CMMC Scoping. Free. No account required.
Determine your CMMC level, define your assessment boundary, map your CUI data flows, and produce a formal scoping package — before you engage a C3PAO.
No account required. No credit card. Takes 20 minutes.
Scope determines assessment cost. Scope is not fixed.
CMMC certification costs money. C3PAO assessments range from $20,000 to $200,000 depending on program scope and complexity. Engaging a C3PAO without a completed scoping analysis increases cost and extends timelines unnecessarily.
Scoping defines the assessment boundary — the specific systems, personnel, facilities, and data flows within scope for the CMMC assessment. Scope determines the number of assets the C3PAO must evaluate and the number of practices they must test.
Scope is not fixed. CUI systems can be isolated from non-CUI systems. Assets that do not process, store, or transmit CUI can be excluded from scope with appropriate documentation. An over-scoped assessment is more expensive and takes longer. An under-scoped assessment is a compliance deficiency.
The REAEGIS CMMC Scoping Wizard guides through the seven scoping decisions required by the CMMC Scoping Guidance: business context, CUI identification, asset inventory, data flow mapping, boundary definition, gap analysis, and output documentation.
Source: CMMC Scoping Guidance, Office of the Under Secretary of Defense for Acquisition and Sustainment
From business context to signed scoping package.
Contract type, prime or sub, DoD agency relationship. Determines which CMMC requirements apply and whether DFARS 252.204-7012 or 252.204-7021 is operative.
Controlled Unclassified Information categories present in the work. If you are uncertain, describe the work — the tool applies the National Archives CUI Registry to determine applicable categories.
Every IT asset that touches the work: endpoints, servers, cloud services, collaboration tools, removable media. Assets are categorized per the CMMC Scoping Guidance: CUI Assets, Security Protection Assets, Contractor Risk Managed, Specialized, Out of Scope.
How CUI enters, moves through, and exits the environment. Data flow diagram generated from your inputs — required for the SSP and C3PAO assessment.
Formal boundary description from the categorized asset inventory. Assets outside the CUI environment that have no security protection role are excluded from scope with documented basis.
Practice-by-practice status across all 14 NIST SP 800-171 domains. SPRS score computed per the DoD Assessment Methodology. Highest-point-weight gaps identified first.
CMMC level determination with regulatory basis. Formal boundary description. Asset inventory with categorization. CUI data flow diagram. Gap analysis with SPRS score.
Five asset categories per the CMMC Scoping Guidance.
Every asset in the environment is assigned to one of five categories. Category determines whether the asset is in scope for the C3PAO assessment and which CMMC practices apply.
| Category | Definition |
|---|---|
| CUI Assets | Store, process, or transmit CUI |
| Security Protection Assets | Provide security capabilities that protect CUI assets |
| Contractor Risk Managed | Connected to CUI environment, managed as a risk |
| Specialized | IoT, OT, GFE, test equipment |
| Out of Scope | No CUI contact, no security protection role |
Source: CMMC Scoping Guidance, Section 2
Know your scope before you engage a C3PAO.
Free scoping. No account required. No credit card. Takes 20 minutes.
Your responses are saved automatically. Return any time to continue where you left off.