Skip to main content
Lightbridge Cloud A Lightbridge.ai company
SK Written by Sarika Krishnan with Robert LabardeeSenior Program Manager and Founder and CEO

CMMC Asset Scoping and CUI Enclave Architecture

Lightbridge Cloud explains CMMC Level 2 asset scoping as the process an Organization Seeking Assessment uses to specify which assets in its environment will be assessed under 32 CFR § 170.19(c)(1). The five Level 2 categories guide treatment. A CUI enclave can support separation, but it is not the assessment scope itself.

CMMC Level 2 scoping uses five asset categories.

Table 3 to 32 CFR § 170.19(c)(1) defines the five categories for a Level 2 assessment. The category determines the asset treatment and assessment requirements. The categories are not a universal CMMC model for every level. Level 1 and Level 3 use different scoping rules.

CUI Assets

Assets that process, store, or transmit CUI. They are in the Level 2 CMMC Assessment Scope and are assessed against all Level 2 security requirements. The OSA documents each asset in the asset inventory, records its treatment in the SSP, and includes it in the scope network diagram.

Security Protection Assets (SPA)

Assets that provide security functions or capabilities to the OSA's CMMC Assessment Scope. Examples include cloud security solutions, hosted VPN services, SIEM solutions, security personnel, and relevant facilities. SPAs are in scope and are assessed against Level 2 security requirements relevant to the capabilities they provide.

Contractor Risk Managed Assets (CRMA)

Assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place. CRMAs do not need physical or logical separation from CUI Assets. They are in scope, documented in the inventory, SSP, and network diagram, and subject to SSP review. A limited check may follow if documentation or other findings raise questions.

Specialized Assets

Assets that can process, store, or transmit CUI but are unable to be fully secured. The category includes IoT and IIoT devices, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and Test Equipment. They are in scope, documented in the inventory, SSP, and network diagram, and managed through the contractor's risk-based security policies, procedures, and practices. The assessor reviews the SSP and does not assess them against other CMMC security requirements.

Out-of-Scope Assets

Assets that cannot process, store, or transmit CUI and do not provide security protections for CUI Assets. Physical or logical separation from CUI Assets can support out-of-scope treatment, but an asset in any in-scope category cannot be treated as out of scope. The OSA must be prepared to justify the classification. Out-of-scope assets have no CMMC assessment requirements.

The Level 2 guide requires each in-scope asset to appear in the asset inventory and the CMMC Assessment Scope network diagram. It requires asset treatment in the SSP, but does not require each individual asset to be embedded in the SSP. CMMC assets can include people, technology, facilities, services, and other assets. For the underlying data category, see our guide to Controlled Unclassified Information.

External Service Providers can be in scope when CUI or Security Protection Data resides on their assets. The OSA must account for the provider, its relationship, and its services in the SSP and the provider's service description and Customer Responsibility Matrix. Table 4 to 32 CFR § 170.19(c)(2) distinguishes Cloud Service Providers from other providers. A CSP that processes CUI must meet the FedRAMP requirements in DFARS 252.204-7012. The OSA's contract determines the minimum assessment type for an external provider.

Level 3 uses a different table. A CRMA that falls within the Level 3 scope is treated as a CUI Asset. Specialized Assets remain in scope and receive a limited Level 2 check plus assessment against all Level 3 security requirements. The Level 3 scope must equal or be a subset of the Level 2 scope. DCMA DIBCAC performs the Level 3 certification assessment.

A CUI enclave can help narrow the assessment boundary when properly separated per the Out-of-Scope criteria.

A CUI enclave is a security architecture for isolating designated components that process, store, or transmit Controlled Unclassified Information. It may limit the assessment scope when assets outside it meet the Level 2 Out-of-Scope criteria. The enclave is not the CMMC Assessment Scope, and the rest of the enterprise does not become out of scope automatically.

What an enclave actually is

A CUI enclave is an architecture that isolates designated components used to process, store, or transmit CUI. NIST SP 800-171 Rev. 2 describes logical or physical isolation through measures such as subnetworks, firewalls, other boundary-protection devices, and information-flow mechanisms. The CMMC Assessment Scope can extend beyond the enclave: it may include other in-scope asset categories and relevant people, facilities, and external-provider services.

Why organizations build one

A separated CUI security domain can limit which assets carry all Level 2 security requirements when the out-of-scope criteria are met. It does not automatically move the rest of an enterprise out of scope. SPAs, CRMAs, Specialized Assets, people, facilities, and relevant external-provider services can remain part of the Level 2 CMMC Assessment Scope even when they sit outside the enclave segment.

What makes separation real

For an Out-of-Scope Asset, logical separation prevents data transfer between physically connected assets through software or network assets such as firewalls, routers, VPNs, or VLANs. Physical separation means there is no wired or wireless connection and data can be transferred only manually. Email, file shares, identity services, and other shared services require architectural analysis. They are not automatic disqualifiers or automatic exclusions.

Where the trade-off lands

A tighter enclave can require CUI-driven workflows to stay within the isolated domain. Before remediation, map information flows and identify the assets, people, facilities, and services that support or protect the CUI environment. The OSA specifies the CMMC Assessment Scope. The applicable assessor determines assessment results and status.

Lightbridge Cloud supports scoping preparation as an independent advisor.

Lightbridge Cloud is an independent, vendor-neutral CMMC readiness advisor. It can help map information flows, organize an asset inventory, document proposed asset treatment, and review enclave, identity, and logging architecture. The OSA specifies the CMMC Assessment Scope before assessment. Level 2 may involve an OSA self-assessment or an independent C3PAO certification assessment. Level 3 certification assessment is performed by DCMA DIBCAC. See our guide to DFARS and NIST 800-171 for related readiness work.

