CMMC and NIST 800-171
The Four Scoping Documents an Assessor Will Ask You For
Missing any of the four required scoping documents during a CMMC assessment can lead to findings that threaten your contract. The CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and Authorized User List must all be ready. Knowing what each one covers and why it is needed helps you avoid costly delays.
What are the four scoping documents required for a CMMC assessment?
The CMMC Scoping and Assessment Guides Level 2 v2.13 require you to produce four specific artifacts before any assessment can proceed:
- CUI Flow Diagram: This shows how Controlled Unclassified Information (CUI) moves through your systems and organization.
- Network Boundary Diagram: This defines your IT environment and illustrates how systems are segmented or protected.
- Physical Site Diagram: This maps out where protected systems and data reside physically.
- Authorized User List: This lists every person with access to your CUI environment.
Each document provides a different view of your environment. Together, they allow an assessor to define the scope of your assessment and ensure you are protecting CUI as required under NIST SP 800-171 Rev 2 and 32 CFR Part 170.
Why are these documents so important for CMMC scoping?
Scoping is the process of defining what parts of your environment must be assessed. According to 32 CFR 170.19(c)(1) Table 3, assets fall into five categories: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out of Scope Assets. CUI Assets are assessed against all 110 controls, while other assets may have reduced requirements.
The four scoping documents are the primary evidence you provide to justify which assets belong in each category. Without them, you cannot demonstrate that you have properly identified and protected CUI, or that you have kept out-of-scope assets truly separate. An incomplete or missing artifact is a red flag for assessors and can result in findings that must be addressed before you can proceed.
What does each scoping document need to include?
CUI Flow Diagram: This document needs to show every point where CUI enters, moves through, is processed by, or leaves your environment. It should be specific about which systems, applications, and users interact with CUI. This is the foundation for all other scoping activities. If CUI flows into a system or location, that asset is in scope.
Network Boundary Diagram: This diagram should display all the parts of your IT environment that connect to CUI Assets, including firewalls, routers, cloud services, and segmentation points. It helps the assessor see how you keep in-scope and out-of-scope assets separated, and whether your security protections are effective.
Physical Site Diagram: A physical map of your facilities, showing where CUI is stored, processed, or accessed. This could be offices, server rooms, or any location with in-scope equipment. It is critical for demonstrating compliance with physical protection controls under the Physical Protection (PE) family.
Authorized User List: A current list of all individuals with access to CUI or CUI Assets. This should include employees, contractors, and any third parties. It is key evidence for Access Control (AC) and Personnel Security (PS) requirements.
What happens if you are missing one of these documents?
Missing or incomplete scoping documentation is one of the most common findings in CMMC assessments. Without these artifacts, you cannot prove you have identified all CUI Assets or maintained required separations. This will almost always delay your assessment and could lead to a failed outcome. Even if you are self-assessing, you still need to maintain these documents to support your SPRS score and annual senior official affirmation.
Remember, with the current suspension of third party certification as of July 2026, the responsibility to get scoping right now falls directly on your organization. The Department of War continues to enforce compliance through self assessments and government-led reviews. The senior official who signs your annual affirmation is personally liable for its accuracy under the False Claims Act. Inflating your score or skipping documentation increases your risk, not the other way around.
How do these documents support your NIST SP 800-171 compliance?
Each of the four scoping documents ties directly to specific NIST SP 800-171 Rev 2 requirements:
- The CUI Flow Diagram supports your ability to identify CUI and ensure it is always protected.
- The Network Boundary Diagram is essential for controls related to network segmentation, monitoring, and protection.
- The Physical Site Diagram is tied to controls on physical access and facility security.
- The Authorized User List is required to demonstrate you control and limit access to CUI as required under several Access Control and Personnel Security practices.
These documents are more than administrative. They are the first step in proving you meet the 110 controls and 320 underlying assessment objectives required at Level 2.
What are the risks if your scoping is inaccurate or incomplete?
The False Claims Act has been used against contractors who falsely certified compliance or failed to properly protect CUI. In several cases, companies faced consequences for not having basic documentation, failing to use FedRAMP authorized email, or lacking a system security plan. Liability can extend beyond your company to primes, subcontractors, affiliates, and even private equity owners. Whistleblowers can bring these issues to the government’s attention through qui tam actions.
Proper scoping is the first and most important step in protecting your organization from these risks. You can find more information about CMMC and NIST SP 800-171 requirements in NIST’s official documentation.
Common questions
What if my environment is very small? Even small environments require all four scoping documents. You must show exactly where CUI is processed, stored, or transmitted, and who can access it.
Do I need to update these documents every year? Yes. You are required to maintain current scoping documentation, especially when submitting your annual self assessment and senior official affirmation.
Can I use existing network diagrams or asset lists? You can, but only if they specifically address CUI flow, boundaries, physical locations, and authorized users as required for CMMC scoping. Generic IT documentation often does not meet these needs.
How to Prepare Your CMMC Scoping Documents
If you need to prepare for a CMMC assessment or simply want to ensure your scoping documents are complete, consider applying for the Cyber Grants Alliance CMMC Gap Assessment Grant. This in kind grant is delivered as services and covers all 110 NIST 800-171 controls for qualifying defense contractors. Learn more about how it can support your compliance at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/. Getting your scoping right is the first step to real compliance, and risk reduction.