What Is Actually in Scope for CMMC?

CMMC scope begins with the information the organization must protect and follows where that information is received, created, stored, processed and transmitted. From there, the organization can determine which people, systems, services, security technologies and external providers affect the assessment environment.

Scoping is one of the most important CMMC decisions an organization makes.

Too broad, and the company may create unnecessary implementation cost, assessment complexity and ongoing operating burden.

Too narrow, and required systems, people or dependencies may be incorrectly excluded.

Hotman Group helps organizations understand CUI flows, technology dependencies and business processes so the resulting CMMC boundary is accurate, defensible and practical to operate.

CMMC scope should follow the real environment. It should not be expanded unnecessarily, and it should not be artificially narrowed around an architecture that does not reflect how the business actually handles CUI.

Who Can Help Us Determine CMMC Scope?

Look for a partner that understands CMMC requirements together with cybersecurity architecture, identity, cloud services, business processes, information flow and actual user behavior.

Hotman Group can help organizations:

  • identify where CUI enters the organization;
  • map where CUI is stored, processed and transmitted;
  • identify users with access;
  • evaluate systems and applications;
  • understand security protection dependencies;
  • evaluate external service providers;
  • analyze enclave options;
  • document the assessment environment;
  • and connect scope decisions to the broader CMMC implementation plan.

What Is CMMC Scope?

CMMC scope defines the environment relevant to the organization's assessment and implementation obligations.

The analysis begins with the information requiring protection and the systems, people and services involved in handling or protecting it.

Scope affects:

  • which systems require applicable controls;
  • which people participate in required processes;
  • what evidence must be produced;
  • what architecture must be documented;
  • what external providers matter;
  • and how large the assessment effort becomes.

Should We Start With a List of Computers?

No.

Start with information flow.

Ask:

  • What CUI do we receive or create?
  • Where does it enter?
  • Where is it stored?
  • Where is it processed?
  • How is it transmitted?
  • Who can access it?
  • What systems protect it?
  • What external services interact with it?

The asset inventory follows from understanding the environment.

Why Does CUI Matter So Much to Scope?

Because the requirement exists to protect controlled information.

The organization cannot accurately define its environment until it understands where that information exists and how the business uses it.

What Is Controlled Unclassified Information?

Controlled Unclassified Information, commonly called CUI, is information requiring safeguarding or dissemination controls under applicable federal requirements but that is not classified national security information.

For CMMC implementation, the practical question is not only the definition.

It is:

What information does this organization actually receive or create that must be protected?

How Do We Identify CUI?

The analysis may involve reviewing:

  • contracts;
  • contract clauses;
  • customer information;
  • technical data;
  • documents;
  • drawings;
  • emails;
  • shared repositories;
  • business workflows;
  • and information received from customers or government entities.

Do not assume every piece of information associated with a government contract is automatically CUI.

Should We Map CUI Flow?

Yes.

A useful CUI flow analysis should understand how information moves through the business.

For example:

customer or government source → user → communication system → application → storage → collaboration → downstream recipient.

Real workflows matter because CUI often moves differently than people initially assume.

Does Email Put a System in Scope?

If CUI is transmitted or stored through an email environment, that environment may become relevant to scope.

The organization should therefore understand whether CUI is:

  • sent by email;
  • received by email;
  • stored in mailboxes;
  • included in attachments;
  • or copied into other systems from email.

What About Microsoft Teams or Other Collaboration Platforms?

If CUI is shared, discussed, stored or transmitted through collaboration tools, those services and their supporting environment need to be considered in the scope analysis.

That is why user behavior matters as much as architecture diagrams.

What About File Storage and SharePoint?

If controlled information is stored in file repositories, the organization needs to understand:

  • where it lives;
  • who can access it;
  • how permissions work;
  • how sharing occurs;
  • how backups work;
  • and whether information moves into other services.

What About End-User Devices?

Devices used to access, process, store or transmit CUI may affect scope.

The organization should understand whether controlled information can be:

  • downloaded;
  • cached;
  • saved locally;
  • printed;
  • copied;
  • or otherwise processed on those devices.

What About BYOD?

Bring-your-own-device arrangements can materially complicate scope when personal devices can interact with CUI.

Organizations should understand:

  • what users can access;
  • whether information reaches the device;
  • what controls protect the device;
  • and whether the architecture can prevent controlled information from leaving the intended environment.

Are Users Part of CMMC Scope?

People matter because they interact with systems and information.