Lightbridge Cloud accepts no vendor kickbacks and carries no reseller quotas, so architecture guidance is based on the contractor's needs. Lightbridge Cloud helps contractors prepare for assessment. It does not determine official scope or status, conduct a CMMC assessment, or issue CMMC certification. The OSA, the applicable C3PAO, or DCMA DIBCAC holds the relevant official role.

This guide is general information, not legal, audit, or accounting advice. The Level 2 category definitions and treatments come from 32 CFR § 170.19(c)(1) and the DoD CIO Level 2 Scoping Guide. Level 1 and Level 3 use different rules. Verify current specifics against the official DoD CIO and eCFR publications, acquisition.gov, and NIST SP 800-171 before relying on a category or boundary decision.

CMMC asset scoping and CUI enclave: frequently asked questions

What is CMMC asset scoping?
CMMC asset scoping is the OSA's process for specifying the CMMC Assessment Scope before a Level 2 self-assessment or certification assessment. The scope is the set of assets in the OSA's environment assessed against CMMC security requirements. For Level 2, the OSA self-assesses or an independent C3PAO conducts the certification assessment. A Level 3 certification assessment is conducted by DCMA DIBCAC. Lightbridge Cloud can support preparation, but it does not determine official scope or status.
What are the five CMMC asset categories?
Table 3 to 32 CFR § 170.19(c)(1) defines five categories for Level 2: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. Their treatment differs. CRMAs remain in the Level 2 CMMC Assessment Scope, while Out-of-Scope Assets do not. These categories are not universal across CMMC levels. Level 1 uses FCI-focused scoping. Level 3 uses a different table: a CRMA within the Level 3 scope is treated as a CUI Asset, and Specialized Assets are assessed against Level 3 requirements. Check the current DoD scoping guide for the contract level at issue.
What is a CUI enclave?
A CUI enclave is an architecture that isolates designated components used to process, store, or transmit CUI. Logical separation can use subnetworks, firewalls, routers, VPNs, VLANs, and information-flow mechanisms. Physical separation means no wired or wireless connection, with manual transfer only. An enclave can support Out-of-Scope treatment for qualifying assets, but it does not become the CMMC Assessment Scope automatically. CUI Assets, Security Protection Assets, CRMAs, Specialized Assets, relevant people, facilities, and external-provider services still count when they are in scope.
Why do organizations use a CUI enclave to reduce assessment scope?
NIST SP 800-171 Rev. 2 describes isolating designated CUI components in a separate security domain as one way to limit the scope of security requirements. Under the Level 2 scoping rules, the separation can support Out-of-Scope treatment only when an asset cannot process, store, or transmit CUI and does not provide security protections for CUI Assets. SPAs, CRMAs, Specialized Assets, people, facilities, and relevant external-provider services can remain in scope.
What documentation supports a proposed CUI enclave boundary?
The OSA must document each in-scope asset in the asset inventory, document asset treatment in the SSP, and provide a network diagram of the CMMC Assessment Scope. The DoD Level 2 guide does not require each individual asset to be embedded in the SSP. For Out-of-Scope Assets, the OSA must be prepared to justify the inability to process, store, or transmit CUI. Lightbridge Cloud can review readiness materials, but it does not determine whether a proposed boundary is official.
Are Contractor Risk Managed Assets and Specialized Assets fully exempt from CMMC requirements?
No. Both categories are in the Level 2 CMMC Assessment Scope, but their assessment treatments differ. A CRMA receives SSP review. If the SSP is sufficiently documented, the assessor does not assess it against other CMMC security requirements, except when questions trigger a limited check. A Specialized Asset receives SSP review and is not assessed against other CMMC security requirements. Both are documented in the asset inventory, SSP treatment, and scope network diagram.
How does asset scoping relate to a System Security Plan and a NIST 800-171 gap assessment?
Scoping comes first. The OSA must inventory each in-scope asset, document asset treatment in the SSP, and include the assets in the scope network diagram. CUI Assets are assessed against all 110 CMMC Level 2 security requirements from NIST SP 800-171 Rev. 2. SPAs are assessed against requirements relevant to their capabilities. CRMAs receive SSP review with a possible limited check, while Specialized Assets receive SSP review without assessment against other CMMC security requirements. NIST SP 800-171 Rev. 3 supersedes Rev. 2 as the current NIST publication, but that publication change alone does not replace the CMMC Level 2 requirements in 32 CFR part 170. See the Lightbridge Cloud DFARS and NIST 800-171 guide for related readiness work.
Does Lightbridge Cloud perform CMMC asset scoping and enclave design?
Lightbridge Cloud can support CMMC readiness preparation by helping map information flows, organize an asset inventory, document proposed asset treatment, and review enclave, identity, and network architecture. The OSA specifies its CMMC Assessment Scope. A Level 2 self-assessment is performed by the OSA, a Level 2 certification assessment is performed by an independent C3PAO, and a Level 3 certification assessment is performed by DCMA DIBCAC. Lightbridge Cloud is an independent readiness advisor. It does not determine official scope or status, conduct those assessments, or issue CMMC certification. See the CMMC compliance readiness service for the readiness path.

Prepare your assessment scope before you remediate.

Lightbridge Cloud can help map information flows, organize asset treatment, and review a proposed enclave architecture. The OSA specifies the CMMC Assessment Scope. The applicable assessor determines assessment results and status.