CMMC Answers
Are Office VoIP Phones in Scope for CMMC?
The Answer
Yes. If employees discuss CUI on office VoIP phones, the phone system transmits CUI, and the components that carry those calls are CUI Assets that must be assessed against all 110 security requirements of NIST SP 800-171 Revision 2.
The Question as Asked on LinkedIn
Your employees discuss CUI on office VoIP phones. Are those phones in scope for CMMC?
- Yes, they transmit CUICorrect
- No, voice is not CUI
- Only if calls are recorded
- Depends on the phone systemPartial Credit
CUI Is Defined by Content, Not Format
The most common wrong answer rests on the assumption that CUI means files. It does not. Under 32 CFR 2002.4(h), Controlled Unclassified Information is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls.1 The definition addresses the information itself. It says nothing that limits CUI to documents, drawings, or data files. A manufacturing tolerance read aloud from a controlled technical drawing is the same information whether it travels as a PDF attachment or as a voice packet.
The safeguarding obligation follows the information. 32 CFR 2002.14 requires protection of the confidentiality of CUI that authorized holders process, store, or transmit on information systems.2 A VoIP system is an information system. Voice on a VoIP call is data in transit on a packet network, indistinguishable in regulatory terms from any other data the network carries.
What the Scoping Rule Does With That
CMMC Level 2 scoping is governed by 32 CFR 170.19(c)(1), which defines the asset categories for a Level 2 assessment.3 The first category, CUI Assets, consists of assets that process, store, or transmit CUI. These assets must appear in the asset inventory, the System Security Plan, and the network diagram, and they are assessed against all 110 security requirements of NIST SP 800-171 Revision 2.4 The DoD CMMC Level 2 Scoping Guide applies the same three verbs and carries the same documentation and assessment consequences.5
Apply the verbs to a phone call about CUI. The handset converts the conversation to packets and transmits it. The call manager or hosted PBX processes the signaling and often the media stream. Session border controllers and the switches carrying the voice VLAN transmit it. If a caller leaves a message describing controlled technical data, the voicemail platform stores it. Each component that touches the call satisfies at least one of the three verbs, and each is therefore a CUI Asset.
Where the Nuance Lives
The fourth poll option, that scope depends on the phone system, earns partial credit because architecture determines how far scope extends, even though it does not change the answer for the phones themselves. The question as asked stipulates that employees discuss CUI on the phones. Once that fact is established, those phones transmit CUI and the category assignment follows. What the architecture governs is everything downstream of that fact.
| Configuration | Scoping Consequence |
|---|---|
| Flat network, VoIP shares infrastructure with the general LAN | Scope extends beyond the phones. Switches, routers, and supporting infrastructure carrying voice traffic transmit CUI and enter the assessment as CUI Assets. |
| Voice VLAN with documented logical separation | The phones and voice infrastructure remain CUI Assets, but separation can keep other network segments out of scope if the separation is documented and defensible. |
| Cloud-hosted VoIP service carrying CUI calls | The provider is processing and transmitting CUI on the contractor's behalf, which raises the FedRAMP Moderate baseline question under DFARS 252.204-7012(b)(2)(ii)(D).6 |
| Written policy prohibits CUI discussion on the phone system, with training and enforcement | Phones that can connect to CUI Assets but are not intended to handle CUI may be categorized as Contractor Risk Managed Assets, documented in the SSP and managed under risk-based policy rather than assessed against all 110 requirements.3 |
The last row is where most contractors should focus. The practical decision is not how to bring a phone system through an assessment. It is whether the phone system needs to carry CUI at all. A short policy directing that controlled technical discussions happen through the secured collaboration environment rather than the office phones, supported by training records and periodic review, is far less expensive than assessing a PBX against 110 requirements. That decision has to be made honestly. A policy that everyone ignores will not survive an assessor's interviews, and the question as asked describes an environment where the discussions are in fact happening.
The Bottom Line
Voice is not exempt from the CUI program, and phones are not exempt from CMMC scoping. If CUI is discussed on the office VoIP system, the components carrying those calls are CUI Assets under 32 CFR 170.19(c)(1). Contractors have two defensible paths: bring the voice environment into scope and secure it, or remove CUI from the voice environment through policy, training, and practice, and document that decision in the SSP. The one position that fails is the assumption that the question never needed to be asked.
This page is part of the CMMC Answers series, where scoping and implementation questions from the field receive short, sourced explanations.
References
- 32 CFR 2002.4, Definitions, Controlled Unclassified Information (CUI) Program, National Archives and Records Administration.
- 32 CFR 2002.14, Safeguarding, Controlled Unclassified Information (CUI) Program, National Archives and Records Administration.
- 32 CFR 170.19, CMMC Scoping, Cybersecurity Maturity Model Certification Program, Department of Defense.
- NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, National Institute of Standards and Technology.
- CMMC Level 2 Scoping Guide, Department of Defense Chief Information Officer.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, Defense Federal Acquisition Regulation Supplement.