Koop CMMC Scoping guide

CMMC scoping guide: how to define your assessment boundary

Key takeaways

  • Scope is a design choice that sets your cost. Every asset inside the boundary is one you secure, document, and prove for years, so drawing it tight is what keeps the program affordable.
  • The July 2026 Phase 2 pause raised the stakes on scoping. With third-party audits suspended, your self-assessment and SPRS score are the government's main view of your compliance, and your affirmation carries the liability.
  • FCI puts you at Level 1 and 15 requirements, CUI puts you at Level 2 and all 110, so scoping starts with knowing which one you actually hold.
  • Build the boundary from the data outward: trace one piece of CUI end to end, sort every asset it touches into the five categories, enforce the line with configuration, and document it in the SSP.
  • An enclave shrinks the scope and the bill, but only if it holds. Wall CUI off and most of your systems drop out of scope, though one leak past the wall puts them right back in.

CMMC scoping is how you identify every asset, person, and facility that handles federal contract information or controlled unclassified information, plus the security systems that guard them, like firewalls, logging, and identity tools. That set is your assessment boundary. It decides what an assessor evaluates and what you pay to secure.

Most contractors who fail a CMMC assessment do not fail on technology. They fail on scope. Set the boundary too wide, and you spend months hardening machines that never touch CUI. Set it too narrow and an assessor finds the gap you left open. Either way, you have spent time and money on the wrong work before your real security even begins.

Scope is not paperwork you finish at the end. It is a design decision you make at the start, and it is the one part of CMMC you still fully control.

The Phase 2 pause put your self-assessment center stage

For two years, the industry braced for third-party audits. Then on July 13, 2026, the Department of War suspended CMMC Phase 2, the stage that would have required a C3PAO to certify your Level 2 environment. That mandate was set for November 10, 2026. It is now on hold, along with Phases 3 and 4, while a 60-day reform task force reviews the program.

The suspension made headlines, but CMMC did not go away. Phase 1 has been in force since November 10, 2025, and nothing about it changed. You still self-assess. You still post your score to SPRS. You still sign an annual affirmation. NIST SP 800-171, DFARS 252.204-7012, and FedRAMP Moderate for cloud CUI all still apply exactly as they did the day before the announcement.

What actually changed is who checks your work. Until the pause lifts, contracts can carry only Level 1 (Self) or Level 2 (Self) designations. No contracting officer can require a C3PAO certification during the suspension. The outside auditor who was going to validate your boundary is gone, and your self-declared scope is now the government's primary view of your compliance.

That shift puts more weight on how you scope. When a signature replaces an audit, the signature carries the liability. Get the boundary wrong, and you are not failing a test in a controlled room. 

In June 2026, Huntsville contractor LOGZONE agreed to pay $507,144 to settle False Claims Act allegations that it billed the Navy for years while failing to implement the cybersecurity controls its contracts required. When the government assessed its systems, it scored -170 on a scale that tops out at 110. A routine assessment drove the case. That is the enforcement model you are operating in right now, and it runs straight through the scope you draw.

FCI is Level 1, CUI is Level 2. Know which you hold.

Your data type decides your level, and your level decides everything downstream. Before you draw a single boundary, you have to know whether you hold federal contract information, controlled unclassified information, or both.

Federal contract information is the floor. It is any non-public information the government gives you or that you generate for the government under a contract, minus the obvious exclusions like public websites and routine payment processing. Almost every defense contractor holds FCI. It puts you at Level 1, assessed against the 15 basic safeguarding requirements in FAR 52.204-21.

Controlled unclassified information is the trigger. It is government information that a law, regulation, or government-wide policy requires or permits you to safeguard, defined by category in the NARA CUI Registry. If you hold CUI, you are at Level 2, assessed against all 110 requirements in NIST SP 800-171. That jump from 15 requirements to 110 is the single most expensive line in your compliance budget, which is why getting the data type right comes first.

All CUI in a contractor's possession is also FCI. Not all FCI is CUI. Picture CUI as the smaller, more sensitive circle sitting inside the larger FCI one. Two terms blur that picture, and both collapse into CUI once you look closely.

