Moving Controlled Unclassified Information (CUI) to the cloud can help organizations centralize sensitive data, strengthen access controls, and simplify the management of systems that support Department of Defense (DoD) contracts. Cloud platforms such as Microsoft 365 GCC High, Microsoft Azure Government, AWS GovCloud, and other environments designed to support government security requirements can play an important role in protecting CUI.
However, moving CUI to a secure cloud environment does not automatically mean the rest of an organization's network is outside the scope of the Cybersecurity Maturity Model Certification (CMMC).
This misconception often comes from focusing exclusively on where CUI is stored. CMMC scoping requires organizations to look beyond data storage and understand how systems, devices, and security technologies interact with and protect CUI. Infrastructure that provides security functions for systems handling CUI may still be part of the CMMC assessment scope even when it never stores CUI itself.
These systems are often classified as Security Protection Assets (SPAs). Firewalls, identity platforms, endpoint security tools, logging systems, and other technologies may all provide security capabilities relied upon to protect CUI.
Understanding these relationships is essential for defining an accurate CMMC assessment scope, documenting the environment, and effectively implementing the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171.
How the CMMC Scoping Guide Determines Assessment Scope
CMMC assessment scope is not determined solely by where CUI physically resides. Instead, organizations should evaluate the role that systems and assets play in storing, processing, transmitting, and protecting CUI.
The CMMC Scoping Guide establishes asset categories that help organizations determine how different technologies should be treated within the assessment environment. For CMMC Level 2, these categories include:
| CUI Assets | |
| Security Protection Assets (SPAs) | |
| Contractor Risk Managed Assets (CRMAs) | |
| Specialized Assets | |
| Out-of-Scope Assets |
CUI Assets are systems that process, store, or transmit CUI. A workstation used to open CUI documents, for example, may qualify as a CUI Asset. A server containing CUI files or a cloud application used to process CUI may also fall into this category.
Security Protection Assets are different. These technologies provide security functions or capabilities to the organization's CMMC assessment scope. They may not process or store CUI as part of their normal operation, but they support the protection of the systems that do. This distinction becomes especially important in cloud environments.
An organization may move its CUI into a cloud service and no longer store sensitive files on traditional file servers. That change may alter how CUI moves through the environment, but it does not automatically eliminate the network, identity, endpoint, and security technologies used to protect access to that information.
To accurately determine CMMC scope, organizations should understand both where CUI exists and what technologies are relied upon to protect it.
Why Moving CUI to the Cloud Does Not Automatically Reduce Scope
Cloud migration can change an organization's CUI environment significantly. It may eliminate local file servers, reduce the number of systems storing sensitive information, and centralize CUI within a controlled cloud platform.
What it does not necessarily eliminate is the security infrastructure surrounding those systems.
Consider an employee who uses a company-managed laptop to access CUI stored in Microsoft 365 GCC High. The CUI may reside in the cloud, but several other technologies can still participate in securing that access.
The employee's identity may be authenticated through an identity and access management platform. Multi-Factor Authentication (MFA) may be required before access is granted. A firewall may secure the organization's network connection. Endpoint Detection and Response (EDR) may monitor the laptop for malicious activity. Security logs may be collected and analyzed by a Security Information and Event Management (SIEM) platform.
These technologies may never serve as the primary storage location for a CUI document. However, the organization relies on them to provide security capabilities that protect systems handling CUI.
Examples can include:
This is why simply asking, "Where is our CUI stored?" is not enough to determine CMMC scope.
Organizations also need to ask, "Which systems and security technologies do we rely on to protect that CUI?"
The answer can reveal assets that remain relevant to the CMMC assessment scope even after CUI has moved to the cloud.
Understanding Security Protection Assets
Security Protection Assets are one of the most important concepts to understand when evaluating CMMC scope in a cloud environment.
A Security Protection Asset provides security functions or capabilities to the CMMC assessment scope. The important consideration is not whether the asset routinely stores CUI, but whether the organization relies on its security capabilities to protect CUI Assets and the environment in which CUI is handled..webp?width=1920&height=1080&name=CUI%20Assets%20vs%20SPA%20Graphic(1).webp)
A firewall is a straightforward example.
An organization's firewall may not be used to store CUI documents, but it may enforce network rules that restrict unauthorized connections and protect systems that access CUI. Its role in protecting the environment makes it relevant when determining the CMMC assessment scope.
The same concept can apply to other security technologies, including:
Identity infrastructure is another useful example. An organization may use a cloud-based identity provider to authenticate employees before allowing them to access CUI. Even though the identity platform is not the location where the CUI document resides, the organization depends on that platform to prevent unauthorized users from reaching sensitive information.
Similarly, an EDR solution may detect malicious activity on a workstation used to access cloud-hosted CUI. A SIEM may collect security events from that workstation, identity platform, firewall, and other systems. These tools provide security capabilities that help protect the overall environment.
Organizations should therefore avoid classifying assets based only on whether they contain CUI. Instead, they should document the security function each asset performs and determine how that function supports the protection of CUI.
Common Cloud Scoping Mistakes Organizations Make
CMMC scoping can become complicated when organizations combine cloud services, on-premises infrastructure, remote workers, security platforms, and third-party technologies. Without a clear understanding of how these components interact, organizations may define their assessment scope too narrowly.
One of the most common mistakes is assuming that moving CUI to the cloud automatically makes the local network out of scope.
Other common mistakes include:
The cloud shared responsibility model is particularly important.
Using a cloud provider does not mean the provider assumes responsibility for every security requirement. Depending on the service and architecture, the customer may still be responsible for identity management, endpoint security, user access, configuration, monitoring, data protection, and other security functions.
