CMMC Enclave Design and Build for CUI Scope Separation
A CMMC enclave is the difference between certifying one controlled environment and certifying your entire company. Petronella Technology Group, Inc. designs, builds, and documents scoped environments so that Controlled Unclassified Information lives in one defensible boundary, and the rest of your network stays out of the assessment.
Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization. We prepare organizations for assessment. We are not a C3PAO and we do not perform certification assessments.
What a CMMC Enclave Is, and What 32 CFR 170.19 Actually Allows
The word enclave does not appear as a defined term in the CMMC Program rule. What the rule does define, at 32 CFR 170.19, is a set of asset categories that determine what an assessor looks at. Everything a practical enclave strategy claims has to trace back to those categories, because they are the only lever that legitimately changes the size of an assessment.
For Level 2, the rule categorizes assets as CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. CUI Assets are the assets that process, store, or transmit CUI. Security Protection Assets are the assets that provide security functions or capabilities to the assessment scope. Contractor Risk Managed Assets are assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place. Specialized Assets are assets that can process, store, or transmit CUI but are unable to be fully secured, a category that expressly includes Internet of Things devices, Industrial Internet of Things devices, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and Test Equipment.
The category that makes enclaves worth building is the last one. Out-of-Scope Assets are defined as assets that cannot process, store, or transmit CUI and that do not provide security protections for CUI Assets, and the definition expressly includes assets that are physically or logically separated from CUI assets. Out-of-Scope Assets receive no assessment.
That single sentence is the entire commercial case for an enclave. If a workstation, a file share, or a business system genuinely cannot touch CUI and does not protect the systems that do, it does not get assessed. The engineering problem is proving cannot, not asserting it. A general-purpose network where someone could plausibly email a technical data package to a shared inbox is not separated in any sense an assessor will accept, no matter what the policy says.
Building an enclave therefore means three things at once: constraining where CUI can physically go, instrumenting the boundary so that constraint is observable, and producing documentation that lets an assessor confirm the constraint without taking your word for it. Skip any one of the three and the scope reduction is theoretical.
Ready to see where your CUI actually lives? Schedule a scoping consultation with Petronella Technology Group, Inc.
Why a CMMC Enclave Beats Enterprise-Wide Compliance for Most Suppliers
Defense suppliers rarely handle Controlled Unclassified Information evenly across the business. In a typical machine shop, engineering firm, or specialty manufacturer, CUI arrives through a small number of channels: a customer portal, a contract-specific email thread, a set of drawings, a quality document package. It is handled by a small number of people. It lives in a small number of applications. Everything else in the company, from accounting to the shop floor scheduling system to the marketing laptop, has nothing to do with it.
Enterprise-wide compliance ignores that distribution and applies the full 110 security requirements to every system. The cost of that choice compounds in four places at once.
Licensing and tooling
Endpoint detection, logging, multifactor authentication, encryption management, vulnerability scanning, and configuration baselines all get priced per seat or per device. Applying them to every device in the company rather than to the subset that touches CUI is the single largest recurring cost difference between the two approaches.
Evidence volume
Every in-scope system generates artifacts an assessor may sample: configuration exports, access reviews, log retention proof, patch records. Evidence is not a one-time cost. It has to be produced continuously and be current at assessment time, and the volume scales with the number of systems inside the boundary.
Operational friction
Controls that are appropriate for a CUI environment are often intolerable when applied to the whole company. Session lock timers, removable media restrictions, and application allowlisting produce a steady stream of help desk exceptions when they are imposed on people who never see CUI, and exceptions erode the control.
Change velocity
Once a system is in scope, changing it involves configuration management discipline. Companies that put their entire environment in scope discover that ordinary IT work slows down permanently, because every change now carries a compliance question.
A scoped design inverts that. The controlled environment is small, the controls inside it can be strict without political cost, and the rest of the business keeps operating normally. This is also why the search intent behind CUI scoped data separation for contractors is fundamentally an architecture question rather than a product question. There is no product that separates your data. There is a design decision, followed by implementation, followed by proof.
