
A laptop, a firewall, a production machine, and a guest Wi-Fi device do not necessarily receive the same treatment during a CMMC assessment. For CMMC Level 2, five asset categories help define what belongs in scope and how it is evaluated.
For a small business, the goal is to keep scope simple, small, and complete. Understand what each asset does before deciding which label fits.
Only need Level 1? Start with FCI
The five-category model below applies to Level 2. Level 1 focuses on systems that process, store, or transmit Federal Contract Information (FCI), with specific exclusions such as qualifying Specialized Assets. Do not add Level 2 classification and documentation requirements to a Level 1-only business. Read CMMC Scoping Explained for Small Businesses and confirm which level your contract requires.
The five CMMC Level 2 asset categories
| Category | What it means | Level 2 assessment treatment |
|---|---|---|
| CUI Assets | Process, store, or transmit Controlled Unclassified Information | In scope; assessed against all Level 2 requirements |
| Security Protection Assets | Provide security functions for the assessment scope | In scope; assessed against requirements relevant to their capabilities |
| Contractor Risk Managed Assets | Can handle CUI, but policies, procedures, and practices establish that they are not intended to | In scope; SSP review, with limited checks when documentation or findings raise questions |
| Specialized Assets | Qualifying assets capable of handling CUI that cannot be fully secured | In scope; SSP review of risk-based management rather than assessment against other requirements |
| Out-of-Scope Assets | Cannot handle CUI, provide no security protection for CUI Assets, and are physically or logically separated | Outside assessment; be ready to justify the exclusion |
The first four categories remain in scope. Source: 32 CFR 170.19, Table 3.
1. CUI Assets: where protected information travels
Illustrative example: An estimator opens a CUI drawing on a laptop, saves a copy to a project repository, and prints it. Investigate the laptop, repository, print path, and paper handling. Do not stop at the original file location.
A personal phone opening CUI email is not exempt because the employee owns it. An encrypted work container is a protection layer, not an automatic exemption for the underlying device. Read our BYOD guidance.
2. Security Protection Assets: what protects the environment
Illustrative example: A security service collects alerts from the company’s CUI workstations. Investigate its role even if its logs contain no CUI. Review security administrators and supporting services as well as appliances.
Security Protection Data can include configurations, vulnerability information, logs, and access credentials. “We only send logs to that provider” does not settle the scope question.
3. Contractor Risk Managed Assets: capable, but not intended
Illustrative example: A general office workstation is technically capable of receiving CUI, but established workflows prohibit that use. It may qualify as a Contractor Risk Managed Asset rather than an Out-of-Scope Asset. Actual use and safeguards must support the classification.
This category is not permission to ignore the workstation. It remains in the inventory, scope diagram, and SSP treatment. Physical or logical separation from CUI Assets is not required for this category.
4. Specialized Assets: equipment with distinct constraints
Qualifying types include IoT/IIoT, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and Test Equipment.
Illustrative example: A manufacturer should investigate a production controller using protected specifications. Determine whether it meets the Specialized Asset definition and how its risks are managed. An ordinary laptop does not become specialized simply because replacing or securing it is inconvenient.
5. Out-of-Scope Assets: a defensible separation
Illustrative example: A guest tablet on a separate network may be a candidate if it cannot reach or handle CUI and provides no security protection to the assessed environment. Verify account access, cloud services, and data-transfer paths as well as network rules.
A VLAN name or handbook statement alone does not demonstrate exclusion. The guide also has a narrow VDI endpoint exception for keyboard/video/mouse-only interaction; unrestricted downloads, clipboard transfers, or drive redirection require further review.
What should you document?
For the four in-scope categories, maintain an asset inventory, document treatment in the System Security Plan (SSP), and include the assets in the scope network diagram. Out-of-Scope Assets have no formal documentation requirement under this scoping guidance, but keeping a short explanation and validation results is useful practice.
These category details and assessment distinctions come from the DoD Level 2 Scoping Guide. Level 1 uses its own scoping guide.
A practical starting point for a small business
Walk through one contract workflow from receipt to disposal. List the people, devices, applications, storage, backups, print paths, and providers involved. For each candidate asset, record its owner, purpose, data handled, proposed category, and reason. Resolve uncertainty before finalizing the boundary.
Limit where protected information needs to go, then protect every part of that workflow. Keeping scope manageable starts with business decisions about access and handling.
Need help organizing your CMMC scope?
Business Communication Solutions helps businesses map information flows, review asset classifications, and plan practical safeguards. Explore our CMMC consulting services.
Austin: 512-257-1433
Houston: 281-815-8784
Lampasas: 512-865-4000
