If your organization handles Controlled Unclassified Information (CUI) under a federal contract, every system, device, and person that touches it falls within your compliance scope — and everything in that scope must meet the safeguarding requirements of NIST 800-171.
That makes scoping CUI one of the most consequential exercises in your entire compliance program.
Where exactly does CUI live and move in your environment? Answer this one question well and you have a defensible assessment boundary you can secure and document. Without a clear answer, you risk either spending resources securing systems that never touch CUI, or leaving gaps that your self-assessment score can’t cover.
This article walks through the scoping process in three stages: identifying what's in scope, mapping how CUI flows through your environment, and how to limit CUI scope.
Stage 1: Identify what's in scope
Under the CMMC Level 2 Scoping Guide and 32 CFR §170.19, every asset in your environment falls into one of five categories, and each is treated differently:
- CUI Assets process, store, or transmit CUI directly: the file servers, engineering workstations, email systems, and databases where CUI actually lives. These are subject to the full set of NIST 800-171 requirements.
- Security Protection Assets (SPAs) provide security functions for your CUI environment: firewalls, SIEM tools, endpoint detection, identity and MFA services. They don't hold CUI, but they generate Security Protection Data and fall within assessment scope.
- Contractor Risk Managed Assets (CRMAs) could access CUI but are prevented from doing so by your policies and practices. They stay in scope but carry lighter requirements, provided your documentation clearly shows how CUI is kept off them.
- Specialized Assets are things like IoT devices, operational technology, and government-furnished equipment that can't be secured through standard methods. They're documented in your SSP and managed through risk-based practices rather than evaluated against the full 800-171 control set.
- Out-of-Scope Assets can't process, store, or transmit CUI and provide no security protections for the assets that do. They carry no CMMC obligations, but be prepared to justify why an asset qualifies, whether through physical separation, logical separation, or the nature of its function.
At this stage of the scoping process your main task is creating asset inventory: every system, application, device, and service in your environment, each assigned to one of these categories with a documented rationale.

Recommended reading
An Expert’s Guide to Level 2 Scoping & Asset Categories
Read MoreStage 2: Map how CUI flows
An asset inventory is a snapshot of where CUI lives, but your scope is defined by everywhere it goes, not just where it rests. Trace each type of CUI you handle through its full lifecycle:
- Where does it enter your systems? Government portals, prime contractor file transfers, email attachments from a program office, physical documents that get scanned. Each entry point is in scope.
- Where does it get accessed? Follow the information into the systems where people actually use it: CAD and PLM systems for technical data, analysis tools, proposal development environments, shared drives where working files accumulate. Include the collaboration layer, since CUI referenced in a chat thread or pasted into a ticket is CUI in that system.
- Where does it get stored? Primary storage, backups, archives, and the informal copies that accumulate in download folders and local drives. And don’t forget backups: if CUI is on the file server, it's in the backup system too.
- Where does it leave? Deliverable submissions, subcontractor transfers, printing, removable media. Every subcontractor transfer extends the obligation beyond your boundary, and your flowdown terms are part of your scoping picture.
- Who touches it? Which personnel access CUI, from which locations and devices, with what training? Remote work arrangements belong in this analysis, since a home office where CUI is regularly accessed is part of the environment.
Create a data flow diagram paired with your network diagram, showing CUI's movement across your environment and the boundary around everything it touches. Both are core scoping documentation: your SSP and NIST 800-171 self-assessment need to match them.
As Mike Gallagher put it during the assessor panel at the Secureframe National Cybersecurity Summit: "Always start with your data flow. How is CUI flowing into your environment? Where is it flowing to? And in order to minimize scope, how do you put the boundaries in place to minimize that as much as possible?"
Recommended reading
Examples of CUI for Defense Contractors
Read MoreStage 3: Limit your CUI scope
With CUI's actual footprint mapped, you can now shrink it. Every system you remove from CUI's path is a system you don't have to secure to NIST 800-171 standards, document in your SSP, or account for in your self-assessment. Scope reduction isn't about lowering the security bar; it's about narrowing the environment that must meet it.
Minimize your CUI exposure
Legacy CUI from completed contracts, duplicate copies, and forgotten downloads all extend your scope. Before securing where CUI lives, reduce how much of it exists, subject to your records retention obligations and approved destruction methods.
Ask your prime or government agency to limit CUI sharing to what's strictly necessary for your scope of work. CUI that never reaches your environment is CUI you don't have to protect, document, or account for in your self-assessment. The DoD actually encourages primes to work with subcontractors to limit CUI flowdown where possible, since fewer people touching sensitive data is better for the supply chain's overall security posture, not just your compliance program.
Narrow where CUI lives
If CUI currently spreads across three file shares, two collaboration tools, and everyone's inbox, designate authorized locations and migrate it there. Fewer authorized locations means fewer CUI Assets, simpler monitoring, and clearer training for your team.
Limit access
Most organizations discover that far fewer people need CUI access than currently have it. Every user removed from CUI access simplifies training requirements, account management, and your self-assessment.
Create formal CUI flows
The mapping stage should reveal whether CUI is moving through channels it shouldn't: personal email, unmanaged devices, consumer file sharing. Closing these paths through policy, data loss prevention controls, and user training keeps your mapped boundary from expanding.
Segment your network
Logical separation between CUI systems and the rest of your environment is what makes out-of-scope designations defensible. Without enforced separation, it's hard to justify why any connected system isn't in scope.
Use a CUI enclave
A secure enclave combines all of these strategies by confining CUI to a purpose-built, isolated environment. Your compliance boundary becomes the enclave itself rather than your entire infrastructure. For most small and mid-sized contractors, this is the most significant scoping decision available you‘ll make.
Recommended reading
What Is a CUI Enclave? How to Reduce CMMC Scope and Compliance Costs
Read MoreKeeping your scope accurate over time
Scope drifts. New contracts bring new CUI categories, new tools enter the environment, teams change how they work, and the boundary you documented last year stops matching reality.
Build periodic scoping reviews into your compliance process: revisit your asset inventory, data flow diagrams, and System Security Plan (SSP) whenever you take on a new contract involving CUI, adopt a new system that could touch it, or change how CUI enters or leaves your environment.
This scoping work becomes the foundation of your SSP, the controls you implement, and your NIST SP 800-171 self-assessment score. Getting your scope right, and keeping it accurate, is what makes the rest of your compliance program run smoothly.