For a longer, non-commercial walkthrough of the concepts and the trade-offs involved, our team maintains a detailed written guide to CUI enclave architecture. This page covers the engagement itself.
The Five Asset Categories, and What Each One Costs You
Every scoping decision resolves into placing each asset in one of five buckets. The table below summarizes the treatment each category receives under 32 CFR 170.19 at Level 2. Getting an asset into a lower-burden category is legitimate only when the facts support it, and an assessor will test the facts.
| Category | Definition under 32 CFR 170.19 | Assessment treatment |
|---|---|---|
| CUI Assets | Assets that process, store, or transmit CUI | Documented in the asset inventory, the System Security Plan, and the network diagram of the assessment scope. Assessed against Level 2 security requirements. |
| Security Protection Assets | Assets that provide security functions or capabilities to the assessment scope | Documented the same way. Assessed against the Level 2 security requirements relevant to the capabilities they provide. |
| Contractor Risk Managed Assets | Assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place | Not required to be physically or logically separated from CUI Assets. Reviewed against the System Security Plan. If sufficiently documented, not assessed against other requirements, subject to the exceptions in the rule. |
| Specialized Assets | Assets that can process, store, or transmit CUI but are unable to be fully secured, including Internet of Things and Industrial Internet of Things devices, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and Test Equipment | Documented and managed using risk-based policies, procedures, and practices. Not assessed against other requirements. |
| Out-of-Scope Assets | Assets that cannot process, store, or transmit CUI and do not provide security protections for CUI Assets, including assets physically or logically separated from CUI assets | No assessment. |
Two practical observations fall out of this table. First, the Contractor Risk Managed category is frequently over-used. It is attractive because it avoids separation work, but it depends on documentation being sufficient, and sufficiency is judged by the assessor rather than by the contractor. Second, Specialized Assets are not a loophole for ordinary computers. The category is bounded by the specific device classes the rule names, and calling a general-purpose laptop test equipment is the kind of claim that turns a smooth assessment into a difficult one.
If you want to understand what qualifies as CUI in the first place before you decide what goes inside the boundary, start with our explainer on Controlled Unclassified Information and how it is identified. Correct identification is upstream of correct scoping, and most scoping mistakes are actually identification mistakes.
How Petronella Technology Group, Inc. Designs and Builds a CMMC Enclave
Our engagement runs in four phases. The order matters. Every phase produces something the next phase depends on, and we do not sell hardware or licensing before the design that justifies them exists.
CUI identification and data flow mapping
We trace Controlled Unclassified Information from the moment it enters the business to the moment it is disposed of. That means reading the actual contract clauses and flow-down language, interviewing the people who receive customer files, and inspecting the systems where those files land. The deliverable is a data flow map and a candidate boundary.
This phase routinely surprises clients. CUI is usually in more places than leadership believes, and the most common discovery is a general-purpose email mailbox or a shared drive that has been quietly accumulating covered technical data for years. Finding it before the assessor does is the point.
Boundary architecture and asset categorization
With the map in hand, we categorize every asset against 32 CFR 170.19 and design the boundary that makes the categorization defensible. Depending on the environment this can be a segmented network with dedicated endpoints, a virtual desktop layer that keeps CUI off local devices, a compliant collaboration tenant, or a combination.
We also design the negative space: the explicit technical controls that prevent CUI from reaching the systems we intend to declare out of scope. Separation that depends solely on user behavior is not separation.
Implementation and control mapping
Implementation covers identity and access management, multifactor authentication, encryption in transit and at rest, endpoint protection, centralized logging, configuration baselines, media handling, and physical protections for the in-scope footprint. Each configuration is mapped to the specific NIST SP 800-171 Rev 2 requirement it satisfies as it is deployed, not reconstructed afterward.
Migration is part of this phase. Existing CUI has to move into the boundary and be removed from where it used to live, and the removal has to be evidenced.
Documentation, evidence, and assessment readiness
The output is the package an assessor works from: a System Security Plan describing the enclave, an asset inventory, a network diagram of the assessment scope, policies and procedures, and the evidence artifacts that show the controls operating rather than merely existing. Where gaps remain, they are captured in a Plan of Action and Milestones with owners and dates.
