Skip to main content
Compliance

CMMC Enclave Architecture: Plan and Validate Assessment Scope

How to plan a CUI enclave and validate CMMC assessment scope under 32 CFR Part 170, including segmentation, asset categories, and architecture considerations.

CMMC Command Team
Compliance Engineering
Feb 15, 20269 min read
Table of Contents(19 sections)

Why Organizations Consider Enclave Architecture

An enclave can limit where CUI is processed, stored, or transmitted, but CMMC scope is not limited to those systems alone. Under 32 CFR 170.19, security protection assets, contractor risk managed assets, specialized assets, people, facilities, and external service providers may also be in assessment scope.

A dedicated CUI enclave, a segmented environment designed for CUI handling, may reduce the number of CUI assets when the boundary and supporting services are validly designed and documented. It does not guarantee a smaller assessment, lower cost, faster implementation, or a particular CMMC result.

Enclave Architecture Patterns

Pattern 1: Virtual Desktop Enclave

How it works:

  • Deploy a Virtual Desktop Infrastructure (VDI) solution
  • CUI is only accessed through virtual desktops
  • Physical workstations never touch CUI directly
  • All CUI stored on centralized, hardened servers

Pros: Minimal hardware, easy to control, clear boundary Cons: Requires reliable network, VDI licensing costs Consider when: Centralized processing fits the actual CUI workflows, connectivity, licensing, device controls, and supporting-service scope.

Architecture:

[User Workstation] → [VPN/Zero Trust] → [VDI Server] → [CUI Storage]
                                              ↓
                                        [CUI Enclave Network]
                                        (Segmented VLAN)

Pattern 2: Dedicated Network Segment

How it works:

  • Create a separate VLAN or network segment for CUI systems
  • Firewall rules enforce boundary between CUI and non-CUI segments
  • Only authorized devices join the CUI segment
  • DNS, DHCP, and other services isolated per segment

Pros: Clear network boundary, works with existing infrastructure Cons: Requires network redesign, more complex management Consider when: Network segmentation aligns with the CUI flows and the organization can govern shared identity, DNS, logging, backup, and boundary services.

Pattern 3: Cloud Enclave

How it works:

  • CUI processing in a dedicated cloud tenant or subscription
  • Cloud services selected against applicable DFARS, FedRAMP, incident-reporting, data-location, and contract requirements
  • Separate from general corporate cloud environment
  • Conditional access policies enforce enclave boundaries

Pros: Minimal on-prem footprint, scalable, inherits cloud provider controls Cons: GCC High licensing premium, cloud expertise required Consider when: The provider, service offering, configuration, shared-responsibility model, and external-service-provider evidence satisfy the applicable requirements.

Designing Your Enclave

Step 1: Map Your CUI Flows

Before designing anything, understand where CUI exists today:

  1. Where does CUI enter your organization? (Email, file transfer, web portal)
  2. Where is it stored? (File servers, cloud, workstations, engineering tools)
  3. Where is it processed? (CAD stations, email, collaboration tools)
  4. Where does it leave? (Deliverables, subcontractor flow-down)

Step 2: Define the Minimum Viable Enclave

Your assessed boundary should include all applicable asset categories and providers under 32 CFR 170.19, including assets that process, store, or transmit CUI and assets or services that protect or can affect the security of CUI. A valid enclave may include:

  • CUI file storage (server or cloud)
  • Workstations that access CUI
  • Network infrastructure connecting them (switches, firewalls)
  • Authentication infrastructure (Active Directory, MFA)
  • Security tools (AV/EDR, SIEM, vulnerability scanner)

Do NOT include:

  • General corporate email (unless CUI is in email)
  • HR and accounting systems (unless they handle CUI)
  • Guest WiFi and personal devices
  • Printers that don't print CUI

Step 3: Implement Boundary Controls

Depending on the validated architecture and applicable requirements, enclave boundary controls may include:

  • Network segmentation: Firewall rules between CUI and non-CUI segments
  • Access control: Only authorized users can access enclave resources
  • Data loss prevention: CUI cannot leave the enclave unauthorized
  • Monitoring: All boundary-crossing traffic is logged and reviewed

Step 4: Document Everything

Your SSP must clearly describe:

  • The enclave boundary and what's inside it
  • Network diagrams showing segmentation
  • Data flow diagrams showing CUI movement
  • Systems inventory for in-scope assets
  • Interconnection agreements with external systems

Common Enclave Mistakes

1. Making the Enclave Too Big

Including assets without analyzing whether they process, store, transmit, protect, or can affect the security of CUI. Categorize assets under 32 CFR 170.19 and document the rationale; do not assume every requirement is implemented identically on every asset.

2. Forgetting Supporting Infrastructure

Identity, DNS, backup, network, and other services may be security protection assets or otherwise in the assessment scope. Classify them under the rule and applicable scoping guide rather than treating shared infrastructure as automatically out of scope.

3. No Data Loss Prevention

The boundary needs mechanisms that enforce authorized CUI flows and media handling. A branded data-loss-prevention product is one possible implementation, not a universal product mandate.

4. Shared Infrastructure Without Documentation

If your enclave shares a firewall or AD with non-CUI systems, document the shared responsibility clearly.

5. Ignoring Physical Boundaries

If CUI is printed or displayed on screens, the physical space is in scope. Limit CUI access to specific rooms or areas.

Enclave Sizing Factors

Company headcount does not determine an authoritative enclave pattern or system count. Size the boundary from actual CUI data flows, users, facilities, applications, endpoints, security protection assets, shared services, external service providers, and operational dependencies.

The Potential Effect of Scope Reduction

A contractor with 100 workstations that validly limits its assessed enclave to 15 workstations has reduced the workstation count in that boundary by 85%. That arithmetic does not establish an equivalent reduction in requirements, implementation effort, maintenance burden, assessment duration, or cost. Other asset categories, people, facilities, and providers can remain in scope.

Model the business case from a validated boundary design and scoped implementation and assessment quotes. An enclave does not guarantee savings or an assessment result.

Tools for Enclave Management

CMMC Command's asset inventory feature helps you:

  • Catalog every system with CUI boundary scope (in-scope / out-of-scope / boundary)
  • Track which systems are in your enclave
  • Map CUI data flows
  • Generate scope documentation for your SSP

Map your CUI enclave. Free asset inventory and CUI boundary mapping with the Starter plan.

CUI EnclaveArchitectureNetwork SegmentationScope Reduction

Organize your CMMC preparation

Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.