Before a single control, one question sets the size and cost of your whole CMMC program: where does your Controlled Unclassified Information (CUI) actually live? The answer is your CUI boundary — the line around every system, person, and place that stores, processes, or transmits CUI.
Why it matters more than any tool
Everything inside the boundary is in assessment scope; everything you can defensibly keep outside is not. A wide, fuzzy boundary means more systems to secure, document, and assess. A tight, well-drawn one is the single biggest lever you have on cost, timeline, and effort.
How to draw it
- Follow the data, not the org chart. Trace where CUI enters (email, portals, transfers), where it is worked on, and where it rests.
- Separate deliberately. Segmenting CUI into a defined enclave — with controlled entry and exit — keeps the rest of your business out of scope.
- Write it down. A boundary an assessor can see and follow is worth far more than one that only lives in your head.
Delphius Beacon helps clients scope and document a defensible boundary first, so the rest of the program is right-sized. See our CMMC services.