Our CMMC Registered Practitioners review the package against the requirement set before you engage a C3PAO, so the first serious critique of your documentation comes from your own side.
Organizations that want the documentation phase accelerated can pair the build with ComplianceArmor(R), our compliance documentation platform, which generates the policy and System Security Plan package from the environment as designed. Organizations that need ongoing ownership of the program rather than a one-time build often add a virtual CISO engagement to carry the affirmation cycle year over year.
Want the four phases scoped against your environment? Talk to Petronella Technology Group, Inc.
A CUI Enclave for Small Businesses: What Changes at Small Scale
Small defense suppliers face a specific version of this problem. The requirement set does not shrink with headcount. A twelve-person shop that handles Controlled Unclassified Information is measured against the same 110 security requirements as a thousand-person prime subcontractor. What does change is the resource available to meet them, and that is exactly why scope discipline matters more at small scale, not less.
Three patterns show up repeatedly in small business enclave work.
- The user population is tiny. Often three to ten people genuinely need CUI access. Designing the boundary around those named users, rather than around departments or physical locations, produces the smallest defensible footprint and the lowest recurring licensing cost.
- There is no dedicated IT staff. Controls that require daily human attention will not survive. The design has to favor configurations that hold on their own and monitoring that escalates rather than requiring someone to watch a dashboard. This is where a managed arrangement is usually more realistic than a hand-off.
- The general environment is genuinely messy. Personal devices, long-lived shared mailboxes, and consumer file sharing are common. The honest answer is often that a clean, separate environment is cheaper to build than the existing one is to remediate.
Small suppliers also face a sequencing question. Some contracts carry only Federal Contract Information and fall under CMMC Level 1, which covers the 15 basic safeguarding requirements from FAR 52.204-21 and is handled as a self-assessment. Others carry CUI and pull you into Level 2. A company can hold both obligations at once, and the enclave is what keeps the Level 2 obligation from expanding into the parts of the business that only ever see Federal Contract Information.
If you are still determining which level applies to your contracts, our CMMC readiness overview walks through the determination, and our page on the Level 2 self-assessment path covers what a self-assessment involves before a C3PAO is in the picture. Suppliers whose contracts reach the highest tier can review the CMMC Level 3 requirements, which layer 24 enhanced requirements from NIST SP 800-172 on top of the Level 2 baseline for 134 total.
What a CMMC Enclave Does Not Solve
Honest scoping means being clear about the limits. An enclave is a powerful tool and it is routinely oversold. Four things it does not do.
It does not reduce the requirement set
Inside the boundary, all 110 NIST SP 800-171 Rev 2 security requirements still apply. The enclave reduces how many systems must satisfy them. Anyone describing an enclave as a way to meet fewer requirements is describing something else.
It does not remove Security Protection Assets from scope
The tools that defend the enclave are themselves in scope under 32 CFR 170.19. Identity providers, logging platforms, and management consoles are assessed against the requirements relevant to the capabilities they provide, even when they sit outside the network segment.
It does not survive undisciplined use
A boundary that people route around is worse than no boundary, because it produces documentation that does not match reality. The enclave has to be the path of least resistance for the people who handle CUI, which is a usability requirement as much as a security one.
It does not eliminate the incident reporting obligation
DFARS 252.204-7012 requires rapid reporting of cyber incidents to the Department of Defense within 72 hours of discovery. That obligation applies to covered contractor information systems regardless of how they are architected, and it requires a tested detection and reporting process, not just a clause acknowledgment.
It does not resolve cloud eligibility on its own
Where a cloud service is used to store, process, or transmit covered defense information, DFARS 252.204-7012 requires that the provider meet security requirements equivalent to the FedRAMP Moderate baseline. Placing a service inside your enclave design does not change what the underlying service is.
It does not replace marking discipline
DoDI 5200.48 governs how Controlled Unclassified Information is identified, marked, and handled within the Department of Defense environment. If inbound material is unmarked or mismarked, no amount of network engineering will tell your people which files belong inside the boundary.
