For many defense contractors, the first Cybersecurity Maturity Model Certification meeting can feel intimidating.
Business owners may expect an auditor to immediately begin testing passwords, reviewing security logs or asking technical questions about all 110 NIST SP 800-171 security requirements.
That is usually not where an effective CMMC readiness engagement should begin.
The first meeting should focus on scoping: identifying the people, facilities, systems, applications, service providers and processes that handle Federal Contract Information or Controlled Unclassified Information.
Scoping establishes the foundation for nearly every activity that follows, including the gap assessment, System Security Plan, asset inventory, network diagrams, evidence collection and remediation plan.
What Is CMMC Scoping?
CMMC scoping is the process of determining which parts of an organization are subject to the applicable cybersecurity requirements.
The scope is based primarily on how sensitive government information enters the organization, where it is stored, how it is processed, who can access it and how it is transmitted to other parties.
CMMC applies to unclassified contractor information systems and is intended to provide assurance that defense contractors are protecting sensitive government information.
Depending on the contract and the information involved, an organization may be required to protect:
Federal Contract Information
Federal Contract Information, commonly called FCI, is information provided by or generated for the government under a contract that is not intended for public release.
Controlled Unclassified Information
Controlled Unclassified Information, commonly called CUI, is government information that requires safeguarding or dissemination controls under applicable laws, regulations or government-wide policies.
When CUI is processed, stored or transmitted within a contractor environment, the organization may be required to implement the applicable NIST SP 800-171 security requirements.
The initial meeting helps determine where these information types exist and which systems are involved.
Why Scoping Comes Before the Gap Assessment
A consultant cannot accurately assess an environment until the assessment boundary is understood.
Without proper scoping, an organization may accidentally assess its entire corporate network even though only a limited enclave handles CUI. This can dramatically increase the cost and complexity of compliance.
The opposite problem is also possible. An organization may exclude systems that should be in scope, such as:
- Email platforms
- Cloud storage services
- Employee laptops
- Remote access tools
- Printers and multifunction devices
- Backup systems
- Security monitoring platforms
- Managed service provider tools
- External applications that receive or process CUI
Incorrect scoping can lead to inaccurate documentation, incomplete security controls and unexpected findings during an assessment.
A well-defined scope helps the organization understand exactly what must be protected.
What Will Be Discussed During the Initial Meeting?
The first meeting is generally a discovery session. The consultant will ask questions about the organization’s contracts, information flows, technology and business processes.
1. Contractual Requirements
The discussion should begin with the contracts, subcontracts or purchase orders that drive the cybersecurity requirement.
The organization may be asked to provide:
- Relevant contract clauses
- Security requirements received from a prime contractor
- Statements of work
- Data handling instructions
- CMMC level requirements
- Existing SPRS information
- Previous NIST SP 800-171 assessment results
The consultant is not replacing legal counsel or the contracting officer. However, these documents help identify the cybersecurity obligations that may apply.
2. The Type of Information Received
The organization should be prepared to explain what information it receives from customers, prime contractors or government agencies.
Examples may include:
- Technical drawings
- Engineering specifications
- Manufacturing information
- Maintenance records
- Testing data
- Project documentation
- Controlled emails
- Export-controlled information
- Personnel or logistics information
Not every government-related document is automatically CUI. The organization should work with the information owner, prime contractor or contracting authority when the information is not clearly identified.
The contractor is responsible for understanding what information enters its environment, while the government or authorized information owner determines whether information is designated as CUI.
3. How Information Enters the Environment
The consultant will ask how sensitive information is received.
Common methods include:
- Microsoft 365 email
- Secure file-transfer portals
- Customer collaboration platforms
- SharePoint
- Teams
- Cloud storage
- Virtual private networks
- Physical media
- Printed documents
- Government-furnished equipment
Each entry point may introduce systems that need to be included in the assessment boundary.
4. Where Information Is Stored
The organization should identify every location where FCI or CUI may be stored.
This could include:
- Employee workstations
- File servers
- SharePoint sites
- Teams channels
- Email mailboxes
- OneDrive accounts
- Cloud applications
- Backup platforms
- Removable media
- Mobile devices
- Printed records
Temporary storage also matters. For example, a file downloaded from a secure portal to an employee’s desktop may place that workstation within scope.
5. How Information Is Processed
Processing includes more than editing a document.
