Why scope is the whole ballgame
Consider a 60-person manufacturer where 12 engineers actually touch controlled technical data. Hardening all 60 users to Level 2 standards means 60 GCC High licenses, 60 managed and monitored endpoints, 60 people in training records, and an assessment that examines every one of those systems.
Put those 12 engineers in a properly isolated enclave and the numbers change completely, and so does the assessment. The rest of the company still needs sound security hygiene, but it is no longer inside the CMMC boundary. This is not a loophole; scoping is an explicit and expected part of the CMMC methodology.
What an enclave actually is
An enclave is a deliberately bounded environment (identity, storage, compute, network path, and endpoints) where CUI is allowed to live, with controlled entry and exit points. Everything outside it is architected so CUI cannot reach it.
The design varies with how your people work. Some clients get a separate GCC High tenant used by a subset of staff. Some get virtual desktops so engineers can reach CUI from existing hardware without that hardware entering scope. Some get a dedicated physical network segment and dedicated workstations. Usually it is a combination.
- Separate identity boundary with its own conditional access and MFA policy
- Dedicated storage with labeling, encryption, and DLP at every egress point
- Virtual desktop or dedicated-endpoint models depending on how staff work
- Network segmentation with controlled, logged, inspected crossing points
- Documented, enforced rules for how data enters and leaves the enclave
The part that makes or breaks it: keeping CUI inside
An enclave only reduces scope if controlled data genuinely cannot leak into the rest of the business. If an engineer can email a drawing to their commercial mailbox, or drop it on a shared drive, the boundary is fiction and an assessor will treat it as such.
So the technical build is only half the work. The other half is data-flow discipline: labeling, DLP enforcement, blocked egress paths, monitored exceptions, trained users, and a documented process for the awkward real-world cases: the prime who sends CUI to a general inbox, the supplier who needs a drawing, the salesperson who quotes from a controlled spec.
- Automatic and manual sensitivity labeling for CUI
- DLP rules blocking controlled content from leaving via mail, chat, or sharing links
- Removable-media controls and print restrictions
- A defined intake process so inbound CUI lands inside the boundary, not in a general mailbox
- Exception handling that is logged and reviewed rather than improvised