These limits are the reason we lead with identification and mapping rather than with an architecture diagram. The design is only as good as the understanding of what has to be protected. Broader defensive coverage for the systems outside the boundary is handled separately through managed security services, because out of assessment scope is not the same as unprotected.
Evidence, Scoring, and the Affirmation That Follows
An enclave is built to be assessed, which means the design has to anticipate how the assessment works. Three mechanics drive most of the pressure.
Scoring and the conditional threshold
CMMC permits a limited Plan of Action and Milestones. Under 32 CFR 170.21, a Conditional CMMC Status requires the assessment score divided by the total number of Level 2 security requirements to be greater than or equal to 0.8. Certain requirements may never be placed on a Plan of Action and Milestones at all, including the Level 2 requirement governing external connections for CUI data. The closing of a Plan of Action and Milestones must be confirmed by a closeout assessment within 180 days of the Conditional CMMC Status Date, and missing that window causes the conditional status to expire.
The practical implication for enclave design is that the requirements which cannot be deferred have to be engineered correctly the first time. They are not candidates for a later phase.
Supplier Performance Risk System posture
Self-assessment scores under the NIST SP 800-171 DoD Assessment Methodology are reported in the Supplier Performance Risk System, and buyers see them. Reducing scope through an enclave changes the environment being scored, which is why the score should be recalculated against the enclave rather than carried forward from an older enterprise-wide assessment. Our page on understanding and improving your SPRS score covers the mechanics of the scoring methodology in detail.
Annual affirmation by a named executive
Under 32 CFR 170.22, the Affirming Official is a senior level representative from within the organization, and affirmations are entered electronically in the Supplier Performance Risk System after every assessment, including Plan of Action and Milestones closeout, and annually thereafter. A named executive is attesting to continuing compliance. That is a durable obligation, and it is the reason we build evidence collection into the operating rhythm of the enclave rather than treating it as a pre-assessment sprint.
For the underlying control framework behind all of this, see our reference on NIST SP 800-171 and the 110 security requirements.
Get your scope, score, and evidence plan on one page. Request a CMMC enclave scoping call
Who a CMMC Enclave Engagement Is For
This engagement is a fit when several of the following are true.
- Your contracts include DFARS 252.204-7012, and CUI or covered defense information reaches your systems.
- Controlled Unclassified Information is handled by a subset of your staff rather than by everyone.
- A prime contractor or contracting officer has asked about your CMMC status, your System Security Plan, or your Supplier Performance Risk System score.
- You have looked at the cost of bringing your whole network to Level 2 and concluded it is not proportionate to the revenue at stake.
- You have legacy systems, engineering equipment, or shop floor technology that cannot realistically be brought into a compliant configuration.
- You need a defensible answer quickly, and you would rather build a small correct environment than remediate a large uncertain one.
It is not a fit when CUI is genuinely pervasive across the business, when the contract terms prohibit the architecture you would need, or when leadership is not prepared to enforce the boundary. In those cases we will say so during scoping rather than after implementation. Our team explains that reasoning in plain terms; you can read more about how we work on the Petronella Technology Group, Inc. company page.
CMMC Enclave: Frequently Asked Questions
What is a CMMC enclave?
A CMMC enclave is a deliberately bounded environment where all Controlled Unclassified Information is processed, stored, and transmitted, separated from the rest of the company network. The regulatory basis is 32 CFR 170.19, which defines CUI Assets as assets that process, store, or transmit CUI, and defines Out-of-Scope Assets as assets that cannot process, store, or transmit CUI and do not provide security protections for CUI Assets, including assets that are physically or logically separated from CUI assets. An enclave is the engineering work that makes that separation real and provable.
Does an enclave reduce the CMMC Level 2 assessment scope?
It can, when the separation is genuine and documented. Under 32 CFR 170.19, Out-of-Scope Assets require no assessment, and that category expressly includes assets that are physically or logically separated from CUI assets. Systems inside the enclave and the Security Protection Assets that defend it remain in scope and are assessed against the 110 NIST SP 800-171 Rev 2 security requirements. Scope reduction comes from shrinking the number of systems inside the boundary, not from exempting them.
