Directory Image
This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.

Clarifying CMMC Level 2 Scope Boundaries for Advanced Manufacturers

Author: Spartan Cs
by Spartan Cs
Posted: Sep 05, 2026

One of the biggest CMMC challenges for advanced manufacturers is determining exactly which systems and assets fall inside the assessment boundary.

A manufacturing facility may contain hundreds of devices, applications, machines, and connected systems. That does not automatically mean every asset must be treated as a CMMC Level 2 assessment asset.

Read More - https://spartan-cs.com/

Under the DoD's Level 2 scoping guidance, the CMMC Assessment Scope includes four primary asset categories:

1. CUI Assets

CUI Assets are assets that process, store, or transmit Controlled Unclassified Information.

For an advanced manufacturer, examples may include:

  • Engineering workstations containing CUI drawings
  • CAD or PLM systems storing controlled technical data
  • File servers containing CUI
  • Microsoft 365 services used to store or transmit CUI
  • Systems used to exchange CUI with defense customers or authorized partners

These assets are at the center of the CMMC assessment boundary.

2. Security Protection Assets

Security Protection Assets provide security functions or capabilities that protect CUI Assets.

Examples may include:

  • Firewalls
  • Identity and authentication infrastructure
  • Security monitoring systems
  • Endpoint security platforms
  • Security management servers
  • Network infrastructure providing security protection

These systems may not necessarily store CUI themselves, but they can still fall within the assessment scope because they protect the CUI environment.

3. Contractor Risk Managed Assets

Contractor Risk Managed Assets may have limited interaction with CUI or support organizational functions related to the CUI environment but are not themselves CUI Assets or Security Protection Assets.

The organization must identify and manage these assets according to the applicable CMMC scoping requirements.

Manufacturing example: A business application used by engineering or production personnel may support CUI-related business processes without directly storing CUI.

4. Specialized Assets

Specialized Assets can include technology such as:

  • Operational technology
  • Industrial control systems
  • IoT devices
  • Government-furnished equipment
  • Restricted or specialized technologies

These assets can be especially important for manufacturers.

A CNC machine, PLC, robotic system, or manufacturing workstation may be difficult to secure using conventional enterprise security controls. The DoD's Level 2 scoping guidance states that Specialized Assets are part of the CMMC Assessment Scope and must be documented and managed using the organization's risk-based security policies, procedures, and practices.

What Is Out of Scope?

An asset may be Out of Scope when it cannot process, store, or transmit CUI, does not provide security protection for CUI Assets, and is physically or logically separated from the CUI environment.

For example, a standalone manufacturing device that has no CUI interaction and is properly separated from the CUI environment may potentially be outside the assessment scope.

However, simply labeling an asset "out of scope" is not enough.

The organization must be able to demonstrate the appropriate physical or logical separation. The DoD guidance specifically states that Out-of-Scope Assets cannot provide security protection for CUI Assets and are not part of the Level 2 assessment.

A Manufacturing Example

Consider an aerospace manufacturer with:

CUI environment: CAD workstations, engineering file servers, PLM applications, and Microsoft 365 services used for controlled technical information.

Security protection: Firewalls, identity systems, endpoint security, logging, and monitoring platforms protecting that environment.

Specialized assets: CNC machines, PLCs, robotics, and industrial systems connected to or supporting the manufacturing environment.

Potentially out-of-scope assets: A physically and logically separated employee network with no CUI access and no security-protection role for the CUI environment.

The key question is therefore not:

"Is this machine in our factory?"

It is:

"How does this asset interact with CUI, and does it process, store, transmit, or protect CUI?"

Why Scoping Should Come First

Incorrect scoping can create two opposite problems.

Over-scoping can unnecessarily expand the systems, evidence, documentation, and remediation effort required.

Under-scoping can leave relevant assets outside the assessment boundary when they should be included.

The DoD's Level 2 guidance requires organizations to define and document their CMMC Assessment Scope, including the applicable asset categories and supporting documentation such as the System Security Plan and network diagram.

For advanced manufacturers, the best starting point is therefore a detailed CUI flow and asset-mapping exercise. Map where CUI enters the company, where it is stored and processed, how it moves to engineering and production environments, which security systems protect it, and which specialized manufacturing assets interact with the environment.

Practical takeaway: Don't begin CMMC Level 2 preparation by applying all 110 requirements to every device in the factory. Establish the CUI boundary first, classify the assets correctly, and then determine the security and documentation requirements that apply to that scoped environment.

About the Author

Spartan Cyber Security Llc is a trusted Cmmc compliance consultant based in Albuquerque, Usa, helping defense contractors and federal suppliers navigate Cmmc 2.0 requirements. https://spartan-cs.com/

Rate this Article
Leave a Comment
Author Thumbnail
I Agree:
Comment 
Pictures
Author: Spartan Cs

Spartan Cs

Member since: Sep 02, 2026
Published articles: 1

Related Articles