Skip to main content
CMMC & CUI

Scoping your CUI boundary so the assessment is affordable

No other compliance decision moves as much money as the boundary drawing. It sets how many systems are assessed, how much evidence you produce, how many licences you buy, and how much of your week goes to keeping it all true. It is also decided early, by people who do not yet know what it costs. Here is how to price one before you build it.

Engineering perspective, not legal advice This is how we think about designing and pricing a regulated environment. Your assessor, your contracting officer and your counsel have the final word on what your boundary contains. The asset categories and clause references here are pointers to the actual text, which you should read.

Cost scales with the drawing, not with the rules

The 110 requirements are the same for everyone. What differs by two orders of magnitude between firms of similar size is how much of the company those requirements land on. An assessment prices roughly as the number of in-scope assets multiplied by the number of requirements that apply to each, multiplied by how hard it is to produce evidence for them. You cannot change the second factor. The first and third are entirely yours.

That is why the boundary drawing is a budget document rather than a technical artifact, and why it deserves more of your attention than any product decision. A firm that lifts its whole network into scope and a firm that builds a small controlled environment around eight people are buying two different things and will find that out in the third year, not the first.

The CMMC rule gives you five categories to sort things into, and the sorting is what does the work. Assets that process, store or transmit CUI are assessed against everything that applies. Assets providing security functions to that environment are assessed against the requirements relevant to what they do. Assets that could carry CUI but are kept away from it by policy and practice are documented and subject only to a limited check. Specialized assets are documented but not assessed against the full set. Assets that cannot carry CUI and provide no security function are out of scope entirely and cost nothing.

Read those five one more time and notice what they imply. Two of the categories are expensive, two are cheap, and one is free. The entire craft of scoping is moving as much of the company as you honestly can into the cheap and free categories, and then being able to prove the move was honest.

You are probably here because

  • Someone quoted you an assessment price and you do not know what drives it
  • Your integrator wants to secure the whole network and you suspect that is more than you need
  • You have one contract with CUI on it and eleven that do not
  • You built an enclave last year and CUI keeps turning up outside it

Start with the data-flow section. Every expensive scoping mistake we have seen began with a drawing based on the org chart instead of on where files actually go.

Follow the data, never the org chart

The first instinct when drawing a boundary is to think in departments: engineering is in, sales is out. That produces a diagram that is wrong within a week, because data does not respect departments.

The method that holds is to trace one real file end to end and write down every place it stops. Pick an actual controlled document you received in the last quarter. Where did it arrive — a portal, an email attachment, a shared link? Who downloaded it, onto what? Where was it saved? Who was it forwarded to, and did they save a copy? Did it get opened in a viewer that caches locally? Was it printed? Did anything derived from it — a quote, a work instruction, a test report, a screenshot in a ticket — get created and stored somewhere else? Did it get backed up, and to where? Is it in an archive of a mailbox belonging to someone who has left?

Do that for three or four representative documents and you will have a truthful map of your actual boundary, which is almost always larger than the intended one. Every stop on that map is either something you bring inside the drawing, something you stop doing, or a finding waiting to be written.

A boundary is not where you decided the data would go. It is where the data actually went. The gap between those two is the entire project.

Two stops account for most of the surprises. The first is search: full-text indexes and desktop search tools quietly hold content from files they have indexed, which means an index outside the boundary can hold CUI inside it. The second is anything with a comment field — ticketing systems, chat, project trackers — where people paste error output, dimensions, and screenshots. Neither is malice. Both are what a helpful employee does.

Four patterns, and what each costs to run

There are really only four shapes in common use. Setup cost is what people compare. Operating cost is what actually decides which one you should have picked.

PatternWhat it isWhere it hurts
Whole company in scopeNo boundary. Every system, user and site is a CUI asset or a security protection assetHighest assessment cost and highest ongoing drag, because every new laptop and every new tool is now a compliance event. Occasionally the right answer — see below
Network enclaveA separate segment with its own file store, reached across a controlled path from the existing corporate estateCheapest to stand up and the easiest to get wrong. Shared identity, shared endpoint management and shared mail all pull the corporate estate back in as security protection assets
Cloud enclave with virtual desktopsA separate environment where the data lives and is worked on, reached by a remote session; files never land on the endpointHighest setup effort and a real licence bill. In exchange, general-purpose laptops become risk-managed rather than assessed, which is the largest single reduction available
Separate tenant or separate entityA distinct identity tenant, distinct mail domain, distinct administration, sometimes a distinct legal entityDuplicated administration forever, and users who live in two worlds. Cleanest possible boundary story; genuine friction every day

The pattern that fails most often is the second one, and it fails for a reason worth stating plainly. A network segment separates traffic. It does not separate identity, and identity is what an assessor follows. If the same directory authenticates both sides, if the same endpoint management platform pushes policy to both, if the same administrators hold privileged credentials in both, then the corporate identity and management stack is providing security protection to your CUI environment and is inside the assessment. Firms discover this after the segment is built, which is the worst time.

