Understanding Asset Types in CMMC 2.0
In CMMC 2.0, assets are categorized based on their role in handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The Cybersecurity Maturity Model Certification (CMMC) Scoping Guidance for Level 1 and Level 2 provides asset definitions to help organizations identify what needs protection.
According to CMMC Scoping Guidance, there are five primary asset types:
Security Protection Assets (ESP - External Service Providers & Security Systems)
People (Personnel who interact with FCI/CUI)
Facilities (Physical locations housing FCI/CUI)
Technology (Hardware, software, and networks that store, process, or transmit FCI/CUI)
CUI Assets (For Level 2 assessments, assets specifically storing CUI)
Why "Technology" Is the Correct Answer
The IT manager is evaluating servers, laptops, databases, and applications—all of which are technology assets used to store, process, or transmit FCI.
According to CMMC Scoping Guidance, Technology assets include:
✅Endpoints (Laptops, Workstations, Mobile Devices)
✅Servers (On-premise or cloud-based)
✅Networking Devices (Routers, Firewalls, Switches)
✅Applications (Software, Cloud-based tools)
✅Databases (Storage of FCI or CUI)
Since the IT manager is focusing on these components, the correct asset category is Technology (Option D).
Why the Other Answers Are Incorrect
A. ESP (Security Protection Assets)
❌Incorrect. ESPs refer to security-related assets (e.g., firewalls, monitoring tools, managed security services) that help protect FCI/CUI but do not store, process, or transmit it directly.
B. People
❌Incorrect. While employees play a role in handling FCI, the question focuses on hardware and software—which falls under Technology, not People.
C. Facilities
❌Incorrect. Facilities refer to physical buildings or secured areas where FCI/CUI is stored or processed. The question explicitly mentions servers, laptops, and applications, which are not physical facilities.
CMMC Official References
CMMC Level 1 Scoping Guide (CMMC-AB) – Defines asset categories, including Technology.
CMMC 2.0 Scoping Guidance for Assessors – Provides clarification on FCI assets.
Thus, option D (Technology) is the most correct choice as per official CMMC 2.0 guidance.