Week 10
Scope a CMMC Level 2 Assessment Boundary
Client Background
A defense contractor handling Controlled Unclassified Information (CUI) needs help defining the assessment boundary for an upcoming CMMC Level 2 certification. Incorrectly scoping the environment is one of the most common causes of failed assessments.
Business Environment
Northwind Defense Systems has 350 employees across two facilities and a hybrid IT environment: on-prem file servers, a managed SIEM, an Azure Government tenant for some workloads, and a SCADA test lab. CUI flows through a dedicated enclave, but a recent acquisition added shared infrastructure that may blur the boundary.
Security Incident
No incident; the engagement is a scoping exercise to correctly bound the CMMC Level 2 assessment before the formal certification review in nine months. The trigger was a pre-assessment report warning that over-broad scoping was driving excessive remediation cost and risking assessment failure.
Scope
Enterprise IT environment review to determine CMMC Level 2 assessment boundary.
Objectives
- Identify systems, applications, and personnel that touch CUI
- Define the CMMC assessment boundary and enclave strategy
- Distinguish in-scope vs. out-of-scope assets
- Document the scoping rationale for the assessor
Required Deliverables