Why Specialized Assets Are the Category That Saves You Money
For a software company, CMMC scoping is mostly about laptops, servers, and cloud services. For a defense manufacturer, it is about the shop floor: CNC machines, PLCs, coordinate measuring machines, environmental test chambers, and a decade of government-furnished test rigs that were never designed to run modern security controls. Try to hold that equipment to all 110 Level 2 requirements and you will fail. Most of it cannot support multifactor authentication, endpoint agents, audit logging, or FIPS-validated encryption, and never will.
The DoD anticipated exactly this. The CMMC Scoping Guide for Level 2 defines five asset categories, and one of them, Specialized Assets, exists specifically for equipment that can touch CUI but "cannot be fully secured." Specialized Assets are still part of your CMMC Assessment Scope. But they are handled through documentation and risk management rather than a control-by-control assessment. Categorizing a machine tool correctly as a Specialized Asset instead of a CUI Asset is often the single largest scope-reduction decision a manufacturer makes.
This guide walks through the five Specialized Asset types exactly as the Scoping Guide defines them, how the assessment treatment differs from the other categories, the Enduring Exception mechanism, the trap that catches contractors heading toward Level 3, and the SSP and network-diagram language assessors actually look for.
The Five Specialized Asset Types
Table 3 of 32 CFR 170.19(c)(1) enumerates what qualifies as a Specialized Asset for a Level 2 assessment. There are exactly five types, each with a specific definition drawn from federal regulation and NIST publications. An asset that does not fit one of these definitions is not a Specialized Asset; it falls into one of the other four categories.
| Type | Definition & Source |
|---|---|
| Government Furnished Equipment (GFE) | All equipment owned or leased by the government, including OSA-acquired equipment based on government-required specifications or configurations. GFE does not include intellectual property or software. [FAR 52.245-1] |
| IoT / IIoT | Networks of devices with the hardware, software, firmware, and actuators that let them connect, interact, and exchange data. They are uniquely identifiable, with sensing/actuation and programmability. Examples: smart electric grids, lighting, HVAC, and fire/smoke detectors. [NIST SP 800-172A] |
| Operational Technology (OT) | Programmable systems or devices that interact with the physical environment (or manage devices that do), detecting or causing change by monitoring or controlling devices, processes, and events. Includes ICS, building management systems, fire control systems, and physical access control mechanisms, and explicitly includes SCADA. [NIST SP 800-160v2 Rev 1; SCADA per DRAFT NIST SP 800-82r3] |
| Restricted Information Systems | Systems and associated IT components configured based on government security requirements (connected to something required to support a functional requirement) and used to support a contract. Examples: fielded systems, obsolete systems, and product deliverable replicas. |
| Test Equipment | Hardware and associated IT components used in testing products, system components, and contract deliverables. Examples: oscilloscopes, spectrum analyzers, power meters, and special test equipment. |
Where Manufacturers Get This Wrong
The most common misclassification is treating an entire production network as CUI Assets because CUI (a technical data package, say) is loaded onto one machine. The Specialized Asset category exists precisely so that the PLC-controlled machining cell, the CMM in the quality lab, and the environmental chamber in test do not each have to satisfy access control, audit, and encryption requirements they physically cannot meet. If the device can process, store, or transmit CUI but cannot be fully secured, it is a candidate for Specialized Asset treatment, not an automatic CUI Asset.
The opposite error is just as costly: sweeping a general-purpose workstation into "Test Equipment" because it sits in the test lab. A standard Windows PC that runs test software but is perfectly capable of enforcing MFA, logging, and encryption is a CUI Asset (or a Contractor Risk Managed Asset), not a Specialized Asset. The category is about assets that cannot be fully secured, not assets that are simply inconvenient to secure.
How Specialized Assets Are Actually Assessed
This is the heart of why the category matters. Specialized Assets are part of the CMMC Assessment Scope, but the OSA's obligations and the assessor's checks are different from every other in-scope category. Per Table 1 of the Scoping Guide, for Specialized Assets the OSA must:
- Document each asset in the asset inventory (there is no requirement to embed every asset individually in the SSP);
- Document these assets in the SSP to show they are managed using the OSA's risk-based security policies, procedures, and practices;
- Provide a network diagram of the CMMC Assessment Scope that includes these assets, to facilitate scoping discussions during the pre-assessment.
