The Diagram That Defines Your Boundary
You place the elements of your environment on the canvas — workstations, servers, the CUI enclave, email and file paths, cloud services, removable media, external connections to primes and subcontractors — and draw the flows that carry CUI between them. The result is a single picture of where controlled information originates, where it is processed and stored, and every path by which it leaves your control. That picture is what determines which assets are in scope, and it is the first thing a C3PAO will ask to see.
Each element on the diagram can be categorized — CUI asset, security protection asset, contractor risk-managed asset, specialized asset, or out-of-scope — aligning the visual with the asset categories the CMMC scoping guidance defines. A flow that crosses the enclave boundary is visible at a glance, which is exactly where scoping decisions are made or missed.