Are a SIEM and an MFA provider that don't touch CUI in scope for a CMMC Level 2 assessment?
Question as asked: Our SIEM and MFA provider don't store or process CUI. Are they in scope for our CMMC Level 2 assessment?
Yes — under 32 CFR Part 170, "not storing or processing CUI" does not take a tool out of scope by itself; what matters is whether it performs a security function for the CUI environment.
SIEM and MFA provider — both are in scope, but the treatment differs depending on who operates them:
If they are your own tools (your SIEM instance, your MFA/identity provider configuration, even if hosted on vendor infrastructure), they are Security Protection Assets (SPAs) under table 3 to 32 CFR 170.19(c)(1). SPAs don't store/process/transmit CUI, but because they "provide security functions or capabilities" to the CUI environment (log aggregation/monitoring, authentication), they are assessed — specifically for the security capability they provide — and must be inventoried, documented in the SSP, and shown on the network diagram.
If either is delivered as a service by an external provider (e.g., a managed SIEM/MSSP, or a third-party identity/MFA service), and that provider handles what 32 CFR 170.2 defines as Security Protection Data (log data, configuration data, or other data used to protect the contractor's environment) without handling CUI, the provider is an External Service Provider (ESP) under table 4 to 170.19(c)(2)(i). The rule is explicit that an ESP handling only Security Protection Data — no CUI — is still in scope: its services are assessed as Security Protection Assets. Every ESP relationship must be documented in the SSP with the ESP's service description and a Customer Responsibility Matrix (CRM).
What would take them out of scope: only if a provider handles neither CUI nor Security Protection Data, and has no security-relevant connection to your CUI assets, would it fall outside 170.19 entirely (an Out-of-Scope Asset). A SIEM ingesting logs from your CUI environment, or an MFA/IdP gating access to it, will not meet that test.
Practical effect on your assessment: budget for inventorying both in the SSP, showing them on the CUI Asset Boundary diagram, and being ready for the assessor to evaluate the security capability each provides (e.g., MFA coverage per IA.L2-3.5.3, log review/alerting per AU-domain practices) — not the full 110-practice assessment that applies to CUI Assets themselves.
One fact that would change this: if either system is a federal information system operated on your behalf for the Government, it falls outside 32 CFR Part 170 altogether under 170.3(b) — governed instead by the contract's own security terms and the Government's ATO process, not CMMC scoping. If that's the case here, say so and the analysis above doesn't apply to that system.
Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.
More answers
- Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? (PCI DSS v4.0.1)
- How many Annex A controls are in ISO 27001:2022, and how are they grouped? (ISO/IEC 27001:2022)
- How long do we have to answer a GDPR subject access request, and can we extend it? (GDPR)
- When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems? (EU AI Act)