My firm has 30 employees, and we are bidding on a federal services contract. We are an SDVOSB, and this is a set-aside. Our NAICS code is 541611. We have four engineers who will be touching CUI, but the rest of the company will not. The CMMC Level 2 requirement is a new one for us, and I am trying to figure out how to scope the assessment so it does not pull our entire network into it. I have read through the CMMC scoping guide, and it talks about asset categories and using an enclave. We are considering setting up a separate virtual desktop environment for those four engineers. How do we document that boundary for the CMMC assessment? Will a virtual desktop environment keep the rest of our company out of scope? What will the assessor test to prove that boundary holds up?
How do I scope a CMMC assessment so my whole network does not end up in it?
Ask a question2 answers
A virtual desktop environment can help define the boundary for a CMMC assessment, but the assessor will test more than just that environment. The CMMC Level 2 requirement means you are dealing with controlled unclassified information (CUI), so the scope needs to protect that data. The assessor will look at all assets that process, store, or transmit CUI. They will also look at the security of the connections to and from the virtual desktop environment, including how users access it and what other systems it interacts with. Documentation of your network topology, data flow diagrams showing CUI movement, and access control policies will be critical. The assessor will verify that access to the CUI environment is restricted to authorized personnel and that no CUI inadvertently leaves that environment. They will also test the effectiveness of your segmentation and access controls to ensure the rest of your company's network is truly isolated from the CUI.
A virtual desktop environment can help define the boundary for a CMMC assessment, but the contracting officer will look to see that your CMMC Status is posted in SPRS. Tom is right that the assessor will test your boundaries, but the government's primary check is on the CMMC status. Your CMMC Level 2 self-assessment is conducted every three years, and the resulting CMMC Status is valid for three years from the CMMC Status Date. The virtual desktop environment is a technical control to limit the scope of your CUI, and you will need to document how it meets all 110 requirements of NIST SP 800-171 Revision 2 for Level 2.