Skip to content

VALIDATE THE BOUNDARY YOU ALREADY DOCUMENTED

Prove That Your CUI Boundary Matches Reality

A documented boundary describes where Controlled Unclassified Information is supposed to live. It does not always describe where CUI is.

Teramis compares your documented boundary with findings from the actual data environment, identifies CUI in unexpected locations, and produces the evidence your team needs to review, correct, and defend the boundary you already have.

 


A boundary is only defensible when the data agrees with it.

 DOCUMENTATION AND DATA CAN DRIFT APART 

Your Boundary Was Accurate the Day You Wrote It

Most organizations define a CUI boundary once, during CMMC planning, enclave design, or SSP development. That work is usually careful and well documented.

The environment then keeps moving. Projects start, people change roles, repositories are created, systems are migrated, contracts are added, and files are copied for reasons that made sense at the time.

Boundary validation is how an organization confirms that the environment still matches the documentation, and identifies the places where it no longer does.

Scoping defines the boundary. Validation tests whether it still holds.

Trusted by leading companies

COMMON REASONS DOCUMENTATION FALLS OUT OF DATE

Drift Is Usually Routine, Not Careless

A boundary can become inaccurate through ordinary business activity, including:

  • New programs, contracts, or customer requirements that introduce CUI
  • New SharePoint sites, Teams, channels, or shared drives created for a project
  • Employee, contractor, and role changes that move files to new locations
  • Engineering and CAD work that generates derivative files in technical repositories
  • Email attachments saved outside approved repositories
  • Migrations that moved data successfully but left copies in the original location
  • Acquisitions, integrations, or reorganizations that bring in unfamiliar environments
  • Archived, legacy, and backup storage retained after a system was retired
  • Documentation updated on a different schedule than the environment it describes

None of these require a policy failure. They only require time.

Can You Support Your Boundary With Evidence Today?

Can You Support Your Boundary With Evidence Today?

Teams reviewing an existing boundary should be able to answer:

  • Does CUI exist in every location the documentation says it does?
  • Does CUI exist in any location the documentation does not mention?
  • Which repositories inside the boundary currently contain CUI?
  • Has CUI appeared in email, endpoints, or personal storage locations?
  • Do engineering or technical repositories contain CUI that scoping did not anticipate?
  • Do archives, backups, or legacy systems still hold CUI from retired projects?
  • Does the SSP reflect the environment as it exists now, or as it existed at authoring?
  • Which findings represent genuine exceptions requiring a decision?
  • When was the boundary last tested against the actual data environment?
  • What evidence would the organization present if a customer or reviewer asked?

An organization that cannot answer these questions with findings is describing an intended environment rather than a validated one. 

FROM DOCUMENTED BOUNDARY TO TESTED BOUNDARY

A Repeatable Workflow for Testing Scope Against Reality

Test the documented CUI boundary against what actually exists across the approved environment.

1

Start From the Documented Boundary

Begin with the existing SSP, asset inventory, network and data-flow diagrams, approved CUI repositories, and enclave documentation. These define what the validation is testing against.

2

Confirm Approved Data Sources for Review

Determine which systems, repositories, business units, users, and environments are authorized for discovery. Validation is only meaningful when it covers both the locations inside the boundary and the approved locations outside it.

3

Discover Candidate CUI Across Those Sources

Teramis examines approved data sources to identify potential CUI, including Microsoft 365, SharePoint, OneDrive, Exchange, network file shares, endpoints, engineering repositories, email and attachments, PDFs, scanned files, archives, and legacy storage where supported.

4

Validate the Findings

Review and sampling workflows help separate a list of possible matches from findings the team can evaluate and act on.

5

Compare Findings With the Documented Boundary

Discovery results are compared against the documented scope to show where the environment and the documentation agree, and where they do not.

6

Classify the Differences

Differences generally fall into a small number of categories:

  • CUI found inside the boundary, as documented
  • CUI found outside the documented boundary
  • Documented CUI locations where no CUI was found
  • Repositories in use that the documentation does not describe
7

Document Exceptions for Review

Findings outside expected locations are recorded with file and location detail so the appropriate team can determine the next action.

8

Re-Validate After Authorized Changes

Once your team or an approved service provider has acted on the findings, run the comparison again to confirm the boundary and the environment now agree, and to establish the baseline for ongoing monitoring.

The result: a repeatable process for comparing the documented CUI boundary with the environment it is intended to describe.

Better Together With Your Existing Stack

What Teramis Produces for Boundary Validation

Evidence Your Team and Your Reviewers Can Use

Turn a documented boundary into a demonstrated one by creating a clearer record of where CUI is found, where exceptions exist, and how the environment changes over time.

Boundary Validation Output

A Shared Record of What the Environment Actually Contains

Teramis identifies, validates, catalogs, reports, and monitors CUI findings so compliance, security, IT, legal, leadership, and advisory teams can compare the documented boundary with the environment it is intended to describe.

CUI inventory information

File-level findings

Repository and location details

Findings outside expected or approved locations

Boundary exceptions for review

Documented locations where no CUI was found

Validation and sampling output

Change reporting between scans

Monitoring history

Evidence to support boundary, scope, and readiness discussions

One shared record. Compliance, security, IT, legal, leadership, and advisory teams can see where the documented boundary and the actual environment agree, and where further review is needed.