An application may be considered part of the information flow when it is used to:
- View information
- Modify information
- Analyze information
- Convert file formats
- Generate reports
- Manufacture components
- Perform testing
- Print documents
- Scan documents
- Back up data
The consultant will want to understand which systems interact with the information and what those systems do.
6. How Information Is Transmitted
The meeting should identify how sensitive information is sent internally and externally.
Examples include:
- File-transfer services
- Customer portals
- Teams or other collaboration platforms
- VPN connections
- Application programming interfaces
- Removable media
- Physical delivery
- Subcontractor exchanges
Encryption, access controls and approved transmission methods will be reviewed later. The first step is documenting how the transmission occurs.
7. Employees and Remote Work
The consultant will ask which employees have access to sensitive information and where they work.
Topics may include:
- Remote employees
- Home offices
- Personally owned equipment
- Company-managed laptops
- Virtual desktops
- Mobile devices
- Shared accounts
- Privileged administrators
- Temporary workers
- Contractors
Remote work does not automatically prevent CMMC compliance, but it must be included in the information-flow and security discussions.
8. External Service Providers
Many organizations depend on managed service providers, managed security service providers, cloud platforms and software vendors.
The initial meeting should identify every external provider that:
- Manages in-scope systems
- Has administrative access
- Stores customer data
- Monitors security events
- Performs backups
- Provides identity services
- Supports email or collaboration
- Hosts business applications
The involvement of an external provider does not automatically transfer the contractor’s compliance responsibility to that provider.
The organization still needs to understand what the provider does, what information the provider can access and how the service supports the applicable requirements.
9. Physical Information and Facilities
CMMC is not limited to electronic information.
The consultant may ask about:
- Printed technical drawings
- Filing cabinets
- Production floors
- Visitor access
- Badge systems
- Security cameras
- Shipping and receiving areas
- Document destruction
- Physical media
- Home-office storage
Facilities that store, process or discuss sensitive information may need to be included in the scope.
The Five Common Asset Categories
During scoping, assets are often grouped according to how they interact with CUI and the assessment environment.
These categories may include:
CUI Assets
Assets that process, store or transmit CUI.
Security Protection Assets
Assets that provide security functions or capabilities to the CMMC environment.
Examples may include firewalls, identity platforms, endpoint-protection systems, logging tools and vulnerability-management platforms.
Contractor Risk Managed Assets
Assets that can—but are not intended to—process, store or transmit CUI because of policies, procedures and technical controls.
Specialized Assets
Specialized assets may include operational technology, Internet of Things devices, government-furnished equipment, test equipment or systems that cannot support traditional security controls.
Out-of-Scope Assets
Assets that do not process, store or transmit CUI and cannot provide a path into the CUI environment.
The exact treatment of an asset depends on its function, connectivity, configuration and relationship to the assessment boundary.
Who Should Attend the Initial Meeting?
CMMC scoping cannot be completed by the IT department alone.
The meeting should include representatives who understand both the contractual and technical sides of the organization.
Recommended attendees include:
- Executive sponsor or business owner
- Contract or compliance manager
- IT administrator
- Security representative
- Operations or engineering representative
- Human resources representative, when appropriate
- Facility or physical-security representative
- Managed service provider representative
- Employees who understand the actual data workflow
The people performing the daily work are often the best source of information.
Leadership may believe that files remain in one secure system, while employees may be downloading them, emailing them or printing them as part of normal operations. The purpose of discovery is to understand what actually happens—not only what a policy says should happen.
What Should You Bring to the Meeting?
Organizations do not need perfect documentation before the first meeting.
However, the following materials can make the discussion more productive:
- Applicable contracts and subcontracts
- DFARS and CMMC clauses
- Existing System Security Plan
- Current SPRS score
- Network diagrams
- Data-flow diagrams
- Hardware inventory
- Software inventory
- User and administrator lists
- Microsoft 365 licensing information
- Cloud-service list
- Managed service provider agreements
- Security policies
- Incident-response procedures
- Previous assessment reports
- Facility information
- List of remote workers
Missing documentation is itself useful information. It may identify one of the first readiness tasks.
Questions You Should Expect
Your consultant may ask questions such as:
- What government information do you receive?
- Who sends it to you?
- Is it marked as CUI?
- Which contracts contain cybersecurity requirements?
- How do employees receive the information?
- Where is the information stored?
- Who can access it?
- Can employees download it locally?
