VALIDATE THE BOUNDARY YOU ALREADY DOCUMENTED
Prove That Your CUI Boundary Matches Reality
A documented boundary describes where Controlled Unclassified Information is supposed to live. It does not always describe where CUI is.
Teramis compares your documented boundary with findings from the actual data environment, identifies CUI in unexpected locations, and produces the evidence your team needs to review, correct, and defend the boundary you already have.
A boundary is only defensible when the data agrees with it.
DOCUMENTATION AND DATA CAN DRIFT APART
Your Boundary Was Accurate the Day You Wrote It
Most organizations define a CUI boundary once, during CMMC planning, enclave design, or SSP development. That work is usually careful and well documented.
The environment then keeps moving. Projects start, people change roles, repositories are created, systems are migrated, contracts are added, and files are copied for reasons that made sense at the time.
Boundary validation is how an organization confirms that the environment still matches the documentation, and identifies the places where it no longer does.
Scoping defines the boundary. Validation tests whether it still holds.
Trusted by leading companies
COMMON REASONS DOCUMENTATION FALLS OUT OF DATE
Drift Is Usually Routine, Not Careless
A boundary can become inaccurate through ordinary business activity, including:
- New programs, contracts, or customer requirements that introduce CUI
- New SharePoint sites, Teams, channels, or shared drives created for a project
- Employee, contractor, and role changes that move files to new locations
- Engineering and CAD work that generates derivative files in technical repositories
- Email attachments saved outside approved repositories
- Migrations that moved data successfully but left copies in the original location
- Acquisitions, integrations, or reorganizations that bring in unfamiliar environments
- Archived, legacy, and backup storage retained after a system was retired
- Documentation updated on a different schedule than the environment it describes
None of these require a policy failure. They only require time.
Can You Support Your Boundary With Evidence Today?
Can You Support Your Boundary With Evidence Today?
Teams reviewing an existing boundary should be able to answer:
- Does CUI exist in every location the documentation says it does?
- Does CUI exist in any location the documentation does not mention?
- Which repositories inside the boundary currently contain CUI?
- Has CUI appeared in email, endpoints, or personal storage locations?
- Do engineering or technical repositories contain CUI that scoping did not anticipate?
- Do archives, backups, or legacy systems still hold CUI from retired projects?
- Does the SSP reflect the environment as it exists now, or as it existed at authoring?
- Which findings represent genuine exceptions requiring a decision?
- When was the boundary last tested against the actual data environment?
- What evidence would the organization present if a customer or reviewer asked?
An organization that cannot answer these questions with findings is describing an intended environment rather than a validated one.
FROM DOCUMENTED BOUNDARY TO TESTED BOUNDARY
A Repeatable Workflow for Testing Scope Against Reality
Test the documented CUI boundary against what actually exists across the approved environment.
Start From the Documented Boundary
Begin with the existing SSP, asset inventory, network and data-flow diagrams, approved CUI repositories, and enclave documentation. These define what the validation is testing against.
Confirm Approved Data Sources for Review
Determine which systems, repositories, business units, users, and environments are authorized for discovery. Validation is only meaningful when it covers both the locations inside the boundary and the approved locations outside it.
Discover Candidate CUI Across Those Sources
Teramis examines approved data sources to identify potential CUI, including Microsoft 365, SharePoint, OneDrive, Exchange, network file shares, endpoints, engineering repositories, email and attachments, PDFs, scanned files, archives, and legacy storage where supported.
Validate the Findings
Review and sampling workflows help separate a list of possible matches from findings the team can evaluate and act on.
Compare Findings With the Documented Boundary
Discovery results are compared against the documented scope to show where the environment and the documentation agree, and where they do not.
Classify the Differences
Differences generally fall into a small number of categories:
- CUI found inside the boundary, as documented
- CUI found outside the documented boundary
- Documented CUI locations where no CUI was found
- Repositories in use that the documentation does not describe
Document Exceptions for Review
Findings outside expected locations are recorded with file and location detail so the appropriate team can determine the next action.
Re-Validate After Authorized Changes
Once your team or an approved service provider has acted on the findings, run the comparison again to confirm the boundary and the environment now agree, and to establish the baseline for ongoing monitoring.
The result: a repeatable process for comparing the documented CUI boundary with the environment it is intended to describe.
Better Together With Your Existing Stack
What Teramis Produces for Boundary Validation
Evidence Your Team and Your Reviewers Can Use
Turn a documented boundary into a demonstrated one by creating a clearer record of where CUI is found, where exceptions exist, and how the environment changes over time.
Boundary Validation Output
A Shared Record of What the Environment Actually Contains
Teramis identifies, validates, catalogs, reports, and monitors CUI findings so compliance, security, IT, legal, leadership, and advisory teams can compare the documented boundary with the environment it is intended to describe.
CUI inventory information
File-level findings
Repository and location details
Findings outside expected or approved locations
Boundary exceptions for review
Documented locations where no CUI was found
Validation and sampling output
Change reporting between scans
Monitoring history
Evidence to support boundary, scope, and readiness discussions
One shared record. Compliance, security, IT, legal, leadership, and advisory teams can see where the documented boundary and the actual environment agree, and where further review is needed.
The Locations That Most Often Fall Outside the Boundary
Where Exceptions Commonly Appear
Look where the documentation is least likely to reach. Within approved data sources, exceptions are frequently found in locations created, copied, retained, or overlooked outside the expected repository structure.
