Table 3 to § 170.19 (c)(1) -CMMC Level 2 Asset Categories and Associated Requirements
Asset category | Asset description | OSA requirements | CMMC assessment requirements |
Assets that are in the Level 2 CMMC Assessment Scope | |||
Controlled Unclassified Information (CUI) Assets | . Assets that process, store, or transmit CUI | . Document in the asset inventory . Document asset treatment in the System Security Plan (SSP). . Document in the network diagram of the CMMC Assessment Scope. . Prepare to be assessed against CMMC Level 2 security requirements. | . Assess against all Level 2 security requirements. |
Security Protection Assets | . Assets that provide security functions or capabilities to the OSA's CMMC Assessment Scope | . Document in the asset inventory . Document asset treatment in SSP. . Document in the network diagram of the CMMC Assessment Scope. . Prepare to be assessed against CMMC Level 2 security requirements. | . Assess against Level 2 security requirements that are relevant to the capabilities provided. |
Contractor Risk Managed Assets | . Assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place . Assets are not required to be physically or logically separated from CUI assets. | . Document in the asset inventory . Document asset treatment in the SSP. . Document in the network diagram of the CMMC Assessment Scope. . Prepare to be assessed against CMMC Level 2 security requirements. | . Review the SSP: . If sufficiently documented, do not assess against other CMMC security requirements, except as noted. . If OSA's risk-based security policies, procedures, and practices documentation or other findings raise questions about these assets, the assessor can conduct a limited check to identify deficiencies. |
. The limited check(s) shall not materially increase the assessment duration nor the assessment cost. | |||
. The limited check(s) will be assessed against CMMC security requirements. | |||
Specialized Assets | . Assets that can process, store, or transmit CUI but are unable to be fully secured, including: Internet of Things (IoT) devices, Industrial Internet of Things (IIoT) devices, Operational Technology (OT), Government Furnished Equipment (GFE), Restricted Information Systems, and Test Equipment | . Document in the asset inventory . Document asset treatment in the SSP. . Show these assets are managed using the contractor's risk-based security policies, procedures, and practices. . Document in the network diagram of the CMMC Assessment Scope. | . Review the SSP. . Do not assess against other CMMC security requirements. |
Assets that are not in the Level 2 CMMC Assessment Scope | |||
Out-of-Scope Assets | . Assets that cannot process, store, or transmit CUI; and do not provide security protections for CUI Assets | . Prepare to justify the inability of an Out-of-Scope Asset to process, store, or transmit CUI | . None. |
. Assets that are physically or logically separated from CUI assets | |||
. Assets that fall into any in-scope asset category cannot be considered an Out-of-Scope Asset | |||
. An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset |
Table 4 to § 170.19 (c)(2)(i) -ESP Scoping Requirements
When the ESP processes, stores, or transmits: | When utilizing an ESP that is: | |
A CSP | Not a CSP | |
CUI (with or without SPD) | The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012 | The services provided by the ESP are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment. |
SPD (without CUI) | The services provided by the CSP are in the OSA's assessment scope and shall be assessed as Security Protection Assets | The services provided by the ESP are in the OSA's assessment scope and shall be assessed as Security Protection Assets. |
Neither CUI nor SPD | A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP | A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP. |
Table 5 to § 170.19 (d)(1) -CMMC Level 3 Asset Categories and Associated Requirements
Asset category | Asset description | OSC requirements | CMMC assessment requirements |
Assets that are in the Level 3 CMMC Assessment Scope | |||
Controlled Unclassified Information (CUI) Assets | . Assets that process, store, or transmit CUI . Assets that can, but are not intended to, process, store, or transmit CUI (defined as Contractor Risk Managed Assets in table 1 to paragraph (c)(1) of this section CMMC Scoping). | . Document in the asset inventory . Document asset treatment in the System Security Plan (SSP). . Document in the network diagram of the CMMC Assessment Scope. . Prepare to be assessed against CMMC Level 2 and Level 3 security requirements. | . Limited check against Level 2 and assess against all Level 3 CMMC security requirements. |
Security Protection Assets | . Assets that provide security functions or capabilities to the OSC's CMMC Assessment Scope, irrespective of whether or not these assets process, store, or transmit CUI | . Document in the asset inventory . Document asset treatment in the SSP. . Document in the network diagram of the CMMC Assessment Scope. . Prepare to be assessed against CMMC Level 2 and Level 3 security requirements. | . Limited check against Level 2 and assess against all Level 3 CMMC security requirements that are relevant to the capabilities provided. |
Specialized Assets | . Assets that can process, store, or transmit CUI but are unable to be fully secured, including: Internet of Things (IoT) devices, Industrial Internet of Things (IIoT) devices, Operational Technology (OT), Government Furnished Equipment (GFE), Restricted Information Systems, and Test Equipment | . Document in the asset inventory . Document asset treatment in the SSP. . Document in the network diagram of the CMMC Assessment Scope. . Prepare to be assessed against CMMC Level 2 and Level 3 security requirements. | . Limited check against Level 2 and assess against all Level 3 CMMC security requirements. . Intermediary devices are permitted to provide the capability for the specialized asset to meet one or more CMMC security requirements. |
Assets that are not in the Level 3 CMMC Assessment Scope | |||
Out-of-Scope Assets | . Assets that cannot process, store, or transmit CUI; and do not provide security protections for CUI Assets | . Prepare to justify the inability of an Out-of-Scope Asset to process, store, or transmit CUI | . None. |
. Assets that are physically or logically separated from CUI assets | |||
. Assets that fall into any in-scope asset category cannot be considered an Out-of-Scope Asset | |||
. An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset |
Table 6 to § 170.19 (d)(2)(i) -ESP Scoping Requirements
When the ESP processes, stores, or transmits: | When utilizing an ESP that is: | |
A CSP | Not a CSP | |
CUI (with or without SPD) | The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012 | The services provided by the ESP are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment. |
SPD (without CUI) | The services provided by the CSP are in the OSA's assessment scope and shall be assessed as Security Protection Assets | The services provided by the ESP are in the OSA's assessment scope and shall be assessed as Security Protection Assets. |
Neither CUI nor SPD | A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP | A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP. |
32 C.F.R. §170.19