Criticality is a triage device. No organization can govern every field, so the CDE list is the honest answer to "which ones actually matter". A field is critical if it feeds a regulatory submission, a financial statement, a payment, a safety decision or an executive metric. That is usually somewhere between 50 and 300 fields in a mid-sized company, out of tens of thousands.

In practice. Derive the list backward from consequence. Take the regulatory reports, the board pack and the top three operational processes, and trace which fields they depend on. That trace is your CDE list, and it comes with its own justification attached — which is what makes it fundable.

Where it goes wrong. Criticality is decided by asking each department which of their data is critical. Everyone answers "all of it", because nobody is rewarded for volunteering that their data does not matter. Criticality has to be derived from use, not collected from opinion.