/

May 13, 2026

How to Define Your CMMC Level 2 Assessment Boundary: A Step-by-Step Guide

CMMC Level 2 assessment boundary step-by-step scoping process showing the 9 stages from contract review through mock assessment

The Definitive 2026 Guide to Scoping Your CMMC Level 2 Assessment Boundary the Right Way — Before a C3PAO Does It for You

Your CMMC Level 2 assessment boundary is the single most important decision in your entire compliance program. Get it right, and your three-year certification cost might come to $120,000. Get it wrong, and that same certification can balloon past $500,000 — with a 15–35% chance of failing the assessment anyway.

Yet most defense contractors approach scoping like an afterthought. They list a few servers, sketch a network diagram, and assume the C3PAO will sort out the details. By the time the assessor arrives and starts asking pointed questions about backup systems, shared drives, and that one engineer’s laptop, the scope has expanded by 40% and the budget is already broken.

This guide walks you through how to define your CMMC Level 2 assessment boundary the right way — step by step, in the order the work actually has to happen, with the same workflow we run with paying clients on day one of every CMMC engagement.

What Is a CMMC Level 2 Assessment Boundary?

Your CMMC Level 2 assessment boundary is the formal definition of every system, network, person, facility, and external service provider that processes, stores, or transmits Controlled Unclassified Information (CUI) — or that protects the systems that do. It’s the perimeter a C3PAO will assess against all 110 NIST SP 800-171 controls.

The boundary is defined by you, not by the assessor. You propose it in your System Security Plan (SSP). The C3PAO then verifies that what you proposed matches what actually exists. If your documented boundary doesn’t match reality — or if you’ve left obvious assets out — the assessor has the authority to expand scope on the spot, and you’re suddenly being audited against controls you never prepared for.

Under 32 CFR § 170.19(c), every asset in your environment must be categorized into one of five buckets. The first four are inside your assessment boundary. The fifth is explicitly outside it. Understanding these categories is the foundation of every other decision you’ll make.

The Five Asset Categories That Define Your CMMC Level 2 Assessment Boundary

1. CUI Assets

Systems that directly process, store, or transmit CUI. This includes user workstations where engineers open technical drawings, file servers hosting export-controlled specifications, email systems carrying CUI attachments, backup systems, and any cloud applications where CUI lives.

Every CUI Asset is assessed against all 110 NIST SP 800-171 controls. These are the assets that drive most of your compliance cost.

2. Security Protection Assets (SPAs)

Systems that protect CUI assets — even if they don’t touch CUI directly. SIEM platforms, EDR tools, firewalls, identity providers, MFA platforms, vulnerability scanners, log aggregators, and configuration management systems all qualify.

SPAs are assessed against the Level 2 controls relevant to the capabilities they provide. A SIEM doesn’t need to meet every control, but it has to meet the ones tied to logging, monitoring, and incident response.

3. Contractor Risk Managed Assets (CRMAs)

Systems that could access CUI but aren’t designed to. The classic example is a corporate workstation that has network access to a CUI file share but is governed by policy that says “don’t open these files.” CRMAs are inside the assessment boundary but assessed differently — the C3PAO reviews your SSP documentation rather than testing all 110 controls against each asset.

If your documentation is weak, the assessor can downgrade CRMAs to CUI Assets and run limited checks anyway. Sloppy CRMA documentation is one of the most common ways a manageable assessment turns into a sprawling one.

4. Specialized Assets

Operational technology (OT), Industrial IoT, IoT devices, Government Furnished Equipment (GFE), restricted information systems, and test equipment. These assets may handle CUI but cannot be fully secured with standard 800-171 controls — you can’t run EDR on a CNC machine.

Specialized Assets are in the CMMC Level 2 assessment boundary, but like CRMAs they’re assessed against your SSP documentation. The C3PAO verifies that you’ve identified them, justified your protection approach, and managed them under a risk-based policy.

5. Out-of-Scope Assets

Systems that cannot process, store, or transmit CUI and do not provide security protection to CUI Assets. These are the only assets explicitly outside your CMMC Level 2 assessment boundary. They have zero documentation requirements.

But here’s the catch: Out-of-Scope Assets must be physically or logically separated from your in-scope environment. If an assessor can demonstrate that an “out-of-scope” system has a network path to your CUI environment, that asset gets pulled back into scope on the spot.

