/

April 24, 2026

What Is a CMMC Assessment Boundary? (And Why It Determines Your Total Compliance Cost)

Diagram showing a CMMC assessment boundary with in-scope CUI assets inside an enclave and out-of-scope business systems outside

Your CMMC Assessment Boundary Is the Single Most Leveraged Decision You’ll Make in Your Entire Compliance Journey — Here’s How to Get It Right

If you asked ten defense contractors what their CMMC assessment boundary is, you’d get ten different answers. Most of them would be wrong — and that matters more than you might think, because the boundary you define is the single biggest cost driver in your entire CMMC program. It determines how many systems you harden, how many policies you write, how much evidence you collect, how many hours your assessor bills, and how much of your environment you maintain in perfect compliance for years after you’re certified.

Get it right, and a $100,000 certification can become a $40,000 one. Get it wrong, and a $75,000 certification can balloon into $300,000 — plus years of scope creep you never budgeted for. Contractors get deep into technical implementation — deploying MFA, standing up encryption, writing policies — before anyone has rigorously asked: what exactly are we protecting, and what exactly is in scope to protect it?

What a CMMC Assessment Boundary Actually Is

A CMMC assessment boundary is the defined collection of people, processes, and technology that handle — or could handle — Controlled Unclassified Information on a DoD contract. It’s the explicit scope against which your C3PAO measures compliance with the 110 requirements of NIST SP 800-171.

Everything inside the CMMC assessment boundary is assessed. Everything outside is not.

That sounds simple, but the boundary isn’t just “the network where CUI lives.” It includes every system that could touch CUI, every system that provides security services to CUI systems, and every person with access to any of the above. The CMMC Level 2 Scoping Guide — codified in 32 CFR Part 170 — defines five asset categories that dictate how each system gets treated. Miscategorize any one of them, and you change the cost, complexity, and defensibility of your entire program.

The Five Asset Categories That Define Your Scope

Understanding these five categories is the single highest-leverage piece of CMMC knowledge you can acquire. Every asset in your environment falls into one of them, and each has dramatically different assessment implications.

1. CUI Assets. Systems that process, store, or transmit CUI — file servers, workstations where engineers open technical data, email systems, cloud storage. All 110 NIST 800-171 requirements apply. Deepest hardening, most rigorous documentation, most granular evidence.

2. Security Protection Assets (SPAs). Systems that provide security services to your CUI assets — SIEM, EDR console, identity provider, jump boxes, MFA platform, backup infrastructure, and domain controllers. Fully in scope for all 110 requirements. This is where contractors get blindsided: “our Duo MFA isn’t really a CUI system” — except Duo protects every account that accesses CUI, which makes it an SPA, which makes it in scope.

3. Contractor Risk Managed Assets (CRMAs). Assets that could access CUI but are managed by policy and procedure to ensure they don’t. In scope, but the assessment is lighter — examine documentation and interview personnel rather than a full technical evaluation. Useful but dangerous: assessors are increasingly skeptical of aggressive CRMA classifications.

4. Specialized Assets. Government-furnished equipment, IoT devices, Operational Technology, test equipment, and restricted information systems — things that can’t reasonably meet every 800-171 control. Documented in the SSP with a risk-based approach, but not fully assessed technically.

5. Out-of-Scope Assets. Systems physically or logically separated from CUI, never touch it, can’t reach anything that touches it. Not assessed — which is exactly why shrinking your in-scope count and growing your out-of-scope count is the most important cost lever you have.

Why Your CMMC Assessment Boundary Determines Your Total Compliance Cost

Here’s the math most contractors miss until they’re mid-implementation: every asset in your boundary has to be hardened, documented, monitored, and assessed. Everyone. Across all 110 controls. Forever.

Every CUI asset needs asset tagging, configuration baselines, patch management, vulnerability scanning, audit logging, MFA, FIPS-validated encryption, role-based access control, and evidence proving it all works. Every SPA needs the same. Plus SSP documentation. Plus a data flow diagram that matches what your assessor finds on the floor.

Multiply that by the number of assets in your boundary. That’s your compliance cost — and it isn’t one-time. CMMC certification requires ongoing maintenance for three years, with annual affirmations and eventual recertification. The boundary you define today is the boundary you’re paying to maintain through 2029.

A contractor with a flat network where 200 endpoints could theoretically touch CUI will spend dramatically more than a contractor with 15 endpoints inside a dedicated enclave — even bidding on identical contracts. Compliance scope isn’t a function of contract size. It’s a function of how your environment is designed.

The Question That Cuts Your Costs in Half

“What is the minimum set of systems, users, and tools that must touch CUI to deliver on this contract?” That’s the boundary worth engineering toward. Anything larger is an optional scope you’re paying for — often without realizing it.

Download the CUI CMMC Assessment Boundary Workbook

Five Boundary Mistakes That Blow Up Compliance Costs

These are the recurring patterns we see when contractors get their boundaries wrong. Each looks innocuous until you’re paying your C3PAO hourly.

