The short answer

A small defense contractor should usually evaluate a CUI enclave when a limited group of people can perform the covered work inside a deliberately separated workflow without routinely moving Controlled Unclassified Information into the broader business environment.

Whole-company scope can be the better choice when CUI is already embedded across email, endpoints, engineering tools, file shares, production systems, remote work, and business processes—or when enforcing an enclave would create constant workarounds.

The decision is not simply "smaller is cheaper." It is whether the company can build, operate, document, and prove a boundary that matches how the work actually gets done. An enclave does not replace a required CMMC assessment or certification. It changes the system boundary presented for assessment.

This guide explains how to make that decision using the current CMMC Level 2 scoping rules, contract requirements, provider dependencies, and operating reality. It is practical cybersecurity guidance, not legal advice. Resolve contract-specific ambiguity with the contracting officer, prime contractor, and qualified counsel.

What does "CMMC enclave" mean?

"Enclave" is a common industry term for a deliberately bounded environment used to handle CUI. Depending on the design, it may include a controlled cloud tenant or application, managed endpoints or virtual desktops, approved collaboration and file-transfer tools, identity services, logging, security tools, administrators, and documented operating procedures.

The CMMC rule does not grant a special exemption merely because a vendor calls a product an enclave. 32 CFR 170.19 requires the Level 2 assessment scope to be specified and categorizes the assets that affect CUI.

The practical test is therefore not the product name. It is whether the organization can show:

  • where CUI enters, moves, is processed, is stored, and leaves;
  • which people, technologies, facilities, and external providers support that flow;
  • which assets provide security protection to the environment;
  • why other assets cannot handle CUI or protect the CUI assets; and
  • whether actual user behavior matches the designed boundary.

If ordinary laptops can download files, personal printers can print them, unmanaged phones can photograph them, or business email can forward them, the boundary is larger than the architecture diagram suggests.

Start with the official Level 2 asset categories

The current CMMC rule distinguishes five important asset categories. These categories are more useful than a simple "inside" or "outside" label.

Asset categoryPractical meaningTreatment under the Level 2 scope rule
CUI AssetsAssets that process, store, or transmit CUIDocument in the inventory, SSP, and network diagram; assess against all applicable Level 2 requirements
Security Protection AssetsAssets that provide security functions or capabilities to the CMMC assessment scopeDocument and assess against requirements relevant to the capabilities provided
Contractor Risk Managed AssetsAssets that can handle CUI but are not intended to because policies, procedures, and practices restrict that useDocument their treatment; the assessor reviews the SSP and may conduct limited checks when questions arise
Specialized AssetsCertain assets that can handle CUI but cannot be fully secured, such as some OT, IoT, test equipment, restricted systems, or government-furnished equipmentDocument and risk-manage them; the SSP is reviewed under the rule's specialized-asset treatment
Out-of-Scope AssetsAssets that cannot handle CUI and do not protect CUI assets, because they are physically or logically separated or inherently unable to do soBe ready to justify why they cannot process, store, or transmit CUI

This is why "we put CUI in one cloud app" is not a complete scope analysis. Identity, endpoint configuration, logging, backups, administration, support, and security monitoring may still affect the CUI environment.

The rule also gives a narrow but useful virtual-desktop example: an endpoint hosting a VDI client can be out of scope when it is configured so that CUI is not processed, stored, or transmitted beyond keyboard, video, and mouse interaction. Clipboard transfer, local drive mapping, printing, screenshots, downloads, browser caching, and other features can change that analysis.

When an enclave usually makes sense

An enclave is often worth serious consideration when most of the following are true:

  • only a limited group needs CUI access;
  • covered work uses a small number of repeatable workflows;
  • the company can prohibit CUI in ordinary corporate email and storage;
  • users can work through controlled endpoints or appropriately configured virtual desktops;
  • integrations with engineering, manufacturing, finance, and customer systems are limited and understood;
  • administrators and service providers can support the environment without creating uncontrolled data paths;
  • leadership will enforce the boundary even when it is inconvenient; and
  • the cost of operating two environments is lower than bringing the wider company environment into scope.

For example, an engineering firm with six CUI users, one approved collaboration workflow, and no need to move CUI into its general customer relationship management system may be able to maintain a credible enclave. The same design may fail for a manufacturer whose estimators, engineers, machinists, quality team, shipping team, and program managers all need the same controlled technical data.

