IT Asset Inventory for CMMC Compliance: A San Diego Scoping Test
A San Diego defense contractor can file a Supplier Performance Risk System (SPRS) self-assessment that looks complete on paper and still miss half the environment that carries Controlled Unclassified Information (CUI). The gap is rarely bad faith. It is a shipyard crane controller, a production-line workstation, a government-furnished laptop, or a cloud tenant that never made the last spreadsheet. Under Cybersecurity Maturity Model Certification (CMMC) 2.0, that missing device is not a housekeeping problem. It is a scoping error, and a scoping error turns the entire self-assessment into a claim the organization cannot defend. An IT asset inventory for CMMC compliance is the documented, network-verified list of every device and system that falls into one of the DoD’s five CMMC asset categories — and closing exactly that gap is what it’s supposed to do before an assessor finds it first.
That pressure lands hardest where the estate is mixed. San Diego’s defense economy is built on Navy and Marine demand, ship-repair operational technology, unmanned-systems manufacturing, and information-warfare contracting sitting next to ordinary business networks. CMMC Phase 1 self-assessment is live. Phase 2 third-party assessments are paused for reform. The obligation to know what exists did not pause with them.
The five CMMC asset categories you have to scope, not just CUI
Most contractors scope for one thing: a CUI asset inventory of where CUI lives. That is only one of five categories the Department of Defense’s own CMMC Level 2 Scoping Guide requires an organization to account for. Under 32 CFR 170.19(c)(1), a Level 2 assessment scope covers five asset categories:
- CUI Assets — directly process, store, or transmit CUI
- Security Protection Assets — provide the security functions protecting those systems
- Contractor Risk Managed Assets — can reach CUI but were not built to handle it
- Specialized Assets — government-furnished equipment, IoT/IIoT, operational technology, restricted information systems, and test equipment
- Out-of-Scope Assets — physically or logically separated from the CUI environment
(DoD CIO CMMC Level 2 Scoping Guide)
Specialized Assets is the category that trips up San Diego’s contractor base specifically, since it splits into five distinct types: government-furnished equipment, IoT and industrial IoT devices, operational technology, restricted information systems, and test equipment. A shipyard running ship-repair OT, a manufacturer building unmanned systems, and an information-warfare contractor each carry a different mix of these five, and that mix changes what “in scope” means facility by facility.


This is not a paperwork exercise. An assessor checks a contractor’s claimed boundary against what the network actually shows, not the other way around. When a device turns up in an interview that never made the submitted inventory, the scoping determination behind the entire self-assessment is what gets questioned, not just that one device’s category.
The SPRS score on file doesn’t always match what’s on the network
The CMMC Level 2 self-assessment still requires a minimum SPRS score of 88 out of 110, and the Department of Defense verifies that score two ways: DIBCAC High assessments and Defense Contract Management Agency spot checks (Secureframe, CMMC SPRS scoring guide). A DIBCAC spot check is a short-notice review where Defense Contract Management Agency assessors verify a contractor’s self-reported score against what is actually running on the network — not just what appears on the submitted inventory document.
That is where the confidence gap shows up. CyberSheath’s State of the DIB research found that only 1% of defense contractors felt fully prepared for a CMMC assessment in 2025, down from 8% the year before (CyberSheath, State of the DIB Report 2025). CyberSheath’s ongoing tracking shows confidence in self-reported SPRS accuracy continuing to fall even as average scores keep climbing — a sign that scores are going up faster than the underlying inventory work that should support them.
A rising score built on a stale device list is not progress. It is a bigger claim resting on the same shaky foundation, and DIBCAC’s spot checks exist precisely to find that gap.
This is not a problem unique to defense compliance. IT operations teams run into the same failure mode every time a CMDB stops being reconciled against the live network and starts reflecting last quarter instead of today Why do Common Service Data Models (CSDM) matter for CMDB success?. CMMC scoping just raises the stakes on a gap that was already costing incident response teams time before an assessor ever asked about it.
See what your current asset inventory would show a DIBCAC assessor. Schedule a demo for a scoping gap review, or keep reading for what a defensible inventory actually requires.
Phase 2 being paused doesn’t pause the obligation
The Pentagon suspended CMMC Phase 2 third-party assessment requirements, originally set to take effect November 10, 2026, and opened a 60-day review of the certification program (The Defense Compliance Report, CMMC Deadlines 2026). That pause changes the timing of third-party C3PAO certification. It does not touch the underlying obligation.
Phase 1 self-assessment requirements stay fully in force during the review. DFARS 252.204-7012 still applies, and the NIST 800-171 asset inventory requirement continues to be enforced through self-assessments and government-led reviews while the Pentagon decides what Phase 2 looks like next. A contractor that treats the pause as a compliance holiday is scoping against a rule that was never actually suspended.
For San Diego’s mixed IT-OT contractor base, that means the asset-scoping work due now is the same work that will matter whenever third-party assessments resume, so there is no version of “wait and see” that reduces the workload later.
Why shadow assets are the hardest part of CMMC scoping
Asset inventory is flagged as the hardest control in the entire CMMC framework, and the reason is structural rather than a discipline problem. Contractors accumulate shadow assets over years of growth, mergers, remote work expansion, and contractor access:
- Laptops that were never formally onboarded
- IoT devices added to a network without a change ticket
- Cloud resources spun up for a project and forgotten
- Test systems still running outdated configurations
(VSO, Asset Inventory Automation for CMMC)
San Diego’s version of the problem is physical, not just digital
A shipyard’s crane controllers and a manufacturer’s production-line systems are not always reachable the way a laptop is. Some operational technology sits on segmented networks specifically because it should not be casually scanned, and some of it is not network-accessible at all. Discovery tools that only speak standard IT protocols will miss it, and manual spreadsheets miss it even faster, since nobody updates a spreadsheet the day a crane controller gets swapped.


