Scoping & Documentation

Data Flows. Mapped.

A C3PAO assessment begins with scope, and scope begins with knowing where your CUI goes. The CUI Data Flow Diagrams module is a visual canvas for mapping how controlled information enters, moves through, is stored in, and leaves your environment — the boundary diagram an assessor expects to see, built into the platform and exported straight into your System Security Plan instead of hand-drawn the night before.

C3PAO Expected scoping artifact
In → out Full CUI lifecycle mapped
To the SSP Exports into your plan
Capability

The Diagram That Defines Your Boundary

You place the elements of your environment on the canvas — workstations, servers, the CUI enclave, email and file paths, cloud services, removable media, external connections to primes and subcontractors — and draw the flows that carry CUI between them. The result is a single picture of where controlled information originates, where it is processed and stored, and every path by which it leaves your control. That picture is what determines which assets are in scope, and it is the first thing a C3PAO will ask to see.

Each element on the diagram can be categorized — CUI asset, security protection asset, contractor risk-managed asset, specialized asset, or out-of-scope — aligning the visual with the asset categories the CMMC scoping guidance defines. A flow that crosses the enclave boundary is visible at a glance, which is exactly where scoping decisions are made or missed.

Dashboard Requirements Evidence POA&M Reports
1TEN CUI data flow diagram mapping how controlled information enters, moves through, and exits the environment
Capability

Versioned, and Wired Into the SSP

CA.L2-3.12.4 requires a System Security Plan that describes system boundaries, the operational environment, and how CUI is handled — and a data flow diagram is the clearest way to convey that. Diagrams built here export directly into the SSP, so the boundary you draw and the plan you submit are the same artifact rather than two documents that disagree. When the environment changes, you update the diagram; the prior version is retained, so you can show how the boundary evolved over time.

Because the diagram draws on the same environment data as the rest of the platform, the elements on the canvas correspond to real entries in your asset inventory. The boundary on the page is not an abstraction — it maps to the systems you actually assess, which is what keeps scoping honest.

Inside the Module

What You See Inside

Visual canvas
Drag-and-place elements and draw the CUI flows that connect them.
Asset categorization
Label each element by CMMC scope category, from CUI asset to out-of-scope.
Enclave boundary
The CUI enclave boundary is drawn explicitly, so flows that cross it are obvious.
External connections
Paths to primes, subcontractors, MSPs, and cloud services shown as in-scope flows.
SSP export
Diagrams export into the System Security Plan to satisfy CA.L2-3.12.4.
Version history
Each revision is retained, showing how the boundary changed over time.
The problem this solves

Data flow diagrams are the artifact contractors most often improvise — a Visio sketch made the week of the assessment that does not match the network, the asset inventory, or the SSP. Assessors notice immediately, because the diagram is how they verify your scope is real. Building the diagram from your actual environment, keeping it versioned, and exporting it into the SSP means the boundary you claim, the boundary you drew, and the boundary you assess are one and the same.

Practices

Practices Supported

Practice IDDescription
CA.L2-3.12.4 Develop, document, and periodically update System Security Plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
SC.L2-3.13.1 Monitor, control, and protect communications at the external boundaries and key internal boundaries of organizational systems.
SC.L2-3.13.2 Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security.
Connected Modules

Related Modules

All 110. Tracked.

1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.

Request a Demo