CMMC Enclave or Full Environment? How to Make the Right Scoping Call
A CMMC enclave can shrink your Level 2 assessment boundary, or quietly double your operating costs. Here's how defense contractors decide, and how Secureframe supports either path.
Take the CMMC readiness assessmentWhat a CMMC enclave actually is
An enclave isolates CUI in a dedicated environment, usually a separate tenant with its own identities, network, storage, and tooling, so only that boundary is in scope for your Level 2 assessment. Local endpoints and network components stay out of scope, which materially reduces complexity and cost.
Scope follows the data, not the architecture. The CMMC scoping guide sorts every asset into five categories, and that categorization determines how much scrutiny each one gets:
| Asset category | What it is | How it's treated |
|---|---|---|
| CUI Assets | Systems that store, process, or transmit CUI. This is what lives inside your enclave. | Must meet all 110 NIST SP 800-171 requirements. |
| Security Protection Assets | Firewalls, SIEM, identity management. They don’t handle CUI directly, but they protect the systems that do. | In scope, and documented in your SSP. |
| Contractor Risk Managed Assets | Systems that don’t process CUI but could affect enclave security if compromised. | Managed through risk-based controls rather than the full set. |
| Specialized Assets | Industrial control systems, CNC machines, test equipment, government-furnished equipment. For manufacturers, this is where most shop-floor equipment lands. | Managed through documented policies and operational constraints, since they often can’t be fully hardened. |
| Out-of-Scope Assets | Systems with no connection to your CUI environment. | Outside the assessment boundary. Maximizing this category is the point of an enclave strategy. |
The cleaner this categorization, the smaller your assessment footprint.
Where enclaves fail is drift. Incomplete scoping is one of the most common findings during CMMC Level 2 assessments. If a C3PAO discovers CUI outside your defined boundary, your scope can expand mid-assessment, pulling in systems, endpoints, and users that now have to meet all 110 requirements.
CMMC enclave or full environment: which side are you on?
| An enclave usually wins when | Full environment usually wins when |
|---|---|
| A small share of your people touch CUI | Most desks touch CUI |
| Federal work is meaningful but not most of your revenue | Defense work is the core business |
| You can draw a clean line between CUI and non-CUI users | That line keeps moving, or never existed |
| Your legacy environment would be expensive to fix wholesale | Your environment is modern enough to bring up to standard |
| You want a contained project | You’d rather migrate once than run two environments forever |
Roughly nine in ten contractors start with an enclave, according to Richard Wakeman, Chief Security Architect for Microsoft's U.S. Aerospace and Defense vertical. For a company with a containable group of CUI users, it's the cheapest way to get compliant and stay that way, and for many it's the permanent answer rather than a stepping stone.
The catch is friction, and it's a compliance risk rather than an annoyance. People end up switching between two identities, a commercial one and a government one, often through a virtual desktop that resets every session. A year in, the question worth asking is whether anyone is actually using it. The same setup invites spillage from outside: tell your primes to use the government address all you like, and one of them replies to the commercial one and puts CUI where it shouldn't be.
Going all in removes that. One environment, one way of working, no commercial side for CUI to leak into. The cost is a license for every employee and a full migration instead of a contained project.
The deciding factor is that third row. If the line keeps moving, an enclave will keep leaking.
The real cost comparison
Which approach is cheaper depends on what share of your people touch CUI, which is why scoping comes before pricing.
In an enclave, only the people who touch CUI need a GCC High license, and that's where the savings come from. People who work in both environments need two licenses, so a large group like that erodes the advantage fast. Going all in shifts the cost to remediation instead: bringing every laptop, account, and vendor up to NIST 800-171, plus a license for everyone.
GCC High runs about 30% more than GCC, and Microsoft raised prices on the government plans on July 1, 2026, so older quotes are stale. If you have 300 employees or fewer, GCC High Business Premium with the Defender and Purview add-ons gets close to what G5 offers at roughly 45% of the price, and the July increase left Business Premium alone. Current per-user pricing for every plan.
