- Views: 1
- Report Article
- Articles
- Computers
- Security
Clarifying CMMC Level 2 Scope Boundaries for Advanced Manufacturers
Posted: Sep 05, 2026
One of the biggest CMMC challenges for advanced manufacturers is determining exactly which systems and assets fall inside the assessment boundary.
A manufacturing facility may contain hundreds of devices, applications, machines, and connected systems. That does not automatically mean every asset must be treated as a CMMC Level 2 assessment asset.
Read More - https://spartan-cs.com/
Under the DoD's Level 2 scoping guidance, the CMMC Assessment Scope includes four primary asset categories:
1. CUI AssetsCUI Assets are assets that process, store, or transmit Controlled Unclassified Information.
For an advanced manufacturer, examples may include:
- Engineering workstations containing CUI drawings
- CAD or PLM systems storing controlled technical data
- File servers containing CUI
- Microsoft 365 services used to store or transmit CUI
- Systems used to exchange CUI with defense customers or authorized partners
These assets are at the center of the CMMC assessment boundary.
2. Security Protection AssetsSecurity Protection Assets provide security functions or capabilities that protect CUI Assets.
Examples may include:
- Firewalls
- Identity and authentication infrastructure
- Security monitoring systems
- Endpoint security platforms
- Security management servers
- Network infrastructure providing security protection
These systems may not necessarily store CUI themselves, but they can still fall within the assessment scope because they protect the CUI environment.
3. Contractor Risk Managed AssetsContractor Risk Managed Assets may have limited interaction with CUI or support organizational functions related to the CUI environment but are not themselves CUI Assets or Security Protection Assets.
The organization must identify and manage these assets according to the applicable CMMC scoping requirements.
Manufacturing example: A business application used by engineering or production personnel may support CUI-related business processes without directly storing CUI.
4. Specialized AssetsSpecialized Assets can include technology such as:
- Operational technology
- Industrial control systems
- IoT devices
- Government-furnished equipment
- Restricted or specialized technologies
These assets can be especially important for manufacturers.
A CNC machine, PLC, robotic system, or manufacturing workstation may be difficult to secure using conventional enterprise security controls. The DoD's Level 2 scoping guidance states that Specialized Assets are part of the CMMC Assessment Scope and must be documented and managed using the organization's risk-based security policies, procedures, and practices.
What Is Out of Scope?An asset may be Out of Scope when it cannot process, store, or transmit CUI, does not provide security protection for CUI Assets, and is physically or logically separated from the CUI environment.
For example, a standalone manufacturing device that has no CUI interaction and is properly separated from the CUI environment may potentially be outside the assessment scope.
However, simply labeling an asset "out of scope" is not enough.
The organization must be able to demonstrate the appropriate physical or logical separation. The DoD guidance specifically states that Out-of-Scope Assets cannot provide security protection for CUI Assets and are not part of the Level 2 assessment.
A Manufacturing ExampleConsider an aerospace manufacturer with:
CUI environment: CAD workstations, engineering file servers, PLM applications, and Microsoft 365 services used for controlled technical information.
Security protection: Firewalls, identity systems, endpoint security, logging, and monitoring platforms protecting that environment.
Specialized assets: CNC machines, PLCs, robotics, and industrial systems connected to or supporting the manufacturing environment.
Potentially out-of-scope assets: A physically and logically separated employee network with no CUI access and no security-protection role for the CUI environment.
The key question is therefore not:
"Is this machine in our factory?"
It is:
"How does this asset interact with CUI, and does it process, store, transmit, or protect CUI?"
Why Scoping Should Come FirstIncorrect scoping can create two opposite problems.
Over-scoping can unnecessarily expand the systems, evidence, documentation, and remediation effort required.
Under-scoping can leave relevant assets outside the assessment boundary when they should be included.
The DoD's Level 2 guidance requires organizations to define and document their CMMC Assessment Scope, including the applicable asset categories and supporting documentation such as the System Security Plan and network diagram.
For advanced manufacturers, the best starting point is therefore a detailed CUI flow and asset-mapping exercise. Map where CUI enters the company, where it is stored and processed, how it moves to engineering and production environments, which security systems protect it, and which specialized manufacturing assets interact with the environment.
Practical takeaway: Don't begin CMMC Level 2 preparation by applying all 110 requirements to every device in the factory. Establish the CUI boundary first, classify the assets correctly, and then determine the security and documentation requirements that apply to that scoped environment.
About the Author
Spartan Cyber Security Llc is a trusted Cmmc compliance consultant based in Albuquerque, Usa, helping defense contractors and federal suppliers navigate Cmmc 2.0 requirements. https://spartan-cs.com/
Rate this Article
Leave a Comment