What Changes When a Mac Is a CUI Asset, an SPA, or Risk-Managed?

The short version

Asset category does not change what the 110 requirements say. It changes which of them that asset is assessed against, and therefore how much evidence it generates for the rest of its life.

So the delta is real, and it is mostly an evidence and cadence delta rather than a hardening one. On a Mac fleet the technical build often barely changes between categories. The recurring workload changes a lot.

Read this before you use the table

The categories below look like a menu for reducing work. They are not. Category follows from what the asset actually does, and the first yes wins: an asset that handles CUI is a CUI Asset even if it also provides a security function.

Recategorising a CUI-handling Mac as risk-managed is the single most expensive scoping mistake available here. It is discovered by an assessor reading your own records, and it puts every downstream claim in doubt.

What actually differs between the categories?

The documentation obligation and the assessment consequence are set by 32 CFR 170.19. They are not a matter of interpretation:

CategoryYou must documentHow it is assessed
CUI Asset Macall 110Inventory, SSP, network diagramAssessed against all Level 2 security requirements.
Security Protection Assetrelevant subsetInventory, SSP, network diagramAssessed against Level 2 requirements that are relevant to the capabilities provided.
Contractor Risk ManagedSSP reviewInventory, SSP, network diagram. No separation requiredIf the SSP is sufficient, not assessed against other requirements. If the risk-based policies raise questions, a limited check is performed and that check is assessed against CMMC requirements.
Specialized AssetSSP reviewInventory, SSP, network diagram, plus management under risk-based policiesReview the SSP. Not assessed against other CMMC security requirements.
Out of ScopenonePrepare to justify the inability to process, store or transmit CUINo assessment.

What does each category look like on a Mac?

Regulation sets the rows above. The paragraphs below are judgement about a typical fleet built on Apple Business Manager, supervised enrollment and an approved MDM. Your architecture may move an asset.

CUI Asset Mac

The baseline. Supervised enrollment, managed baseline, FileVault with escrowed keys, endpoint security, log forwarding, and an evidence trail for every endpoint-settled requirement at its stated cadence.

Security Protection Asset

Your MDM server, identity broker, EDR console, or the admin Mac used to drive them. Hardened at least as hard as a CUI Asset in practice, because it can reach every CUI Asset, but assessed only on the capability it provides rather than on CUI handling it never does.

Contractor Risk Managed

Still enrolled, still inventoried, still on the diagram. The delta is that technical enforcement is replaced by a written risk position, and that position has to survive questioning on its own.

Specialized Asset

Government furnished Macs, a Mac driving instrumentation, a Mac locked to a vendor image. Narrow, and defined by what the asset is rather than by how awkward it is to manage.

Out of Scope

The burden runs the other way. You are showing that CUI could not reach it, which is a harder claim than showing that it does not.

Where does the Security Protection Asset case get vague?

The regulation says an SPA is assessed against requirements relevant to the capabilities provided. It does not enumerate which ones, and neither does any DoD guidance we can point to. Anyone publishing a definitive per-requirement SPA mapping is publishing an opinion.

The workable reading is to scope by capability. An admin Mac that drives your MDM is providing privileged administration, so the requirements about privileged access, authentication, its own baseline, its own logging and its own maintenance path are clearly in. Requirements about marking and handling CUI media are not, because it never touches CUI. Write that reasoning down in the SSP, because the reasoning is what gets assessed.

The under-hardened SPA

The most common Mac scoping error is not misclassification. It is treating a Security Protection Asset as lower risk because it is assessed against fewer requirements.

An admin Mac that can push configuration to every CUI Asset in the fleet is a higher-value target than any single CUI Asset. Fewer requirements assessed is not less risk carried.

How does category change the ongoing workload?

This is the part that shows up months later, not on assessment day. Every requirement an asset is assessed against brings evidence with it, and evidence carries a refresh interval.

  • CUI Asset. The full evidence set at full cadence. In Access Control alone that is dozens of recurring obligations, and Access Control is one family of fourteen.
  • Security Protection Asset. A smaller set, but the security-critical part of it. Privileged access reviews and administrative logging do not become optional because the asset holds no CUI.
  • Contractor Risk Managed. Technically lighter, documentally heavier. The written risk position is doing the work that technical enforcement does elsewhere, so it has to be specific, current, and consistent with what your MDM actually enforces.
  • Specialized and out of scope. Lightest, but the justification has to stay true. An asset quietly repurposed into CUI work is a scoping change nobody recorded.
What risk-managed actually trades

Contractor Risk Managed does not reduce the work. It moves the work from engineering to writing, and the writing then has to hold up alone.

If the policy says CUI never reaches these Macs, and nothing technically stops it, the policy is the only control. An assessor is entitled to test whether it holds, and a limited check is assessed against CMMC requirements. The category that looked cheaper becomes the one with the least margin for error.

How do you keep the categories honest over time?

  • Record the reasoning, not just the label. "CRMA" in an inventory cell is not a position. The sentence that explains why is.
  • Tie the category to enforcement. If a Mac is risk-managed because policy keeps CUI off it, name what enforces that policy.
  • Re-check on change. New software, a new sync folder, a new person, and the category can move without anyone deciding it should.
  • Watch observed use, not stated intent. Category follows what actually happens on the device.
Planning use only

Category definitions and assessment consequences are from 32 CFR 170.19. The Mac implementation guidance is one worked view of a typical architecture, not a required answer and not an assessment finding. Scoping decisions are yours to make and to defend, and this is not legal advice.

Recording the category so it survives an assessment

A category is only as good as the record behind it. The suite carries the asset inventory workbook that holds the classification and its reasoning, the shared responsibility matrix for the provider side, and the SSP template where the scoping narrative has to hold up.

See what is in the suite

Mac-first, one-time purchase, no subscription.

Where this fits