Skip to main content

Compliance as code for federal DevSecOps. Now accepting design partners

REAEGIS
CMMC Scoping

CMMC Scoping. Free. No account required.

Determine your CMMC level, define your assessment boundary, map your CUI data flows, and produce a formal scoping package — before you engage a C3PAO.

No account required. No credit card. Takes 20 minutes.

32 CFR Part 170 · NIST SP 800-171 Rev 2 · DFARS 252.204-7021 · CMMC Model v2.0
Why scoping comes first

Scope determines assessment cost. Scope is not fixed.

CMMC certification costs money. C3PAO assessments range from $20,000 to $200,000 depending on program scope and complexity. Engaging a C3PAO without a completed scoping analysis increases cost and extends timelines unnecessarily.

Scoping defines the assessment boundary — the specific systems, personnel, facilities, and data flows within scope for the CMMC assessment. Scope determines the number of assets the C3PAO must evaluate and the number of practices they must test.

Scope is not fixed. CUI systems can be isolated from non-CUI systems. Assets that do not process, store, or transmit CUI can be excluded from scope with appropriate documentation. An over-scoped assessment is more expensive and takes longer. An under-scoped assessment is a compliance deficiency.

The REAEGIS CMMC Scoping Wizard guides through the seven scoping decisions required by the CMMC Scoping Guidance: business context, CUI identification, asset inventory, data flow mapping, boundary definition, gap analysis, and output documentation.

Source: CMMC Scoping Guidance, Office of the Under Secretary of Defense for Acquisition and Sustainment

Seven scoping decisions

From business context to signed scoping package.

01
Business context2 min

Contract type, prime or sub, DoD agency relationship. Determines which CMMC requirements apply and whether DFARS 252.204-7012 or 252.204-7021 is operative.

02
CUI identification3 min

Controlled Unclassified Information categories present in the work. If you are uncertain, describe the work — the tool applies the National Archives CUI Registry to determine applicable categories.

03
Asset inventory5 min

Every IT asset that touches the work: endpoints, servers, cloud services, collaboration tools, removable media. Assets are categorized per the CMMC Scoping Guidance: CUI Assets, Security Protection Assets, Contractor Risk Managed, Specialized, Out of Scope.

04
CUI data flow mapping4 min

How CUI enters, moves through, and exits the environment. Data flow diagram generated from your inputs — required for the SSP and C3PAO assessment.

05
Assessment boundary definition2 min

Formal boundary description from the categorized asset inventory. Assets outside the CUI environment that have no security protection role are excluded from scope with documented basis.

06
Gap analysis against 110 practices3 min

Practice-by-practice status across all 14 NIST SP 800-171 domains. SPRS score computed per the DoD Assessment Methodology. Highest-point-weight gaps identified first.

07
Scoping packageinstant

CMMC level determination with regulatory basis. Formal boundary description. Asset inventory with categorization. CUI data flow diagram. Gap analysis with SPRS score.

Asset categorization

Five asset categories per the CMMC Scoping Guidance.

Every asset in the environment is assigned to one of five categories. Category determines whether the asset is in scope for the C3PAO assessment and which CMMC practices apply.

CategoryDefinition
CUI AssetsStore, process, or transmit CUI
Security Protection AssetsProvide security capabilities that protect CUI assets
Contractor Risk ManagedConnected to CUI environment, managed as a risk
SpecializedIoT, OT, GFE, test equipment
Out of ScopeNo CUI contact, no security protection role

Source: CMMC Scoping Guidance, Section 2

Know your scope before you engage a C3PAO.

Free scoping. No account required. No credit card. Takes 20 minutes.

Your responses are saved automatically. Return any time to continue where you left off.