Security Protection Assets

Security tools in the CMMC scope, without a FedRAMP bar.

A Security Protection Asset is an asset that provides security functions or capabilities to the CMMC assessment scope. Contractors document it and assess it. FedRAMP is a different question, and it attaches when an external cloud stores, processes, or transmits CUI.

Not legal advice. This is a plain-language reading aid for contractors and the providers who support them. It is not a CMMC assessment, not a FedRAMP determination, and not a substitute for 32 CFR Part 170, the contract, or advice from counsel. Templates and worksheet results are starters. Replace every example with your own facts.

01

What an SPA is

32 CFR § 170.19 Table 3 defines Security Protection Assets as assets that provide security functions or capabilities to the assessment scope. If that asset also processes, stores, or transmits CUI, it is a CUI asset too, and the CUI fact is what selects FedRAMP.

02

How an SPA is assessed

The same table says to assess them against Level 2 requirements that are relevant to the capabilities they provide. Document them in the asset inventory, document their treatment in the system security plan, and show them on the network diagram.

03

Why FedRAMP is not the bar

DFARS 252.204-7012(b)(2)(ii)(D) applies when an external cloud stores, processes, or transmits covered defense information. Table 4 of § 170.19 puts that FedRAMP requirement on the cloud-provider cell for CUI, not on the cell for security protection data without CUI.

The category is a function, not a product label.

The Level 2 Scoping Guide’s technology examples include cloud-based security solutions, hosted VPN services, and SIEM solutions. Its people examples include consultants who provide cybersecurity services and managed-service personnel who maintain systems. A SIEM in the guide’s example may sit apart from CUI and still be in scope, because it contributes to the requirements.

Endpoint detection, vulnerability scanning, identity, device management, logging, and a managed security service are the same kind of question when they protect the in-scope environment. The product does not arrive pre-labeled. You categorize the deployment you actually use.

External cloud that handles CUISecurity tool that does not handle CUI
Rule to readDFARS 252.204-7012(b)(2)(ii)(D) and § 170.19 Table 4, cloud column, CUI row§ 170.19 Table 3 SPA row, and Table 4 where the data is security protection data without CUI
What “in scope” meansCUI asset. Assessed against all Level 2 requirements.Security Protection Asset. Assessed against Level 2 requirements relevant to the capability.
FedRAMPFedRAMP Moderate authorization, or equivalency as the December 2023 DoD memorandum describes it.Not the requirement in that Table 4 cell. The service is still assessed as an SPA.
What you write downInventory, system security plan, network diagram, and the cloud body of evidence or authorization the clause calls for.Inventory, treatment in the system security plan, network diagram, and the provider’s responsibility split.

Security protection data

The Scoping Guide describes security protection data as data stored or processed by these assets to protect the assessed environment, and as security-relevant information that could help an attacker if disclosed. Its examples include configuration, logs, vulnerability status, and passwords that grant access. The guide says the list is not exhaustive.

If the logs, the tenant, or the long-term copy of the logs contain CUI, you are no longer in the “without CUI” cell.

Equivalency is not authorization

The December 2023 DoD CIO memorandum explains what “equivalent” means when a cloud offering is used to store, process, or transmit covered defense information. It says that meeting the equivalency criteria does not confer FedRAMP authorization. It is not a second program you apply to every security tool that never sees CUI.

The memorandum says a cloud offering that is already FedRAMP Moderate authorized can be used for covered defense information without a further equivalency assessment. This site’s directory is for that cloud question.

Level 2 and NIST SP 800-171 are the frame

This section follows Level 2 scoping in 32 CFR § 170.19(c). The CMMC Program FAQ says Level 2 assessments use NIST SP 800-171 Revision 2. Level 3 has its own asset table in the same section. Do not assume a Level 2 SPA write-up carries unchanged into a Level 3 assessment.

Revision 3, published in May 2024, regroups the requirements into 17 families and adds organization-defined parameters. Write the SPA treatment against both revisions so the inventory and the responsibility split carry through the transition without a rewrite.

Sources

NIST SP 800-171 Revision 2

Protecting CUI in Nonfederal Systems and Organizations. 110 requirements in 14 families. The revision cited in current contracts and assessments.

Official source

NIST SP 800-171 Revision 3

May 2024. 97 requirements in 17 families, adding Planning, System and Services Acquisition, and Supply Chain Risk Management, with organization-defined parameters.

Official source

32 CFR Part 170

The CMMC Program rule. Level 2 asset categories are in § 170.19(c)(1) Table 3. External service provider rules are in § 170.19(c)(2) Table 4. Definitions are in § 170.4.

Official source

DoD CMMC Scoping Guide — Level 2

Version 2.13, September 2024. Guidance on asset categories, Security Protection Data, and external service providers. The guide says it does not itself have the force and effect of law.

Official source

DFARS 252.204-7012

Safeguarding Covered Defense Information and Cyber Incident Reporting. Paragraph (b)(2)(ii)(D) is the requirement for an external cloud service provider that stores, processes, or transmits covered defense information.

Official source

DoD FedRAMP Moderate Equivalency memorandum

DoD CIO memorandum, December 2023: “Federal Risk and Authorization Management Program Moderate Equivalency for Cloud Service Provider’s Cloud Service Offerings.” It explains equivalency for cloud offerings used to store, process, or transmit covered defense information. It states that equivalency does not confer FedRAMP authorization.

Official source

CMMC Program Frequently Asked Questions

Revision 2.3, July 2026. Section E covers cloud providers, encrypted CUI, and managed security providers that receive no CUI. Section B states that Level 2 assessments use NIST SP 800-171 Revision 2.

Official source