CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

CMMC

How do you scope a CUI enclave?

A CUI enclave is a deliberately small part of your environment where Controlled Unclassified Information is allowed to live, separated from everything else so that NIST SP 800-171 applies to the enclave rather than to the whole company. Scoping it well is the single decision that most changes the cost, the timeline and the risk of a CMMC Level 2 effort. This article walks through how we draw the boundary, where Microsoft GCC High and Azure Virtual Desktop fit, and what a defensible scope document contains.

What is a CUI enclave?

A CUI enclave is a defined set of people, systems and data flows that are the only places CUI is stored, processed or transmitted. Everything inside the boundary has to meet all 110 requirements. Everything outside it has to be kept from touching CUI, and the controls that keep it out are part of what an assessor examines.

An enclave can be a separate cloud tenant, a set of virtual desktops, a segmented network with its own servers, or a combination. The design follows the data, not the org chart. The engineers who read drawings need to be inside it. The receptionist who schedules deliveries usually does not.

Why scope before buying any tools?

Because the scope decides what every tool has to cover, and a tool bought first quietly decides the scope for you. A company that buys an endpoint product for every laptop has made every laptop part of the conversation, whether or not those laptops ever needed to see CUI.

Start with a data flow inventory. Where does CUI arrive, from which customers and in what form? Who opens it, on what devices, and where is it saved, printed, emailed or sent to a machine on the shop floor? Where does it leave, and to whom? The answers usually reveal that CUI touches far fewer people and systems than the company assumed, and that is the opportunity an enclave exploits.

How do you draw the authorization boundary?

You draw it around every asset that stores, processes or transmits CUI, plus every asset that provides security for those assets, and then you prove the line holds. The boundary is drawn on a network diagram and described in the System Security Plan, and the two must agree.

The proof is in the connections. Every path in and out of the enclave should be known, filtered and logged: identity, email, file transfer, remote access, printing and any link to production equipment. An assessor will test the boundary by asking how CUI could escape it. If the honest answer is that a user can copy a drawing to a personal laptop, the boundary is not where the diagram says it is.

Where does Microsoft GCC High fit?

GCC High is Microsoft's government cloud for email, files and collaboration, and it is often the right home for an enclave when CUI arrives by email and lives in documents. It is built for contractors with DFARS 252.204-7012 and export control obligations, and Microsoft supports those obligations contractually, which is a large part of why it is chosen.

GCC High is not a compliance program by itself. It gives you a platform where the requirements can be met, but the configuration, the conditional access rules, the logging, the data loss prevention and the procedures are still yours. It also has real operational cost in licensing, migration and a smaller set of compatible third party tools, so it should be chosen because the data flows call for it, not by default.

When does Azure Virtual Desktop make sense?

Azure Virtual Desktop, hosted in a government region, makes sense when a small group of users needs to work with CUI in applications rather than only in email and documents. Users connect to a virtual desktop where the CUI and the applications live, and the session sends only screen, keyboard and mouse traffic back to the device in front of them.

The CMMC scoping rule addresses this pattern. An endpoint that runs a virtual desktop client configured so that CUI cannot be processed, stored or transmitted beyond the keyboard, video and mouse traffic is treated as out of scope. The configuration is what earns that treatment, so clipboard, drive mapping, printing and file transfer controls have to be set deliberately and shown to an assessor.

How do the CMMC asset categories work?

The CMMC scoping guidance sorts every asset into a category, and each category carries different obligations. CUI Assets handle the information directly. Security Protection Assets provide security for the enclave, such as the identity provider, the logging platform or a managed security provider's tools. Contractor Risk Managed Assets are able to handle CUI but are kept from doing so by policy and procedure.

Specialized Assets include operational technology, test equipment, Internet of Things devices and government property, which often cannot be fully configured to the requirements. Out of Scope Assets cannot handle CUI at all because they are physically or logically separated. Getting each asset into the right category, and documenting why, is a large part of what a scope review produces.

What about machines on the shop floor?

Machine tools and the computers that feed them programs are often the hardest part of a manufacturer's scope. A CNC controller that receives a program derived from a controlled drawing may be handling CUI, and it may run an operating system that cannot be patched or fitted with modern controls.

The usual answer is to treat those machines as Specialized Assets, isolate them on their own network segment, control how programs reach them, and describe all of it in the SSP. The goal is not to make a twenty year old controller meet every requirement. It is to show that the risk is understood, contained and managed.

What does a scope document contain?

A good scope document contains the CUI data flow diagram, the network diagram with the boundary marked, the asset inventory with a category and a reason for each asset, and the external service providers involved along with what each one does. It names the cloud services in use and how each meets the cloud requirements of DFARS 252.204-7012.

It should also record the decisions that were made and why, so that the next person, or the assessor, can follow the reasoning. A scope is not finished when the diagram is drawn. It is finished when someone outside the project can read it and agree that CUI cannot be anywhere the document does not say it is.

Which engagements cover this?

CUI enclave design

CUI enclave design in Microsoft Azure and M365 GCC High, with a defined authorization boundary, for defense contractors.

SSP and POA&M review and assessor readiness

Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.

CMMC Level 2 program leadership

Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.

What else do readers ask?

Do we have to move to GCC High for CMMC Level 2?

Not always. GCC High is a common choice when CUI arrives by email and lives in documents, but the right platform depends on your data flows and contracts. What matters is that the cloud service used for CUI meets DFARS 252.204-7012.

Is an enclave cheaper than bringing the whole company into scope?

Usually, for a company where only a small group handles CUI, because fewer systems and people have to meet every requirement. It depends on how many people truly need the data.

Can a virtual desktop really take laptops out of scope?

The CMMC scoping rule treats an endpoint as out of scope when its virtual desktop client is configured so CUI cannot be processed, stored or transmitted beyond keyboard, video and mouse traffic. The configuration has to be shown, not assumed.

This article is general information about the regulations as written, not legal advice. Read your contract clauses and the regulation text, and take legal advice where the answer matters.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.