How CMMC Scoping works
In CMMC, scope determines everything. Every system, location, device, and person that touches Controlled Unclassified Information (CUI) is part of your assessment scope, and everything in scope must be implemented, documented, and defensible. Keeping your scope accurate, no bigger than your real environment and no smaller, is the most effective way to make CMMC manageable.
The CMMC Scoping module is where Secureframe learns what your environment actually looks like. You answer simple yes/no questions about how your organization operates, and your answers define your assessment scope and the requirements and tests that apply.
Question areas
Scoping walks you through questions in four areas:
Physical & Environmental: Whether you operate physical locations where CUI is processed, stored, or accessed, whether visitors can enter those areas, whether people access CUI from alternate work sites like home offices or while traveling, and whether equipment containing CUI ever leaves your controlled boundary for repair or maintenance.
Media Protection: Whether CUI exists outside your primary systems and cloud services, on paper documents, removable media like USB drives, media transported off-site, or physical backups.
Access Control: Whether your environment includes things like wireless networks, mobile devices, and connections to external systems.
System and Communications Protection: How CUI moves, including remote access and whether CUI travels over voice systems.
Every question is written in plain language, with each answer choice explained so you know exactly what you are saying yes or no to. A help panel on each question explains why it is being asked and what your answer affects. Some answers reveal a short follow-up question. Your progress saves automatically.
Note: Not sure about a question? Choose I'm not sure. That keeps the related requirements in scope for now, which is the safe default. You can revisit the question later, or ask your CSM before answering.
What your answers change
Your scoping answers automatically tailor your entire CMMC program:
Requirements: Requirements that do not apply to your environment are marked Not Applicable, each with a documented justification. Some answers scope out an entire practice; others scope out only specific parts of one.
Tests: Automated tests tied to requirements that do not apply are turned off, so your dashboard tracks only what actually applies to you.
Policies and SSP: Your policy language and System Security Plan (SSP) implementation statements adapt to your answers, so your documentation describes what you actually run and never claims something you scoped out.
Why accuracy matters
An honest "no" removes requirements you would otherwise waste time implementing and documenting. An inaccurate "no" hides requirements you are still responsible for meeting. When in doubt, keep it in scope or ask your CSM.
Changing your answers later
If your environment changes and you need to revisit your scoping answers, you can return to the module and update them at any time. Because scoping drives so much downstream, Navigator asks you to confirm before changes take effect.
When your changes are applied:
Requirements and tests: Requirements that are newly out of scope are marked Not Applicable and their tests are turned off. Requirements that come back into scope are restored along with their tests.
SSP implementation statements: Updated statement text is proposed for the affected requirements. Statements you have not touched update automatically; statements with your own content show the proposed change for you to accept or ignore.
Policies: Draft policies reflect your new answers right away. Published policies stay exactly as your team accepted them, and you choose when to update them.
Anything you have manually adjusted is preserved throughout: re-running scoping will not silently undo your changes.