And the assessment requirement, verbatim in effect: review the SSP, and do not assess against other CMMC security requirements. The assessor reviews the SSP to verify that Specialized Assets are managed using the OSA's risk-based information security policy, procedures, and practices, and are accounted for within the scope. Notably, the Scoping Guide states the assessor will not retain a copy of the SSP.
Put side by side with the other in-scope categories, the leverage is obvious:
| Category | Assessment Treatment |
|---|---|
| CUI Assets | Assessed against all Level 2 security requirements. |
| Security Protection Assets | Assessed against the Level 2 requirements relevant to the security capability they provide. |
| Contractor Risk Managed Assets | Not assessed against the full set if sufficiently documented, but the assessor may run a limited check if documentation raises questions. |
| Specialized Assets | Documented and managed via risk-based practices; SSP reviewed; not assessed against other CMMC security requirements. |
| Out-of-Scope Assets | No CMMC assessment requirements; must be justified as unable to process, store, or transmit CUI. |
The practical takeaway: a Specialized Asset's compliance burden is a documentation burden. The quality of your SSP narrative and network diagram, not the technical configuration of a twenty-year-old test rig, is what the assessor evaluates.
The Enduring Exception
The Scoping Guide adds one clause that is easy to skim past: "Note that a Specialized Asset may be eligible for an Enduring Exception." That single sentence points to one of the more useful mechanisms in the CMMC program for equipment that will never comply.
An Enduring Exception, defined in 32 CFR 170.4, is a special circumstance or system where remediation and full compliance with a security requirement is not feasible. It is fundamentally different from a Plan of Action and Milestones (POA&M):
| POA&M | Enduring Exception | |
|---|---|---|
| Nature | Temporary gap with a plan to close it | Ongoing condition that will not be remediated |
| Timeline | Expected close-out within 180 days | No close-out; persists for the life of the asset |
| Where documented | POA&M register | System Security Plan |
For a Specialized Asset, an Enduring Exception is documented and justified in the SSP: what the asset is, why full compliance is not feasible, and how the risk is managed through compensating and risk-based practices. This is the correct home for the "our SCADA vendor will never support MFA on this controller" reality, not a POA&M that you can never actually close. Document the exception, describe the compensating controls (network isolation, monitoring, physical protection), and you have satisfied the requirement without pretending the device can do something it cannot.
The Level 2 vs Level 3 Trap
Here is the nuance that catches contractors who intend to pursue a CMMC Status of Final Level 3 (DIBCAC). The assessment requirements for Specialized Assets differ between Level 2 and Level 3. If Level 3 is on your roadmap, decisions you make about Specialized Assets at Level 2 have downstream consequences.
The Scoping Guide spells out the mechanics:
- Because Specialized Asset requirements differ between the levels, the OSC may choose to have its Specialized Assets assessed by a C3PAO during the Level 2 certification assessment.
- Specialized Assets (and Contractor Risk Managed Assets) that are not assessed to the Level 3 scoping requirements by a C3PAO during the Level 2 certification assessment will undergo limited checks for compliance with Level 2 security requirements during the DCMA DIBCAC certification assessment.
- During a Level 3 certification assessment, DCMA DIBCAC may check any Level 2 security requirement of any in-scope asset.
For contractors who will remain at Level 2, none of this applies; the standard Specialized Asset treatment (document, manage via risk-based practices, SSP review) is the whole story. But the moment Level 3 enters the conversation, Specialized Assets stop being a pure documentation exercise. See our Level 2 scoping pillar for how the five categories interact across the rest of your environment.
Documenting Specialized Assets Correctly
Since the assessment of Specialized Assets is a review of your documentation, the documentation has to carry the weight. Three artifacts do the work: the asset inventory, the network diagram, and the SSP.
Asset inventory
Every Specialized Asset is recorded in the asset inventory with enough detail to identify it and its category designation. This is where you distinguish the machining cell (Specialized: OT) from the engineering workstation next to it (CUI Asset). A defensible inventory shows the category for each asset and a short justification for the designation. 1TEN's Asset Inventory and Software Catalog modules are built to carry these category tags and justifications.
