CMMC Scoping Worksheet
Filled in by IT and the compliance lead together, using the flows from the CUI Flow Mapping Template, this worksheet produces a first draft of your Cybersecurity Maturity Model Certification (CMMC) assessment scope: every person, system, endpoint, network, cloud service, facility and external service provider sorted into the asset categories the CMMC Program rule uses, with a written reason for each. The point is not the list; it is that for every asset left outside the boundary you can say, in one sentence, why it is out.
- 01
Have your completed CUI Identification Worksheet (CMMCg-R001) and flow maps (CMMCg-R002) open. Every stop on every flow must land somewhere on this worksheet.
- 02
Work through Part 1 first and place each asset in one of the five categories. If you argue about a category for more than a few minutes, record the asset as a CUI asset for now and note the disagreement; scoping smaller later is easier than discovering an omission in front of an assessor.
- 03
Work through Part 2 component by component: users, locations, Microsoft 365 and cloud, SaaS, external service providers, endpoints, networks. Each table asks the same question from a different direction so that nothing hides between them.
- 04
For every asset you place outside the boundary, write the reason in the row. "We do not think it touches CUI" is not a reason; "no CUI flow passes through it and it is on a separate network segment with no route to the CUI VLAN" is.
- 05
Answer the closing question in Part 3 honestly and record it in the findings block. Then carry the in-scope list into the CMMC Technology Inventory (CMMCg-R004).
12 working tables, 1 checklist, a findings section and recommended next steps. Every page carries the resource number, the version and the licence.
- Part 1 — Asset categories
- CUI assets — assets that process, store or transmit CUI
- Security protection assets — assets that provide security functions to the CUI environment
- Specialized assets — government-furnished equipment, Internet of Things, operational technology, restricted information systems, test equipment
- Contractor risk managed assets — can, but are not intended to, handle CUI because of the way you manage them
- Out-of-scope assets — cannot process, store or transmit CUI, and are separated from the CUI environment
- Part 2 — Environment components
- Users
- Locations and facilities
- Microsoft 365 and cloud platforms
- SaaS applications
- External service providers
- Endpoints
- Networks
- Part 3 — The question this worksheet exists to ask
- Answer for the whole organization, then for each excluded asset
- Turn every weak exclusion into either a technical separation you can show or a decision to bring the asset in scope.
- Draft the boundary description and the asset categories into your System Security Plan (SSP); the assessor will read scope there first.
- Take the in-scope list into the CMMC Technology Inventory (CMMCg-R004) and record each asset in detail.
This resource is general guidance for organizations preparing for Cybersecurity Maturity Model Certification (CMMC). It is not legal advice, it does not constitute an assessment or a certification, and completing it does not by itself establish compliance with NIST SP 800-171 Rev 2, 32 CFR Part 170 or any contract clause. Determinations about what information constitutes Controlled Unclassified Information (CUI) rest with the designating agency and the terms of your contract. Confirm requirements against the current regulation and your contracting officer.
Filled it in and found gaps?
That is what it is for. The readiness call turns a completed worksheet into a scoped plan, and an engineer runs it.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.