Term What it actually is Where it lands you
CTI (Controlled Technical Information) A category of CUI marked CUI//SP-CTI, covering things like engineering drawings, specs, and source code with a military or space application Level 2. If you hold CTI, you hold CUI.
ITAR data Export-controlled technical data, which maps to the CUI Specified category CUI//SP-EXPT Level 2, plus separate export-control obligations that CMMC does not cover on its own

Do not scope from what you assume you hold. Scope from what your contracts and your incoming data actually contain. A single email from a program office, marked CUI, can turn a shop that believed it was FCI-only into a Level 2 environment overnight. When a marking shows up you did not expect, treat the data as CUI and confirm with the originator who sent it.

Build a defensible boundary in six steps

Scoping is not a meeting where you gesture at a network diagram. It is a sequence you can repeat and defend, and it runs in order. Skip ahead, and you end up redrawing the line twice.

  1. Read the contract before you touch the network

    Your obligations live in the contract language, so that is where you start. The DFARS and FAR clauses, the CUI guidance, and any DD Form 254 tell you what data you are receiving and what you owe on it. Opening the network first only tells you what you own, which is the wrong question this early and the reason so many teams end up protecting the wrong assets.

  2. Follow one piece of CUI from arrival to destruction

    Trace it end to end, noting where it lands, who opens it, where it gets copied, what backs it up, and where it leaves. This walk is where hidden scope surfaces. The shared inbox nobody thought about, the Teams channel, the ticketing system, the personal phone syncing a folder, the backup quietly replicating to a consumer cloud. An assessor will follow that same path to test your boundary, so map it before they do.

  3. Sort each asset into a category, and write down why

    The reason carries more weight than the label. A Contractor Risk Managed Asset or a Specialized Asset stands or falls on the risk justification behind it, not the name you attached, and a bare label with no reasoning is the first place an assessor probes.

  1. Draw the line and make it visible

    Mark the boundary on a network diagram and a data-flow diagram, showing every point where CUI enters or leaves. The line has to be enforced by configuration. A boundary an assessor cannot see in your architecture is a boundary that does not exist.

  2. Put all of it in the SSP

    The System Security Plan holds the scope together and is the foundation your SPRS score is built on, capturing the inventory, the diagrams, the categories, and the service providers. No current SSP means no defensible score, and a score with no plan behind it is the same gap between a claimed number and what was actually implemented that cost LOGZONE half a million dollars.

  3. Keep the boundary alive after assessment day

    Scope drifts. A new contract, a new tool, an acquisition, or a fresh CUI flow can all move the line, and a boundary nobody maintains quietly stops matching what you actually run. Tie scope review to your change process so the diagram and the reality never separate.

Shrink your scope and your bill with an enclave

Every earlier section points at one lever. If in-scope assets drive cost, then the cheapest CMMC environment is the smallest one you can legitimately draw. An enclave is how you build it small on purpose.

A CUI enclave is a walled-off environment where all your CUI lives, separated from the rest of the business by configuration. Everything inside faces the full weight of the 110 requirements. Everything outside, if the wall holds, stays out of scope. Instead of putting your whole company through Level 2, you scope one controlled zone.

The savings are not marginal, and the reason is simple. An enclave shrinks the number of machines, people, and facilities that face the 110 requirements, and fewer of each means less to do at every stage. Every asset you keep outside the wall is one you never have to harden, document, monitor, or prove to an assessor, and every user outside it is a GCC High license and a training seat you never buy. Scope is the multiplier on almost every line of the invoice, so shrinking it is the one move that lowers all of them at once.

Most enclaves live in a FedRAMP-authorized cloud, the same environments DFARS requires for CUI, such as Microsoft 365 GCC High, Azure Government, or AWS GovCloud. Some contractors run a physical enclave instead, a locked room or a segmented on-premises network. The model matters less than the discipline behind it.

