Skip to content

 

Moving Controlled Unclassified Information (CUI) to the cloud can help organizations centralize sensitive data, strengthen access controls, and simplify the management of systems that support Department of Defense (DoD) contracts. Cloud platforms such as Microsoft 365 GCC High, Microsoft Azure Government, AWS GovCloud, and other environments designed to support government security requirements can play an important role in protecting CUI.

However, moving CUI to a secure cloud environment does not automatically mean the rest of an organization's network is outside the scope of the Cybersecurity Maturity Model Certification (CMMC).

This misconception often comes from focusing exclusively on where CUI is stored. CMMC scoping requires organizations to look beyond data storage and understand how systems, devices, and security technologies interact with and protect CUI. Infrastructure that provides security functions for systems handling CUI may still be part of the CMMC assessment scope even when it never stores CUI itself.

These systems are often classified as Security Protection Assets (SPAs). Firewalls, identity platforms, endpoint security tools, logging systems, and other technologies may all provide security capabilities relied upon to protect CUI.

Understanding these relationships is essential for defining an accurate CMMC assessment scope, documenting the environment, and effectively implementing the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171.

 

How the CMMC Scoping Guide Determines Assessment Scope 

CMMC assessment scope is not determined solely by where CUI physically resides. Instead, organizations should evaluate the role that systems and assets play in storing, processing, transmitting, and protecting CUI.

The CMMC Scoping Guide establishes asset categories that help organizations determine how different technologies should be treated within the assessment environment. For CMMC Level 2, these categories include:

CUI Assets
Security Protection Assets (SPAs)
Contractor Risk Managed Assets (CRMAs)
Specialized Assets
Out-of-Scope Assets

CUI Assets are systems that process, store, or transmit CUI. A workstation used to open CUI documents, for example, may qualify as a CUI Asset. A server containing CUI files or a cloud application used to process CUI may also fall into this category.

How the CMMC Scoping Guide Determines Assessment ScopeSecurity Protection Assets are different. These technologies provide security functions or capabilities to the organization's CMMC assessment scope. They may not process or store CUI as part of their normal operation, but they support the protection of the systems that do. This distinction becomes especially important in cloud environments.

An organization may move its CUI into a cloud service and no longer store sensitive files on traditional file servers. That change may alter how CUI moves through the environment, but it does not automatically eliminate the network, identity, endpoint, and security technologies used to protect access to that information.

To accurately determine CMMC scope, organizations should understand both where CUI exists and what technologies are relied upon to protect it.


Why Moving CUI to the Cloud Does Not Automatically Reduce Scope 

Cloud migration can change an organization's CUI environment significantly. It may eliminate local file servers, reduce the number of systems storing sensitive information, and centralize CUI within a controlled cloud platform.

What it does not necessarily eliminate is the security infrastructure surrounding those systems.

Consider an employee who uses a company-managed laptop to access CUI stored in Microsoft 365 GCC High. The CUI may reside in the cloud, but several other technologies can still participate in securing that access.

Why Moving CUI to the Cloud Does Not Automatically Reduce ScopeThe employee's identity may be authenticated through an identity and access management platform. Multi-Factor Authentication (MFA) may be required before access is granted. A firewall may secure the organization's network connection. Endpoint Detection and Response (EDR) may monitor the laptop for malicious activity. Security logs may be collected and analyzed by a Security Information and Event Management (SIEM) platform.

These technologies may never serve as the primary storage location for a CUI document. However, the organization relies on them to provide security capabilities that protect systems handling CUI.

Examples can include:

Firewalls that control network traffic
VPN gateways that provide secure remote connectivity
Identity platforms that authenticate users
MFA technologies that strengthen authentication
EDR solutions that monitor endpoints
SIEM platforms that centralize security events
Intrusion detection and prevention technologies
DNS security services
Network monitoring platforms

This is why simply asking, "Where is our CUI stored?" is not enough to determine CMMC scope.

Organizations also need to ask, "Which systems and security technologies do we rely on to protect that CUI?"

The answer can reveal assets that remain relevant to the CMMC assessment scope even after CUI has moved to the cloud.

 

Understanding Security Protection Assets 

Security Protection Assets are one of the most important concepts to understand when evaluating CMMC scope in a cloud environment.

