Skip to content

CUI Scope Indicator

Your compliance cost is determined before remediation ever begins. The single biggest driver is scope — how many systems, users, and vendors touch your CUI environment. Answer the questions below to get your scope complexity rating and a plain-language breakdown of what it means for your timeline and budget.

CUI Scope Indicator — ISI
CUI Scope Indicator

Answer the questions below to understand your CUI environment complexity and what it means for your compliance path. Takes about 3 minutes.

?
Before you begin
Does your organization handle Controlled Unclassified Information (CUI) under a DoD contract?
CUI is sensitive government information requiring protection under DoD contracts — distinct from FCI (Federal Contract Information), which carries fewer obligations. If you've been flowed down a CMMC clause but don't yet handle CUI, talk to an advisor before using this tool.
i
This tool is designed for CUI environments (CMMC Level 2)

Based on your answer, your organization likely falls under CMMC Level 1, which applies to contractors who handle Federal Contract Information (FCI) but not CUI. Level 1 has a narrower set of requirements — 15 practices focused on basic cyber hygiene — and does not require a third-party assessment.

This worksheet is scoped for CMMC Level 2 environments where CUI is present. Using it for a Level 1 context would overstate your compliance burden and may send you down the wrong path.

If you're unsure whether you handle CUI, that's actually a common and important question. We'd encourage you to explore our CUI quiz for a quick starting point, or schedule time with an ISI advisor to talk through your specific obligations.

1
CUI identification
Which of these generate or receive CUI at your organization? (select all that apply)
DoD prime contracts
Subcontracts / flow-downs
Technical drawings / specs
R&D / export-controlled work
Government-furnished info
Not sure / need to verify
Where does CUI live or move in your environment? (select all that apply)
Email (Outlook / Gmail)
Shared file drives
Laptops / workstations
On-premise servers
Cloud storage (non-GCC High)
Microsoft 365 GCC High
Collaboration tools (Teams, Slack)
Printers / copiers
CUI sent to print is physical CUI
Physical / paper copies
Mail, drawings, printed specs
Machinery / industrial equipment
CNC machines, IoT, USB-transferred files
Not sure where it lives
How many cloud service providers (CSPs) store, process, or transmit CUI for your organization?
Examples: Microsoft, Google, AWS, Salesforce, DocuSign, any SaaS tool that touches CUI
Do you have a shared responsibility matrix (SRM) with each of those cloud providers?
An SRM documents which security controls your provider handles vs. which are your responsibility
Yes — we have SRMs in place
Partially — for some providers
No — we don't have SRMs
This is a common gap — and a common audit finding
We don't use cloud services for CUI
2
Boundary definition
Total employees at your organization
50
Employees with access to CUI
10
Cannot exceed total employees
Where do employees who handle CUI primarily work?
In-office only
Controlled, defined physical boundary
Hybrid — mix of office and remote
Boundary definition becomes more complex
Fully remote
Home offices may be in scope depending on CUI handling
Do any vendors, subcontractors, or managed service providers have access to your CUI environment?
No external access
1–2 vendors with limited access
Multiple vendors / MSP has full access
3
Current posture
How would you describe your current CMMC preparation?
Haven't started — just exploring
Planning — trying to understand what's needed
In progress — gap assessment underway
Nearly ready — preparing for assessment
Do you have a System Security Plan (SSP) in place?
No
Partially — some documentation exists
Yes — current and complete
Scope complexity indicator
This tool and any generated report are provided solely for general informational and preliminary assessment purposes. Results are based on the information provided and automated analysis methods, and may not fully reflect your company’s actual CUI scope. You should not rely on this tool as legal, cybersecurity, compliance, audit, or professional advice, or as the sole basis for business or compliance decisions. By using this tool, you acknowledge that use of and reliance on the tool and report is at your own risk, and the provider disclaims all liability arising from or related to such use or reliance, to the fullest extent permitted by law. An ISI advisor can help you validate these results and identify factors that may not be captured here.