CMMC scoping guide
Scoping is where most CMMC Level 2 programs go off the rails. Get it wrong and you’re either hardening systems that never needed to be in scope, or hiding from controls you can’t escape. This guide walks you through the asset categories, boundary decisions, and documentation an assessor expects to see.
Get the guide
TABLE OF CONTENTS
Every dollar you spend on CMMC controls is a dollar you spend because of how you scoped your environment. A clean scope means fewer systems to harden, less documentation to maintain, and a faster path to assessment. A messy scope means months of remediation and a much bigger compliance bill.
This guide is the same scoping reference we walk our own clients through before we touch their System Security Plan. It covers every asset category in the CMMC Level 2 model, what triggers each one, and how to defend your decisions to an assessor.
Who it’s for:
- Defense contractors getting ready for a CMMC Level 2 assessment
- IT and security leaders trying to shrink scope before remediation gets expensive
- Compliance teams writing or revising the asset inventory in their SSP
- Anyone who’s been told their scope is “too big” or “too small” and needs to figure out why
Click the Download Free Guide button to get the full PDF. No follow-up calls, no sales pressure.
CMMC Level 2 Scoping After the Final Rule
Watch our free playlists on YouTube where we walk through real-world scoping questions and decisions from defense contractors.
What’s Inside the Guide
The guide is built around the practical scoping decisions defense contractors make every day, mapped to what assessors actually look for.
- The five CMMC Level 2 asset categories explained: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets
- How CUI flow determines which systems land in scope (and which don’t)
- Boundary decisions: enclaves, network segmentation, and when each makes sense
- How to handle gray-area assets like personal devices, contractor laptops, and shared infrastructure
- Documentation an assessor will ask for to verify your scoping decisions
- The most common scoping mistakes and how to fix them before they cost you
Why Scoping Decisions Matter More Than Controls
Most contractors who fail their CMMC assessment didn’t fail because a control was misconfigured. They failed because their scope didn’t match reality. Either CUI was flowing through systems they hadn’t included, or assets they thought were out of scope turned out to be in.
Getting scoping right is the highest-leverage thing you can do early in your CMMC program. Every control you implement is anchored to it. Every dollar of remediation budget depends on it. Every assessor question starts there.
This guide gives you the framework to make those decisions defensibly the first time.
Don't miss these
No one wants to start from blank templates.
No one wants to start from
blank templates.
Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.