The organization should understand who:

  • accesses CUI;
  • administers relevant systems;
  • operates security controls;
  • supports the environment;
  • and performs required processes.

What About Administrators Who Do Not Read CUI?

Administrative access to systems that handle or protect CUI can still make those individuals and their activities relevant to the CMMC environment.

Scope should consider security influence, not only direct business use of the information.

What Are Security Protection Assets?

Some systems may not themselves store or process CUI but provide security functions protecting systems that do.

Examples may include technologies supporting:

  • identity;
  • authentication;
  • endpoint security;
  • logging;
  • monitoring;
  • network security;
  • vulnerability management;
  • and backup.

These dependencies need to be understood during scope analysis.

Does That Mean Every Security Tool Is Fully in Scope?

Not necessarily in exactly the same way.

The important point is to understand how the tool supports protection of the CMMC environment and how applicable assessment requirements treat that dependency.

What About External Service Providers?

External providers may matter when they:

  • store or process CUI;
  • manage relevant systems;
  • provide security functions;
  • administer the environment;
  • provide cloud services;
  • or otherwise influence protection of CUI.

Organizations should understand these relationships early rather than discovering them immediately before assessment.

What About Managed Service Providers?

If an MSP administers systems in the CMMC environment, its people, processes, tools and access may materially affect the organization's security posture and assessment preparation.

The relationship should be evaluated as part of architecture and operating-model design.

What About Managed Security Service Providers?

An MSSP may provide security capabilities such as:

  • monitoring;
  • endpoint security;
  • logging;
  • incident response;
  • vulnerability management;
  • or other security functions.

Those dependencies should be understood in the context of the controls the organization is relying on them to support.

Can We Use Cloud Services for CMMC?

Cloud services can be part of an appropriate CMMC architecture.

The organization needs to understand:

  • what information the service handles;
  • what security responsibility belongs to the provider;
  • what responsibility remains with the organization;
  • what assurance the provider offers;
  • and what contractual or government requirements apply.

What Is Shared Responsibility?

Cloud and managed services divide security responsibilities between provider and customer.

A secure provider does not mean the customer has no implementation obligations.

The organization needs to know exactly which controls it is relying on the provider to support and which controls it must still operate itself.

Can We Reduce CMMC Scope?

Potentially.

Organizations can sometimes redesign information flows or architecture so CUI is handled within a more controlled environment.

Possible approaches may involve:

  • limiting where CUI is stored;
  • restricting access;
  • separating workloads;
  • using a dedicated environment;
  • changing collaboration methods;
  • or reducing unnecessary copies of controlled information.

The design still has to support the business.

Should We Make Scope as Small as Possible?

Not necessarily.

Smaller scope can reduce complexity, but an architecture that is too restrictive or disconnected from normal operations can create:

  • poor usability;
  • workarounds;
  • shadow systems;
  • operational inefficiency;
  • and new security problems.

The better objective is appropriate scope.

What Is a CMMC Enclave?

An enclave is a deliberately bounded environment used to handle CUI or support relevant work separately from other enterprise systems.

An enclave may limit the number of systems and users subject to the most complex implementation requirements.

But its success depends on whether business processes can realistically remain inside the boundary.

When Does an Enclave Make Sense?

An enclave may be useful when:

  • a limited group handles CUI;
  • only certain applications are required;
  • information flows can be controlled;
  • the business can tolerate separation;
  • and the reduction in scope justifies the additional architecture and administration.

When Can an Enclave Become a Problem?

It may become difficult when:

  • many employees need access;
  • normal workflows cross the boundary constantly;
  • users need applications outside the enclave;
  • information is repeatedly transferred;
  • or employees work around restrictions because the environment does not support the business.

Should Scope Be Designed Around the Assessment?

It should be designed around accurate information protection and sustainable operations.

Assessment implications matter, but an environment built solely to simplify an assessment may fail operationally afterward.

How Does Scope Affect CMMC Cost?

Scope can materially affect cost because it influences:

  • systems requiring changes;
  • users requiring controls;
  • software licensing;
  • security technology;
  • technical implementation;
  • evidence;
  • documentation;
  • assessment effort;
  • and ongoing administration.

Accurate scope is therefore also an economic decision.

Should We Buy Technology Before Finalizing Scope?

Usually not.

The organization should first understand the target environment.

Otherwise, it may buy technology for systems that ultimately sit outside the assessment boundary or fail to purchase capabilities the actual architecture requires.

Should We Perform the Gap Assessment Before Scoping?

Not a full implementation assessment.