- Is it emailed internally or externally?
- Is it shared with subcontractors?
- Can employees print it?
- Are personal devices used?
- Do remote employees access it?
- Which vendors can access the environment?
- How is the information backed up?
- How is the information destroyed?
- What happens when an employee leaves?
- How are security incidents reported?
It is acceptable not to know every answer during the meeting.
The consultant should document open questions and identify the people or evidence needed to resolve them.
What the Initial Meeting Is Not
The initial scoping meeting should not be treated as a certification assessment.
It is generally not the time to:
- Declare the organization compliant or noncompliant
- Assign final assessment findings
- Purchase security products
- Rewrite every policy
- Test all 110 requirements
- Produce a final SPRS score
- Guarantee certification
- Assume that a specific cloud license solves every requirement
Technology decisions should come after the environment, requirements and risks are understood.
What Happens After the Meeting?
After the initial meeting, the consultant will typically begin developing or validating several core artifacts.
These may include:
Assessment Boundary
A documented description of the people, systems, facilities and service providers included in the CMMC environment.
Asset Inventory
A categorized list of hardware, software, cloud services and specialized assets.
Network Diagram
A visual representation of systems, connections, security boundaries and external services.
Data-Flow Diagram
A representation of how FCI and CUI enter, move through and leave the environment.
System Security Plan
The SSP describes the system boundary, operational environment, implementation of security requirements and relationships with other systems.
Gap Assessment Plan
Once the scope is sufficiently understood, the consultant can evaluate the applicable requirements and identify missing or partially implemented controls.
Remediation Roadmap
Findings can then be prioritized based on risk, cost, contractual urgency and technical dependencies.
How Long Does a Scoping Meeting Take?
The length depends on the size and complexity of the organization.
A small contractor with a limited environment may complete the initial discussion in approximately one to two hours.
A company with several locations, multiple business units, remote employees, manufacturing systems and numerous service providers may require multiple workshops.
Scoping should not be rushed. A few additional hours spent understanding the environment can prevent months of unnecessary remediation work.
Common Scoping Mistakes
Assuming the Entire Company Is Automatically in Scope
Some companies can isolate sensitive work within a smaller enclave. Others cannot. The answer depends on actual information flows and system connectivity.
Assuming Microsoft 365 Is Automatically Compliant
Microsoft licensing and cloud architecture must be evaluated against the organization’s specific contractual, technical and information-handling requirements.
Ignoring Email
If CUI is sent or received through email, the email environment may become part of the assessment boundary.
Forgetting Backups
Backups that contain CUI must be considered when defining the environment.
Excluding the Managed Service Provider
A provider with administrative access or security responsibilities may play an important role in the assessment.
Relying Only on Leadership Interviews
Employees who perform the actual work should be included in the discovery process.
Confusing Readiness Consulting With Certification
A readiness consultant helps an organization prepare. A formal certification assessment must follow the applicable CMMC assessment process and independence requirements.
Does the Current CMMC Phase II Suspension Eliminate the Need for Scoping?
No.
On July 13, 2026, the Department announced the suspension of CMMC Phase II requirements that had been scheduled to begin on November 10, 2026. The Department also announced a broader review of the program. However, Phase I self-assessment requirements remain in place.
The suspension does not eliminate existing obligations to protect sensitive government information or comply with applicable contractual cybersecurity requirements.
Organizations should use the additional time to:
- Confirm their scope
- Validate information flows
- Update their SSP
- Review their SPRS score
- Close security gaps
- Improve evidence collection
- Review service-provider responsibilities
- Prepare for future contract requirements
Waiting until a solicitation contains a certification requirement can leave the organization without enough time to address major architectural or procedural gaps.
Final Thoughts
A successful CMMC engagement begins with clarity.
Before evaluating controls, purchasing software or writing policies, the organization must understand:
- What information it receives
- Where that information goes
- Who can access it
- Which technologies support it
- Which external providers are involved
- Which systems belong inside the assessment boundary
Scoping is not simply an administrative exercise. It is the process that determines the size, cost, accuracy and defensibility of the entire CMMC readiness effort.
Define the scope first. Assess the requirements second. Remediate the gaps third.
NTS Solutions helps defense contractors understand their CMMC environment, define assessment boundaries, evaluate NIST SP 800-171 readiness and develop practical remediation plans.
Contact NTS Solutions to schedule an initial CMMC scoping and readiness discussion.