What Changes When a Mac Is a CUI Asset, an SPA, or Risk-Managed?
Asset category does not change what the 110 requirements say. It changes which of them that asset is assessed against, and therefore how much evidence it generates for the rest of its life.
So the delta is real, and it is mostly an evidence and cadence delta rather than a hardening one. On a Mac fleet the technical build often barely changes between categories. The recurring workload changes a lot.
The categories below look like a menu for reducing work. They are not. Category follows from what the asset actually does, and the first yes wins: an asset that handles CUI is a CUI Asset even if it also provides a security function.
Recategorising a CUI-handling Mac as risk-managed is the single most expensive scoping mistake available here. It is discovered by an assessor reading your own records, and it puts every downstream claim in doubt.
What actually differs between the categories?
The documentation obligation and the assessment consequence are set by 32 CFR 170.19. They are not a matter of interpretation:
| Category | You must document | How it is assessed |
|---|---|---|
| CUI Asset Macall 110 | Inventory, SSP, network diagram | Assessed against all Level 2 security requirements. |
| Security Protection Assetrelevant subset | Inventory, SSP, network diagram | Assessed against Level 2 requirements that are relevant to the capabilities provided. |
| Contractor Risk ManagedSSP review | Inventory, SSP, network diagram. No separation required | If the SSP is sufficient, not assessed against other requirements. If the risk-based policies raise questions, a limited check is performed and that check is assessed against CMMC requirements. |
| Specialized AssetSSP review | Inventory, SSP, network diagram, plus management under risk-based policies | Review the SSP. Not assessed against other CMMC security requirements. |
| Out of Scopenone | Prepare to justify the inability to process, store or transmit CUI | No assessment. |
What does each category look like on a Mac?
Regulation sets the rows above. The paragraphs below are judgement about a typical fleet built on Apple Business Manager, supervised enrollment and an approved MDM. Your architecture may move an asset.
CUI Asset Mac
The baseline. Supervised enrollment, managed baseline, FileVault with escrowed keys, endpoint security, log forwarding, and an evidence trail for every endpoint-settled requirement at its stated cadence.
Security Protection Asset
Your MDM server, identity broker, EDR console, or the admin Mac used to drive them. Hardened at least as hard as a CUI Asset in practice, because it can reach every CUI Asset, but assessed only on the capability it provides rather than on CUI handling it never does.
Contractor Risk Managed
Still enrolled, still inventoried, still on the diagram. The delta is that technical enforcement is replaced by a written risk position, and that position has to survive questioning on its own.
Specialized Asset
Government furnished Macs, a Mac driving instrumentation, a Mac locked to a vendor image. Narrow, and defined by what the asset is rather than by how awkward it is to manage.
Out of Scope
The burden runs the other way. You are showing that CUI could not reach it, which is a harder claim than showing that it does not.
Where does the Security Protection Asset case get vague?
The regulation says an SPA is assessed against requirements relevant to the capabilities provided. It does not enumerate which ones, and neither does any DoD guidance we can point to. Anyone publishing a definitive per-requirement SPA mapping is publishing an opinion.
The workable reading is to scope by capability. An admin Mac that drives your MDM is providing privileged administration, so the requirements about privileged access, authentication, its own baseline, its own logging and its own maintenance path are clearly in. Requirements about marking and handling CUI media are not, because it never touches CUI. Write that reasoning down in the SSP, because the reasoning is what gets assessed.
The most common Mac scoping error is not misclassification. It is treating a Security Protection Asset as lower risk because it is assessed against fewer requirements.
An admin Mac that can push configuration to every CUI Asset in the fleet is a higher-value target than any single CUI Asset. Fewer requirements assessed is not less risk carried.
How does category change the ongoing workload?
This is the part that shows up months later, not on assessment day. Every requirement an asset is assessed against brings evidence with it, and evidence carries a refresh interval.
- CUI Asset. The full evidence set at full cadence. In Access Control alone that is dozens of recurring obligations, and Access Control is one family of fourteen.
- Security Protection Asset. A smaller set, but the security-critical part of it. Privileged access reviews and administrative logging do not become optional because the asset holds no CUI.
- Contractor Risk Managed. Technically lighter, documentally heavier. The written risk position is doing the work that technical enforcement does elsewhere, so it has to be specific, current, and consistent with what your MDM actually enforces.
- Specialized and out of scope. Lightest, but the justification has to stay true. An asset quietly repurposed into CUI work is a scoping change nobody recorded.
Contractor Risk Managed does not reduce the work. It moves the work from engineering to writing, and the writing then has to hold up alone.
If the policy says CUI never reaches these Macs, and nothing technically stops it, the policy is the only control. An assessor is entitled to test whether it holds, and a limited check is assessed against CMMC requirements. The category that looked cheaper becomes the one with the least margin for error.
How do you keep the categories honest over time?
- Record the reasoning, not just the label. "CRMA" in an inventory cell is not a position. The sentence that explains why is.
- Tie the category to enforcement. If a Mac is risk-managed because policy keeps CUI off it, name what enforces that policy.
- Re-check on change. New software, a new sync folder, a new person, and the category can move without anyone deciding it should.
- Watch observed use, not stated intent. Category follows what actually happens on the device.
Category definitions and assessment consequences are from 32 CFR 170.19. The Mac implementation guidance is one worked view of a typical architecture, not a required answer and not an assessment finding. Scoping decisions are yours to make and to defend, and this is not legal advice.
A category is only as good as the record behind it. The suite carries the asset inventory workbook that holds the classification and its reasoning, the shared responsibility matrix for the provider side, and the SSP template where the scoping narrative has to hold up.
See what is in the suiteMac-first, one-time purchase, no subscription.
- Not sure of the category yet? four questions, answered in your browser, nothing stored.
- What evidence an assessor asks for the evidence a CUI Asset generates, per objective.
- What the ongoing workload looks like why category changes the cadence more than it changes the build.