  1. Treating the whole company as in-scope. Most contractors don’t need their entire business to be a CUI environment. Accounting, HR, marketing, the shop floor network — none of that handles CUI if you design your environment correctly. Contractors who never separate CUI work from general operations end up assessing three times the infrastructure they needed to.
  2. Forgetting that SPAs are in scope. Your identity provider, SIEM, EDR console, backup system, and domain controller all provide services to your CUI environment. That makes them SPAs. That makes them in scope. Contractors routinely exclude these and get blindsided when the C3PAO pulls them back in.
  3. Flat networks without segmentation. If every workstation can reach every file server and nothing is segmented, everything is in scope. Network segmentation is often the single highest-ROI engineering investment in a CMMC program.
  4. Ignoring SaaS and cloud sprawl. Every cloud service that stores, processes, or transmits CUI has to meet FedRAMP Moderate or equivalent. If your engineers are using a non-compliant SaaS tool to share technical data — even occasionally — that tool is within your boundary, and you have a problem.
  5. BYOD and personal devices in the CUI workflow. If a user can check email on their personal phone and that email contains CUI attachments, that phone is arguably in scope. Most contractors cannot realistically assess personal devices against 110 controls. The answer is to prohibit the workflow via policy and technical controls — not to bring personal devices into compliance.

How to Shrink Your Boundary (and Your Bill)

The contractors who certify most affordably treat boundary definition as an engineering exercise, not a documentation exercise. The highest-impact moves:

Deploy a dedicated enclave for CUI work. Instead of treating your entire environment as a CUI environment, stand up a purpose-built, compliance-hardened space — a GCC High tenant, a CUI-compliant VDI environment, or a dedicated physical segment — where all CUI is processed. Everything outside becomes out of scope. This is the single biggest cost-reduction strategy available to small and mid-sized contractors, and it’s why enclave architectures have become the dominant pattern for Level 2 readiness.

Map your CUI data flows explicitly. You cannot define a defensible boundary if you don’t know where CUI enters your environment, where it’s stored, who touches it, and where it leaves. A clear data flow diagram is the foundation of a clean boundary.

Eliminate unnecessary CUI handling. A surprising amount of “CUI” in contractor environments didn’t need to be there. If you avoid downloading CUI to local systems, avoid emailing it internally, and force all interaction through the enclave, you dramatically reduce both the attack surface and the assessment surface.

Segment ruthlessly. Network segmentation, identity segmentation, and role-based access all serve the same goal: making the boundary small, clear, and defensible.

What Your C3PAO Will Actually Check

When your assessor walks in, the CMMC assessment boundary is one of the first things they evaluate. They’ll compare your boundary diagram, asset inventory, data flow diagrams, and SSP against what they actually observe in the environment. If those don’t line up, every subsequent control conversation becomes harder.

Assessors look for clarity on which assets are CUI, SPA, CRMA, Specialized, or Out-of-Scope — and they look for the justification. They probe the edges: “You’ve classified this workstation as out-of-scope. How do you prevent it from accessing the file server that contains CUI?” A boundary that can’t survive that kind of questioning isn’t really a boundary — it’s a wish list.

Frequently Asked Questions

Does my entire company have to be in the assessment boundary?

No — and in most cases it shouldn’t be. If you design your environment with a clear separation between CUI work and general business operations, only the CUI-handling portion needs to be assessed. Accounting, marketing, and general corporate IT can be out of scope if properly isolated.

What happens if my CMMC assessment boundary changes after I’m certified?

Material changes — adding new systems that handle CUI, expanding to new business units, introducing new cloud services — have to be reflected in your SSP and may require reassessment. Annual affirmations include a representation that your environment still matches your assessment, so unmanaged drift becomes an FCA exposure over time.

How do I know if a cloud tool is within my boundary?

If it stores, processes, or transmits CUI — or provides security services to systems that do — it’s in your boundary. And if it handles CUI, it must meet FedRAMP Moderate or equivalent. “We only use it occasionally for CUI” is not a scope-reduction strategy; it’s an inclusion confession.

Helpful Articles & Information

How Greypike Helps GovCons Define Smarter Boundaries

Greypike works with small and mid-sized Defense Industrial Base contractors on CMMC assessment boundary readiness every day, and we’ve watched enough botched boundaries become six-figure mistakes to know where the leverage is. A well-engineered boundary is the difference between a manageable compliance program and a financial albatross.

We help contractors map CUI data flows, categorize every asset against the five CMMC scoping categories, and design enclave architectures that keep the assessment surface as small as the contract requires. Our GreypikeEnclave service deploys a hardened, CUI-compliant VDI environment on Google or Microsoft government clouds, giving you a defensible boundary on day one. Our Obolix compliance platform keeps every asset categorized and every piece of evidence mapped to the boundary you defined.

If you’ve already built a boundary and have a sinking feeling it’s bigger than it needs to be, there’s one piece of work worth doing before anything else. We built a free workbook to help.

Download the CUI CMMC Assessment Boundary Workbook → FREE DOWNLOAD

It walks you through mapping your CUI data flows, categorizing every asset against the CMMC Level 2 scoping model, identifying systems that can move out of scope, and producing a boundary diagram that will stand up to a C3PAO’s questions. Same framework we use with paying clients on day one.

Visit greypike.com or call (703) 214-9246 to talk through your CMMC assessment boundary.

Greypike Inc. — Veteran-Owned. Mission-Focused. Compliance-Ready.