Back to category

Week 10

Scope a CMMC Level 2 Assessment Boundary

Intermediate
GRC Analyst
Security Consultant
CMMC
NIST 800-171
CMMC Scoping

Client Background

A defense contractor handling Controlled Unclassified Information (CUI) needs help defining the assessment boundary for an upcoming CMMC Level 2 certification. Incorrectly scoping the environment is one of the most common causes of failed assessments.

Business Environment

Northwind Defense Systems has 350 employees across two facilities and a hybrid IT environment: on-prem file servers, a managed SIEM, an Azure Government tenant for some workloads, and a SCADA test lab. CUI flows through a dedicated enclave, but a recent acquisition added shared infrastructure that may blur the boundary.

Security Incident

No incident; the engagement is a scoping exercise to correctly bound the CMMC Level 2 assessment before the formal certification review in nine months. The trigger was a pre-assessment report warning that over-broad scoping was driving excessive remediation cost and risking assessment failure.

Scope

Enterprise IT environment review to determine CMMC Level 2 assessment boundary.

Objectives

  • Identify systems, applications, and personnel that touch CUI
  • Define the CMMC assessment boundary and enclave strategy
  • Distinguish in-scope vs. out-of-scope assets
  • Document the scoping rationale for the assessor

Required Deliverables

CMMC Assessment Scoping Document
2 hrs estimated