The CMMC Enclave: When a Smaller Boundary Beats Certifying the Whole Company
A CMMC enclave is a contained environment where Controlled Unclassified Information is stored, processed, and transmitted, separated from the rest of the company by identity, network, and data flow controls so that only the enclave and the systems protecting it fall inside the assessment boundary. For most defense contractors under about 500 employees, it is the single largest cost lever in the program: a well built enclave removes 60 to 90 percent of assets from scope, and every removed asset is one fewer endpoint to harden against all 110 Level 2 requirements, one fewer configuration to defend, and one fewer sample an assessor can pull. The catch is that a boundary only counts if it holds. Most enclave failures are leaks rather than architecture, and the leak paths are predictable.
When scoping down beats enterprise-wide compliance
The decision is arithmetic plus operations. Count the people who actually touch CUI, the systems they need to do that work, and what it costs to bring only those systems to full compliance versus everything. Take a 150-person manufacturer with 400 endpoints where 20 engineers handle CUI. Certifying the enterprise means remediating all 400 endpoints, roughly $150,000 to $200,000 in remediation and $90,000 to $130,000 in assessment fees. Building an enclave for the 20 costs $25,000 to $75,000 up front, drops in-scope assets to a few dozen, and cuts remediation to $50,000 to $70,000 with an assessment near $45,000 to $60,000. The enclave path commonly saves more than $100,000 on the first cycle and saves again at every triennial recertification. The full arithmetic sits in what CMMC certification costs.
The rule of thumb: when CUI touches less than about a third of the company, the enclave usually wins. Enterprise-wide compliance makes sense in the other cases. A 30-person shop where everyone works defense contracts has no meaningful boundary to draw, because the enclave would be the company. And a business whose ERP, email, and shop floor all legitimately process CUI cannot shrink its way out; it can only clean up data flows and accept the larger scope.
Enclave patterns that work
- Microsoft 365 GCC High. The most common pattern for document-centric CUI work: email, files, and collaboration move into a government cloud tenant assessed at the FedRAMP High baseline, built to support the DFARS 252.204-7012 incident reporting paragraphs and staffed by screened US persons, which matters when the CUI is export controlled. Licensing runs roughly $10 to $35 per user per month over commercial equivalents, plus migration labor commonly in the $15,000 to $60,000 range.
- AWS GovCloud (US). The infrastructure-level answer for engineering, simulation, and application workloads. You get regions operated by US persons with FedRAMP High authorization, and you build the environment on top, which means more control and more of the 110 requirements implemented by you rather than inherited.
- Purpose-built VDI enclaves. A virtual desktop environment where CUI never leaves the hosted boundary and the user's physical device becomes a viewer. Strong for distributed engineering teams and companies that cannot rip out their corporate IT, weaker where large CAD files and shop floor integration make thin sessions painful.
- Commercial managed CUI enclave products. Turnkey hosted enclaves sold specifically for CMMC, with a shared responsibility matrix and a large slice of the technical controls inherited from the provider. Fastest to stand up, priced as a subscription, and dependent on the provider's own posture: if the offering is a cloud service handling CUI, it needs FedRAMP Moderate authorization or documented equivalency, and you carry the burden of confirming that before signing.
Choosing between the patterns is mostly a question of where the CUI work actually happens. Document-heavy programs, proposals and contracts and drawings exchanged with primes, fit the GCC High pattern. Compute-heavy engineering fits GovCloud. A company with capable corporate IT and distributed users leans toward VDI, and a company with no internal IT capacity is the natural customer for a managed enclave, because the inherited controls are the product. Export control is the constraint that overrides preference: ITAR data needs US persons handling and pushes toward the government cloud options regardless of what would otherwise be convenient. Mixed workloads mix patterns, and that is normal. A GCC High tenant for documents beside a GovCloud environment for compute is a common and defensible shape.
The cost tradeoff
The enclave saves money on remediation, assessment fees, and recertification, and it charges for those savings in operational friction. Some employees work in two environments and learn which one a given file belongs in. Data movement becomes deliberate: getting a drawing into the enclave is a process, and getting anything out is a decision with a record. Some tooling gets duplicated, because the enterprise SIEM or backup platform either comes into scope or stays out and gets a twin. And someone has to own the boundary as a standing job, reviewing what crosses it, or the scope quietly regrows until the enclave is a fiction with a diagram. Budget the friction alongside the build: the build is $25,000 to $75,000 for most small and mid-sized contractors, and the ongoing tax is measured in process, licensing premiums, and a boundary owner's hours.
The scoping traps
Every failed enclave we see in readiness work failed on one of a short list of paths. Email is the first: the enclave is pristine and CUI keeps arriving in corporate mailboxes, because primes send attachments to the addresses they have always used, and forwarding into the enclave leaves a copy behind in the commercial tenant. Print is the second: an enclave desktop printing through corporate print servers just moved CUI across the boundary, spool files included. Backups are the third: pointing enterprise backup agents at enclave systems pulls the entire backup infrastructure, and everywhere it replicates, into scope. Sync clients, personal drives, and clipboard or drive mapping in VDI sessions round out the list. None of these are exotic. All of them turn up in data flow interviews, which is exactly where an assessor will find them.
External service providers are the structural trap. If an MSP administers enclave systems, its people, tools, and access paths come into the assessment with you, and the final rule's answer is a documented responsibility matrix rather than a separate certification for the provider: MSPs no longer need their own CMMC certification, but their services get assessed as part of yours. Cloud services are stricter: any cloud offering that stores, processes, or transmits CUI needs FedRAMP Moderate authorization or documented equivalency. And the systems that protect the enclave from outside it, the identity provider, the SIEM, the patching infrastructure, are security protection assets that stay in scope no matter where they sit. An enclave does not remove them; it shortens the list of what they defend.
How assessors treat enclave boundaries
Scope validation is the first act of a C3PAO assessment, before any control is examined, and an enclave gets validated skeptically because the assessor knows every trap in the section above. Expect to produce a data flow diagram showing how CUI enters, moves within, and leaves the enclave, an asset inventory sorted into the CMMC categories, and evidence that the separation is technical rather than aspirational: tenant restrictions, conditional access policies, firewall rules, DLP or transfer controls at the edges. Assessors interview the people who work across the boundary and ask the simple questions, such as what happens when a prime emails you a drawing, and the answers either match the diagram or they do not. Contractor risk managed assets, the corporate machines that could touch CUI but are kept from it by policy and configuration, get lighter treatment only when the keeping-from is documented and real. A boundary that fails validation stalls the assessment before it starts, which is the expensive way to discover a leak. The full assessment sequence is covered in what happens in a CMMC audit.
Deciding, then building
The enclave decision belongs at the very start of a CMMC program, before any tooling is bought, because every downstream number moves with it. The sequence that works: map where CUI actually lives today, pick the pattern that fits how your CUI-handling people work, design the boundary and its crossing controls, then migrate the data and shut the old paths behind it, in that order. Our CMMC consulting practice runs that sequence, from scoping and enclave design through remediation and mock assessment. The boundary statement, as always: BD Emerson is not a C3PAO, and a separate certified assessor performs the certification assessment. That independence is worth having on this topic in particular, because a firm with no stake in the assessment outcome has no reason to bless a boundary that will not survive validation.

