Asset Inventory

Build a categorized inventory of every asset in your CMMC environment, classify each one by CUI scope to define your assessment boundary, and track what still needs review.

The Asset Inventory is a categorized record of the assets — devices, applications, accounts, and equipment — that make up your CMMC environment. You group each asset under a category, classify it by its CUI scope, and keep the details current so your inventory always reflects reality.

Categorization is not just bookkeeping: an asset's CUI scope is what places it inside or outside your assessment boundary. A CUI Asset pulls in all 110 CMMC Level 2 practices; an out-of-scope asset is excluded entirely. Getting the classification right is how you define — and defend — the scope an assessor will test. The inventory feeds your SSP and your compliance posture.

Find it in the sidebar under Asset Inventory (/dashboard/inventory). It's visible to every role that can read compliance data; adding and editing assets requires a manager role, and changing the field layout requires an admin role — see Permissions.

Key concepts

CUI scope

Every asset carries a CUI scope — the classification that decides how CMMC applies to it. This is the single most important field on each asset, and it drives your assessment boundary.

ScopeWhat it means
CUI AssetProcesses, stores, or transmits CUI. Sits inside your boundary — all 110 Level 2 practices apply.
Security ProtectionProvides a security capability to CUI Assets (for example a firewall or identity provider). All 110 practices apply.
Contractor Risk-ManagedCan access CUI but does not. Documented in the SSP and assessed selectively at assessor discretion.
SpecializedOperational Technology, IoT, or Government-Furnished Equipment. Limited applicability — document compensating controls and handling.
Out of ScopeHandles no CUI and provides no security capability. Excluded from the boundary.
UnreviewedNo scope decision has been made yet. The default for any new asset until you triage it.
New assets start as Unreviewed so nothing slips into your boundary silently. Working the Unreviewed count down to zero is a clean, defensible way to show an assessor your scoping is complete.

Category

Assets are organized into categories (for example workstations, servers, or applications). DIBFI ships a set of standard categories, and admins can add organization-specific ones. Each category defines its own set of fields, so the columns you see change as you move between categories.

Status

Separate from scope, each asset has an operational status.

StatusMeaning
ActiveIn service
InactiveTemporarily out of service
DecommissionedRetired from service

Fields

Each category has a mix of standard fields (name, asset tag, scope, status, location, assignee, and notes) and custom fields your admins add. Custom fields can be text, long text, numbers, dates, yes/no toggles, single- or multi-select dropdowns, URLs, and email addresses. A few core fields — name, asset tag, CUI scope, status, and notes — are mandatory and can never be hidden.


Using the module

The inventory page is a filterable table. Scope chips across the top let you filter by CUI scope (each showing its live count), category tabs switch between categories, and a search box matches on name, tag, and location. Most editing happens directly in the table — click a cell, change the value, and it saves automatically.

Add an asset

There are three ways to get assets into the inventory.

Add a row

Pick a category and add a new row. It appears immediately as an Unreviewed asset, ready for you to type its name and details straight into the table.

Import a spreadsheet

Use Import CSV to bring in many assets at once. You map your spreadsheet to a category, and each row becomes an asset. Rows missing a required name are reported back to you so you can fix and re-import.

Request an inventory

Use Request inventory to ask a colleague to fill in assets for one or more categories — useful when the person who knows the equipment isn't the person managing compliance. They complete the request, and the results flow into your inventory.

Edit an asset

Click any editable cell to change it in place — name, tag, location, assignee, status, or any custom field. Changes save as you go. Open an asset's detail view for the full record, including its notes and every custom field for its category.

Assignees can be an existing user in your organization or a free-text name for someone not yet in DIBFI — handy for recording who owns a device before they have an account.

Review and classify an asset

Reviewing an asset means deciding its CUI scope. This is the step that moves it out of Unreviewed and into your defined boundary.

Open the asset

Find the asset in the table — filter by the Unreviewed chip to work through everything still pending.

Set its CUI scope

Choose the scope that fits: CUI Asset, Security Protection, Contractor Risk-Managed, Specialized, or Out of Scope. Each choice shows a short assessor-facing note explaining when it applies.

Record a justification

Where the classification isn't obvious, add a justification so your scoping decision is documented for the assessor. Marking something out of scope with a reason is itself part of a defensible scope argument.

Customize fields

Admins can tailor each category with Customize fields: show or hide standard fields, curate the options in a dropdown, and add custom fields specific to your environment. The mandatory fields stay visible no matter what.

Read the summary counts

The page header summarizes your inventory at a glance: the total number of assets, how many are still Unreviewed, and how many are classified as CUI Assets. The scope chips and category tabs each carry their own counts, so you can see your distribution across scopes and categories without leaving the page.


Permissions

Access is governed by three permissions in the role matrix.

CapabilityPermission
View the inventory, filters, and summary countsVIEW_ASSET_INVENTORY
Add, edit, import, request, and classify assetsMANAGE_ASSET_INVENTORY
Change the field layout (show/hide, dropdown options, custom fields)MANAGE_INVENTORY_FIELDS

VIEW_ASSET_INVENTORY is held by every non-platform role, including Assessor (read-only). MANAGE_ASSET_INVENTORY is held by Org Admin, Org User, MSP Super, and MSP Admin — not Assessor. MANAGE_INVENTORY_FIELDS is reserved for admin roles (Org Admin, MSP Super, MSP Admin) — an Org User can edit assets but not restructure a category's fields.

Deleting an asset doesn't erase it — the record is retained behind the scenes for your audit trail and simply hidden from the active inventory.

How it works

Extra detail on what the inventory stores and how it behaves — product behavior, not internals.

What an asset record holds

Each asset is a single record that belongs to your organization and sits under one category.

Name
A short identifier for the asset (required).
Asset tag
Your internal tag or serial number, if you use one.
Category
The group the asset belongs to, which determines its field layout.
CUI scope
The classification that places the asset inside or outside your boundary — CUI Asset, Security Protection, Contractor Risk-Managed, Specialized, Out of Scope, or Unreviewed.
Scope justification
An optional note explaining why the scope was chosen — read by your assessor.
Status
Active, Inactive, or Decommissioned.
Location & facility
Where the asset physically lives.
Assignee
The person responsible — either a user in your organization or a free-text name.
Linked system
The parent system this asset belongs to, if any.
Custom fields
Any additional fields your admins defined for the asset's category.

Why scope drives your boundary

Your assessment boundary is the sum of the assets that fall in scope. CUI Assets and Security Protection assets bring the full weight of all 110 Level 2 practices. Contractor Risk-Managed and Specialized assets have limited, documented applicability. Out of Scope assets are excluded. Because the classification determines what an assessor tests, keeping every asset reviewed and correctly scoped is what makes your boundary both accurate and defensible.

Asset details are treated as sensitive

The individual field values on your assets can describe your environment in detail, so they're treated as sensitive. When the AI Connector is enabled, an assistant can read a summary of your inventory — counts of assets by category and by CUI scope, plus the unreviewed count — but never the individual field values of any asset. That keeps environment specifics from being exposed while still letting an assistant report on your scoping progress.

The asset summary an assistant sees is a different population from the system-level scope breakdown elsewhere in your posture: one counts assets, the other counts systems. Their totals shouldn't be compared directly.

Systems

Group your in-scope assets under the systems that form your assessment boundary.

Risk Management

Link risks to the specific systems and assets they affect.

AI Connector

Read a summary of your asset inventory through an AI assistant.