Protecting Controlled Unclassified Information (CUI) is one of the most important obligations defense contractors face today. But the challenge can go beyond simply protecting CUI. For contractors who also work in the commercial space, it becomes about protecting CUI without turning your entire business into a CMMC-controlled environment.
Between DFARS 252.204-7012, NIST SP 800-171, and the CMMC 2.0 assessment model, organizations are responsible for consistently safeguarding CUI wherever it resides. Larger CUI environments are more complex, and require significantly more time, money, and attention to manage.
For many companies, one practical way to meet these requirements without overhauling the entire business is to build a CUI enclave. A well-designed enclave creates a clearly defined, isolated environment where CUI is stored, processed, and transmitted, helping reduce the number of systems and personnel that fall inside the CMMC assessment boundary.
Understanding Government Information Types: FCI and CUI, and CDI
Before designing an enclave or defining its boundary, it’s important to understand the types of government information commonly encountered in defense contracting.
What is Federal Contract Information (FCI)?
FCI is non-public information provided by the government for the purpose of contracting. This is the most common type of covered information. FCI is subject to basic safeguarding requirements, while CUI is subject to additional security requirements under NIST SP 800-171.
What is Controlled Unclassified Information (CUI)?
CUI is unclassified government information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy. The determination for is or what is not CUI rests with the originating government agency, and must be marked accordingly as defined by contract or agreement. When applicable to the contract, CUI handling may be governed by requirements such as DFARS 252.204-7012.
CUI includes two primary designations:
- CUI Basic: Requires standard safeguarding and dissemination controls.
- CUI Specified: Requires specific handling controls established by the underlying law, regulation, or government-wide policy.
What is Covered Defense Information (CDI)?
Covered Defense Information (CDI) is a DFARS-defined category of information associated with covered contractor information systems and DOD contracts. Contractors typically encounter CDI in connection with requirements such as DFARS 252.204-7012.
This distinction matters because contractors can sometimes assume that all non-public government information is CUI. Over-scoping can lead to unnecessary costs and operational disruption. Further, incorrect scoping can lead organizations to miss other requirements, such as distribution limitations which require additional marking.
Choosing your scope isn’t just a technical decision, it’s the foundation that determines your timeline, cost, and long-term success. Watch this on-demand webinar, Getting CMMC Scope Right the First Time, for more on building a scope strategy that reflects how your environment operates.
Properly identifying the information you are required to protect is the first step in determining whether an enclave is necessary and how to design it.
What Is a CUI Enclave?
A CUI enclave is a defined set of systems, users, devices, and workflows—often cloud-based—that are isolated from the rest of the business and architected to protect CUI in accordance with NIST SP 800-171 and applicable contractual requirements.
Key aspects of a CUI enclave include:
- It is boundary-driven: The enclave is designed around the specific systems, users, devices, and processes that need to handle CUI.
- It can help limit CMMC assessment scope: By isolating CUI-related workflows, organizations may be able to keep broader commercial systems outside the assessment boundary.
- It supports security requirements: Access control, monitoring, logging, encryption, and other capabilities can be designed into the environment to support NIST SP 800-171 implementation.
A well-scoped enclave can help organizations manage CUI securely while minimizing disruption to commercial or non-CUI business operations.
Why Contractors Choose an Enclave Approach
Many organizations find that although CUI touches certain employees, systems, or specialized workflows, the majority of the business does not handle CUI. Securing every system, device, and user to NIST SP 800-171 standards can be costly and complex.
A CUI enclave can help organizations:
- Limit CMMC assessment scope: The enclave can help limit assessment scope to the enclave systems and relevant dependencies identified through the organization’s scoping analysis.
- Avoid unnecessary modernization of legacy systems: Legacy equipment that does not need to handle CUI may remain outside the enclave.
- Reduce operational disruption: Non-CUI teams can continue using their existing commercial environment.
- Accelerate readiness: Purpose-built architectures can provide many of the security capabilities needed to implement NIST SP 800-171.