Organizations should therefore understand where the cloud provider's responsibility ends and where their own responsibility begins. Inaccurate scoping can create additional problems. An incomplete boundary may lead to gaps in the implementation of NIST SP 800-171 requirements, inaccurate asset inventories, incomplete System Security Plans (SSPs), or security technologies that are not adequately documented.
.webp?width=1920&height=1080&name=myth%20vs%20reality%20(2).webp)
Proper CMMC scoping requires organizations to look at the entire security architecture surrounding CUI, not simply the location where a CUI file happens to reside.
How to Validate Your CMMC Assessment Scope
Accurately defining CMMC assessment scope starts with understanding how CUI moves through the organization.
Organizations should identify where CUI enters the environment, where it is stored, who can access it, how users connect to it, and what technologies protect those interactions. Mapping these relationships can help identify assets that might otherwise be overlooked.
A useful scope validation process should review documentation and technical information such as:
Network and data flow diagrams are particularly valuable because they can reveal security dependencies that may not be obvious from an asset inventory alone.
For example, an asset inventory might show that CUI resides in a cloud collaboration platform. A data flow diagram may reveal that users authenticate through a separate identity service, connect through managed endpoints, and generate security events that are monitored by a SIEM.
Those relationships provide important context for determining which technologies provide security functions to the CMMC assessment scope.
Organizations should also compare their documented environment with their actual technical configuration. Networks and cloud environments change over time. New applications are introduced, security tools are replaced, employees begin working remotely, and access paths evolve.
If documentation does not evolve with the environment, the documented CMMC scope may no longer accurately represent how CUI is protected.
Best Practices for Maintaining an Accurate CMMC Assessment Scope

CMMC scoping should not be treated as a one-time documentation exercise. Organizations should periodically review their environment to ensure the defined assessment scope continues to reflect how CUI is stored, processed, transmitted, and protected.
An effective scoping process should include the following best practices:
Maintaining an accurate scope helps organizations better understand the systems responsible for protecting CUI and supports a more sustainable approach to NIST SP 800-171 implementation.
Security Functions Define Scope, Not Storage Location
Moving CUI to a cloud environment can be an effective part of an organization's cybersecurity strategy, but cloud storage alone does not determine CMMC assessment scope.
Organizations need to understand the entire environment responsible for protecting CUI. A firewall, identity platform, EDR solution, SIEM, VPN gateway, or other security technology may not routinely store CUI, but that does not automatically make it irrelevant to the assessment scope.
The determining factor is the function the asset performs.
By identifying CUI Assets, Security Protection Assets, and other relevant asset categories, organizations can develop a more accurate understanding of their environment and better document how CUI is protected.
This approach also helps organizations avoid one of the most common scoping mistakes: assuming that moving sensitive information to the cloud automatically eliminates the supporting network and security infrastructure from assessment scope consideration.
Organizations should regularly review their CUI environment, security architecture, asset classifications, and documentation as technology and business processes change. Accurate scoping provides a stronger foundation for implementing NIST SP 800-171 and maintaining an effective cybersecurity program.
MAD Security helps defense contractors understand their CUI environments, accurately define CMMC assessment scope, identify Security Protection Assets, perform NIST SP 800-171 gap assessments, and build sustainable cybersecurity programs designed to protect sensitive information and support applicable DFARS and CMMC requirements.
Frequently Asked Questions (FAQs)
Does storing CUI in the cloud put my local network out of scope for CMMC?
Not automatically. CMMC scope depends on how systems and assets interact with and protect CUI, not simply where CUI is stored. Network infrastructure and security technologies may remain within the assessment scope when they provide security capabilities used to protect CUI Assets.
What is a Security Protection Asset in CMMC?
A Security Protection Asset (SPA) provides security functions or capabilities to the CMMC assessment scope. Examples can include firewalls, identity platforms, MFA solutions, EDR technologies, SIEM platforms, and other systems relied upon to protect CUI Assets.
Is a firewall in scope if CUI is stored entirely in the cloud?
It may be. If the firewall provides security functions relied upon to protect the CMMC assessment scope, it may qualify as a Security Protection Asset. Organizations should evaluate the firewall's actual role within their architecture rather than determining scope solely based on whether the firewall stores CUI.
Does using Microsoft GCC High automatically reduce CMMC scope?
No. Microsoft GCC High can be an important component of an environment designed to handle CUI, but using the platform does not automatically make endpoints, identity systems, network infrastructure, or security technologies out of scope. Organizations should evaluate how each asset interacts with or protects CUI.
How can an organization validate its CMMC assessment scope?
Organizations should review their asset inventory, CUI data flows, network diagrams, System Security Plan, identity architecture, security technologies, cloud configurations, and other relevant documentation. Each asset should be evaluated according to the function it performs and its relationship to CUI.
Original Publish Date: August 25, 2026
Author: Jaclyn Jones | CISSP, Lead CCA, CySA+ |
Jaclyn Jones is a GRC Compliance Lead specializing in security operations and compliance, with more than 12 years of cybersecurity experience. She holds CISSP, Lead CCA, and CySA+ certifications and brings deep expertise in CMMC, NIST SP 800-171, DFARS, and CIS frameworks. Jaclyn helps organizations strengthen security controls, improve audit readiness, and build resilient compliance programs.
Scott Hutcheson is a Cybersecurity Consultant specializing in security operations and compliance, with a strong background in leading SOC operations. He brings hands-on expertise in incident response, log analysis, and threat monitoring, along with CMMC implementation, documentation development, and audit readiness. Scott helps organizations strengthen their security posture by combining operational leadership with practical compliance support.