Is a CUI enclave a good fit for a small business?
Often yes. Many small defense suppliers touch CUI on a handful of contracts and with a handful of people. Bringing an entire general-purpose network up to the full 110 requirements is expensive and slow. A CUI enclave for small businesses concentrates the compliant environment around the specific people, applications, and data flows that need it, which lowers licensing count, evidence volume, and ongoing administrative load. Fit depends on whether CUI can be kept out of general email, general file shares, and engineering workstations, which is what the scoping workshop determines.
How many security requirements apply inside the enclave?
CMMC Level 2 is built on the 110 security requirements of NIST SP 800-171 Rev 2. CMMC Level 1 covers the 15 basic safeguarding requirements from FAR 52.204-21 and applies to Federal Contract Information rather than CUI. CMMC Level 3 adds 24 selected enhanced requirements from NIST SP 800-172 on top of the Level 2 baseline, for 134 total, and is assessed by the Government rather than a C3PAO under 32 CFR 170.18.
Can I put CUI in Microsoft 365 Commercial instead of building an enclave?
That decision needs to be made against DFARS 252.204-7012, which requires that a cloud service provider used to store, process, or transmit covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline, and which requires cyber incidents to be reported to the Department of Defense within 72 hours. The practical answer depends on the specific service, the tenant configuration, and the flow-down terms in your contract. Petronella Technology Group, Inc. evaluates the tenant you already own before recommending a migration, because moving tenants is expensive and is not always necessary.
What does the enclave boundary actually consist of?
In most builds it is a combination of identity, network, and endpoint controls: a defined set of user accounts with conditional access, a segmented network path or dedicated virtual desktop layer, encrypted storage and transport for CUI, logging and monitoring that feeds an evidence trail, and a written prohibition on CUI leaving the boundary. The exact composition is driven by where CUI actually enters the business, which is why the design starts with data flow mapping rather than with a product.
Do I still need a System Security Plan if I use an enclave?
Yes. The System Security Plan is central to how the assessment works. Under 32 CFR 170.19, CUI Assets must be documented in the asset inventory, documented in the System Security Plan, and shown in the network diagram of the CMMC Assessment Scope. Contractor Risk Managed Assets are reviewed against the System Security Plan as well. An enclave changes what the plan covers; it does not remove the requirement to have one.
How long does a CMMC enclave build take?
It varies with the number of users, the number of CUI-handling applications, and how much data has to be migrated out of general systems. Scoping and data flow mapping is the phase that determines the rest of the schedule, and it is deliberately done first so the timeline is based on the real environment rather than on an assumption. Petronella Technology Group, Inc. provides a schedule after the scoping workshop rather than before it.
What happens if some requirements are not met at assessment time?
CMMC allows a limited Plan of Action and Milestones. Under 32 CFR 170.21 a Conditional CMMC Status requires an assessment score divided by the total number of Level 2 security requirements greater than or equal to 0.8, certain requirements may never be placed on a Plan of Action and Milestones, and the closing of a Plan of Action and Milestones must be confirmed by a closeout assessment within 180 days of the Conditional CMMC Status Date. A well-designed enclave is one way to keep the remaining gaps inside that envelope.
Who confirms ongoing compliance after the assessment?
Under 32 CFR 170.22, a senior level representative of the organization, the Affirming Official, submits an affirmation of continuing compliance electronically in the Supplier Performance Risk System after every assessment, including Plan of Action and Milestones closeout, and annually thereafter. That is a personal attestation by a named executive, which is why the evidence behind the enclave has to stay current rather than being assembled once.
About the Author
Find out how small your CMMC assessment scope can defensibly be
A scoping consultation with Petronella Technology Group, Inc. maps where Controlled Unclassified Information actually lives in your business, categorizes your assets against 32 CFR 170.19, and gives you a written boundary recommendation you can price and plan against. Final engagement cost depends on user count, application count, and site topology, and is confirmed after scoping.
Petronella Technology Group, Inc. serves defense suppliers nationwide from Raleigh, North Carolina.