Common Exception Pattern
CUI Does Not Always Stay Where the Boundary Says It Should
Files may be copied, saved, retained, archived, or moved through normal business activity. Boundary validation helps surface the approved locations where the documented environment and the actual data environment do not align.
Email and saved attachments
Individual OneDrive and personal storage locations
Project folders created outside the approved repository structure
Engineering, CAD, and technical repositories
Scanned documents and image-based files
Compressed archives and nested folders
Endpoints and local working copies
Source locations retained after a migration
Legacy file shares and retired system storage
Backup and archive sets
Authorized sources only. Teramis reports what it finds in the sources your organization authorizes. It does not access systems outside that authorization.
Validation Is a Checkpoint, Not a One-Time Event
When to Validate the Boundary
Common triggers for testing an existing boundary. Validation helps confirm whether the documented CUI boundary still reflects what exists across the approved environment.
Before a Self-Assessment or Assessment Preparation
Confirm that the environment supports the scope and representations your organization intends to submit.
After an Enclave or Migration Project
Verify that CUI reached the approved environment and did not remain in source locations.
Explore Migration Planning Support →When the Business Changes
New contracts, acquisitions, reorganizations, and system retirements all change where data lives.
On a Recurring Schedule
Periodic validation identifies drift before it becomes an assessment or contractual issue.
Explore Spillage Monitoring →After a Suspected Incident
Establish factually whether CUI may have been present in affected systems.
Explore Post-Incident CUI Review →If You Have Not Defined a Boundary Yet
Start with scoping rather than validation.
Explore CMMC Scoping →The boundary should evolve with the environment. Validation provides another evidence checkpoint when the systems, data, business, or compliance context changes.
Keep the Stack. Add CUI Evidence.
How Teramis Fits With Advisors and Existing Tools
Give the teams reviewing your boundary better data.
Teramis does not replace CMMC advisors, RPOs, MSPs, MSSPs, GRC platforms, secure enclave providers, Microsoft security tools, DLP systems, legal counsel, or DIBCAC assessments.
Teramis supplies the CUI discovery and validation information those teams and systems use.
Evidence Layer
Teramis Helps Establish
Where candidate CUI exists today
Which documented locations are confirmed by findings
Which findings fall outside the documented boundary
Which repositories require review
Which assumptions in the documentation need revision
What should be monitored after validation
Action Layer
Authorized Teams Then Determine
Whether the boundary is revised or the environment is corrected
Which findings require administrative action
How documentation and the SSP are updated
Which controls apply to newly identified locations
What is reported, and to whom
Assessment and readiness strategy
Teramis provides the evidence. Existing tools and authorized professionals act on it.
A Shared View of Where the Boundary Stands
Who Benefits From Boundary Validation
Support the people responsible for scope, evidence, and risk. Boundary validation gives different stakeholders a common technical record they can use for decisions, documentation, and review.
Organization
Defense Contractors
Confirm that the documented boundary reflects the environment before an assessment, customer review, or contract commitment.
Leadership
Executives and Owners
Improve confidence that compliance representations are supported by the actual environment.
Operations
Security and IT Teams
Identify the repositories, systems, and endpoints that require review or cleanup.
Compliance
Compliance and GRC Teams
Compare technical findings against the SSP, asset inventory, and documented scope, and record the exceptions that need resolution.
Advisory
CMMC Advisors and RPOs
Test client boundary assumptions with technical findings rather than interviews alone.
Managed Services
MSPs and MSSPs
Deliver recurring boundary validation as a service alongside managed security and compliance work.
One boundary. Multiple stakeholders. Boundary validation gives each team a shared evidence base while leaving compliance decisions, remediation, documentation changes, and assessment strategy with the appropriate authorized professionals.
A Precise Role in Boundary Validation
What Teramis Does and Does Not Do
Discovery evidence, not final determinations. Teramis provides technical findings that authorized teams can use to evaluate the boundary and determine appropriate next steps.
Teramis Role
What Teramis Does
Teramis helps organizations:
Discover candidate CUI across approved data sources
Identify where findings are located
Categorize and catalog findings
Validate discovery results
Compare findings with the documented boundary
Identify CUI outside expected or approved locations
Document boundary exceptions for review
Report changes between scans
Establish and maintain a monitoring baseline
Decision Boundary
What Teramis Does Not Do
Teramis does not:
Approve or certify the CUI boundary
Perform a formal CMMC assessment
Complete the organization's self-assessment
Guarantee certification or an assessment outcome
Make legal, reporting, or notification determinations
Tag or alter discovered content
Decide which contracts or requirements apply
Guarantee that a customer, assessor, or government reviewer will accept a boundary
Authorized customer personnel, advisors, legal counsel, and assessment professionals retain responsibility for their respective decisions.
Teramis identifies, validates, reports, and monitors CUI. It does not move, tag, delete, or alter discovered data.
Test the Boundary Before Someone Else Does
Find Out Whether Your Documented Boundary Still Holds
Talk with Teramis about your documented scope, your approved data sources, and the locations you are least certain about.
Begin with a review of your current boundary documentation and the environment it is meant to describe.
Security reminder: Do not submit Controlled Unclassified Information, credentials, sensitive file paths, incident evidence, or other protected information through this form.