So the honest way to choose is to ask the identity question first, before the network question. Will the CUI environment authenticate against something separate, or against what you already have? If the answer is what you already have, then what you already have is in scope, and you should price the pattern accordingly rather than pretending otherwise.

What the boundary has to actually separate

A drawing counts as a boundary when these hold. Where one of them does not, the boundary is a statement of intent.

  • Identity. Separate accounts, and ideally a separate directory. Federation into the enclave makes the source directory a security protection asset
  • Mail. The single most common leak. If the enclave cannot send and receive on its own terms, corporate mail is in scope
  • Storage. One authoritative place. Every additional copy is another asset in the inventory and another paragraph in the plan
  • Endpoints. Decide whether controlled data is ever allowed to land on a laptop. This decision alone moves whole families of requirements
  • Backups. Backups of CUI are CUI. So are snapshots, replicas, and the vault holding the keys
  • The administration plane. Remote monitoring, patch management, log aggregation and ticketing reach into the environment and therefore belong to it
  • People and place. Who is authorized, who has been screened, where they physically work, and what happens at a second site or a kitchen table

The last one is underrated. Scope covers people and facilities, not only machines. A remote worker handling controlled data at home makes that home part of the physical protection story, and the requirements about visitors, escorting and physical access apply to whatever space you have designated. The usual resolution is to keep the data server-side so that the home has nothing in it, which is another point in favour of the virtual desktop pattern.

The providers who are inside your drawing whether you like it or not

Two kinds of outside company end up inside your boundary, and firms consistently underestimate both.

Anyone who handles the data. If a cloud service stores, processes or transmits your controlled data, the safeguarding clause requires it to meet security requirements equivalent to the FedRAMP Moderate baseline. That is a real constraint on product choice and it is not satisfied by a vendor blog post saying they are secure. Ask the provider for its documented position on that requirement, in writing, and read what their own agreements say about which of their environments the claim covers. Vendors frequently operate several, and the answer differs between them.

Anyone who protects the data. A managed service provider that does not touch a single controlled file still administers the systems that hold them. Their remote access tooling, their patch platform, their monitoring agent and their privileged accounts are providing security functions to your scope. That makes those systems security protection assets, assessed for what they do.

The conversation to have with a provider is short and specific. Which of the 110 do you implement on our behalf? What is written in our agreement about it? Which of your own systems reach into our environment? What is your own posture, and can you show it? A provider who has been through this will answer in an afternoon. A provider who treats the question as an insult has given you information you needed.

The treatment of external service providers in the rules has been clarified more than once since the program rule was published, including on the question of what a provider must hold in its own right. Read the current text and ask your assessor rather than relying on a summary written last year — this specific corner is one where guidance has moved.

How much does a boundary actually save

Before building anything, count. Write down the number of in-scope assets under the current arrangement and under the proposed one. Users with access. Endpoints that can reach the data. Servers and services. Physical locations. Third parties.

How much each scoping decision reduces scope — our read

Keeping CUI off general-purpose endpoints
95
Separate identity for the CUI environment
88
Separate mail path for controlled documents
80
Reducing the number of authorized users
72
Consolidating storage to one location
64
Network segmentation on its own
30

Our judgement of how much each decision reduces assessed scope, not a survey. Segmentation ranks low alone because it rarely separates identity or administration.

If the proposed boundary does not cut those counts substantially, it is not earning the complexity it adds, and you should either make it smaller or abandon it and secure the whole company properly. An enclave that reduces your assessed estate by fifteen percent has bought you a second environment to run and almost nothing else.

Holding the line after the drawing is signed

Scoping is a week of work. Keeping the scope is a permanent operational problem, and it loses to ordinary convenience unless it is enforced by something other than a policy document.

The rule of thumb we use: every boundary crossing that depends on a person remembering will eventually be crossed. So make the easy path the compliant one. If the enclave is slower to log into than the corporate laptop, people will use the corporate laptop. If sharing a file with a colleague inside the boundary takes four steps and emailing it takes one, the file will be emailed. This is not a training problem and it will not be solved by another annual module.