That discipline is the catch, and it is where enclaves fail. An enclave saves nothing if CUI leaks back out of it. The moment someone emails a CUI file to a commercial mailbox, saves it to a local desktop, or drops it in an unmanaged share, the wall is breached, and the outside environment is back in scope. This is also why a VLAN alone is not an enclave. Separation counts only when access controls and monitoring actively keep CUI inside, with evidence you can put in front of an assessor. Build the boundary, then hold the line, or the savings evaporate.

Five scoping mistakes that fail assessments

The failures that sink assessments are rarely complicated. They are the same handful of scoping errors, made by people who understood the controls but drew the boundary wrong. Here are the five that show up most.

  1. Remote work quietly extends your boundary

    A person working from home who prints CUI or copies it to a USB stick has just pulled their home office into scope. The fix is prevention. Block local printing and removable media for anyone who touches CUI, so the boundary stops at the enclave.

  2. The systems that protect CUI get missed

    Contractors map the systems that hold CUI and forget the ones that guard it. Your SIEM, logging platform, identity provider, backup, and device management all count as Security Protection Assets, and so does the data they hold. They feel invisible because they never touch CUI directly, which is exactly why they get overlooked and exactly why assessors go looking for them.

  3. One CUI app can widen the whole boundary

    An ERP or file system that touches a single CUI field becomes a CUI Asset, and if it is wired into everything else, it brings the systems around it in with it. Contain the CUI-handling piece before the assessment, so one connected system does not expand the boundary to everything it touches.

  4. Commercial Microsoft 365 cannot hold CUI

    This is the most common real-world gap, and it is not a judgment call. DFARS 252.204-7012 requires any cloud that stores, processes, or transmits CUI to meet a FedRAMP Moderate baseline, and a December 2023 DoD memo set the equivalency bar high enough that commercial Microsoft 365 does not clear it. CUI sitting in a commercial tenant is a finding waiting to happen, and the answer is a compliant environment like GCC High.

  5. The boundary on paper is not the boundary you run

    After scope itself, the most common reason assessments fail is documentation that does not match reality. The SSP describes one environment, and the assessor walks into another. A boundary is only real when the diagram, the plan, and the live system all agree, so reconcile them before someone else does it for you.

How Koop keeps your scope accurate after day one

Everything above is work you can do by hand. The reason most teams do not keep it up is that scope is not a one-time task, it is a living record that has to match a moving environment, and hand-maintained records fall behind.

That is the specific problem Koop is built for. It is an AI-native platform that pulls compliance, third-party risk management, requirements management, and business insurance into one place, so the boundary you define and the evidence that proves it live in the same system. For CMMC specifically, Koop covers Level 1 and Level 2 readiness and generates the artifacts this guide keeps pointing at: the SSP, the POA&M, and the SPRS score, with GovCloud integrations for evidence and a gap analysis that strips out the controls that do not apply to your scope. 

The payoff shows up where scoping is hardest, in the upkeep. Drawing the boundary once is the easy part. Holding it steady month after month, so what you affirm to the government still matches what you actually run, is where a live system beats a static spreadsheet.

Frequently Asked Questions

  1. Is encrypted CUI still in scope?

    Yes. Encryption lowers risk, but it does not remove data from your boundary. Under 32 CFR Part 2002, CUI stays controlled until it is formally decontrolled, and the Department of War's CMMC FAQ confirms that encrypted CUI keeps the same control designation as its plaintext version. The systems that hold it stay in scope.

  2. Does my MSP need its own CMMC assessment?

    Usually not. An outside IT provider is treated as an External Service Provider and assessed as part of your scope, not certified separately. The one exception is a cloud provider that stores, processes, or transmits your CUI, which must meet the FedRAMP Moderate baseline under DFARS 252.204-7012.

  3. Can CUI and non-CUI data live on the same computer?

    Yes, but that device then becomes a CUI Asset measured against all 110 requirements unless you separate the CUI. The DoD Level 2 Scoping Guide requires logical or physical separation, and encryption by itself does not count as separation. Without it, the whole endpoint is assessed against the full control set.

article highlights: