Skip to main content
Compliance & ATO

A realistic CUI boundary for a small firm

The control list is published and fixed. The scope is not. It is a drawing your firm makes, and it is the one variable that decides whether protecting controlled unclassified information costs a segmented environment or costs the whole company.

The line you draw is the bill you pay

A firm that has just learned it will receive controlled unclassified information almost always starts with the control list. That is the second question. The first is where the information is allowed to travel inside your company, because that answer decides how many of the requirements apply to how much of what you own. Draw the line by default and you have volunteered every laptop, every mailbox, every backup set and every contractor's phone for assessment. Draw it deliberately and the same contract is satisfied by one segmented environment, a short list of named people, and a document that says clearly which systems are inside and which are not.

The requirements are not negotiable and not secret. The scope is the lever, and it is a lever the government expects you to use. What follows is read from 32 CFR part 2002, 32 CFR part 170, the DFARS, the FAR, the Uniform Guidance and published program documentation. Every citation can be checked against the same public text.

The state and local version surprises firms coming from the defense side. A county health agency, a state revenue department and a public university all redistribute information that came from a federal source, and the duty to protect it travels with the data. It arrives in a contract exhibit, an information exchange agreement or a grant condition rather than in a clause you can look up. Same drawing, different envelope.

You do not decide what counts, and the marking is not the trigger

32 CFR 2002.4 defines CUI as information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. The same section splits it in two. CUI Basic is the subset for which the authorizing authority sets out no specific handling or dissemination controls. CUI Specified is the subset whose authorizing law, regulation or policy contains specific handling controls that differ from the Basic default. That distinction is not academic: Specified categories drag their own statutory regime along with them, and those regimes frequently demand more than the general standard does.

Designation is not yours to make. The rule assigns it to the designating agency, defined as the executive branch agency that designates or approves the designation of a specific item of information as CUI, and 32 CFR 2002.20 puts the marking obligation on that agency as well. Which produces the trap that catches new firms. The same marking section states that the lack of a CUI marking on information that qualifies as CUI does not exempt the authorized holder from abiding by applicable handling requirements. Unmarked CUI is still CUI. A firm that has decided its boundary based on what arrived with a banner marking has decided it on the wrong evidence.

The practical move is to ask in writing, before performance: which CUI categories does this effort involve, and who is the designating agency. Then read those categories in the CUI Registry maintained by the National Archives. The groupings that show up in state and local delivery work are easy to name. Federal Taxpayer Information sits under Tax. Criminal History Records Information sits under Law Enforcement. Student Records and Health Information sit under Privacy. Protected Critical Infrastructure Information sits under Critical Infrastructure. Controlled Technical Information sits under Defense. A firm building a claims model for a state health agency and a firm building a diagnostics tool for a defense program sit in the same structure, reading different pages of the same registry.

One more sentence in 32 CFR 2002.14 anchors everything that follows: CUI Basic is categorized at no less than the moderate confidentiality impact level under FIPS 199, and agencies must use NIST SP 800-171 when establishing security requirements to protect the confidentiality of CUI on non-federal systems. That is why the same document appears in defense contracts, civilian agency contracts and state exhibits alike.

Five buckets, and only two of them get read closely

The most useful scoping language in current federal regulation is 32 CFR 170.19, from the CMMC Program rule published October 15, 2024 and effective December 16, 2024. Even for a firm that will never face a CMMC assessment, its five asset categories are the cleanest published taxonomy for deciding what belongs inside a boundary, and the treatment of each says how much work a given classification costs.

Asset categoryWhat it meansWhat it costs you
CUI AssetsAssets that process, store or transmit CUIDocumented in the asset inventory, the system security plan and the network diagram, then assessed against all applicable Level 2 security requirements. This is the expensive bucket.
Security Protection AssetsAssets providing security functions or capabilities to the assessment scopeSame documentation, assessed against the requirements relevant to the capabilities they provide. Your identity provider, your logging stack and your endpoint agent live here.
Contractor Risk Managed AssetsAssets that can, but are not intended to, process, store or transmit CUI because of policy, procedure and practice in placeDocumented, and subject to a limited check. The rule states a limited check shall not materially increase the assessment duration nor the assessment cost.
Specialized AssetsIoT and industrial IoT devices, operational technology, government furnished equipment, restricted information systems and test equipment that can carry CUI but cannot be fully securedDocumented in inventory, plan and diagram. Not assessed against the other requirements at Level 2.
Out-of-Scope AssetsAssets that cannot process, store or transmit CUI and do not provide security protections for CUI AssetsNothing. No documentation obligation, no assessment. This is the bucket a boundary exists to fill.

