CMMC Enclave Architecture: Plan and Validate Assessment Scope
How to plan a CUI enclave and validate CMMC assessment scope under 32 CFR Part 170, including segmentation, asset categories, and architecture considerations.
Table of Contents(19 sections)
Why Organizations Consider Enclave Architecture
An enclave can limit where CUI is processed, stored, or transmitted, but CMMC scope is not limited to those systems alone. Under 32 CFR 170.19, security protection assets, contractor risk managed assets, specialized assets, people, facilities, and external service providers may also be in assessment scope.
A dedicated CUI enclave, a segmented environment designed for CUI handling, may reduce the number of CUI assets when the boundary and supporting services are validly designed and documented. It does not guarantee a smaller assessment, lower cost, faster implementation, or a particular CMMC result.
Enclave Architecture Patterns
Pattern 1: Virtual Desktop Enclave
How it works:
- Deploy a Virtual Desktop Infrastructure (VDI) solution
- CUI is only accessed through virtual desktops
- Physical workstations never touch CUI directly
- All CUI stored on centralized, hardened servers
Pros: Minimal hardware, easy to control, clear boundary Cons: Requires reliable network, VDI licensing costs Consider when: Centralized processing fits the actual CUI workflows, connectivity, licensing, device controls, and supporting-service scope.
Architecture:
[User Workstation] → [VPN/Zero Trust] → [VDI Server] → [CUI Storage]
↓
[CUI Enclave Network]
(Segmented VLAN)
Pattern 2: Dedicated Network Segment
How it works:
- Create a separate VLAN or network segment for CUI systems
- Firewall rules enforce boundary between CUI and non-CUI segments
- Only authorized devices join the CUI segment
- DNS, DHCP, and other services isolated per segment
Pros: Clear network boundary, works with existing infrastructure Cons: Requires network redesign, more complex management Consider when: Network segmentation aligns with the CUI flows and the organization can govern shared identity, DNS, logging, backup, and boundary services.
Pattern 3: Cloud Enclave
How it works:
- CUI processing in a dedicated cloud tenant or subscription
- Cloud services selected against applicable DFARS, FedRAMP, incident-reporting, data-location, and contract requirements
- Separate from general corporate cloud environment
- Conditional access policies enforce enclave boundaries
Pros: Minimal on-prem footprint, scalable, inherits cloud provider controls Cons: GCC High licensing premium, cloud expertise required Consider when: The provider, service offering, configuration, shared-responsibility model, and external-service-provider evidence satisfy the applicable requirements.
Designing Your Enclave
Step 1: Map Your CUI Flows
Before designing anything, understand where CUI exists today:
- Where does CUI enter your organization? (Email, file transfer, web portal)
- Where is it stored? (File servers, cloud, workstations, engineering tools)
- Where is it processed? (CAD stations, email, collaboration tools)
- Where does it leave? (Deliverables, subcontractor flow-down)
Step 2: Define the Minimum Viable Enclave
Your assessed boundary should include all applicable asset categories and providers under 32 CFR 170.19, including assets that process, store, or transmit CUI and assets or services that protect or can affect the security of CUI. A valid enclave may include:
- CUI file storage (server or cloud)
- Workstations that access CUI
- Network infrastructure connecting them (switches, firewalls)
- Authentication infrastructure (Active Directory, MFA)
- Security tools (AV/EDR, SIEM, vulnerability scanner)
Do NOT include:
- General corporate email (unless CUI is in email)
- HR and accounting systems (unless they handle CUI)
- Guest WiFi and personal devices
- Printers that don't print CUI
Step 3: Implement Boundary Controls
Depending on the validated architecture and applicable requirements, enclave boundary controls may include:
- Network segmentation: Firewall rules between CUI and non-CUI segments
- Access control: Only authorized users can access enclave resources
- Data loss prevention: CUI cannot leave the enclave unauthorized
- Monitoring: All boundary-crossing traffic is logged and reviewed
Step 4: Document Everything
Your SSP must clearly describe:
- The enclave boundary and what's inside it
- Network diagrams showing segmentation
- Data flow diagrams showing CUI movement
- Systems inventory for in-scope assets
- Interconnection agreements with external systems
Common Enclave Mistakes
1. Making the Enclave Too Big
Including assets without analyzing whether they process, store, transmit, protect, or can affect the security of CUI. Categorize assets under 32 CFR 170.19 and document the rationale; do not assume every requirement is implemented identically on every asset.
2. Forgetting Supporting Infrastructure
Identity, DNS, backup, network, and other services may be security protection assets or otherwise in the assessment scope. Classify them under the rule and applicable scoping guide rather than treating shared infrastructure as automatically out of scope.
3. No Data Loss Prevention
The boundary needs mechanisms that enforce authorized CUI flows and media handling. A branded data-loss-prevention product is one possible implementation, not a universal product mandate.
4. Shared Infrastructure Without Documentation
If your enclave shares a firewall or AD with non-CUI systems, document the shared responsibility clearly.
5. Ignoring Physical Boundaries
If CUI is printed or displayed on screens, the physical space is in scope. Limit CUI access to specific rooms or areas.
Enclave Sizing Factors
Company headcount does not determine an authoritative enclave pattern or system count. Size the boundary from actual CUI data flows, users, facilities, applications, endpoints, security protection assets, shared services, external service providers, and operational dependencies.
The Potential Effect of Scope Reduction
A contractor with 100 workstations that validly limits its assessed enclave to 15 workstations has reduced the workstation count in that boundary by 85%. That arithmetic does not establish an equivalent reduction in requirements, implementation effort, maintenance burden, assessment duration, or cost. Other asset categories, people, facilities, and providers can remain in scope.
Model the business case from a validated boundary design and scoped implementation and assessment quotes. An enclave does not guarantee savings or an assessment result.
Tools for Enclave Management
CMMC Command's asset inventory feature helps you:
- Catalog every system with CUI boundary scope (in-scope / out-of-scope / boundary)
- Track which systems are in your enclave
- Map CUI data flows
- Generate scope documentation for your SSP
Map your CUI enclave. Free asset inventory and CUI boundary mapping with the Starter plan.
Related Resources
Organize your CMMC preparation
Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.