What works is technical: block external sharing on the controlled store rather than discouraging it; prevent the enclave's mail from reaching non-enclave addresses, or route it through a controlled path; disable local drive redirection in remote sessions so files cannot be dragged out; put egress controls on the environment; alert on volume anomalies in downloads. Then add the two human practices that do carry weight — a short written rule that says exactly where controlled files may live, and a named person who answers the question “can I put this here?” within a day, because if nobody answers it people decide for themselves.

  • Drawing the boundary from the org chart instead of from where files have actually travelled
  • Segmenting the network and calling it an enclave while identity, endpoint management and mail stay shared
  • Forgetting the archive — old mailboxes, departed employees, the file server nobody has logged into since the migration
  • Leaving the ticketing system outside while engineers paste controlled content into it daily
  • Assuming a cloud vendor's marketing page answers the FedRAMP Moderate equivalency question
  • Never counting assets before and after, so nobody can say whether the enclave paid for itself
  • Building the enclave to be secure rather than to be usable, which guarantees it is bypassed

When an enclave is the wrong answer

Three situations where we would tell you not to build one, and mean it.

Most of the company touches controlled data every day. If forty of your fifty people work on controlled programs, an enclave is not a boundary, it is a second copy of your company. Secure the whole estate once, properly, and stop paying the tax of maintaining two environments.

The volume is tiny and occasional. A firm that receives four controlled documents a year may be better served by a single hardened, controlled workstation in a locked room, with a written procedure, than by a cloud environment with a licence bill. Small and boring beats sophisticated and unmaintained.

You cannot staff it. An enclave needs someone to run it: accounts, patching, log review, evidence collection. If nobody owns that, the environment decays and you end up with a compliant drawing describing a system that has drifted. In that case either buy the operating capability with the environment, or choose a pattern with less to run.

And a fourth, which is less about the boundary than about honesty: if your contracts never actually bring controlled data to you, do not build any of this. Confirm the data question in writing first. We have watched firms spend a quarter designing an environment for information they were never going to receive.

Bottom line

Price the boundary before you build it, and price it in operating cost rather than setup cost. Trace real documents rather than reasoning from the org chart. Ask the identity question before the network question, because identity is what decides whether a segment is a boundary or a diagram. Count your in-scope assets before and after and refuse to build anything that does not move the count materially. Then enforce the crossings technically, because the ones that rely on memory will be crossed.

Everything expensive about compliance follows from this drawing. It is worth a week of genuine argument before anyone buys a licence.

Frequently asked questions

Is a VLAN enough to create an enclave?

Rarely, on its own. A segment separates network traffic, but an assessor follows identity and administration. If the same directory authenticates both sides, the same platform manages both sets of endpoints, and the same administrators hold privileged access in both, the corporate stack is providing security protection to the CUI environment and is inside the assessment. Segmentation is a useful part of a boundary and a poor substitute for one.

Do virtual desktops really keep laptops out of scope?

They can, if configured so that data genuinely cannot land locally — no drive redirection, no clipboard out, no local printing, no downloads. Under those conditions the endpoint becomes a device that displays pixels, and a strong argument exists for treating it as risk-managed rather than as a CUI asset. The argument depends entirely on the configuration and on your ability to evidence it, so document the settings and test them.

Does our managed service provider need its own certification?

The treatment of external service providers has been clarified more than once, so check the current rule text and ask your assessor rather than trusting a summary. What is stable is the practical position: a provider whose tooling administers or protects your CUI environment is inside your assessment scope, and their implementation is evidence you have to produce. Get their answers in writing and attach them to your plan.

Can we keep our existing email and still have a boundary?

Only if controlled documents genuinely never travel through it, and that is harder to guarantee than it sounds. The workable versions are a separate mail path for controlled correspondence, or a rule that controlled documents are never attached at all and are only ever accessed inside the environment, enforced by blocking external sharing rather than by asking. If mail carries CUI, mail is in scope, and mail brings identity with it.

How long does scoping take?

The analysis is one to three weeks for a firm of fifty, most of it spent tracing real documents and interviewing the people who handle them. Building whatever the analysis calls for takes longer and varies enormously by pattern. The part worth protecting is the analysis: it is cheap, it is reversible, and every hour of it removes weeks from what comes after.

1 business day response

Want a second opinion on a boundary before you build it?

Send the network diagram and a list of where controlled documents currently live, and we will tell you which parts of the drawing we think will hold. Email bo@precisionfederal.com.

Email an engineerCapabilitiesMore insights →
CUI EnclaveAssessment ScopeService ProvidersCMMC Level 2