CMMC 2.0 Scoping Guidance Limits the Scope of Cybersecurity Assessments
Client Alert | 1 min read | 12.23.21
The Department of Defense (DoD) recently released the initial guidance documents for Version 2.0 of its Cybersecurity Maturity Model Certification (CMMC) program, including its much-anticipated Scoping Guidance. While the guidance documents generally adhere to the current requirements for the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), the Scoping Guidance includes notable developments. Chief among them is the introduction of two asset categories — “Specialized Assets” and “Contractor Risk Managed Assets” — that could potentially limit the scope of a contractor’s CMMC assessment, as well as the number and types of assets to be assessed against the applicable CMMC practices.
- Specialized Assets include government property; internet of things (IoT) and industrial internet of things (IIoT) devices; operational technology; systems configured based entirely on government requirements and used to support a contract; and test equipment.
- Contractor Risk Managed Assets include computing resources that are capable of handling CUI but are prevented from doing so by the contractor’s security policies, procedures, and practices.
Contractors expecting to be subject to CMMC should carefully review the Scoping Guidance, as well as the other guidance documents, to determine whether and how they may wish to limit the scope of CMMC’s applicability.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 3 min read | 06.03.26
Important EU Court Judgment Clarifies Rules on Interest Due in Cartel Damages Cases
In a judgment that will have direct and immediate consequences, the Court of Justice of the European Union (CJEU) has clarified that for all competition damages actions brought after 26 December 2014, interest runs from the date on which the harm occurred. The ruling addressed two important questions: (1) whether national provisions implementing Article 3(2) of the EU Damages Directive — which requires interest to run from the date harm occurred —apply to cases in which the harm preceded the adoption of those provisions; and (2) how the date of harm should be determined in cartel cases involving the purchase of goods at inflated prices.
Client Alert | 2 min read | 06.02.26
SBA OHA Confirms That the Submission Date for a Proposal with Pricing Controls Size Determination
Client Alert | 5 min read | 06.01.26
California Court Upholds Insurer’s Duty to Defend After Covered Claim Is Dismissed
Client Alert | 2 min read | 05.29.26
California Assembly Passes AB 1776, Sending Major Antitrust Bill to the Senate