A Security Protection Asset provides security functions or capabilities to the CMMC assessment scope. The important consideration is not whether the asset routinely stores CUI, but whether the organization relies on its security capabilities to protect CUI Assets and the environment in which CUI is handled.

CUI Assets vs SPA Graphic(1)

A firewall is a straightforward example.

An organization's firewall may not be used to store CUI documents, but it may enforce network rules that restrict unauthorized connections and protect systems that access CUI. Its role in protecting the environment makes it relevant when determining the CMMC assessment scope.


The same concept can apply to other security technologies, including:


Firewalls
VPN gateways
Identity and Access Management (IAM) platforms dentity platforms that authenticate users
MFA Solutions 
EDR platforms 
SIEM solutions 
Intrusion Detection and Prevention Systems (IDS/IPS) 
Secure email gateways 
DNS filtering services
Network monitoring technologies 

Identity infrastructure is another useful example. An organization may use a cloud-based identity provider to authenticate employees before allowing them to access CUI. Even though the identity platform is not the location where the CUI document resides, the organization depends on that platform to prevent unauthorized users from reaching sensitive information.

Similarly, an EDR solution may detect malicious activity on a workstation used to access cloud-hosted CUI. A SIEM may collect security events from that workstation, identity platform, firewall, and other systems. These tools provide security capabilities that help protect the overall environment.

Organizations should therefore avoid classifying assets based only on whether they contain CUI. Instead, they should document the security function each asset performs and determine how that function supports the protection of CUI.

 

Common Cloud Scoping Mistakes Organizations Make

Common Cloud Scoping Mistakes Organizations MakeCMMC scoping can become complicated when organizations combine cloud services, on-premises infrastructure, remote workers, security platforms, and third-party technologies. Without a clear understanding of how these components interact, organizations may define their assessment scope too narrowly.

One of the most common mistakes is assuming that moving CUI to the cloud automatically makes the local network out of scope.

Other common mistakes include:

Focusing only on systems that directly store CUI
Overlooking Security Protection Assets
Assuming that a cloud provider is responsible for every security function
Misclassifying shared security services 
Failing to understand how endpoints access cloud-hosted CUI
Maintaining outdated network or data flow diagrams 
Failing to document relationships between CUI Assets and the technologies protecting them 
Treating every cloud-connected system as automatically out of scope 

The cloud shared responsibility model is particularly important.

Using a cloud provider does not mean the provider assumes responsibility for every security requirement. Depending on the service and architecture, the customer may still be responsible for identity management, endpoint security, user access, configuration, monitoring, data protection, and other security functions.

Organizations should therefore understand where the cloud provider's responsibility ends and where their own responsibility begins. Inaccurate scoping can create additional problems. An incomplete boundary may lead to gaps in the implementation of NIST SP 800-171 requirements, inaccurate asset inventories, incomplete System Security Plans (SSPs), or security technologies that are not adequately documented.

myth vs reality (2)

Proper CMMC scoping requires organizations to look at the entire security architecture surrounding CUI, not simply the location where a CUI file happens to reside.

 

How to Validate Your CMMC Assessment Scope 

Accurately defining CMMC assessment scope starts with understanding how CUI moves through the organization.

Organizations should identify where CUI enters the environment, where it is stored, who can access it, how users connect to it, and what technologies protect those interactions. Mapping these relationships can help identify assets that might otherwise be overlooked.

A useful scope validation process should review documentation and technical information such as:


Asset inventories 
Network diagrams
CUI data flow diagrams 
System Security Plans (SSPs) 
Firewall configurations
Identity and authentication architecture 
Access control configurations
Endpoint security technologies 
Logging and monitoring platforms
Cloud service configurations

Network and data flow diagrams are particularly valuable because they can reveal security dependencies that may not be obvious from an asset inventory alone.

For example, an asset inventory might show that CUI resides in a cloud collaboration platform. A data flow diagram may reveal that users authenticate through a separate identity service, connect through managed endpoints, and generate security events that are monitored by a SIEM.

Those relationships provide important context for determining which technologies provide security functions to the CMMC assessment scope.

Organizations should also compare their documented environment with their actual technical configuration. Networks and cloud environments change over time. New applications are introduced, security tools are replaced, employees begin working remotely, and access paths evolve.

Why Cloud Storage Does Not Put Your Network Out of Scope

If documentation does not evolve with the environment, the documented CMMC scope may no longer accurately represent how CUI is protected.

