9.2 The 5 Asset Categories: CUI, SPA, CRMA, Specialized & Out-of-Scope
Key Takeaways
- Level 2 uses five asset categories: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets.
- CUI Assets are assessed against all Level 2 requirements; Security Protection Assets are assessed against requirements relevant to the security capabilities they provide.
- Contractor Risk Managed Assets can but are not intended to handle CUI because of documented risk-based policies, procedures, and practices; the rule expressly says they need not be physically or logically separated from CUI Assets.
- Specialized Assets remain in scope, are documented and managed through risk-based practices, and receive SSP review rather than assessment against the other Level 2 requirements.
- Out-of-Scope Assets cannot handle CUI, do not provide security protection for CUI Assets, and are physically or logically separated; the OSA must be prepared to justify that status.
The Five Level 2 Asset Categories
32 CFR §170.19(c) uses five categories to define Level 2 scope and assessment treatment. A category is not a risk ranking and does not place every enterprise object on a single “maximum to zero scrutiny” scale. Categorization follows capability, intended use, security function, separation, and documented facts.
1. CUI Assets
A CUI Asset processes, stores, or transmits CUI. It is in the Level 2 CMMC Assessment Scope. The OSA documents it in the asset inventory, SSP, and network diagram and prepares it for assessment against all Level 2 security requirements.
Examples may include a workstation that edits controlled drawings, a database that stores CUI, a print device that receives CUI, or a provider service that handles it under the applicable scoping rule. Encryption does not make the receiving asset out of scope if the asset can decrypt or process the information.
2. Security Protection Assets
A Security Protection Asset (SPA) provides security functions or capabilities to the CMMC Assessment Scope. Identity services, logging systems, endpoint-security management, boundary devices, vulnerability services, and physical-access systems can be SPAs even when they do not process document-level CUI.
SPAs are documented in the inventory, SSP, and network diagram. They are assessed against Level 2 requirements relevant to the capabilities provided, not automatically all 110 and not merely one family with a similar name. A SIEM may support AU, IR, SI, access, and provider responsibilities depending on its functions.
3. Contractor Risk Managed Assets
A Contractor Risk Managed Asset (CRMA) can process, store, or transmit CUI but is not intended to do so because risk-based security policies, procedures, and practices are in place. The regulation expressly says CRMAs are not required to be physically or logically separated from CUI Assets.
The OSA documents the CRMA in the inventory, SSP, and network diagram and explains its treatment. The assessor reviews the SSP. If documentation is sufficient, the asset is not assessed against the other CMMC requirements. If the documented practices or other findings raise questions, the assessor may perform a limited check against CMMC requirements. That check must not materially increase assessment duration or cost.
This is not a casual “policy-only” exclusion. The team can examine whether the risk-based practices actually keep CUI from the asset. But it is also incorrect to impose out-of-scope separation criteria on every CRMA.
4. Specialized Assets
Specialized Assets can handle CUI but cannot be fully secured. The regulatory examples are IoT, IIoT, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and Test Equipment.
They remain in the Level 2 scope. The OSA documents them in the inventory, SSP, and network diagram and shows how risk-based security policies, procedures, and practices manage them. Assessment treatment is SSP review; they are not assessed against the other Level 2 requirements. Calling an ordinary unsupported workstation “test equipment” does not establish the category—the asset must fit the specialized facts.
5. Out-of-Scope Assets
An Out-of-Scope Asset cannot process, store, or transmit CUI and does not provide security protection for CUI Assets. It is physically or logically separated from CUI Assets. An asset that meets any in-scope category cannot be called out of scope.
The OSA prepares to justify the asset’s inability to handle CUI. The table assigns no CMMC assessment requirements to out-of-scope assets. One explicit example is a VDI endpoint configured so it cannot process, store, or transmit CUI beyond keyboard, video, and mouse interaction. Clipboard, local-drive mapping, print, download, cache, or another path may change that conclusion.
Documentation matrix
| Category | Inventory / SSP / network diagram | Assessment treatment |
|---|---|---|
| CUI Asset | Required | All Level 2 requirements |
| SPA | Required | Requirements relevant to provided capabilities |
| CRMA | Required | SSP review; limited check only when questions arise |
| Specialized Asset | Required, plus risk-based management | SSP review; not other Level 2 requirements |
| Out-of-Scope | OSA justifies inability; not an in-scope category | None under the table |
Scenario method
Start with what the asset can do, what it is intended to do, and whether it supplies a security capability. Then inspect actual data flows, configurations, provider functions, and risk-based practices. Apply the table’s documentation and assessment column exactly.
A corporate workstation able to reach CUI but governed by documented practices preventing that use may be a CRMA; it is not automatically required to be separated. A firewall protecting CUI is an SPA. An industrial controller that can process CUI but cannot be fully secured may be Specialized. A VDI client is out of scope only when its technical channels meet the narrow no-CUI condition. Labels follow evidence.
Which statement about Contractor Risk Managed Assets is correct?
How are Security Protection Assets assessed?
What is the assessment treatment for a properly categorized Specialized Asset at Level 2?