CMMC Enclave or Full Scope: How to Decide
An enclave is a deliberately small, segmented environment where all your Controlled Unclassified Information lives, so that your CMMC assessment covers the enclave and the assets protecting it rather than your whole company. The decision between an enclave and a full-environment migration is not about company size and not about revenue. It is about people: an enclave pays when a minority of your staff touch CUI and the workflows that need it are few enough to live behind a boundary, and a migration pays when most of your staff handle CUI, because a boundary that most of the company crosses every day will be crossed incorrectly and will not survive an assessment. The reason scoping moves everything downstream is written into 32 CFR 170.19, which defines assessment scope by asset category rather than by organization.
This article gives you the asset vocabulary the decision is actually made in, works the crossover, and then names the costs of an enclave that are not on any invoice.
Key takeaways
- Scope under 32 CFR 170.19 is defined by asset category, so the question is never "how big are we" but "which assets touch CUI".
- An enclave does not reduce the 110 requirements. It reduces the number of assets those requirements apply to, which is where the savings come from.
- The crossover is a headcount ratio: enclaves pay while few people need CUI, migrations pay once most people do.
- The costs an enclave adds are friction and drift, and both show up as findings rather than as invoices.
- Export-controlled data can override the arithmetic entirely, because personnel and residency requirements are separate obligations.
The five asset categories, because the decision is made in this vocabulary
Before anything else, learn the five buckets. The CMMC Level 2 Scoping Guide and 170.19's tables sort every asset in your environment into one of them, and every scoping argument you will have with an assessor happens in these terms.
CUI Assets process, store, or transmit CUI. They are in scope and are assessed against the Level 2 requirements.
Security Protection Assets provide security functions or capabilities to your assessment scope: firewalls, the SIEM, endpoint protection, identity providers, the tooling your managed provider runs. The rule's tables describe them as assets that "provide security functions or capabilities to the OSA's CMMC Assessment Scope". They are in scope, assessed against the requirements relevant to the capabilities they provide.
Contractor Risk Managed Assets are, in the rule's words, assets that "can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place". They are in scope and managed under your own risk-based policy rather than assessed against everything.
Specialized Assets are assets that can handle CUI but cannot be fully secured: Internet of Things and Industrial Internet of Things devices, operational technology, government furnished equipment, restricted information systems, and test equipment. Manufacturing shops have more of these than they expect.
Out-of-Scope Assets cannot process, store, or transmit CUI and provide no security protection to CUI assets. Physical or logical separation is what puts an asset here.
The enclave strategy, stated precisely, is an engineering effort to move as much of your environment as possible into that last category. Everything else follows from that sentence.
What an enclave actually is, and what it is not
An enclave is a bounded environment (a separate tenant, a segmented network, a virtual desktop estate, or some combination) that holds every CUI asset and the security protection assets serving them, with controlled entry and exit points and a documented data flow.
It is not a folder with permissions on it. The test is whether an assessor can draw your boundary on one page and whether the data flow diagram accounts for every way CUI gets in and out, including email, portable media, printing, and the engineer who takes a drawing home to look at on a laptop.
Two things an enclave does not do, both of which get oversold.
It does not reduce the number of requirements. Level 2 is 110 requirements regardless of how you are organised. What changes is the number of assets, users, and processes those 110 requirements have to be implemented on and evidenced across, which is the actual driver of effort in both the readiness work and the assessment.
It does not remove the rest of the company from consideration. Your assessor still needs to see how the boundary is enforced, which means the systems doing the enforcing are in scope even though the business systems behind them are not. An enclave shrinks the assessment; it does not hide the network.
The crossover, worked
Here is the arithmetic, done in ratios rather than in prices, because the price part depends on quotes you have and we do not.
Enclave cost scales with the number of people who need CUI access, plus a roughly fixed engineering cost to build and maintain the boundary. Full-environment cost scales with total headcount and total asset count, with no boundary to build but nowhere out of scope either.
So take two numbers: the count of people who genuinely need to open, edit, or transmit CUI, and your total headcount. If the first is a small fraction of the second, the enclave wins easily, because you are paying per-user costs for a handful of people and leaving the rest of the business out of scope. As that fraction rises, two things happen at once: the per-user saving shrinks, and the boundary gets harder to hold because more people are crossing it more often.
The second effect is the one that decides it, and it is not linear. A boundary crossed by five people a week is a control. A boundary crossed by sixty people an hour is a queue, and queues get routed around. Every workaround someone invents to avoid the friction (a file emailed out, a drawing printed, a copy on a personal drive) creates a CUI asset outside the enclave, which is a scoping failure and, at assessment, a finding.
Our working rule, stated as the judgment it is rather than as a statistic: if you cannot name the people who need CUI access, you do not have an enclave candidate, you have a migration. The ability to list them by name is the test.
One more input worth knowing before you model anything. Government cloud tenant pricing is not published the way commercial licensing is; it comes from an authorized partner after an eligibility check, and it moved in 2026. Secureframe's July 2026 pricing update (a compliance platform vendor, so read their figures accordingly) reports that "Microsoft raised list prices for government licenses across GCC and GCC High effective July 1, 2026, with the exception of Business Premium", and puts the per-tier change at four percent on G5, nine percent on G3 and seven percent on F3, with Business Premium unchanged. The same page notes that where a government increase would exceed ten percent, Microsoft phases it over multiple years at no more than ten percent per year, so a tier can still be climbing toward its full list price. The point is not the individual percentages. It is that the per-user input to your model is a quote with an expiry date, so a comparison built on last year's blog post is already wrong.
