CMMC Level 2 Asset Inventory Template & Overview
If you're preparing for a CMMC Level 2 assessment, one of the first things a C3PAO or RPO will ask for is your asset inventory. This template gives you a structured starting point for building one, so you walk into scoping conversations with a clear picture of your environment instead of a blank page.
Written By Stephanie
Why asset inventory comes first
CMMC Level 2 scoping isn't just about which systems touch Controlled Unclassified Information (CUI). It's about every system, service, vendor, and person that could reasonably interact with that data or the security functions protecting it. Getting this inventory right early has a direct effect on assessment cost and timeline: the more clearly you've categorized your assets, the less back-and-forth there is once a formal assessment begins.
Think of this template as your organization's first draft of that picture. It's meant to be filled in, argued over internally, and refined, not treated as a final answer.
What's in the template
The workbook has five tabs, each doing a specific job:
Instructions – A quick orientation to the workbook and a color legend for the fill-in cells.
CMMC Asset Categories – A reference guide to the five asset categories, what evidence an assessor expects for each, and how they affect assessment scope. Read this one first.
Asset Inventory – Where you list every system, application, cloud service, and facility relevant to your CUI environment, with a running count by category.
Personnel & Endpoints – Where you list the people and devices that touch in-scope systems.
Vendor / ESP Tracker – Where you track External Service Providers (ESPs) and whether you've collected their shared-responsibility or Customer Responsibility Matrix (CRM) documentation.
CMMC Level 2 Asset Inventory Template
The five asset categories, at a glance
Each category carries a different evidence expectation and assessment impact, which is exactly why getting the categorization right matters. The full reference tab in the workbook goes deeper on what an assessor will look for in each case.
How to use it, step by step
Start with the CMMC Asset Categories tab. Understand the five categories and the short decision logic behind them before you touch the inventory itself.
Fill in the Asset Inventory tab. One row per system, application, cloud service, or facility. Use the Category dropdown (data validation is already built into that column) rather than typing free text.
Fill in the Personnel & Endpoints tab. People and their devices count as assets too. Someone with administrative access to a CUI Asset is in scope, even if their day-to-day device is just a laptop.
Fill in the Vendor / ESP Tracker tab. Every vendor categorized as an SPA or CRMA needs a shared-responsibility or CRM document on file. This tab tracks whether you have it yet.
Bring it to a C3PAO or RPO for validation. Asset categorization drives scope and cost directly, so treat every categorization here as a draft until a qualified third party has reviewed it.
A few things to keep in mind
Green-shaded cells are yours to fill in. Yellow-shaded rows are illustrative examples, delete or replace them once you've entered your own data. Light blue is reference content, and doesn't need editing.
This template is a starting structure, not a certified scoping determination. Every organization's environment is different, and the example rows won't map exactly onto yours.
If your organization provides a product or platform to customers who are themselves pursuing CMMC certification, you'll typically need to produce your own CRM for them, separate from collecting one from your vendors.
Used this way, the template turns asset inventory from an open-ended question into a concrete checklist, which is the fastest way to walk into a scoping conversation prepared.
Questions?
Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.