Count your CUI users honestly before you build. Scope creep is what makes these projects expensive, and it usually starts with an optimistic headcount.
How Secureframe supports either path
Most CMMC enclave solutions sell you the environment and leave the compliance program to you. Secureframe Defense does both, on either boundary.
We provision a CMMC-aligned enclave in Microsoft GCC High or Google Workspace, with identity, access, data protection, logging, and alerting configured from day one. You own the tenant. For access, Virtual Desktops run in Azure Government and keep physical devices out of scope, and Secureframe Federal MDM is a FedRAMP Moderate authorized option for teams that need to work on their own hardware. Plenty of organizations use both, depending on the role.
Already have a GCC High tenant? Connect it and Secureframe works inside it: segregating CUI in SharePoint, writing the technical configurations the APIs allow, enforcing separation of duties, and walking you through the settings GCC High doesn’t expose. We ask for the admin permissions we need and give them back once the configuration is in place. The platform also connects to Azure Government, Entra ID, and AWS GovCloud.
Whichever boundary you land on, Defense Navigator turns the 110 requirements into prioritized tasks with your SPRS score updating live, Automated Documentation builds your SSP and POA&M from your real configuration instead of a template, and continuous monitoring catches drift before an assessor does.
Secureframe is a Registered Practitioner Organization and one of the first companies to earn CMMC Level 2 certification.
Build it yourself, or don't
Once you've settled the boundary question, there's a second one: do you build the enclave or buy it. A DIY build takes Azure Government expertise, security engineering, knowledge of which configurations satisfy which NIST requirements, and ongoing maintenance: patches, user provisioning, evidence collection, drift detection. For organizations with a dedicated IT security team and strong Microsoft cloud expertise, that's feasible. For most small and mid-size contractors, where IT is one person or a part-time function, it's a significant undertaking, and a misconfigured enclave creates a false sense of compliance that fails assessment in ways that are hard to diagnose.
Consider building when:
- You have internal staff with Azure Government and CMMC expertise
- Your compliance deadline is 12+ months out
- A limited number of employees need CUI access
- You have dedicated resources to monitor drift and maintain documentation over time
Consider a managed solution when:
- You would need to hire or engage consultants to build a CMMC-compliant enclave
- You have a near-term compliance deadline
- A significant portion of your workforce handles CUI
- You don’t have ongoing internal capacity to maintain a compliant enclave after initial certification
An enclave is not a compliance program
Standing up an enclave and being compliant are different things. As Wakeman put it at the Secureframe National Cybersecurity Summit:
“Just because you go into GCC or GCC High doesn’t make you magically compliant with CMMC Level 2. If you turn all the knobs and dials and configure all the products and services that Microsoft offers you, you’re around maybe 86 of the controls, and that’s in a purely cloud-native enclave approach. To get to a full 110, you have training, monitoring operations, and a number of other things that are not technology.”
That remaining gap is the part no enclave closes. Policies, background checks, physical security, vendor reviews, training records, incident response drills, and ongoing evidence for all 110 requirements sit outside any boundary you can build. Writing them into your SSP is what an assessor actually reads.
Frequently Asked Questions
No. Scope follows where CUI actually goes, not where you meant it to stay, and if an assessor finds CUI outside your boundary those systems come into scope mid-assessment.
Yes. Connect an existing tenant and Secureframe configures and monitors inside it, or we can provision a new enclave in GCC High or Google Workspace if you don’t have one.
Yes. An enclave gets you to roughly 86 of the 110 requirements, and the rest are organizational: training, monitoring, personnel, physical security, incident response.
Only when a small share of your staff touches CUI, since only those people need a GCC High license. Running two environments has permanent overhead, and people who work in both need two licenses.
Your timeline is your contract pipeline, not the government’s rollout, because primes set their own deadlines. A DIY build takes months; automated provisioning stands the infrastructure up in hours, and the rest is documentation and control work.