Read the Contractor Risk Managed row twice, because it is the one small firms misuse. That category is earned by policy, procedure and practice that keep CUI off an asset, and an assessor may run a limited check to see whether the practice matches the claim. Calling a machine risk-managed while it still receives CUI attachments by email is not a scoping decision. It is a finding waiting to be written.

Unmarked CUI is still CUI. A firm that drew its boundary around what arrived with a banner marking drew it on the wrong evidence.

What an enclave has to separate before it counts as one

An enclave is a separated environment where the regulated work happens. The failure mode is a boundary that exists in a diagram and not in the systems. Seven separations decide whether the drawing survives an assessor, an auditor or an incident.

  • Identity. Separate accounts, and where affordable a separate directory. Shared single sign-on reaching into the enclave makes the corporate identity provider a security protection asset.
  • Network path. Traffic in and out should traverse controlled, documented paths. A flat network with a firewall rule anyone can edit is a policy statement, not a boundary.
  • Storage. One authoritative place where regulated data lives. Every extra copy is a new asset in the inventory and a new item in the plan.
  • Endpoints. Decide whether regulated data ever lands on a laptop. Virtual desktops that keep data server-side are the most effective way to hold general-purpose machines out of scope.
  • Backups and recovery. Backups of CUI are CUI. Snapshot targets, replication regions and the vault holding the encryption keys are all inside the drawing.
  • The administration plane. Remote monitoring, configuration management, ticketing and log aggregation hold data used to protect the environment, and the CMMC rule treats that class of data as worth protecting in its own right.
  • People and place. Scope covers people and facilities, not only machines. Who is authorized, who is screened and where the work is performed belong in the same document.

A boundary fails at its weakest separation. A firm can run a well-isolated cloud environment and lose the whole benefit because the ticketing system where engineers paste error output sits outside it and holds regulated content in a comment field.

The flows that widen a boundary after you have drawn it

Scoping is a one-day exercise. Holding the scope is a standing operational problem, defeated by ordinary convenience. Six flows account for most of the drift.

Email. The most common escape from a well-designed enclave is an attachment forwarded to a general-purpose mailbox. If the enclave cannot send and receive mail on its own terms, the corporate mail system is in scope, and mail in scope pulls the identity stack with it.

File transfer with the customer. Agencies and primes send data by several routes, some sanctioned and some improvised. Agree the route in writing before the first delivery, because whatever happens in week one becomes permanent.

Development and test copies. An extract copied into a development environment to reproduce a defect is the classic silent expansion. Either that environment is inside the boundary or the extract never leaves the enclave, with synthetic or de-identified data covering the gap.

Logs and telemetry. Application logs capture payloads and error trackers capture stack frames with data in them, creating copies in systems nobody put on the diagram.

Subcontractors and named individuals. Every person with access is inside the drawing, and so is the company employing them. Access granted informally between engineers is a scope decision made without the person who signs the affirmation.

General-purpose AI assistants. A coding assistant, a transcription service or a document summarizer touching regulated content is a processing system outside the boundary unless it was designed into it. Many written policies have not caught up, so it deserves an explicit line in the plan rather than an assumption.

The providers you rent are inside the drawing

Almost no small firm builds its own environment from bare metal, which makes external providers the most consequential part of a boundary. The CMMC rule at 32 CFR 170.4 defines an External Service Provider as external people, technology or facilities that an organization uses for provision and management of IT or cybersecurity services. That definition covers a managed service provider, a security operations vendor, a hosted identity service and a cloud platform alike.

The scoping treatment in 32 CFR 170.19 is direct. Where a provider handles security protection data rather than CUI, the services it provides are in the assessment scope and are assessed as Security Protection Assets. A provider may voluntarily undergo its own certification assessment to reduce the effort during your assessment, but the obligation to account for it is yours either way. And the rule requires the relationship to be documented in your system security plan and described in the provider's service description and customer responsibility matrix, which sets out which side owns which control.

Ask for that responsibility matrix before signing. It tells you how many controls you inherit and how many you still implement yourself, and a provider who cannot produce one is telling you something useful about how many federal customers it supports.

For cloud platforms holding CUI, the requirement points back to the DFARS. 32 CFR 170.19 states that the cloud service provider shall meet the FedRAMP requirements in 48 CFR 252.204-7012, and that clause requires a contractor using an external cloud service provider to store, process or transmit covered defense information to ensure the provider meets security requirements equivalent to those established for the FedRAMP Moderate baseline. Two words in that sentence carry all the risk: or equivalent. An authorization listed in the FedRAMP marketplace is a fact you can verify in a minute. Equivalency is an assertion your firm ends up defending. Choosing a service that already holds the authorization is the cheapest architecture decision available.

