Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

CMMC and NIST 800-171

CMMC Scoping: The Five Asset Categories Most Companies Get Wrong

If you are responsible for cybersecurity compliance at a small or mid-sized defense contractor, CMMC scoping is one of the most critical steps to get right. The Department of War’s CMMC program, defined in 32 CFR Part 170, requires you to accurately categorize your assets before you can even begin to assess compliance. Many companies make costly mistakes here, often due to misunderstandings about the five asset categories described in 32 CFR 170.19(c)(1) Table 3: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out of Scope Assets. Getting this wrong can lead to gaps in your System Security Plan (SSP), an inflated SPRS score, and exposure under the False Claims Act if your senior official affirms compliance that does not exist.

What are the five CMMC asset categories, and why do they matter?

The CMMC scoping process begins with mapping every information system asset to one of five categories. This step determines which assets will be assessed, which controls apply, and how much evidence you will need to provide. The five categories are:

  • CUI Assets: These are assets that process, store, or transmit Controlled Unclassified Information (CUI). They are assessed against all 110 NIST SP 800-171 Rev 2 controls. If you mishandle this category, you risk missing critical gaps, since every control applies, a misclassified system can undermine your entire assessment.
  • Security Protection Assets: These assets provide security functions for CUI Assets, such as firewalls, intrusion detection systems, or security monitoring tools. Only the controls relevant to their specific security function are assessed. Companies often over- or under-scope here, either missing key systems or unnecessarily expanding the assessment boundary.
  • Contractor Risk Managed Assets (CRMAs): These are assets that could access CUI but are managed with alternative, risk-based controls. At Level 2, they require a review of your SSP and a limited spot check. The most frequent mistake is treating CRMAs as fully out of scope, when in fact, they must be documented and reviewed. At Level 3, CRMAs are no longer a separate category and are assessed as CUI Assets.
  • Specialized Assets: This includes government furnished equipment, Internet of Things (IoT) devices, operational technology, and test equipment. These assets are subject only to an SSP review, not a full technical assessment. Companies often forget to list these assets in their SSP or fail to describe their handling and separation from CUI workflows.
  • Out of Scope Assets: These are assets that have no access to or impact on CUI and are fully separated from the CUI environment. The separation must be justifiable, simply stating an asset is out of scope is not enough. You must be able to prove the separation with diagrams and documentation.

How does CMMC scoping affect your self-assessment and legal exposure?

As of July 13, 2026, the Department of War suspended the CMMC Phase II third party certification requirement, pending a 60-day review. However, all other requirements remain in force: DFARS 252.204-7012, NIST SP 800-171 Rev 2, Level 1 and Level 2 self-assessments, SPRS posting, and annual senior official affirmation. With no C3PAO between you and the government, your senior official’s signature is the sole assurance. If your CMMC scoping is inaccurate and you affirm an inflated SPRS score, you increase your exposure under the False Claims Act. Past enforcement actions have targeted companies for inadequate vulnerability management, missing SSPs, and misrepresenting their compliance posture.

What evidence must you have to prove your CMMC scoping decisions?

Documentation alone is not enough. You need four scoping artifacts to defend your asset categorization:

  • CUI Flow Diagram: Shows how CUI moves through your environment.
  • Network Boundary Diagram: Maps the logical and physical boundaries between asset categories.
  • Physical Site Diagram: Demonstrates where assets are located and how physical access is managed.
  • Authorized User List: Identifies who can access each asset category.

If you cannot produce these artifacts, or if they do not clearly support your scoping decisions, your assessment will not stand up to scrutiny, whether from a government-led review or a False Claims Act investigation.

What are the most common mistakes companies make in CMMC scoping?

Most companies get tripped up in these five areas:

  • Over-including or under-including CUI Assets: Failing to identify every system that processes, stores, or transmits CUI leads to incomplete assessments.
  • Misclassifying Security Protection Assets: Not recognizing that security tools protecting CUI Assets are themselves in scope for relevant controls.
  • Ignoring CRMAs or treating them as out of scope: Not documenting alternative controls or failing to note that at Level 3, CRMAs become CUI Assets.
  • Forgetting Specialized Assets: Not listing government furnished equipment, IoT, or operational technology in the SSP, or failing to describe their risk management.
  • Weak justification for Out of Scope Assets: Simply declaring systems out of scope without providing evidence of separation.

Each of these mistakes can lead to a failed assessment, a lost contract, or legal risk if the government determines your self-assessment was inaccurate.

How should you approach CMMC scoping for Level 2 and Level 3?

For Level 2, you must assess all CUI Assets against the full 110 controls from NIST SP 800-171 Rev 2. Security Protection Assets are assessed only for the controls that apply to their function. CRMAs require careful documentation in your SSP and are subject to spot checks. Specialized Assets require an SSP review only, but must be clearly described. Out of Scope Assets must be truly separated, and you must be able to defend that separation.

At Level 3, CRMAs are no longer a separate category, they become CUI Assets and are fully assessed. This change is critical for companies planning to move from Level 2 to Level 3, as it expands the assessment boundary and increases the number of assets subject to the most rigorous controls.

For more on the official definitions and requirements, see the CMMC Scoping and Assessment Guides L2 v2.13.

Common questions

What happens if I misclassify an asset during CMMC scoping? If an asset is misclassified, you risk leaving gaps in your controls, which can lead to compliance failures and potential False Claims Act liability if your self-assessment is inaccurate.

Do I need to assess government furnished equipment? Yes, government furnished equipment falls under Specialized Assets. While it does not require a full technical assessment, you must describe how it is managed and separated from CUI workflows in your SSP.

Are Out of Scope Assets safe from review? Out of Scope Assets are not assessed, but you must be able to prove they are fully separated from CUI Assets. If the separation is not justifiable or defensible, those assets may be brought into scope during an assessment.

Closing section: Next steps for getting CMMC scoping right

Getting CMMC scoping right is a paperwork exercise, and it is also the foundation for your entire compliance program. If you are unsure whether your systems are properly categorized, it is worth getting outside help. The Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant, delivered as services, covering all 110 controls for qualifying defense contractors. This can help you identify exactly where your scoping or documentation might fall short before you sign your next annual affirmation. Learn more at Cyber Grants Alliance CMMC Gap Assessment Grant.

Accurate scoping is the first step to confident compliance, and to protecting your business from unnecessary risk.

At a glance

The five CMMC asset categories and how each is assessedThe five asset categories, 32 CFR 170.19(c)(1)CUI AssetsProcess, store or transmit CUIAssessed against all 110 controlsSecurity Protection AssetsProvide security functionsAssessed against relevant controlsContractor Risk ManagedCould but should not touch CUISSP review plus limited spot checkSpecialized AssetsGFE, IoT, OT, test equipmentSSP review onlyOut of ScopeCannot touch or protect CUINo assessment, separation must be justified
The five CMMC asset categories and how each is assessed
The five CMMC asset categories
The five CMMC asset categories

More on CMMC