Stuck Defining Your Scope?

Greypike offers a free 30-minute CUI scoping session for defense contractors trying to figure out where their CMMC Level 2 assessment boundary actually sits. We’ll walk through your contracts, your CUI workflows, and your current architecture — and give you a defensible scoping framework you can take to any C3PAO.

Book a Free CUI Scoping Session →

Step-by-Step: How to Define Your CMMC Level 2 Assessment Boundary

Here’s the working sequence. Skip a step and you’ll redo all the downstream work.

Step 1: Identify Every Contract That Triggers CMMC Level 2

Pull every active contract, task order, and subcontract. Look for DFARS 252.204-7012 (signals CUI) and DFARS 252.204-7021 (signals CMMC). Note which CDRLs specify CUI handling, and capture any ITAR or export-control language.

If you have contracts that only handle Federal Contract Information (FCI), separate them out — they fall under CMMC Level 1, not Level 2. Mixing them into your Level 2 assessment boundary is one of the most expensive mistakes contractors make.

Step 2: Identify the Specific CUI You Handle

For each Level 2 contract, document exactly what CUI flows in, gets generated, and flows out. Reference the National Archives CUI Registry to assign categories. Technical drawings, source code, vulnerability data, export-controlled specifications — be specific.

This step often surprises people. The phrase “we handle CUI” usually breaks down into 4–8 distinct artifact types, each with its own workflow. Each artifact is a thread to trace.

Step 3: Map Every Data Flow

For each CUI artifact, document its full lifecycle:

  • Entry points — secure portals, encrypted email, government file-sharing platforms, physical media
  • Storage locations — file servers, SharePoint sites, cloud drives, engineer laptops, backup systems
  • Processing systems — engineering applications, PLM tools, CAD software, code repositories
  • Transmission paths — internal messaging, email, secure file transfer, VPN, prime contractor portals
  • Egress points — government uploads, prime deliverables, subcontractor handoffs, archival systems

Build a visual data flow diagram. The C3PAO will ask for one anyway, and the act of building it surfaces assets you didn’t know were in scope.

Step 4: Inventory Every Asset That Touches the Flow

For every system that appears in the data flow — and every system adjacent to it — capture: hostname, IP, OS, owner, location, business function, and connection points. Don’t forget mobile devices, printers, backup appliances, and cloud-tenanted services.

This inventory is the raw material your CMMC Level 2 assessment boundary will be built on. If it’s incomplete, your scope will be incomplete.

Step 5: Categorize Each Asset Into One of the Five Buckets

Walk through your inventory and assign every asset to one of the five categories: CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, or Out-of-Scope Asset. Document your rationale for each — especially anything you’re calling Out-of-Scope, because that’s where assessors look first.

Step 6: Identify Every External Service Provider in the Chain

Any ESP that processes, stores, or transmits your CUI — or processes Security Protection Data — is in your CMMC Level 2 assessment boundary. Cloud Service Providers handling CUI must be FedRAMP Moderate authorized (or equivalent). For every ESP, you’ll need a Customer Responsibility Matrix (CRM) describing the shared security responsibilities.

Missed ESPs are a leading cause of assessment failure. Your IT MSP, your cloud backup vendor, your help-desk platform, your SIEM provider — each one needs to be evaluated.

Step 7: Apply Physical and Logical Separation to Shrink the Boundary

This is where the cost-saving leverage lives. Every asset you can legitimately move out of your CMMC Level 2 assessment boundary saves you three years of compliance work. The two recognized methods:

  • Physical separation — no wired or wireless connection between systems. Different buildings, different networks, no shared infrastructure.
  • Logical separation — connected systems with software-enforced isolation. VLANs, firewalls, VPNs, identity-based access controls, and dedicated enclaves with controlled egress.

A CUI enclave — a hardened virtual desktop environment on GCC High, AWS GovCloud, or a compliant VDI platform — is the highest-leverage architectural decision for most small to mid-sized contractors. It lets you place a small, well-defined CMMC Level 2 assessment boundary around the enclave itself, keeping the rest of your business systems firmly out of scope.