How much of a company each design keeps outside the boundary

Dedicated enclave in a separate tenant with its own directory
92%
Virtual desktops, no regulated data stored on endpoints
86%
Data held only in one authorized cloud service, nothing on premises
82%
Segmented network zone inside the existing corporate domain
67%
Shared systems separated by written policy alone
38%
One flat environment, no separation attempted
8%

Editorial ranking of how much of a firm's estate each design keeps out of assessment scope, read from the 32 CFR 170.19 asset categories and published federal guidance. An ordering of effect, not a measured statistic.

The ordering is a judgement about scope removal, not a security score. A separate tenant ranks highest because it moves identity, storage and administration out of the shared estate at once. Policy-only separation ranks low for a specific reason: the Contractor Risk Managed category exists for assets kept clean by policy, and it still carries documentation and a limited check. The bottom row is the cost of never having made the drawing at all.

The same problem, in a state or county contract

State and local buyers hold enormous quantities of information that came from a federal source, and the obligation follows it. 32 CFR 2002.16 tells agencies to enter a formal agreement whenever feasible before sharing CUI with a non-executive branch entity, and to require in that agreement that the entity handle CUI in accordance with the executive order, the rule and the CUI Registry, understand that misuse carries penalties established in applicable law, and report non-compliance to the disseminating agency. Where an agreement is not possible but the mission requires dissemination, the agency must communicate that the Government strongly encourages protection to the same standard.

Federal grant money adds a second thread. 2 CFR 200.303 requires a recipient or subrecipient to take reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information and other information the federal awarding agency or pass-through entity designates as sensitive. That is how a security obligation reaches a county program that has never seen a DFARS clause.

RegimeData it governsHow it reaches a vendor
NIST SP 800-171CUI generally, on non-federal systemsNamed in 32 CFR 2002.14 as the standard agencies use for non-federal systems; reaches DoD suppliers through DFARS 252.204-7012 and, increasingly, state exhibits that cite it directly.
IRS Publication 1075Federal tax information held by state and local agenciesThrough the agency's own safeguards obligation under IRC 6103(p)(4). The current revision is dated November 2021, and it reaches agencies, agents and contractors alike.
FBI CJIS Security PolicyCriminal justice informationThrough the state CJIS systems agency and the contract with the criminal justice agency, and it reaches individual contractor personnel, not only the company.
HIPAA and FERPA regimesHealth information and student records, both CUI Registry categories under PrivacyThrough a business associate agreement, a data use agreement or a school-official designation in the contract, layered on top of any CUI obligation.
GovRAMPHosted offerings sold to state, local, tribal and education buyersThrough a procurement condition. StateRAMP has operated under the GovRAMP name since February 2025, and its tiers run from a Security Snapshot at 40 controls through Core at 60, Ready at 80, and Authorized at 300-plus.
2 CFR 200.303Anything the awarding agency or pass-through entity designates as sensitiveThrough the grant or subaward terms, applying to the recipient and flowing to whoever performs the work.

The difference between the federal and the state version is who reads your answer. A defense assessment is run against a published method by an assessor trained on it. A state security exhibit is usually read by a program manager and an agency information security officer who want two things: where the data will live, and who can reach it. A one-page boundary description with a diagram answers both, better than a control matrix nobody has time to read.

Three documents make the boundary real

Whatever regime applies, the artifacts are close to identical, and they are what an assessor, an agency reviewer or an incident responder asks for first.

Building a boundary you can defend

1
Ask the customer in writing which CUI categories are involved and who the designating agency is
Before performance
2
Decide the one place regulated data lives, and the one sanctioned route it arrives by
1 week
3
Sort every asset into the five categories; write the asset inventory and the network diagram
1–2 weeks
4
Collect the customer responsibility matrix from every external provider inside the drawing
2–4 weeks
5
Write the system security plan against the actual boundary, not against a template
3–6 weeks
6
Open a plan of action for what is not yet implemented, with owners and dates
Ongoing

The system security plan is the load-bearing one. It is where the boundary is stated, where each asset category is justified, where each external provider and its responsibility split appears, and where a reviewer looks first when something goes wrong. A plan written from a template describes a company that does not exist. A plan written from the drawing describes yours, and it is faster to produce because you are recording decisions rather than inventing them.

The arithmetic the drawing determines

For firms in the defense supply chain the numbers are published, and they measure the gap between where a firm is and where a contract needs it to be.

CMMC Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21, which applies where a system holds federal contract information: information not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service. It is an annual self-assessment, all 15 met, no plan of action permitted. Level 2 covers the 110 security requirements of NIST SP 800-171 Revision 2, either self-assessed or certified by a third-party assessment organization every three years, with an annual affirmation in the Supplier Performance Risk System. Level 3 adds 24 selected requirements from NIST SP 800-172, is assessed by the Defense Contract Management Agency's DIBCAC, and requires a final Level 2 certification first.

