TheCMMC 2.0 framework applies to nonfederal systemsthat process, store, or transmitCUI.
Scoping determineswhich system components must comply with CMMC practices.
If a systemprocesses, stores, or transmits CUI, orprovides security for those systems, itmust be included in the assessment scope.
CMMC Applies to Contractors, Not Federal Systems
CMMC isdesigned for Department of Defense (DoD) contractors, notfederal systems.
Federal systems arealready governed by NIST SP 800-53and other regulations.
Scope Includes Systems That Process CUI AND Those That Protect Them
Systemsprocessing, storing, or transmitting CUIare in scope.
Systems thatprovide protection for CUI systems(e.g., firewalls, monitoring tools, security appliances) arealso in scope.
A. Federal systems that process, store, or transmit CUI.→Incorrect
B. Nonfederal systems that process, store, or transmit CUI.→Partially correct but incomplete
Itexcludes security systemsthat protect CUI assets, whichare also in scope.
C. Federal systems that process, store, or transmit CUI, or that provide protection for the system components.→Incorrect
CMMC Scoping Guide (Nov 2021)– Confirms that CMMCapplies to nonfederal systemsprocessingCUI.
NIST SP 800-171 Rev. 2– Specifies security requirements fornonfederal systemshandling CUI.
DFARS 252.204-7012– Requires DoD contractors to implementNIST SP 800-171onnonfederal systemshandling CUI.
Understanding Scoping in CMMC 2.0Why the Correct Answer is "D. Nonfederal systems that process, store, or transmit CUI, or that provide protection for the system components"?Why Not the Other Options?Relevant CMMC 2.0 References:Final Justification:SinceCMMC applies to nonfederal systems that process CUI or protect those systems, the correct answer isD. Nonfederal systems that process, store, or transmit CUI, or that provide protection for the system components.