For CMMC Level 1 scoping , the DoD’s CMMC Scoping Guide – Level 1 (v2.13) instructs an organization performing a Level 1 self-assessment to consider what is in scope for protecting Federal Contract Information (FCI) . Specifically, it states that to appropriately scope a Level 1 self-assessment, the OSA should consider the people, technology, facilities, and external service providers (ESPs) within its environment that process, store, or transmit FCI .
In this scenario, the director is evaluating company offices and data centers where FCI is stored. These are physical locations and physical environments—exactly what the scoping guidance categorizes under Facilities . Facilities in a Level 1 context include physical sites and spaces that may house systems or media containing FCI (e.g., offices, server rooms, data centers), because those locations affect physical access controls, environmental protections, and overall safeguarding of where FCI is handled and stored.
This is distinct from Technology (devices/systems), People (personnel who handle FCI), and ESPs (external providers delivering IT/cyber services). Since the question is explicitly about which offices and data centers store FCI —a physical boundary and location question—the correct asset type is Facilities .
Submit