← Custodia
Definition

Contractor Risk Managed Asset

Also known as: CRMA

A Contractor Risk Managed Asset (CRMA) is an asset that can, but is not intended to, handle CUI, and that the contractor chooses to manage with policies and practices rather than full technical implementation of every requirement. CRMAs are in scope for CMMC Level 2 but are assessed against the contractor's own risk-based policies, and are documented in the System Security Plan.

Primary source
CMMC Level 2 Scoping Guide v2.13 (DoD CIO)

Related terms

Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements, no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual, two months free)