That gap between what the inventory says and what the network holds is exactly the assessment risk industry researchers keep pointing back to. It is also the reason a one-time inventory sprint before an assessment date does not hold up. Assets change between quarterly reviews, and the scoping boundary moves with them.
Closing that gap takes the same continuous discovery discipline IT operations teams already use to keep incident response fast: agentless, agent-based, and API-based scanning that catches a new device the week it appears instead of the quarter someone remembers to update a spreadsheet Agent-based vs. agentless discovery: which is best for your business?. Scoping is a snapshot; the network is not, and only continuous discovery keeps the two aligned.
Building an IT asset inventory for CMMC compliance that can survive a DIBCAC spot check
Building an IT asset inventory for CMMC compliance starts with knowing what is actually running, not what was documented last quarter. Virima’s CMDB is built on continuous, IT discovery across agentless, agent-based, and API-based methods, so the asset list an IT or compliance team works from reflects what the network shows today rather than what a spreadsheet said at the last audit cycle. For operational technology, that discovery covers devices that are network-accessible and speak a compatible discovery protocol; it is not a substitute for physical inventory of air-gapped or isolated shipyard systems, and no discovery tool should be sold as one.
Once the inventory is current, ViVID™ service maps show how CUI Assets, Security Protection Assets, and Contractor Risk Managed Assets actually connect, which is the same logical-separation question a scoping determination has to answer. That combination, discovery-sourced ground truth plus a visual dependency map, gives an IT Director something closer to what an assessor is actually going to ask for: proof that the claimed boundary matches the network, not just a document that says so.
It is the same dependency context IT teams already lean on to cut incident response time when something breaks Virima blog post on service dependency mapping and blast radius for change management. A scoping boundary and a blast radius are answering a related question: what is actually connected to what, right now.
None of this replaces a C3PAO assessment or claims any DoD authorization. Trusted Runtime Truth is about keeping the inventory an assessment depends on accurate between audits, alongside whatever GRC or ITSM platform a contractor already runs.


Contractors managing this alongside existing ITSM and GRC tooling do not need to replace what already works. See the full list of Virima’s integrations for how discovery-sourced asset data flows into the systems a compliance team already checks daily.
A five-question CMMC asset-scoping self-check
Before an assessor or a DIBCAC spot check does it for you, run the inventory behind your next SPRS submission against these five questions, each tied to one of the CMMC asset categories above:
- Does every device that touches CUI — including shipyard OT, GFE laptops, and IoT sensors — appear on the current inventory, not last quarter’s?
- Can you show which Security Protection Assets and Contractor Risk Managed Assets connect to each CUI Asset, not just that they exist?
- Is any device excluded as Out-of-Scope actually isolated, or just assumed to be?
- Would a network scan turn up a device that isn’t on the submitted list?
- If DIBCAC asked today, could the inventory be produced in hours, or would it take a manual reconciliation first?
Answering “no” or “not sure” to any of these means the scoping boundary behind the SPRS score won’t survive a spot check.






