CUI Scoping: What Belongs in the CMMC Assessment Boundary?
A practical method to scope systems that process, store, transmit, or protect CUI without turning the entire company network into the assessment boundary.
Read guide →Boundary and scoping questions: what's in scope, what's out, enclaves, VDI, and the assets that most often get scoped wrong.
A practical method to scope systems that process, store, transmit, or protect CUI without turning the entire company network into the assessment boundary.
Read guide →How a CUI enclave can reduce assessment complexity, what it does not solve, and which hidden dependencies often pull systems back into scope.
Read guide →What remote work changes in a CMMC environment: endpoints, local storage, printing, networking, support, physical exposure, and evidence.
Read guide →Why bring-your-own-device access creates CUI scope and evidence problems, plus safer patterns for small contractors that need flexibility.
Read guide →How printers and multifunction devices can process or store CUI, plus the configuration and evidence questions teams often miss.
Read guide →Why backups can silently expand CUI scope and how to document storage, encryption, access, retention, restoration, and provider responsibilities.
Read guide →Separate the systems that hold CUI from the systems that protect them, with practical examples for identity, logging, EDR, firewalls, and management tools.
Read guide →A focused Level 2 guide to Contractor Risk Managed Assets: what qualifies, why CRMAs stay in scope, what belongs in the SSP and network diagram, and when assessors can perform limited checks.
Read guide →How CMMC Level 2 treats Specialized Assets such as OT, IoT/IIoT, Government Furnished Equipment, restricted systems, and test equipment that can handle CUI but cannot be fully secured.
Read guide →
How Level 2 out-of-scope treatment works, what separation must accomplish, why 'no CUI intended' is not enough, and how the VDI keyboard/video/mouse condition affects endpoint scoping.
Read guide →