The real cost of getting your assessment boundary wrong

A boundary defines more than a network perimeter. It determines which assets, people, facilities, service providers, controls, and evidence become part of the assessment.

The objective is not the smallest possible boundary. It is the smallest accurate and defensible boundary that reflects how protected information is actually handled and protected.

The objective is not the smallest possible boundary. It is the smallest accurate and defensible boundary that reflects how protected information is actually handled and protected.

Oversized and incomplete boundaries create different risks

An oversized boundary can increase implementation, evidence, monitoring, and assessment effort by bringing additional systems and dependencies into scope. However, it does not mean that every requirement applies identically to every asset. Under CMMC Level 2, for example, CUI assets, security protection assets, contractor risk-managed assets, and specialized assets receive different assessment treatment.

An incomplete boundary is more serious. If Controlled Unclassified Information (CUI), Specified Information (SI), or the security services protecting that information sit outside the declared boundary, the organization may face findings, rework, or a challenge to the validity of its assessment scope.

What belongs in scope

For CMMC Level 2, the scope includes assets that process, store, or transmit CUI, as well as assets and external services that provide security functions to the assessed environment. Assets can be out of scope only when they cannot handle CUI and do not provide security protection for CUI assets.

For CPCSC, scoping includes the systems, devices, people, facilities, processes, and external providers that handle or protect SI. The scope may be enterprise-wide or limited to a bounded enclave, but it must reflect actual access and information flows.

Narrow and defensible

An enclave can reduce cost and complexity, but only when separation is effective. Physical or logical isolation, boundary protection, access restrictions, and information-flow controls must prevent protected information from moving into systems that the organization has declared out of scope.

The boundary should follow the business process, not the preferred assessment price. Email, cloud platforms, remote administration, backups, printers, removable media, security monitoring, managed service providers, and home-based work can all expand the scope if they handle or protect protected information.

Document the flows and dependencies

A defensible boundary is supported by current documentation, including:

  • a data-flow diagram showing where protected information enters, is created, stored, transmitted, printed, backed up, and destroyed;
  • a network diagram showing logical and physical boundaries, connections, remote access, and external services;
  • an asset inventory with clear asset categories and ownership;
  • a scoping rationale explaining why assets are included or excluded;
  • a current System Security Plan or equivalent description of the environment and its dependencies; and
  • contracts, service descriptions, and responsibility matrices for relevant external providers.

Five questions to answer before remediation begins

1

What CUI or SI does the organization receive, create, or generate?

2
 

Where is it processed, stored, transmitted, printed, backed up, and destroyed?

3

Which people, systems, facilities, and providers can access or protect it?

4

Which assets can technically handle it, even if policy says they should not?

5

What evidence proves that excluded assets cannot handle or protect it?

Correct scoping before remediation prevents unnecessary investment, reduces assessment rework, and gives leaders a defensible basis for architecture and funding decisions.