Scope check

Is this tool an SPA or a CUI asset?

Answer from the deployment you have, not from the brochure. The result is a worksheet you can download or print. It applies Table 3 and Table 4 of 32 CFR § 170.19. It does not certify the answer.

Not legal advice. This is a plain-language reading aid for contractors and the providers who support them. It is not a CMMC assessment, not a FedRAMP determination, and not a substitute for 32 CFR Part 170, the contract, or advice from counsel. Templates and worksheet results are starters. Replace every example with your own facts.

Does it process, store, or transmit CUI?

The Level 2 Scoping Guide describes process as CUI used by the asset, store as CUI at rest, and transmit as CUI moved from one asset to another.

Can CUI show up in what it holds?

File contents, message bodies, document text, or screenshots. A product sold as a security tool can still hold CUI.

Does it provide a security function to the CUI environment?

Monitoring, detection, identity, vulnerability scanning, device management, logging, a hosted VPN, or a managed security service are the kinds of functions this question means.

Does it hold security protection data, and not CUI?

Configuration, logs, vulnerability status, or credentials that grant access to the in-scope environment. The Scoping Guide says those examples are not a complete list.

Who operates the service?

Answers stay in this browser. This page does not send them to the site.