ASSESS · Federal

Settle the boundary before you price anything else.

$2,500 fixed fee · one boundary · 1–2 weeks

The assessment boundary decides how many of the 110 NIST SP 800-171 requirements apply to you, whether you need an enclave, and what every later stage costs. It is the first question and the one most often guessed at.

When this is the right first step

You are not yet certain what is in scope.

A prime flowed requirements down

A DFARS clause or a prime’s flow-down has arrived and you need to know which of your systems it actually reaches before you commit budget.

You are not sure you hold CUI at all

Plenty of contractors handle Federal Contract Information and no CUI. Establishing that is a smaller, cheaper answer than assuming the larger one.

Your boundary is “everything”

Treating the whole company as in scope is the most expensive possible answer, and it is usually wrong. A defensible boundary is normally much smaller.

What you get

A scoping memo you can hand to an assessor.

  • Where CUI enters, is stored, is processed, and leaves — documented as a data-flow view
  • A defensible assessment boundary, with the reasoning written down rather than assumed
  • Your assets categorized — CUI, Security Protection, Contractor Risk Managed, Specialized, and out of scope
  • How many of the 110 requirements apply to you, and which ones the boundary removes
  • Whether an enclave or GCC High is indicated, stated plainly either way
  • The recommended next step, including “nothing further right now” if that is the honest answer

Why this is priced separately

Scoping is the one decision every other CMMC cost depends on, and quoting a full readiness engagement before it is settled means quoting a guess. Running it as its own small engagement means you find out what you are actually facing before committing to the larger work — and if the answer is that your exposure is smaller than you feared, you have paid for a short engagement rather than a long one.

What this is not

This is not a control-by-control assessment, and it does not produce an SSP, a POA&M, or an SPRS score. It establishes the boundary those artifacts are written against. If your boundary is already settled and documented, skip this and go straight to the gap assessment.

Compare the federal engagements →

Questions

Common questions.

How long does a CUI boundary definition take?

One to two weeks for a typical small or mid-size defense contractor. Most of the elapsed time is scheduling short conversations with the people who actually handle the work — contracts, engineering, and IT — because the boundary is decided by how information really moves, not by how an org chart says it should.

What if it turns out we do not hold CUI at all?

Then that is the finding, and it is a good one. Plenty of contractors handle Federal Contract Information and no CUI, which puts them at CMMC Level 1 rather than Level 2 — a much smaller obligation. Establishing that costs far less than assuming the larger answer and building for it.

Can we just treat the whole company as in scope?

You can, and it is almost always the most expensive possible answer. Every system inside the boundary has to meet the requirements, so an unnecessarily wide boundary multiplies both the implementation work and the ongoing cost of keeping it compliant. A defensible boundary is usually much smaller than a first guess.

Is this the same as a gap assessment?

No. This establishes the boundary; a gap assessment measures a boundary against the 110 requirements. Doing them in the wrong order means assessing systems that may not be in scope and missing ones that are. If your boundary is already settled and documented, go straight to the gap assessment.

Does the fee count toward later work?

Yes. The full fee is credited toward your next engagement when it starts within 90 days, so scoping first does not cost you anything if you continue.