Skip to content

Intake and discovery

Collect basic facts before the first working session. Use working sessions for decisions that require context, and keep sensitive evidence in a controlled environment.

Prepare basic identifiers, applicable contracts and clauses, locations, workforce roles, technology providers, and an initial asset inventory.

Walk through how CUI is received, accessed, processed, stored, transmitted, backed up, and destroyed. Follow-up questions matter because the boundary depends on how work actually happens.

Gather policies, inventories, diagrams, configuration exports, screenshots, logs, training records, and other artifacts that support implementation claims.

  • Contract and subcontract flow-down requirements
  • CUI categories and representative workflows
  • Users, roles, privileged accounts, and non-US-person considerations
  • Endpoints, servers, networks, cloud services, and security tools
  • External service providers that process, store, transmit, or protect CUI
  • Existing SSP, policies, assessments, POA&Ms, and SPRS records
  • Available evidence and known implementation gaps

A useful discovery package includes a written boundary, a CUI-flow diagram, an asset and service inventory, named control owners, open questions, and an evidence request list.

Published by Eagle Ridge Advisory. Public guidance only: this site holds no client information, completed security plans, evidence, or legal advice. Current CMMC rules and contract terms control.