CMMC Technology Inventory
Filled in by IT, or by your managed service provider with IT checking it, this inventory produces the asset register that sits behind your scope: every endpoint, server, network device, identity system, cloud platform, security product, SaaS application and external service, with an owner, a location, its scope status and whether it handles Controlled Unclassified Information (CUI). NIST SP 800-171 Rev 2 asks for baseline configurations and inventories (CM.L2-3.4.1); an assessor will compare this list against what they see on the network.
- 01
Start from the in-scope list on your CMMC Scoping Worksheet (CMMCg-R003) and from whatever automated inventory you already have (MDM, RMM, domain, cloud console exports). Automated data first, then correct it by hand.
- 02
Fill in one group at a time. Every row needs a named owner; "IT" is a department, not an owner.
- 03
Use the Category column for the CMMC asset category you settled in the scoping worksheet (CUI, security protection, specialized, contractor risk managed, out of scope). If the category here disagrees with the scoping worksheet, fix one of them today.
- 04
Mark "Managed by" as the thing that actually enforces configuration on the asset (MDM, domain policy, RMM, vendor, nobody). "Nobody" is a valid answer and a finding.
- 05
Reconcile the count in each group against a second source (licence count, switch port count, invoice from the provider). Where the numbers differ, the difference is your first finding.
9 working tables, 1 checklist, a findings section and recommended next steps. Every page carries the resource number, the version and the licence.
- Inventory by category group
- Endpoints — laptops, desktops, workstations, tablets, phones, shop-floor and field devices
- Servers — physical, virtual, on-premises and hosted
- Network infrastructure — firewalls, switches, wireless, VPN, routers
- Identity systems — directory, single sign-on, MFA, privileged access
- Microsoft 365 / cloud platforms — tenants, workloads, subscriptions
- Security products — endpoint protection, logging and SIEM, backup, vulnerability scanning, email security
- SaaS applications — anything a user logs into that could hold project information
- External services — managed service providers, hosting, cloud service providers, print, shredding, courier
- Reconciliation
- Counts against a second source
- Before you call this inventory complete
- Fix the category disagreements between this inventory and the scoping worksheet, then update the SSP boundary description to match.
- Put the inventory under change control: name who updates it and what event triggers an update (new hire, new device, new SaaS sign-up).
- With scope and inventory settled, review your posture family by family with the CMMC Level 2 Readiness Checklist (CMMCg-R005).
This resource is general guidance for organizations preparing for Cybersecurity Maturity Model Certification (CMMC). It is not legal advice, it does not constitute an assessment or a certification, and completing it does not by itself establish compliance with NIST SP 800-171 Rev 2, 32 CFR Part 170 or any contract clause. Determinations about what information constitutes Controlled Unclassified Information (CUI) rest with the designating agency and the terms of your contract. Confirm requirements against the current regulation and your contracting officer.
Filled it in and found gaps?
That is what it is for. The readiness call turns a completed worksheet into a scoped plan, and an engineer runs it.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.