https://www.sikich.com

Self-assessment is not a free pass: Why CMMC scoping quality now matters more than ever

INSIGHT 5 min read

TL;DR: With the CMMC Phase 2 rollout paused, contractors should not mistake the absence of a required C3PAO assessment for an absence of cybersecurity obligations. Your CUI boundary, System Security Plan (SSP), SPRS assessment, supporting evidence, and Plan of Action and Milestones (POA&M), where applicable, need to tell the same story. If they do not, the issue is bigger than simply being unprepared for a future CMMC assessment.

The Department of Justice has already pursued False Claims Act cases involving allegations that contractors misrepresented their cybersecurity compliance.

Here are the three CMMC scoping mistakes we see most often, and what a defensible deliverable set needs to include.

Why scoping matters even more during the pause

CMMC Phase 2 may be paused, but the underlying cybersecurity requirements have not disappeared.

For contractors subject to DFARS 252.204-7012, covered contractor information systems must continue to provide adequate security and implement the applicable NIST SP 800-171 requirements. Contractors subject to DFARS 252.204-7019 and 252.204-7020 must also maintain a current NIST SP 800-171 DoD Assessment in SPRS. Applicable CMMC requirements introduce additional assessment and affirmation requirements.

Without a C3PAO independently validating the environment, contractors need to be particularly confident that the scope and implementation represented through their SSP, SPRS information, and supporting documentation accurately reflect the environment where CUI is processed, stored, and transmitted.

That is not just an assessment-readiness issue. It can become a legal one.

In 2022, Aerojet Rocketdyne agreed to pay 9 million dollars to resolve allegations that it misrepresented its compliance with federal cybersecurity requirements. The settlement resolved allegations, and there was no determination of liability.

The lesson for contractors is straightforward: your documented cybersecurity posture should match your actual environment.

The three scoping mistakes we see most often

1. Over-scoping the entire network.

More scope does not automatically mean better security.

Bringing corporate systems, users, applications, and infrastructure into the CUI boundary when they never process, store, or transmit CUI can significantly increase implementation costs and the eventual assessment burden.

The objective should be an accurate and defensible boundary—not simply the largest or smallest one possible.

2. Documenting where CUI lives—but not where it goes.

Most organizations can identify the primary location where CUI is stored.

The harder questions are what happens before and after it gets there.

Does CUI move through email? Is it downloaded to endpoints? Does it enter a ticketing or project management platform? Is it printed? Can employees access it remotely? Is it transferred to subcontractors? Are backups included?

A defensible scope follows the entire CUI data flow, not simply the primary repository.

3. Leaving shared responsibilities undefined.

Using an MSP, MSSP, cloud provider, enclave provider, or other external service does not eliminate the contractor’s responsibility to understand how the applicable security requirements are satisfied.

One of the most common gaps we find is simple:

The contractor believes the provider owns a requirement.
The provider believes the contractor owns it.

Unless those responsibilities are documented and supported by evidence, the gap may remain invisible until someone actually tests the requirement.

What a defensible documentation package should contain

Three deliverables form the foundation.

A defensible scoping document

It should identify the systems, assets, users, locations, service providers, and interfaces involved in creating, processing, storing, or transmitting CUI.

Just as importantly, it should explain why assets are in scope, out of scope, or treated as specialized or security protection assets.

A System Security Plan that reflects reality

The SSP should address all 110 NIST SP 800-171 security requirements and explain how they are implemented within the actual environment.

Generic statements such as “the organization restricts access to authorized users” are not enough.

A reviewer should be able to understand who performs the activity, what technology or process supports it, where it occurs, and what evidence demonstrates that it operates as described.

A POA&M that functions as a remediation plan

Where POA&Ms are permitted, they should identify actual deficiencies, responsible owners, planned remediation activities, dependencies, and realistic completion dates.

A POA&M should demonstrate active remediation—not serve as a permanent parking lot for unresolved requirements.

And the documentation needs to reconcile. The scope should match the SSP. The SSP should match the assessment. The assessment should match the SPRS representation. And all of it should match the environment that actually exists.

Get ready for what’s next

The Phase 2 pause changes the immediate assessment timeline. It does not make accurate scoping, NIST SP 800-171 implementation, or defensible documentation less important.

In many ways, it makes them more important.

Organizations that use this period to validate their CUI flows, tighten their boundaries, reconcile their SSP to the actual environment, and address open POA&M items will be better positioned for whatever requirements emerge from the Department’s review.

Organizations that wait may find themselves rebuilding those artifacts under a much tighter deadline.

At Sikich, our STARS program works with contractors to build this foundation from the ground up: scoping, SSP development, assessment support, POA&M development, and preparation for independent scrutiny.

I’ll walk through the scoping mistakes that create the greatest compliance risk—and what a defensible package looks like in practice—during our October 29 webinar, CMMC After the Pause.

Register for the October 29 webinar: CMMC After the Pause

Want a second set of eyes on your CMMC scope before the revised requirements become clearer? Talk to Sikich’s CMMC team. We can help identify where your boundary, SSP, assessment results, and supporting evidence align—and where they may not hold up under scrutiny.

Author

Matt Schiavone, CPA, CISSP, CISA, CMMC-CCA, is a director of System and Organization Controls (SOC®) Report services. He works extensively with companies in the high-tech, government contracting, financial services and healthcare industries to align risk mitigation initiatives to business needs. Matt possesses comprehensive advisory and audit experience across the myriads of cybersecurity standards and attestation engagements.