The Locations That Most Often Fall Outside the Boundary

Where Exceptions Commonly Appear

Look where the documentation is least likely to reach. Within approved data sources, exceptions are frequently found in locations created, copied, retained, or overlooked outside the expected repository structure.

Common Exception Pattern

CUI Does Not Always Stay Where the Boundary Says It Should

Files may be copied, saved, retained, archived, or moved through normal business activity. Boundary validation helps surface the approved locations where the documented environment and the actual data environment do not align.

Email and saved attachments

Individual OneDrive and personal storage locations

Project folders created outside the approved repository structure

Engineering, CAD, and technical repositories

Scanned documents and image-based files

Compressed archives and nested folders

Endpoints and local working copies

Source locations retained after a migration

Legacy file shares and retired system storage

Backup and archive sets

Authorized sources only. Teramis reports what it finds in the sources your organization authorizes. It does not access systems outside that authorization.

Validation Is a Checkpoint, Not a One-Time Event

When to Validate the Boundary

Common triggers for testing an existing boundary. Validation helps confirm whether the documented CUI boundary still reflects what exists across the approved environment.

1

Before a Self-Assessment or Assessment Preparation

Confirm that the environment supports the scope and representations your organization intends to submit.

2

After an Enclave or Migration Project

Verify that CUI reached the approved environment and did not remain in source locations.

Explore Migration Planning Support →
3

When the Business Changes

New contracts, acquisitions, reorganizations, and system retirements all change where data lives.

4

On a Recurring Schedule

Periodic validation identifies drift before it becomes an assessment or contractual issue.

Explore Spillage Monitoring →
5

After a Suspected Incident

Establish factually whether CUI may have been present in affected systems.

Explore Post-Incident CUI Review →
6

If You Have Not Defined a Boundary Yet

Start with scoping rather than validation.

Explore CMMC Scoping →

The boundary should evolve with the environment. Validation provides another evidence checkpoint when the systems, data, business, or compliance context changes.

Keep the Stack. Add CUI Evidence.

How Teramis Fits With Advisors and Existing Tools

Give the teams reviewing your boundary better data.

Teramis does not replace CMMC advisors, RPOs, MSPs, MSSPs, GRC platforms, secure enclave providers, Microsoft security tools, DLP systems, legal counsel, or DIBCAC assessments.

Teramis supplies the CUI discovery and validation information those teams and systems use.

Evidence Layer

Teramis Helps Establish

Where candidate CUI exists today

Which documented locations are confirmed by findings

Which findings fall outside the documented boundary

Which repositories require review

Which assumptions in the documentation need revision

What should be monitored after validation

Action Layer

Authorized Teams Then Determine

Whether the boundary is revised or the environment is corrected

Which findings require administrative action

How documentation and the SSP are updated

Which controls apply to newly identified locations

What is reported, and to whom

Assessment and readiness strategy

Teramis provides the evidence. Existing tools and authorized professionals act on it.

A Shared View of Where the Boundary Stands

Who Benefits From Boundary Validation

Support the people responsible for scope, evidence, and risk. Boundary validation gives different stakeholders a common technical record they can use for decisions, documentation, and review.

Organization

Defense Contractors

Confirm that the documented boundary reflects the environment before an assessment, customer review, or contract commitment.

Leadership

Executives and Owners

Improve confidence that compliance representations are supported by the actual environment.

Operations

Security and IT Teams

Identify the repositories, systems, and endpoints that require review or cleanup.

Compliance

Compliance and GRC Teams

Compare technical findings against the SSP, asset inventory, and documented scope, and record the exceptions that need resolution.

Advisory

CMMC Advisors and RPOs

Test client boundary assumptions with technical findings rather than interviews alone.

Managed Services

MSPs and MSSPs

Deliver recurring boundary validation as a service alongside managed security and compliance work.

One boundary. Multiple stakeholders. Boundary validation gives each team a shared evidence base while leaving compliance decisions, remediation, documentation changes, and assessment strategy with the appropriate authorized professionals.

A Precise Role in Boundary Validation

What Teramis Does and Does Not Do

Discovery evidence, not final determinations. Teramis provides technical findings that authorized teams can use to evaluate the boundary and determine appropriate next steps.

Teramis Role

What Teramis Does

Teramis helps organizations:

Discover candidate CUI across approved data sources

Identify where findings are located

Categorize and catalog findings

Validate discovery results

Compare findings with the documented boundary

Identify CUI outside expected or approved locations

Document boundary exceptions for review

Report changes between scans

Establish and maintain a monitoring baseline

Decision Boundary

What Teramis Does Not Do

Teramis does not:

Approve or certify the CUI boundary

Perform a formal CMMC assessment

Complete the organization's self-assessment

Guarantee certification or an assessment outcome

Make legal, reporting, or notification determinations

Tag or alter discovered content

Decide which contracts or requirements apply

Guarantee that a customer, assessor, or government reviewer will accept a boundary

Authorized customer personnel, advisors, legal counsel, and assessment professionals retain responsibility for their respective decisions.

Teramis identifies, validates, reports, and monitors CUI. It does not move, tag, delete, or alter discovered data.

 

Test the Boundary Before Someone Else Does

Find Out Whether Your Documented Boundary Still Holds

Talk with Teramis about your documented scope, your approved data sources, and the locations you are least certain about.

Begin with a review of your current boundary documentation and the environment it is meant to describe.

Security reminder: Do not submit Controlled Unclassified Information, credentials, sensitive file paths, incident evidence, or other protected information through this form.