An enclave works when the business process fits the boundary. It fails when the boundary exists only in policy.

When whole-company scope may be the better decision

Broader scope can be more practical when:

  • many employees need access to CUI;
  • CUI moves through several business applications or production systems;
  • users must constantly transfer information between the enclave and corporate systems;
  • shared identity, administration, networking, security, or backup services cannot be cleanly separated;
  • engineering or manufacturing equipment must directly use controlled technical data;
  • remote and field work make a narrow workflow difficult to enforce;
  • the company expects CUI-dependent defense work to become a large share of revenue; or
  • maintaining duplicate tools, identities, policies, and support processes would cost more than securing the broader environment.

Whole-company scope does not mean every device is automatically a CUI Asset. The organization still needs to categorize assets correctly. It means leadership has concluded that the operational burden and leakage risk of a narrow enclave outweigh the benefit of a smaller boundary.

For a growing defense contractor, a broader design can also avoid rebuilding the environment every time another team or workflow needs CUI. The tradeoff is a larger implementation, documentation, evidence, and assessment burden.

The scope expanders contractors commonly miss

Before comparing architecture or C3PAO pricing, trace these areas explicitly:

Email and collaboration

Can employees send CUI through ordinary email, chat, meeting recordings, or shared links? Do notifications reveal controlled content outside the enclave? Are mobile applications allowed to cache files?

Endpoints and peripherals

Can users download, copy, print, scan, photograph, or synchronize CUI? Where do temporary files, browser caches, crash logs, and print queues reside?

Identity and administration

Which identity platform authenticates users? Who can reset credentials, change conditional-access rules, administer endpoints, or alter security configurations? Privileged systems may provide security capabilities even when they do not store the underlying CUI.

Logging, monitoring, and support

Security tools may handle Security Protection Data such as logs or configuration information. Remote monitoring, help-desk, ticketing, SIEM, endpoint detection, vulnerability-management, and backup services all require responsibility and scope analysis.

Engineering, manufacturing, and test systems

CAD workstations, CNC equipment, shop-floor systems, quality records, removable media, test equipment, and government-furnished equipment can defeat a cloud-only boundary if the controlled work depends on them.

Backup, recovery, and archives

CUI remains CUI in backups and exports. Recovery procedures must preserve the boundary rather than restore information into an uncontrolled environment.

External service providers

The CMMC rule treats external-provider relationships according to the services and data involved. A cloud service provider that handles CUI must meet the applicable FedRAMP requirements referenced by DFARS 252.204-7012. A non-cloud external service provider that handles CUI becomes part of the organization's assessment scope. Services that handle Security Protection Data are treated as Security Protection Assets.

The organization should document the provider relationship, service description, and customer responsibility matrix in its SSP. Buying a compliant platform does not make the customer responsibilities disappear.

A decision matrix for a small defense contractor

Decision factorEnclave tends to fitBroader environment tends to fit
Number of CUI usersLimited and stableBroad or rapidly expanding
CUI workflowsFew and repeatableDistributed across departments
Engineering or manufacturing integrationMinimal or cleanly controlledDeep integration with shop-floor or engineering systems
User behaviorBoundary can be enforcedWork requires frequent transfers and exceptions
Shared servicesCan be separated or clearly treatedHeavily shared identity, security, backup, and administration
Growth planCUI work remains focusedCUI-dependent work is becoming core business
Operational capacityTeam can run two environments wellDuplicate environments would overwhelm staff
Total costSeparation lowers lifecycle costDuplication and workarounds erase the savings

Treat this as a screening tool, not a scope determination. A defensible decision requires a data-flow review, asset categorization, provider analysis, and validation against the actual contract and operating environment.

A seven-step CUI scoping process

Step one: Confirm the business and contract driver

Record the solicitation, contract, subcontract, and flow-down provisions that create the requirement. Determine the information involved and the required CMMC status or assessment type when specified. DFARS 252.204-7021 ties the required status to information systems used in contract performance that process, store, or transmit FCI or CUI when the clause applies.

Do not let an architecture vendor decide what information is CUI. Use the contract, security classification guidance, markings, the CUI Registry, and written clarification from the responsible customer or prime.

Step two: Trace the real CUI lifecycle

Interview the people who perform the work. Follow representative information from receipt or creation through use, sharing, storage, backup, physical handling, subcontractor transfer, retention, and destruction.