Enough scope analysis should occur first so the organization knows what environment it is assessing.

Scoping and assessment may iterate as new technical dependencies are discovered.

How Does Scope Affect the System Security Plan?

The SSP should describe the actual environment and how applicable requirements are implemented within it.

An inaccurate boundary creates an inaccurate SSP.

How Does Scope Affect Evidence?

Evidence must demonstrate control operation for the appropriate environment.

An artifact from one system does not prove implementation across a broader scope unless it genuinely covers that population.

See how to build a reliable cybersecurity evidence model.

How Does Scope Affect Control Ownership?

Scope identifies which teams and people operate controls in the relevant environment.

That helps define:

  • technical owners;
  • control owners;
  • evidence providers;
  • administrators;
  • and remediation responsibilities.

See how to create clear cybersecurity control ownership.

What If Our Environment Changes?

Scope should be reconsidered when:

  • new applications are added;
  • CUI flows change;
  • new users require access;
  • new providers are introduced;
  • architecture changes;
  • or business processes change.

Scope is not a one-time diagram that can be ignored after assessment.

What Happens If CUI Leaks Outside the Intended Boundary?

That indicates the documented architecture and actual business process may not match.

The organization should investigate:

  • how the information left the intended environment;
  • whether controls failed;
  • whether the receiving system is appropriate;
  • and whether scope or architecture needs to change.

How Does Scope Fit Into the Larger Cybersecurity Program?

CMMC scope should not create an environment nobody understands except the compliance team.

It needs to fit:

  • identity;
  • security operations;
  • incident response;
  • vulnerability management;
  • change management;
  • business continuity;
  • vendor management;
  • and the broader cybersecurity operating model.

Can Existing Cybersecurity Controls Be Reused Inside the CMMC Boundary?

Yes, when existing controls operate appropriately within the defined scope and satisfy the applicable requirements.

See how to reuse existing cybersecurity controls for CMMC.

Where Does Scope Fit in the CMMC Readiness Process?

A practical sequence is:

requirement → CUI analysis → scope → current-state assessment → remediation → documentation and evidence → readiness → assessment → sustainment.

See where to start when you need CMMC Level 2.

How Hotman Group Approaches CMMC Scoping

Hotman Group approaches CMMC scope as a cybersecurity architecture and business-process question, not simply an asset-list exercise.

HG can help:

  • understand CUI;
  • map information flow;
  • identify systems and users;
  • evaluate external providers;
  • understand security dependencies;
  • evaluate enclave options;
  • identify scope-reduction opportunities;
  • assess operational consequences;
  • document the target environment;
  • and connect scope to implementation, evidence and assessment readiness.

Good CMMC Scope Should Survive Contact With the Real Business

A diagram can make scope look clean.

Real users may:

  • email files;
  • copy data;
  • collaborate;
  • download documents;
  • use multiple applications;
  • work remotely;
  • and depend on services outside the intended boundary.

Good scoping accounts for how the organization actually works.

CMMC scope is not simply where you want CUI to be. It is where CUI and the systems protecting it actually exist within the operating environment.

Frequently Asked Questions

What is in scope for CMMC?

Scope is determined by the environment involved in receiving, creating, storing, processing, transmitting and protecting relevant controlled information, including applicable users, systems, services and security dependencies.

Does the entire company have to be in CMMC scope?

Not automatically. The appropriate boundary depends on actual CUI flows, technology, users and security dependencies.

Can we reduce our CMMC scope?

Potentially. Organizations may be able to constrain CUI to a more controlled environment, but the architecture must still support real business operations and satisfy applicable requirements.

Should we build a CMMC enclave?

An enclave can be useful when CUI can realistically be limited to a defined group of users and systems. It is not automatically the right architecture for every organization.

Should we perform a CMMC gap assessment before scoping?

Scope should be sufficiently understood first so the organization knows what environment is being assessed. Scope and assessment may then be refined as dependencies are discovered.

Does scope affect CMMC cost?

Yes. Scope influences the number of systems, users, technologies, controls, evidence requirements and ongoing operating processes involved in implementation and assessment.

Can Hotman Group help determine our CMMC scope?

Yes. Hotman Group can analyze CUI flows, users, systems, security dependencies, external providers and business processes, evaluate enclave options, document the environment and connect scope decisions to the broader CMMC implementation plan.

About Hotman Group

Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance, compliance and technology problems.

HG helps organizations define CMMC scope around real CUI flows, technical dependencies and business operations so the resulting environment is accurate, defensible and sustainable.

Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.