Open navigation menu - Kieri Solutions
The Complete Guide to CMMC Level 2 Scoping

CMMC scoping guide

Scoping is where most CMMC Level 2 programs go off the rails. Get it wrong and you’re either hardening systems that never needed to be in scope, or hiding from controls you can’t escape. This guide walks you through the asset categories, boundary decisions, and documentation an assessor expects to see.

Strategy and planning approach to CMMC Level 2 compliance for defense contractors

Get the guide

TABLE OF CONTENTS

Every dollar you spend on CMMC controls is a dollar you spend because of how you scoped your environment. A clean scope means fewer systems to harden, less documentation to maintain, and a faster path to assessment. A messy scope means months of remediation and a much bigger compliance bill.

This guide is the same scoping reference we walk our own clients through before we touch their System Security Plan. It covers every asset category in the CMMC Level 2 model, what triggers each one, and how to defend your decisions to an assessor.

Who it’s for:

  • Defense contractors getting ready for a CMMC Level 2 assessment
  • IT and security leaders trying to shrink scope before remediation gets expensive
  • Compliance teams writing or revising the asset inventory in their SSP
  • Anyone who’s been told their scope is “too big” or “too small” and needs to figure out why

Click the Download Free Guide button to get the full PDF. No follow-up calls, no sales pressure.

Kieri Solutions teal brand graphic representing CMMC compliance services

CMMC Level 2 Scoping After the Final Rule

Watch our free playlists on YouTube where we walk through real-world scoping questions and decisions from defense contractors.

What’s Inside the Guide

The guide is built around the practical scoping decisions defense contractors make every day, mapped to what assessors actually look for.

  • The five CMMC Level 2 asset categories explained: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets
  • How CUI flow determines which systems land in scope (and which don’t)
  • Boundary decisions: enclaves, network segmentation, and when each makes sense
  • How to handle gray-area assets like personal devices, contractor laptops, and shared infrastructure
  • Documentation an assessor will ask for to verify your scoping decisions
  • The most common scoping mistakes and how to fix them before they cost you

Why Scoping Decisions Matter More Than Controls

Most contractors who fail their CMMC assessment didn’t fail because a control was misconfigured. They failed because their scope didn’t match reality. Either CUI was flowing through systems they hadn’t included, or assets they thought were out of scope turned out to be in.

Getting scoping right is the highest-leverage thing you can do early in your CMMC program. Every control you implement is anchored to it. Every dollar of remediation budget depends on it. Every assessor question starts there.

This guide gives you the framework to make those decisions defensibly the first time.

Don't miss these

Is Your Security Plan Telling the Truth?
Server room corridor lined with racks in a data center covered by a System Security Plan
Is Your Security Plan Telling the Truth?
What Does the Government Actually Require of You Today?
A network of yellow lines connecting round nodes against a dark background.
What Does the Government Actually Require of You Today?
NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
Man at a desk in a dark office reading text on a computer monitor, NIST SP 800-171 Rev 3
NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline

No one wants to start from blank templates.

No one wants to start from
blank templates.

Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.