Step three: Compare two workable architectures

Model an enclave and a broader-environment option using the same assumptions. Include migrations, integrations, identity, endpoints, security tooling, providers, implementation labor, evidence, user support, recurring licenses, and assessment preparation.

Step four: Categorize every relevant asset

Classify assets using the current Level 2 categories. Record why each asset belongs in that category and what evidence supports the decision. Pay particular attention to security tools, administrator systems, provider services, and equipment that can receive CUI even if policy says it should not.

Step five: Assign provider and customer responsibilities

Obtain service descriptions, authorization information where applicable, and responsibility matrices. Map every shared responsibility to an owner and evidence source. A contract with an MSP or cloud provider is not a substitute for this analysis.

Step six: Build the documentation while designing

Update the asset inventory, network and data-flow diagrams, SSP, procedures, and evidence index as decisions are made. Documentation created after implementation often exposes contradictions that would have been cheaper to resolve during design.

Step seven: Validate readiness and the assessment path

Test whether ordinary users and administrators can follow the designed workflow. Then discuss the proposed boundary with qualified C3PAOs before the official assessment when a Level 2 certification assessment is required or strategically chosen.

Comparing two or three C3PAOs early can help the contractor understand availability, pricing assumptions, retest terms, travel, cancellation provisions, and the evidence each will expect. Ask each C3PAO to price the same documented boundary so the proposals are comparable. Finalize the official assessment after the scope is stable enough to support a meaningful quote.

HostBreach is not a C3PAO and does not conduct certification assessments. We help clients define, implement, document, and validate the readiness boundary, then coordinate an independent assessment path.

What should you ask before buying an enclave?

Use these questions with an advisor, managed provider, platform vendor, and internal team:

  1. Which exact CUI workflows will the enclave support?
  2. Which people, locations, endpoints, administrators, and providers remain in scope?
  3. How are downloads, clipboard use, printing, screenshots, scanning, removable media, and mobile access controlled?
  4. Which systems provide identity, logging, monitoring, backup, incident response, and recovery?
  5. What customer responsibilities remain after implementation?
  6. How will engineering, manufacturing, quality, and subcontractor workflows operate?
  7. Which existing systems must be migrated, decommissioned, or cleaned of CUI?
  8. What evidence will the platform and service providers produce?
  9. What recurring operating work will internal staff or the MSP perform?
  10. What assumptions could cause the quoted implementation or assessment price to change?

A credible proposal should answer these questions in business language and show the proposed boundary. "CMMC-ready platform" is not enough.

Does a smaller enclave always reduce CMMC cost?

No. A smaller boundary can reduce the number of systems, users, providers, and artifacts involved, but lifecycle cost depends on more than asset count.

Budget for:

  • architecture and migration;
  • licenses and managed services;
  • controlled endpoints or VDI;
  • integrations and data transfer;
  • identity and security tooling;
  • user training and support;
  • documentation and evidence maintenance;
  • remediation;
  • readiness validation; and
  • the required assessment path.

An enclave can save money when it contains a stable workflow. It can increase cost when the company pays for duplicate technology while employees repeatedly need exceptions. Compare the three-year operating model, not only the initial project quote.

Add the attacker's view without confusing it with scope

CMMC scope is determined by information flow, asset function, contract requirements, and the scoping rule—not by an external scan.

Outside-in intelligence can still improve the decision. It can help identify internet-facing systems, exposed services, credential-exposure records, email-security signals, and technology associated with vulnerability context that may warrant internal validation. It can also test whether the public attack surface matches the architecture leadership believes it operates.

The HostBreach CMMC Cyber Snapshot and proprietary Cyber Intel Engine provide that outside-in layer within end-to-end readiness. They do not prove exploitability, compromise, CUI exposure, assessment scope, or compliance.

The HostBreach approach to CUI scoping

HostBreach helps small and midsized defense contractors turn contract requirements and CUI workflows into a defensible operating boundary. Our work can include CUI discovery, architecture decision support, Level 2 asset categorization, provider-responsibility mapping, SSP and diagram development, readiness assessment, remediation planning, evidence organization, and C3PAO preparation.

The objective is not the smallest diagram. It is the smallest boundary the business can operate truthfully and sustainably while protecting the information and supporting the contract.

If your team is deciding between an enclave and a broader environment, start with HostBreach CMMC Advisory. We can help compare the options before you commit to a platform, migration, or assessment date.

Primary sources