Network diagram
Specialized Assets must appear in the network diagram of the CMMC Assessment Scope. The diagram is what drives the scoping discussion in your pre-assessment, so it should make clear how OT/IoT/test equipment connects to, or is isolated from, the CUI environment. If you rely on network segmentation to contain these assets, the diagram is where that architecture becomes visible to the assessor.
System Security Plan
The SSP is where you show that Specialized Assets are managed using your risk-based information security policies, procedures, and practices. You are not writing a control-by-control implementation statement for each device; you are describing how the category is governed: the policy that covers them, the compensating controls (isolation, monitoring, physical protection), and any Enduring Exceptions with their justifications. For the broader boundary discussion, see our guide to the SSP and system boundary.
| Common Mistake | Why It's a Problem |
|---|---|
| No category designation in the inventory | An inventory that lists assets but does not classify them gives the assessor no basis to accept Specialized Asset treatment. The designation, and its justification, is the whole point. |
| Specialized Assets missing from the network diagram | If OT or test equipment does not appear on the diagram, the assessor cannot see how it is contained and may pull it into a broader scope during the pre-assessment. |
| Over-claiming the category | Labeling standard, fully-securable IT as Specialized to dodge controls is a fast way to lose assessor trust across the entire assessment. |
| Using a POA&M where an Enduring Exception belongs | A permanent limitation parked on a POA&M is a gap you can never close. Document it as an Enduring Exception in the SSP instead. |
| No compensating controls described | "It cannot be secured" is not a plan. The SSP must show how the risk is managed: isolation, monitoring, physical protection, restricted connectivity. |
This category matters most for the defense manufacturers we work with across aerospace and defense, weapons and munitions, naval and maritime, ground vehicle, and defense electronics. These are the environments where OT, test equipment, and government-furnished gear are the rule, not the exception.
Frequently Asked Questions
Specialized Assets are one of the five asset categories in the DoD CMMC Scoping Guide for Level 2. They are assets that can process, store, or transmit CUI but are unable to be fully secured, and they fall into five types: Government Furnished Equipment (GFE), IoT and IIoT devices, Operational Technology (OT) including ICS and SCADA, Restricted Information Systems, and Test Equipment. They are in the assessment scope but are documented and managed via risk-based practices rather than assessed against all Level 2 requirements.
No. The OSA documents each Specialized Asset in the asset inventory and describes in the SSP how the assets are managed using the organization's risk-based security policies, procedures, and practices. The assessor reviews the SSP to confirm the assets are accounted for and appropriately managed, but does not assess them against the other CMMC security requirements the way CUI Assets are assessed against all Level 2 controls.
Yes. Operational Technology, meaning programmable systems or devices that interact with the physical environment, including industrial control systems, building management systems, and SCADA, is explicitly listed as a Specialized Asset type in the CMMC Scoping Guide. OT is documented in the inventory and SSP and managed under risk-based practices rather than assessed against the full Level 2 requirement set.
A Contractor Risk Managed Asset (CRMA) is a standard asset that is capable of processing CUI but is not intended to, and is governed by policy and configuration; if its documentation raises questions, the assessor can run a limited check. A Specialized Asset is equipment that cannot be fully secured (OT, IoT, GFE, restricted systems, or test equipment) and is not assessed against the other CMMC requirements at all, only documented and managed via risk-based practices. The distinction turns on capability: CRMAs could be secured but are managed by risk; Specialized Assets cannot be fully secured by design.
Yes. Assessment requirements for Specialized Assets differ between Level 2 and Level 3. Specialized Assets not assessed to the Level 3 scoping requirements by a C3PAO during a Level 2 certification assessment will undergo limited checks during the DCMA DIBCAC assessment, and at Level 3 DIBCAC may check any Level 2 requirement of any in-scope asset. If Level 3 is on your roadmap, consider having a C3PAO assess your Specialized Assets during the Level 2 certification so there are no surprises later. You must also close out any Level 2 POA&M and reach Final Level 2 (C3PAO) status before starting a Level 3 assessment.