Level 2 scoring starts at the maximum, which is the total number of requirements, and unmet requirements subtract their assigned value. At least 80 percent of the maximum earns a Conditional status, which on 110 requirements means 88, and the plan of action behind it must close within 180 days or the status lapses. Separately, DFARS 252.204-7019 requires an offeror to have summary level scores of a current assessment in SPRS, current meaning not more than three years old unless the solicitation says less.

The clause tying an award to that status is DFARS 252.204-7021, dated November 2025, paired with the notice provision at 252.204-7025. DFARS 204.7504 sets the phase-in: through November 9, 2028 the clause is used when the program office determines a required level, and on or after November 10, 2028 whenever contractor systems will process, store or transmit federal contract information or CUI. Solicitations solely for commercially available off-the-shelf items are excluded. The second date is the one that matters, and the years before it are the window in which a boundary can be built calmly rather than during a proposal.

What is genuinely still moving

Three parts of this picture are unsettled, and a vendor who tells you otherwise has stopped reading.

Which revision of the standard applies. NIST published SP 800-171 Revision 3 in May 2024. The CMMC Program rule assesses against Revision 2 of February 2020 with updates as of January 28, 2021, and that is what the current clause structure requires. Build to what the contract cites, keep the Revision 3 change analysis on hand, and do not assume the newest document is the operative one.

How cloud authorization will work. FedRAMP is running a modernization effort called FedRAMP 20x, with a first phase completed in September 2025 across 26 provider submissions, automated key security indicators in place of static annual review, and a certification structure organized into classes. Phase 3 is underway during fiscal 2026. The practical consequence: verify a provider's current status in the marketplace when you design the boundary, and again at renewal.

How the state programs interlock with the federal one. GovRAMP noted federal recognition of its program in updated Class A rules in July 2026. Whether a given state accepts a federal authorization, a GovRAMP verification, or insists on its own review is decided state by state and sometimes agency by agency. Ask during the solicitation period rather than assuming reciprocity.

Bottom line

The requirements are published, stable and long. The scope is yours, and it is where nearly all the cost lives. Get the category list from the customer in writing, pick one place for the data to live and one route for it to arrive by, sort every asset into the five buckets and stay honest about which ones really stay clean, pull the responsibility matrix from every provider inside the drawing, and write the plan from what you built. A firm that skips this has not avoided the work. It has agreed to do the work across its whole company instead of across the part that needed it.

Frequently asked questions

How do we know whether the data we are receiving is CUI?

Ask the customer in writing which CUI categories are involved and which agency designated them, then read those categories in the CUI Registry. Do not use the presence of a marking as the test. 32 CFR 2002.20 states that the lack of a CUI marking on information that qualifies as CUI does not exempt the holder from the applicable handling requirements, and designation is the designating agency's job rather than yours.

Can we keep most of the company out of scope?

That is the purpose of an enclave, and 32 CFR 170.19 supports it directly: assets that cannot process, store or transmit CUI and do not provide security protections for CUI assets are out of scope entirely. The separation has to be real in identity, network path, storage, endpoints, backups and the administration plane. Assets kept clean by policy alone fall into the Contractor Risk Managed category, which still requires documentation and is subject to a limited check.

Does our managed service provider need its own certification?

Not necessarily. Under 32 CFR 170.19, where a provider handles security protection data rather than CUI, its services are inside your assessment scope and are assessed as Security Protection Assets, and the provider may choose to hold its own certification to reduce effort during your assessment. Either way the relationship must appear in your system security plan, and the provider must supply a service description and customer responsibility matrix showing which controls each side owns.

Which cloud services can hold CUI?

32 CFR 170.19 points to the FedRAMP requirements in 48 CFR 252.204-7012, and that clause requires an external cloud service provider handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. An authorization you can verify in the FedRAMP marketplace is a checkable fact; equivalency is a position your firm has to defend. Pick the authorized service when one exists.

Do state and local contracts carry the same obligation?

Often, through a different instrument. 32 CFR 2002.16 directs agencies to require, by agreement, that non-executive branch entities handle CUI in accordance with the executive order, the rule and the CUI Registry. 2 CFR 200.303 requires recipients and subrecipients of federal awards to take reasonable cybersecurity measures to safeguard protected personally identifiable information and other information designated as sensitive. Above that sit the specific regimes: IRS Publication 1075, the FBI CJIS Security Policy, and the health and student record rules.

1 business day response

Scoping an enclave before the data arrives?

We design and build the environments regulated data actually runs in, and the pipelines, models and reporting tools that run inside them, for federal, state and county programs as prime or as the technical subcontractor.

CapabilitiesMore insights →Start a conversation
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512SAM.GOV ACTIVE