9.1 Scoping Fundamentals: Organizational Scope, Level 1 & Level 2

Key Takeaways

  • Organizational scope identifies business units, contracts, information flows, people, technology, and facilities before the formal assessment boundary is validated.
  • Level 1 follows FCI assets and their protection; it is an annual self-assessment and has no C3PAO certification option.
  • Level 2 uses five asset categories and includes providers according to CUI access or security-protection functions.
  • The OSC proposes and documents scope, while a C3PAO validates the Level 2 certification-assessment scope during CAP Phase 1.
  • Segmentation can reduce scope only when physical or logical separation and data flow are demonstrated with adequate evidence.
Last updated: August 2026

9.1 Scoping Fundamentals: Organizational Scope, Level 1 & Level 2

Scoping determines where an assessment applies. A technically strong control outside the relevant boundary does not prove an in-scope requirement, and an omitted service can invalidate conclusions. Begin with information and business processes, not with a preferred network diagram.

Organizational scope before assessment scope

The organization first identifies the legal entity and CAGE information, contracts, programs, business units, host and supporting units, locations, people, technologies, facilities, and external services associated with FCI or CUI. It traces how the information is received, created, processed, stored, transmitted, backed up, printed, discussed, supported, and destroyed.

This discovery produces the proposed assessment scope and evidence set. It should align the asset inventory, System Security Plan, network and data-flow documentation, provider responsibilities, and physical locations. A diagram is valuable evidence, but scoping does not pass merely because a diagram exists.

Level 1 scope

Level 1 covers contractor assets that process, store, or transmit FCI, together with people, technology, and facilities providing protection. Assets can be outside the Level 1 assessment scope when they do not handle FCI, do not provide protection to FCI assets, and are physically or logically separated under the Level 1 Scoping Guide.

The organization performs the Level 1 self-assessment annually. There is no “select program” C3PAO Level 1 certification path. Consultants may assist, but the organization owns the result and the Affirming Official submits the affirmation.

Level 1 uses the FCI boundary; do not mechanically apply the five Level 2 asset-category labels. Still investigate identity, firewall, endpoint, backup, email, help desk, remote administration, and facility functions because a service that protects the FCI system can be in scope even if it does not hold the business file itself.

Level 2 scope

Level 2 begins with CUI and applies five asset categories:

  1. CUI Assets process, store, or transmit CUI.
  2. Security Protection Assets provide security functions or capabilities to CUI Assets.
  3. Contractor Risk Managed Assets can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices.
  4. Specialized Assets include government-furnished equipment, Internet of Things or operational technology, restricted information systems, and test equipment that cannot be fully secured like conventional IT.
  5. Out-of-Scope Assets cannot process, store, or transmit CUI and do not provide security protection because they are physically or logically separated.

The category affects assessment treatment, not just labeling. CUI Assets and Security Protection Assets receive the full applicable requirement assessment. CRMA and Specialized Asset treatment depends on the scoping guide, documented management, and risk. An “out-of-scope” label must be proven by architecture and operation.

People, technology, facilities, and providers

Scope is more than hardware. People with CUI access or security responsibilities, technologies providing storage or protection, and facilities where CUI is handled can all be relevant. Remote administrators, SOC analysts, identity providers, backup services, ticketing platforms, and cloud administrators may matter even when no appliance sits in the OSC's server room.

A cloud service provider that processes, stores, or transmits CUI triggers the cloud requirements and must be represented accurately in the SSP and responsibility evidence. An external service provider that supplies a security protection function may bring its service components into scope. Provider certification is not presumed; verify the exact service boundary and shared responsibilities.

Scope validation in CAP

For a Level 2 certification assessment, the OSC proposes and documents the scope. During CAP Phase 1, Conduct the Pre-Assessment, the assessment team validates that scope against the contract, SSP, inventories, diagrams, flows, provider relationships, and facilities. Validation is a Phase 1 readiness activity, not a Phase 2 gateway invented after fieldwork begins.

If scope information is incomplete or inconsistent, the parties resolve readiness according to CAP before proceeding. Assessors do not design the boundary for the OSC or conceal an omitted system to preserve the schedule.

Segmentation and enclaves

An enclave can reduce cost and complexity when CUI is deliberately confined. Effective segmentation requires controlled ingress and egress, identity and administrative separation, secure remote access, logging, backups, print and media controls, and physical boundaries appropriate to the facts. A VLAN label alone is not logical separation. Shared enterprise services can pull dependencies into scope as Security Protection Assets.

Use focused evidence: firewall rules and routing tests, identity trust and group membership, data-loss prevention or transfer controls, provider configurations, physical walkthroughs, interviews, and data-flow demonstrations. CAP uses focused, nonstatistical sampling; it does not require a statistically representative sample of every device.

Worked example

An engineering enclave stores CUI. Its workstations and file server are CUI Assets. The shared enterprise identity provider, firewall, EDR console, and SIEM protect them and are Security Protection Assets. A CNC device that consumes controlled files may be a Specialized Asset, not automatically out of scope. Corporate laptops that are prohibited and technically blocked from the enclave may be CRMAs or out of scope depending on capability, policy, and separation. An MSP with privileged access and security duties must be represented through its people, tools, and responsibility assignments.

The reliable order is: follow the data, identify protection, identify capability and connectivity, categorize each asset, document external dependencies, and validate the boundary.

Test Your Knowledge

When is a Level 2 certification-assessment scope validated under CAP 2.0?

A
B
C
D
Test Your Knowledge

Which statement about Level 1 assessment is correct?

A
B
C
D
Test Your Knowledge

What sampling approach does CAP use?

A
B
C
D