For many defense contractors, preparing for CMMC raises a difficult question: How much of our IT environment actually needs to be in scope?
If Controlled Unclassified Information (CUI) is spread across employee devices, email, file shares, business applications, and other systems, bringing the entire environment into the CMMC assessment boundary can create significant cost and complexity.
A CUI enclave offers another approach.
A CUI enclave is a defined environment designed to isolate the systems, applications, users, and data that handle CUI from the rest of an organization’s IT environment. Instead of bringing an entire corporate environment into the CMMC assessment boundary, an organization can use an appropriately designed enclave to concentrate CUI-related activity in a smaller, more manageable environment.
CyberSheath’s Federal Enclave is a purpose-built CUI enclave solution for organizations in the defense industrial base (DIB). Built on Microsoft Azure technology and supported by a managed cybersecurity and compliance framework, Federal Enclave is designed to help contractors protect CUI while minimizing disruption to their existing business environment.
What Is a CUI Enclave?
Controlled Unclassified Information is information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy. For defense contractors, CUI may be encountered across many parts of the business, including engineering, professional services, contracts, legal, accounting, sales, email, desktops, mobile devices, and shared storage.
A CUI enclave creates a defined boundary around the environment used to handle that information.
Depending on the organization’s needs, an enclave can include:
- Users who need to access CUI
- Workstations or virtual desktops used to work with CUI
- Applications that process or store CUI
- Email and collaboration tools required for CUI-related work
- Storage for CUI documents and other files
- Security, identity, monitoring, and logging capabilities
- Connections to approved applications or external systems that must interact with CUI
The goal is to limit CUI data sprawl and establish a clearly defined environment for protecting sensitive information and to simplify self-assessments or third-party audits.
An enclave does not mean that an organization can simply declare a group of systems to be “out of scope.” The boundary, and what is inside it, has to reflect how CUI actually moves through the organization, including the systems, users, applications, and connections that have access to or interact with the data.
What Is a Federal Enclave?
CyberSheath’s Federal Enclave is a secure, encrypted environment designed to store and process Federal Contract Information (FCI) and CUI. It is built on Microsoft Azure technology and is designed to provide the technical environment, security capabilities, compliance processes, and ongoing support needed by organizations working toward CMMC requirements.
The environment is designed to work alongside an organization’s existing infrastructure rather than requiring the entire company to move into a new IT environment.
That distinction is important for contractors with established commercial operations, legacy applications, or employees who only need access to CUI for specific projects.
How Does a CUI Enclave Reduce CMMC Assessment Scope?
One of the biggest reasons organizations consider an enclave is to reduce the size and complexity of their CMMC assessment boundary.
Without an enclave, CUI may be distributed throughout a company’s broader IT environment. That can bring a large number of systems, applications, users, endpoints, and supporting technologies into consideration during scoping.
An appropriately designed enclave can concentrate CUI-related activity into a defined environment.
For example, instead of moving an organization’s entire corporate IT environment into a CMMC-focused architecture, the company may be able to isolate:
- Employees who need to work with CUI
- Applications that process or store CUI
- Devices or virtual desktops used to access CUI
- CUI-specific email and collaboration workflows
- Storage containing CUI
- Security and administrative functions supporting the enclave
The result can be a significantly smaller and more manageable assessment boundary. Isolating CUI into its own security domain is a potentially cost-effective and efficient approach for organizations seeking to protect CUI.
An important qualification
An enclave does not automatically remove CMMC requirements or make connected systems irrelevant.
The resulting scope depends on the enclave’s architecture and how it connects to the rest of the organization’s environment. Shared services, applications, administrative functions, and data flows can create dependencies that still need to be evaluated.
That’s why effective enclave design starts with scoping the current environment and understanding where CUI is located and how it moves, rather than starting with the technology.
CUI Enclave vs. Full IT Environment
Organizations generally have a choice between bringing a broad corporate environment into their CMMC boundary or creating a more focused CUI environment.
| Approach | CUI Enclave | Non-CUI Business Operations | Potential Assessment Boundary |
| Full environment | CUI is handled throughout the corporate environment | Operates alongside CUI | Broader |
| CUI enclave | CUI is isolated into a defined environment | Remains outside the enclave where appropriate | More limited |
| Hybrid environment | CUI enclave plus connected corporate systems | Combination of both environments | Depends on architecture and connections |
An enclave can be particularly useful for organizations that do not want to redesign their entire commercial IT environment around the security requirements associated with CMMC and CUI handling.
However, there are tradeoffs. A separate environment can require additional licensing, applications, security tools, administrative processes, and user training. In some cases, departments that support both commercial and government business may need to work across separate environments.
