CMMC scoping: the enclave decision that sets your entire cost

CMMC: Hands-on Self-Assessment, Templates & Full Scenarios — Nexus Academy course

Every CMMC project has one decision that costs more than all the others combined, and it happens in the first fortnight: what is in scope. Get it right and you are securing a defined enclave. Get it wrong and you are applying NIST SP 800-171 to the entire company, including the laptops of people who have never seen a government contract.

Start by finding the data, not the systems

Scoping begins with Federal Contract Information and Controlled Unclassified Information — where they enter, where they are stored, where they are processed, and where they leave. Follow the actual workflow. In most small defence suppliers, CUI arrives by email, gets saved somewhere convenient, gets opened on an engineer laptop, and gets returned by email. Each of those stops is in scope until you deliberately change the workflow.

The enclave option

An enclave is a deliberately narrowed environment — often a dedicated virtual desktop, file store and mail flow — where all CUI is handled, separated from the rest of the business. It costs money to build. It usually costs far less than assessing every system you own, and it makes the boundary explainable in one diagram.

  • Fewer assets to harden, monitor, patch and evidence.
  • A clearer story for the assessor, who can see the boundary rather than infer it.
  • Contained change — a new laptop for the marketing team no longer has assessment consequences.
  • The trade: people have to work inside the enclave, and enforcing that is a management problem as much as a technical one.

Scoring honestly beats scoring well

The self-assessment score you submit to SPRS is a claim you may later have to defend. A high score built on generous interpretation is a liability; a lower score with a credible POA&M and visible progress is a normal position for a supplier who is working the problem. Assessors and primes have seen both, and they can tell the difference quickly.

Documentation that carries its weight

Two documents do the heavy lifting. The System Security Plan describes the boundary, the assets and how each requirement is met — it should be readable by someone who has never seen your network. The Plan of Action and Milestones records what is not met, who owns it, and when it will be. Together they answer almost every question an assessor opens with.

If your scope diagram does not fit on one page, the scope is probably wrong. Narrow it before you start writing controls.

Go deeper

CMMC: Hands-on Self-Assessment, Templates & Full Scenarios

If you hold federal contract information or CUI, CMMC decides whether you keep the contract. This course takes you from zero to a completed self-assessment, with SSP, POA&M, SPRS submission and two full end-to-end scenarios.

Enrol on UdemyCourse details

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *