CMMC 2.0 Scoping Guidance Limits the Scope of Cybersecurity Assessments
Client Alert | 1 min read | 12.23.21
The Department of Defense (DoD) recently released the initial guidance documents for Version 2.0 of its Cybersecurity Maturity Model Certification (CMMC) program, including its much-anticipated Scoping Guidance. While the guidance documents generally adhere to the current requirements for the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), the Scoping Guidance includes notable developments. Chief among them is the introduction of two asset categories — “Specialized Assets” and “Contractor Risk Managed Assets” — that could potentially limit the scope of a contractor’s CMMC assessment, as well as the number and types of assets to be assessed against the applicable CMMC practices.
- Specialized Assets include government property; internet of things (IoT) and industrial internet of things (IIoT) devices; operational technology; systems configured based entirely on government requirements and used to support a contract; and test equipment.
- Contractor Risk Managed Assets include computing resources that are capable of handling CUI but are prevented from doing so by the contractor’s security policies, procedures, and practices.
Contractors expecting to be subject to CMMC should carefully review the Scoping Guidance, as well as the other guidance documents, to determine whether and how they may wish to limit the scope of CMMC’s applicability.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 11 min read | 12.15.25
New York LLC Transparency Act: Key Requirements and Deadlines
On January 1, 2026 (“Effective Date”), the New York LLC Transparency Act ("New York Act”) is scheduled to take effect, introducing new disclosure requirements for limited liability companies (“LLCs”) formed or registered to do business in New York State. The New York Act is expected to impose the type of broad beneficial ownership requirements the federal CTA and rules implementing it was designed to require, before the federal government’s decision to limit the scope of the CTA’s beneficial ownership reporting requirements to foreign companies and foreign beneficial owners.
Client Alert | 7 min read | 12.15.25
The New EU “Pharma Package:” EU Reaches Landmark Deal on Pharma Package
Client Alert | 5 min read | 12.12.25
Eleventh Circuit Hears Argument on False Claims Act Qui Tam Constitutionality
Client Alert | 8 min read | 12.11.25
Director Squires Revamps the Workings of the U.S. Patent Office