- Enhance security: Strong access controls, monitoring, and other safeguards can reduce risk to sensitive information.
For organizations that can clearly isolate their CUI-related work, an enclave can be a practical way to manage compliance while maintaining day-to-day operations.
5 Steps to Build a CUI Enclave for CMMC
Step 1: Identify CUI Within Your Organization
Many contractors struggle to identify the CUI within their environment because government marking practices have historically been inconsistent.
Contractors cannot independently designate information as CUI based solely on assumptions or individual interpretations. However, they may be responsible for marking or safeguarding CUI generated or received during contract performance when applicable contract or governing requirements designate it as CUI.
Recommended steps to help identify CUI include:
- Complete required CUI training.
- Review contract clauses, program communications, and government-provided markings.
- Examine both digital and physical information flows.
- Identify where CUI is received, created, stored, processed, transmitted, and disposed of.
- Confirm with contracting officers or program managers when markings or requirements are unclear.
Examples of information that may be subject to CUI requirements include:
- Technical drawings, specifications, or data packages.
- Export-controlled information.
- Building plans or sensitive facility information.
- Manufacturing details, quality records, or process documentation.
- CUI generated or received during contract performance when required by the applicable contract or governing requirements.
Accurate identification of the information you are required to protect provides the foundation for determining your CUI boundary and designing an appropriate enclave.
Step 2: Map Your CUI Boundary
Your CUI boundary is the set of workflows, systems, facilities, devices, and people that store, process, transmit, or create CUI. Understanding the boundary will help not only address the control requirements associated with CMMC but also help determine whether an enclave is appropriate or preferred.
This analysis affects:
- CMMC Level 2 assessment scope
- Required documentation, including the System Security Plan (SSP)
- System architecture
- Enclave design
- Security controls and dependencies
Include Both Physical and Digital CUI Flows
Many contractors focus exclusively on digital CUI, but physical CUI, including CUI stored on physical devices (such as CDs or USBs), must also be considered.
Example 1: Manufacturing Physical Components
A company receiving physical components under contract may involve receiving personnel, shipping and logistics, engineers, manufacturing systems, quality control, and other personnel or systems involved in processing associated information.
These activities should be evaluated based on how CUI enters, moves through, and leaves the organization.
Example 2: Construction Projects
A construction firm designing a government facility may handle building plans, facility location information, and site access requirements.
Whether particular information qualifies as CUI depends on the applicable law, regulation, government-wide policy, or contractual requirements.
Activities included in the CUI boundary do not automatically translate into CMMC assessment scope. Each system, role, process, and dependency must be evaluated carefully. The goal is to understand the flow of CUI and determine which assets and activities must be included in the assessment boundary—not assume every related system belongs in the enclave.
Step 3: Determine Whether an Enclave Is the Right Approach
An enclave is typically a good fit when:
- Only specific teams or workflows handle CUI
- The organization wants to reduce assessment scope
- Critical legacy systems cannot reasonably meet NIST SP 800-171 requirements
- The company needs to restrict access to CUI based on location or other conditions
- The bulk of commercial operations does not involve CUI
- Little or no physical CUI is present or created (e.g., by printing)
An enclave may not be ideal if:
- CUI permeates nearly all business units
- Shop-floor equipment or specialized systems must handle CUI and cannot be effectively isolated
- Business processes cannot be segmented in a practical way
The right approach depends on the organization’s CUI flows, technology environment, business processes, and assessment boundary.
Step 4: Design and Build Your Enclave Architecture
A CUI enclave is not a single product or technology. It is an environment where the applicable NIST SP 800-171 security requirements are implemented, documented, monitored, and maintained.
Below are several NIST SP 800-171 control families and examples of how an enclave architecture can support them.
