What’s In Scope for CMMC?
Define It Before It Defines Your Cost
Once you know CMMC applies, the next challenge is defining scope. This is where many contractors either overspend unnecessarily or create audit risk without realizing it.
Identify systems, users, and environments in scope
Understand where CUI actually exists and flows
Avoid over-scoping and unnecessary cost
Reduce audit risk with clear boundary definition
Get the CMMC Scoping Best Practices Guide, Built by a CMMC Level 2 Certified RPO with a perfect SPRS score of 110.
This guide explains how to define your CMMC scope correctly, identify where CUI exists, avoid over-and-under scoping, and prepare for a smoother Level 2 assessment. >>
Now You Need To Define
What Is Actually In Scope
This is where planning turns into real decisions.
You know CMMC applies. Now you need to determine exactly what needs to be secured and what does not.
That usually means answering:
What systems store, process, or transmit CUI?
Where does CUI actually live across our environment?
Who has access to that information?
Are shared systems automatically in scope?
Can we segment or isolate to reduce scope?
What happens if we get this wrong during an assessment?
This is where most organizations get stuck.

Because scoping is not just a technical exercise, it is a strategic decision that impacts cost, timelines, and audit outcomes.
As outlined in the guide, scoping determines which systems, users, processes, and even third-party services are evaluated based on their interaction with CUI.
Missteps
Including systems that do not interact with CUI “just to be safe”
Missing systems that actually store or transmit CUI
Failing to map how CUI flows across systems
Not documenting scope decisions clearly
Overlooking third-party providers that handle CUI
Treating scoping as a one-time activity instead of an ongoing process
These mistakes are more common than most organizations expect.
Over-scoping leads to unnecessary controls, documentation, and cost.
Under-scoping leads to non-compliance findings, reassessments, and delays.
Accurate CMMC scoping starts with one critical concept: CUI drives scope
You need to understand:
Where CUI is stored, processed, and transmitted
How that data moves across systems and users
Which endpoints, applications, and environments interact with it
How segmentation can reduce scope and complexity
How access controls affect boundary definition
How third-party providers impact your assessment scope
As outlined in the guide, scoping includes everything that interacts with CUI including cloud platforms, endpoints, applications, identity systems, and even manual processes.
It also requires:
Mapping data flows across the environment
Separating CUI systems from general IT infrastructure
Restricting access to limit scope expansion
Documenting boundaries clearly for assessors

The guide walks through best practices such as:
Identifying all systems, users, and processes touching CUI
Segmenting CUI environments
Documenting data flow diagrams
Reviewing boundaries regularly to prevent scope creep
Define Your Scope Before You Commit Time And Budget
This guide walks you through:
How to identify and map CUI across your environment
How to determine which systems truly belong in scope
How to reduce scope through segmentation strategies
How to avoid over-scoping and under-scoping
How scoping impacts cost, timelines, and assessment outcomes
MAD Security helps contractors define scope correctly before they invest in the wrong controls, architecture, or remediation efforts.
We help organizations:
Validate where CUI actually exists
Map data flows across systems and users
Confirm system inventories and segmentation strategies
Identify hidden scope risks early
Account for third-party services handling CUI
As highlighted in the guide, validating scope early reduces uncertainty, prevents costly surprises, and leads to smoother assessments.
Proof points
CMMC Level 2 Certified RPO
Perfect SPRS score of 110
Deep expertise in DFARS, CMMC, and NIST
Experience supporting contractors handling CUI
Trusted by Defense Industrial Base (DIB) Contractors

CMMC Level 2 Certified MSSP with a 110 SPRS score

CMMC Registered Provider Organization (RPO)

Ranked in the Top 250 MSSPs for five consecutive years

"Early on in the program, we entered into an alliance with Cliff and MAD Security to help develop the information technology and cybersecurity controls and policies. We treated IT infrastructure and cybersecurity much like any other major system on the ship and not as an afterthought. Cybersecurity was built into the vessel from the beginning."
Senior Program Manager, Marad


