/multi-site: 5–8 weeks

Timeline depends on environment complexity, existing documentation, and stakeholder availability.

Common scoping mistakes that inflate cost

Pulling everything into scope by default

Without a deliberate scoping exercise, teams treat every networked device as "in scope." This inflates the remediation list, the SSP, and the assessment surface significantly.

Assuming GCC High resolves the scoping question

Moving to GCC High without first scoping the environment often expands cost without solving the underlying boundary problem. Scoping should happen before architecture decisions.

Skipping external provider documentation

Cloud, MSP, and external IT or cybersecurity providers should be documented when their services or assets process, store, or transmit CUI or security protection data, or provide security capabilities used to meet CMMC requirements.

Building diagrams that don't match reality

Assessors compare SSP documentation against what they observe. Network and data-flow diagrams built after the fact — without following actual CUI flows — create inconsistencies.

Leaving separation strategy until remediation

Scope reduction often requires physical or logical separation. Decisions made late in the process are more expensive to implement and create delays before assessment.

Treating scoping as a one-time activity

Contract scope changes, new cloud services, and technology additions affect the CUI boundary. Scoping must be maintained — not just completed once before the first assessment.

Ready to define your boundary?

A scope workshop is the right first step — whether you're months from an assessment or just starting to plan. We'll walk through your environment, map CUI flows, and identify what's actually in scope before you commit to any technology or remediation spend.

Related: Scope Sprint package · boundary memo proof preview · scope-first CMMC consulting · CMMC Scoping and Boundary Guide · Readiness Assessment · GCC High vs. Enclave