Guide

What is a System Boundary?

Your boundary decides how much compliance work you have. Learn how to draw one that is defensible and small.

Intended audience
Owners, IT leads, and contractors
Difficulty
Intermediate
Estimated time
11 minutes
Access
Free
NIST SP 800-171
CMMC
Government contracting

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Define a system boundary in the context of a compliance assessment.
  • Follow the data to determine what should be included inside the boundary.
  • Explain why cloud services must be listed explicitly in scoping work.
  • Document what is out of scope and the justification for excluding it.
  • Apply boundary-drawing logic to a small business example scenario.

Definition

The boundary is the set of people, devices, applications, and services that store, process, or transmit the data in question — plus anything that can materially affect their security.

How to draw it

  • Start from the data, not the org chart.
  • Follow it: where does it arrive, where does it rest, where does it leave?
  • List cloud services explicitly, including email and file storage.
  • Write down what is out of scope and why.

Example

A ten-person engineering firm might scope to one cloud tenant, six laptops, one file repository, and one CAD application — and deliberately exclude the marketing website and the public-facing brochure store.

Key takeaways

  • The system boundary is the set of people, devices, applications, and services that store, process, or transmit the data in question, plus anything that can materially affect their security.
  • Boundaries should be drawn by following the data itself, not by mirroring the org chart.
  • Cloud services, including email and file storage, must be explicitly identified rather than assumed.
  • A defensible boundary always documents what was excluded and the reasoning behind that exclusion.
  • A smaller, well-justified boundary directly reduces the total compliance workload.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 3
Knowledge check

80% required to pass. Answers are graded on our servers.

1. What is included in a system boundary?

2. What should scoping start from?

3. Why should cloud services like email be listed explicitly?

4. What should accompany anything excluded from the boundary?

5. In the ten-person engineering firm example, what was deliberately excluded?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal); DoD supply chain
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Template

SSP Outline

A section-by-section outline for a System Security Plan a small business can maintain.

Advanced
60 min
Premium
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Government Contractor Startup Checklist

What to put in place before your first federal award creates security obligations you cannot meet.

Intermediate
40 min
Free
FAR
DFARS

Published · v1.0.0 · 2026-08-01

Exercise

Identify CUI Examples

Practice separating CUI from FCI and from ordinary business information.

Advanced
15 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Checklist

NIST SP 800-171 Preparation Checklist

A plain-language preparation pass across the requirement families, focused on what a small business must produce and prove.

Advanced
60 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.