The right approach depends on the organization’s CUI footprint, existing infrastructure, contracts, users, applications, and business processes.
Who Needs Access to a CUI Enclave?
The answer depends on who actually handles CUI and what they need to do with it.
Employees who never access, process, store, or transmit CUI generally do not need to work inside the enclave simply because they work for the same company. Users who do interact with CUI may need enclave access. That can include people in:
- Engineering
- Program and project management
- Professional services
- Contracts
- Legal
- Accounting
- IT and security
- Executive leadership
- Other functions that handle CUI as part of their responsibilities
The important question is not simply an employee’s job title. It’s what that person needs to do with CUI.
CyberSheath’s Federal Enclave implementation process is designed to understand users’ day-to-day tasks involving CUI and shape the environment around those requirements. Limiting access to the people who actually need it can also help organizations manage licensing and operational costs.
What Are the Benefits of a CUI Enclave?
Reduced CMMC assessment scope
A properly designed enclave can isolate CUI from an organization’s broader commercial environment, potentially reducing the number of systems, applications, users, and other components that need to be included within the assessment boundary.
A smaller boundary can also make remediation and ongoing compliance management more manageable.
Lower cost and complexity
Full-environment compliance can require an organization to upgrade or replace systems that have little to do with its government contracts.
An enclave allows contractors to focus resources on the environment that actually handles CUI. For organizations with a relatively small CUI user population, limited CUI datasets, or a small number of government contracts, this can be a practical alternative to redesigning the entire corporate environment.
The cost equation is not simply about the number of users, however. Organizations should also consider licensing, duplicate applications, administration, training, migration, integration, and ongoing management.
Better separation of CUI
Keeping CUI in a defined environment can help limit data sprawl and reduce the number of places where sensitive information is stored.
An effective enclave also establishes clear rules around what belongs inside the environment and how information can move in and out. CyberSheath’s Federal Enclave, for example, is designed specifically for CUI handling and includes controls intended to help prevent unnecessary data movement and scope creep.
Centralized security and monitoring
A CUI enclave can bring security capabilities into a dedicated environment rather than requiring an organization to independently assemble and maintain every component.
CyberSheath’s Federal Enclave includes capabilities such as multifactor authentication, conditional access, endpoint detection and response, log aggregation, private certificates and domain services, managed SIEM and SOC support, incident alerting and reporting, and data-leak safeguards.
Minimal disruption to commercial operations
A major advantage of an enclave is that the entire company does not necessarily have to operate inside the CUI environment.
Commercial operations can continue in the existing environment while users who need to handle CUI access the enclave for those activities.
CyberSheath designed Federal Enclave to work alongside legacy systems, allowing organizations to maintain existing infrastructure while providing a separate environment for CUI-related work.
What Happens to Legacy Applications?
Legacy applications are one of the most common challenges organizations face when designing a CUI environment.
Some applications may be straightforward to move into a cloud environment. Others may depend on older infrastructure, proprietary software, specific integrations, or on-premises systems that cannot easily be replaced.
An enclave does not necessarily require an organization to abandon those systems.
Instead, the implementation process should identify which applications interact with CUI and determine how each application should be handled. Depending on the use case, an application may be migrated, accessed through an appropriate connection, replaced, or kept outside the enclave with carefully defined interfaces.
CyberSheath’s Federal Enclave is specifically designed to “meet you where you are,” including support for organizations that need to continue operating legacy systems while establishing a separate environment for CUI.
The key is understanding the application’s relationship to CUI before deciding where it belongs.
How Does a CUI Enclave Implementation Work?
A successful enclave implementation starts with scope, not software.
1. Scope the current environment
First, identify the systems and applications that interact with CUI. This includes looking beyond obvious CUI repositories to understand how information moves through email, endpoints, shared storage, business applications, and other systems.
CyberSheath’s Federal Enclave Playbook recommends beginning by identifying systems and applications that may interact with CUI.
2. Assess the existing environment
Next, evaluate the current protection status of the relevant systems and understand the organization’s existing network and security architecture.
This helps identify what can remain in place, what needs to change, and where an enclave can provide the greatest benefit.
3. Review business requirements
An enclave has to support the way people actually work.
That means understanding which users need access, which applications they use, how they collaborate, what information they need to exchange, and what connections to other environments are required.
CyberSheath uses this information to determine how the Federal Enclave should be shaped around an organization’s day-to-day CUI workflows.
4. Design and configure the environment
Once the requirements are understood, the enclave can be configured around the organization’s users, applications, CUI workflows, security requirements, and necessary connections.
5. Migrate users and CUI workflows
Users, applications, and data are transitioned into the enclave based on the implementation plan.
The objective is to move the CUI-related work that belongs inside the boundary while minimizing disruption to the organization’s broader business operations.