Step 8: Document Everything in Your SSP

Your System Security Plan is where the boundary lives officially. It needs to include:

  • A network diagram of the entire CMMC Level 2 assessment boundary
  • A complete asset inventory with category assignments
  • A CUI data flow diagram
  • ESP documentation and Customer Responsibility Matrices
  • Separation justification for any assets categorized as Out-of-Scope
  • Rationale for every CRMA and Specialized Asset designation

The SSP is the first document a C3PAO reviews. If your boundary documentation is sloppy, the assessment goes sideways before it starts.

Step 9: Validate with a Mock Assessment

Before a C3PAO sees your CMMC Level 2 assessment boundary, run a mock assessment against it. Walk the network, verify segmentation, test isolation, and confirm every asset is where the SSP says it is. Discrepancies found in mock are cheap. Discrepancies found by a C3PAO are expensive.

The Five Most Common CMMC Level 2 Assessment Boundary Mistakes

  1. The “everything is CUI” sprawl. Contractors who can’t distinguish CUI from FCI default to protecting everything at Level 2 — and pay six figures more than they need to.
  2. The phantom enclave. A CUI enclave that engineers regularly bypass (downloading CUI to local laptops, emailing it from corporate accounts) provides zero scope benefit. The enclave only works if the workflows actually stay inside it.
  3. The forgotten backup system. Your CUI lives on a hardened file server, but the backup runs to a general-purpose target on the corporate network. That backup target is now in your CMMC Level 2 assessment boundary, regardless of intent.
  4. The undocumented ESP. The cloud platform your team adopted last quarter to “make collaboration easier” is processing CUI and isn’t FedRAMP authorized. You’ll find out during the assessment.
  5. The stale scope. Your CMMC Level 2 assessment boundary was correct 18 months ago. Three contract modifications and a new task order later, it’s meaningfully wrong — and nobody updated the SSP.

Frequently Asked Questions About CMMC Level 2 Assessment Boundaries

Who defines the CMMC Level 2 assessment boundary — me or my C3PAO?

You define it. The C3PAO assesses what you propose. But if your proposed boundary leaves obvious gaps (assets that clearly touch CUI but were marked Out-of-Scope), the assessor has the authority to expand scope during the assessment. The boundary you propose has to hold up under scrutiny.

Can I change my CMMC Level 2 assessment boundary after certification?

Operational changes within an existing boundary — adding or removing assets that follow your SSP — are covered by your annual affirmation and don’t require a new assessment. But significant changes to the boundary itself may trigger a delta assessment before your three-year recertification.

How small can my CMMC Level 2 assessment boundary realistically be?

For a small contractor with concentrated CUI workflows, a properly designed enclave-based boundary can be as small as 10–25 users, a dedicated VDI environment, and a handful of Security Protection Assets. That’s the architecture that produces $120K–$220K three-year compliance costs instead of $500K+.

What happens if my boundary documentation is wrong?

If your SSP doesn’t match your environment, the C3PAO either expands the scope (more controls assessed, higher cost, more findings) or pauses the assessment and sends you back for remediation. Either outcome is expensive. Accurate documentation is non-negotiable.

Helpful Articles & Information

How Greypike Helps GovCons Get Their CMMC Level 2 Assessment Boundary Right

Greypike works with small and mid-sized Defense Industrial Base contractors on CMMC readiness every day, and we’ve watched enough scope mistakes turn into six-figure problems to know exactly where the leverage is. Defining your CMMC Level 2 assessment boundary correctly — before you spend a dollar on remediation — is the single highest-leverage decision in any compliance program.

We help contractors map every contract-driven CUI data flow, categorize every asset under the five-category framework, design enclave architectures that keep the boundary as small as the contracts require, and produce SSP documentation that survives C3PAO scrutiny. Our GreypikeEnclave service deploys a hardened, CUI-compliant VDI environment on Google or Microsoft government clouds, giving small contractors a defensible technical boundary on day one with predictable per-user costs.

If you’re staring at a CMMC Level 2 deadline and trying to figure out where your assessment boundary actually sits, the cheapest hour you’ll ever spend is the one before you commit to an architecture.

Book a Free CUI Scoping Session →

We’ll walk through your contracts, your CUI workflows, your existing systems, and your timeline, then produce a defensible scoping framework you can take to any C3PAO. Same workflow we run with paying clients on day one of every engagement.

Visit https://greypike.com or call (703) 214-9246 to schedule your free scoping session.

Greypike Inc. — Veteran-Owned. Mission-Focused. Compliance-Ready.