 

Best Practices for Maintaining an Accurate CMMC Assessment Scope 

Best Practices for Maintaining an Accurate CMMC Assessment Scope
CMMC scoping should not be treated as a one-time documentation exercise. Organizations should periodically review their environment to ensure the defined assessment scope continues to reflect how CUI is stored, processed, transmitted, and protected.


An effective scoping process should include the following best practices:


Identify where CUI exists. Document the systems, applications, cloud platforms, and endpoints that store, process, or transmit CUI.
Identify the technologies protecting CUI. Determine which security systems provide capabilities to the CMMC assessment scope.
Properly classify assets. Use the applicable CMMC Scoping Guide to categorize assets based on their function.
Maintain accurate network diagrams. Document connections between cloud services, endpoints, network infrastructure, and security technologies.
Maintain CUI data flow diagrams. Understand how CUI enters, moves through, and exits the environment.
Keep the SSP current. Update the System Security Plan when systems, security technologies, or CUI workflows change.
Review cloud security responsibilities. Understand which security functions are performed by the cloud provider and which remain the organization's responsibility.
Perform periodic NIST SP 800-171 gap assessments. Regular reviews can help identify security and documentation gaps before they become larger problems.
Reevaluate scope when technology changes. Cloud migrations, new security platforms, mergers, remote access solutions, and other changes can affect the assessment boundary.

Maintaining an accurate scope helps organizations better understand the systems responsible for protecting CUI and supports a more sustainable approach to NIST SP 800-171 implementation.

 

Security Functions Define Scope, Not Storage Location

Moving CUI to a cloud environment can be an effective part of an organization's cybersecurity strategy, but cloud storage alone does not determine CMMC assessment scope.

Organizations need to understand the entire environment responsible for protecting CUI. A firewall, identity platform, EDR solution, SIEM, VPN gateway, or other security technology may not routinely store CUI, but that does not automatically make it irrelevant to the assessment scope.

The determining factor is the function the asset performs.

By identifying CUI Assets, Security Protection Assets, and other relevant asset categories, organizations can develop a more accurate understanding of their environment and better document how CUI is protected.

This approach also helps organizations avoid one of the most common scoping mistakes: assuming that moving sensitive information to the cloud automatically eliminates the supporting network and security infrastructure from assessment scope consideration.

Organizations should regularly review their CUI environment, security architecture, asset classifications, and documentation as technology and business processes change. Accurate scoping provides a stronger foundation for implementing NIST SP 800-171 and maintaining an effective cybersecurity program.

MAD Security helps defense contractors understand their CUI environments, accurately define CMMC assessment scope, identify Security Protection Assets, perform NIST SP 800-171 gap assessments, and build sustainable cybersecurity programs designed to protect sensitive information and support applicable DFARS and CMMC requirements.

interactive-194075349118

Frequently Asked Questions (FAQs) 

Does storing CUI in the cloud put my local network out of scope for CMMC?

Not automatically. CMMC scope depends on how systems and assets interact with and protect CUI, not simply where CUI is stored. Network infrastructure and security technologies may remain within the assessment scope when they provide security capabilities used to protect CUI Assets.

What is a Security Protection Asset in CMMC?

A Security Protection Asset (SPA) provides security functions or capabilities to the CMMC assessment scope. Examples can include firewalls, identity platforms, MFA solutions, EDR technologies, SIEM platforms, and other systems relied upon to protect CUI Assets.

Is a firewall in scope if CUI is stored entirely in the cloud?

It may be. If the firewall provides security functions relied upon to protect the CMMC assessment scope, it may qualify as a Security Protection Asset. Organizations should evaluate the firewall's actual role within their architecture rather than determining scope solely based on whether the firewall stores CUI.

Does using Microsoft GCC High automatically reduce CMMC scope?

No. Microsoft GCC High can be an important component of an environment designed to handle CUI, but using the platform does not automatically make endpoints, identity systems, network infrastructure, or security technologies out of scope. Organizations should evaluate how each asset interacts with or protects CUI.

How can an organization validate its CMMC assessment scope?

Organizations should review their asset inventory, CUI data flows, network diagrams, System Security Plan, identity architecture, security technologies, cloud configurations, and other relevant documentation. Each asset should be evaluated according to the function it performs and its relationship to CUI.