6. Validate and maintain the environment
CMMC compliance is an ongoing responsibility, not a one-time implementation project.
The organization needs processes for maintaining the environment, managing users and access, monitoring activity, maintaining documentation, and responding to changes in its CUI environment and contractual requirements.
How Long Does It Take to Implement a CUI Enclave?
There is no universal implementation timeline. The amount of time required depends on factors such as:
- Number of enclave users
- Number and complexity of applications
- Amount and location of CUI
- Existing infrastructure
- Legacy applications
- Required integrations
- Data migration requirements
- User training
- Security and compliance requirements
For a typical user population, CyberSheath’s Federal Enclave guidance estimated that transitioning users could take a few months depending on scope. The more useful way to think about the timeline, however, is in terms of the complexity of the organization’s CUI environment rather than a fixed number of weeks or months.
A thorough assessment and scoping exercise at the beginning can help establish a realistic implementation timeline.
Is a CUI Enclave Right for Your Organization?
An enclave can be particularly useful for contractors that:
- Have a relatively small CUI user population
- Handle CUI for a limited number of contracts
- Operate a primarily commercial business alongside government work
- Have significant legacy infrastructure
- Need to support transient or distributed workers
- Want to separate CUI from their commercial environment
- Need to process CUI using Microsoft Office or other business applications
- Work with third-party, private, or custom applications that need to handle CUI
- Do not use physical CUI or physical infrastructure as part of their CUI wok
Small and midsize contractors, organizations with low-CUI user populations, contractors with transient workers, and organizations that need to securely process CUI in third-party or custom applications are key use cases.
The DOD contracts your business handles dictate your usage of the Federal Enclave. Here are a few examples.
- A company that sells accounting software would potentially only have a few enclave users because of potential CUI data in the financial records they have access to.
- An IT firm working on projects for government contracts, would require more users access to the enclave, depending on what government contracts they accept and what users work on those projects.
- Commercial companies that do most of their business in the retail space but still realize a portion of their revenue serving the government would only need that part of their infrastructure that touches government contracts in the enclave.
That does not mean an enclave is the right answer for every contractor. The decision should begin with understanding the organization’s CUI, contracts, users, systems, data flows, and existing infrastructure.
Federal Enclave Frequently Asked Questions
What is the difference between a CUI enclave and a federal enclave?
A CUI enclave is a defined environment used to isolate and protect CUI. Federal Enclave is CyberSheath’s name for its purpose-built CUI enclave solution for defense contractors.
How does a Federal Enclave reduce CMMC assessment scope?
An appropriately designed enclave can reduce the size of the CMMC assessment boundary by isolating CUI-related users, systems, applications, and data from the broader commercial environment. The actual boundary depends on the enclave architecture and its connections to other systems.
Who needs to use the Federal Enclave?
Users who need to access, process, store, or transmit CUI may need access to the enclave. The specific user population should be determined during the scoping and assessment process based on each user’s responsibilities and CUI workflows.
How long does Federal Enclave onboarding take?
Implementation timelines vary based on the organization’s users, applications, CUI data, legacy infrastructure, integrations, and other requirements. A typical transition can take a few months, but the appropriate timeline should be established after assessing the environment.
Can legacy applications remain outside the enclave?
Potentially. Each application’s relationship to CUI needs to be evaluated. Some applications may be migrated, integrated with the enclave, replaced, or otherwise accommodated depending on the organization’s requirements.
Can employees work remotely from the enclave?
A cloud-based enclave can support users who need to work with CUI without requiring them to be physically located in a particular office. The specific access architecture and controls depend on the organization’s environment and requirements.
Can the Federal Enclave support third-party or custom applications?
Yes. CyberSheath’s Federal Enclave is designed to support organizations that need to securely process CUI in third-party, private, or custom applications, including environments where CUI permissions need to be segmented.
Is the Federal Enclave FedRAMP authorized?
The Federal Enclave uses Microsoft Azure technology and supporting services. FedRAMP authorization should not be assumed simply because an environment uses a FedRAMP-authorized cloud platform. Organizations should evaluate the authorization status and scope of the specific services used in their environment.
Build a CUI Environment Around Your Business
A CUI enclave can give defense contractors a practical way to isolate sensitive government information without redesigning their entire IT environment around CMMC.
The first step is understanding your CUI boundary: where the information resides, who handles it, which applications interact with it, and how it moves through the organization.
CyberSheath can help you scope your CUI environment, determine whether an enclave approach makes sense, and design a Federal Enclave around your organization’s requirements.
Additional Resources
- Explore CyberSheath Federal Enclave.
- Learn how to build a compliant CUI enclave for CMMC.
- Read the CUI Enclave Guide.