Access Control (AC)
- Separate identities and credentials for enclave access
- Multifactor authentication and conditional access
- Device restrictions, protecting the enclave and reducing overall scope
- Location-based access controls where appropriate
Audit and Accountability (AU)
- Centralized logging
- Log correlation and alerting
- Continuous monitoring
Configuration Management (CM)
- Standardized configurations
- Control of approved applications compliant for use with CUI
- Prevention and detection of unauthorized changes
Media Protection (MP)
- Sensitivity labels for CUI
- Controls restricting printing, screenshots, copy/paste, and downloads where supported
- Managed removable-media workflows when required
System and Communications Protection (SC)
- Encryption for data in transit and at rest
- Defined enclave boundary
- Secure communication pathways
- Controls governing connections between the enclave and external systems
Incident Response (IR)
- Role & environment-specific incident response procedures
- Evidence collection targeted only to in-scope enclave systems
- Monitoring integrated with the incident response process
The advantage of an enclave is that these controls can be concentrated around a well-defined environment rather than applied indiscriminately across the entire corporate network.
Step 5: Shape Your Workflows Inside the Enclave
Technical architecture alone is not enough. Organizations must also align business processes with enclave workflows.
Best practices include:
- Perform CUI-related work inside the designated environment
- Label and handle CUI appropriately
- Document enclave workflows, data flows, and handling processes
- Restrict access to approved devices, users, and locations
- Train enclave users on required procedures
- Define how information enters and leaves the enclave
Common Pitfalls to Avoid:
- Mixing CUI and non-CUI data unnecessarily
- Installing unnecessary applications inside the enclave
- Using unapproved commercial email or collaboration tools for CUI
- Creating unnecessary interconnections between the enclave and external systems
- Allowing uncontrolled data movement out of the enclave
Business process clarity is critical not only during a CMMC assessment, but also for maintaining the environment after the assessment is complete.
Real-World Example: SEP’s Enclave Implementation
Challenge: SEP needed to isolate defense-related software development from commercial operations, maintain existing workflows, and prepare for a CMMC Level 2 assessment.
Approach: CyberSheath designed and implemented a dedicated enclave aligned with NIST SP 800-171, defining the environment’s boundaries, configuring required controls, and working with SEP’s technical team under a shared responsibility model.
Outcome: The enclave provided a secure environment for CUI handling while preserving SEP’s existing workflows and operations. SEP earned a perfect 110 SPRS score and successfully completed a CMMC Level 2 assessment with A-LIGN. Just as importantly, it sets SEP up to pursue new and expanding defense work as CMMC requirements continue to roll out across Department of Defense contracts.
The engagement demonstrates how a well-designed enclave can help an organization isolate CUI-related operations while avoiding unnecessary changes to the broader business environment.
Frequently Asked Questions
Can contractors designate information as CUI themselves?
Contractors should not independently designate information as CUI based solely on their own assumptions, beliefs, or interpretations. CUI requirements originate from applicable law, regulation, government-wide policy, and contractual requirements. Contractors may be responsible for marking or safeguarding information when those requirements apply.
Does every system that touches physical CUI become part of the enclave?
Not necessarily. Each system, role, and process should be evaluated based on how it interacts with CUI and whether it must be included in the applicable assessment boundary. Review the CMMC Level 2 Scoping Guide for more information.
Does a CUI enclave support CMMC 2.0 Level 2?
A properly designed and implemented enclave can help organizations implement the NIST SP 800-171 security requirements applicable to CMMC Level 2. However, an enclave by itself does not make an organization CMMC compliant. The environment must be properly scoped, configured, documented, and maintained, and the organization must satisfy the applicable assessment requirements.
Next Steps
For organizations that can clearly isolate their CUI workflows, a CUI enclave can be an effective way to reduce CMMC assessment scope, protect government information, and preserve commercial operations.
CyberSheath has helped hundreds of organizations identify CUI, define enclave boundaries, and implement secure environments designed around the realities of defense contracting.
Looking for help managing CUI and leveraging an enclave for compliance? Contact a CyberSheath expert today for the guidance and support your organization needs.