The costs of an enclave that are not on an invoice
Three, and all three show up in assessments rather than in budgets.
Friction becomes shadow paths. Covered above, and it is the single largest reason enclaves fail. Design the sanctioned path for every real workflow (receiving a drawing from a prime, sending a quote back, letting a machinist see a spec on the floor) before you build the boundary, not after users start complaining.
Two environments drift. An enclave is a second estate to patch, monitor, back up, and account-manage. Organizations that build one and staff it with the same people who were already fully occupied end up with the enclave running an older baseline than the business network, which is the opposite of the intent.
The boundary has to be re-proven continuously. Out-of-scope is a claim you make to an assessor, and it is only true while the segmentation holds. A firewall rule added during an outage and never removed can move a whole subnet into scope silently. Whatever else your enclave has, it needs a periodic check that the separation still exists, with records.
None of this argues against enclaves. We recommend them often. It argues against treating one as a purchase rather than an operating model.
The export-control question that overrides the arithmetic
If the technical data you handle is subject to ITAR or EAR, the scoping arithmetic stops being the only input.
Export control brings requirements about who may access data and where it may reside that CMMC does not impose and that a well-scoped commercial environment may not satisfy. Those obligations run in parallel with CMMC and are not discharged by meeting Level 2. Meeting them can force a specific hosting decision regardless of how few people touch the data.
The practical consequence: establish whether you hold export-controlled technical data before you model enclave-versus-migration, because a yes can decide the platform for you and make the headcount analysis a secondary question. If you are unsure what you hold, that determination comes first, and we work through the identification problem in FCI vs CUI.
When neither answer is right yet
Two cases where the correct decision is to build nothing.
If you have not confirmed that you handle CUI at all, do not build a boundary around a hypothesis. The confirmation is an email to your contracting officer or your prime, and it is free. Our piece on what level you need has the decision tree. We have watched a company stand up a full segmented environment for a prime relationship that never produced an award, and the recurring cost outlived the opportunity by years.
If you handle only Federal Contract Information, this entire article is about someone else's problem. Level 1 is 15 requirements assessed by you, annually, and nobody needs an enclave to hold them.
And if defense work is genuinely marginal for you, the honest option nobody sells is declining the work. A company where two people touch CUI twice a year is paying an enclave's operating cost every month for that. Do that arithmetic before you do ours.
Where Top Floor fits
Scoping is most of what our CMMC practice does in the first weeks of an engagement: establish what data arrives, trace where it lands, sort the environment into the five asset categories, and only then argue about architecture. We build the data flow diagram and the boundary description that the system security plan depends on, because an assessor assesses the boundary you documented rather than the one you intended.
We do not sell an enclave product, host one, or resell government cloud licensing, which is why we are able to tell clients that a migration is the better answer when it is. Where a company has no security leader to own the decision across contracts, a virtual CISO engagement is usually a cheaper structure than hiring for it.
How to decide this week
Write down, by name, every person who needs to open, edit, or transmit CUI. Not job titles. Names. If the list is unwritable, you have your answer.
Divide that count by your headcount, and write the ratio next to the two or three workflows those people actually perform. The workflows matter as much as the count, because a boundary crossed by four people forty times a day is worse than one crossed by twenty people twice a week.
Sort a sample of your environment into the five asset categories from 170.19. Do fifty assets, not five thousand. The proportion that lands in Out-of-Scope is your enclave's upside, measured rather than assumed.
Answer the export-control question in writing before you request a single quote, because a yes changes the platform decision and makes the rest of this analysis secondary.
Frequently asked questions
What is a CMMC enclave?
An enclave is a segmented, bounded environment holding every asset that processes, stores, or transmits CUI, together with the security protection assets serving them, so that the rest of the organization can be documented as out of scope. Under 32 CFR 170.19 assessment scope is defined by asset category rather than by organization, and out-of-scope assets are those that cannot process, store, or transmit CUI and provide no security protection to CUI assets. An enclave is the engineering effort to move as much of the environment as possible into that category, and it is only real if the separation can be evidenced.
Does an enclave reduce the number of CMMC requirements?
No. CMMC Level 2 is 110 security requirements whatever your architecture, because 32 CFR 170.14(c)(3) fixes the Level 2 requirement set to NIST SP 800-171 Revision 2 in full. What an enclave reduces is the population those requirements have to be implemented on and evidenced across: fewer users, fewer endpoints, fewer systems in the assessment, and a smaller body of evidence to produce. That is where the effort saving comes from, and it is why scoping is the decision that moves every other number in the program.
How many people are too many for an enclave?
There is no published threshold, and anyone quoting one is guessing. The practical test is behavioural rather than numerical: can you name the individuals who need CUI access, and are their workflows few enough that a sanctioned path can be designed for each one. If yes, an enclave is viable. If the list is unwritable, or if the boundary would be crossed continuously by most of the company during normal work, the boundary will be routed around, the workarounds will create CUI assets outside it, and a migration is the more honest answer.
Do I need a government cloud tenant to build an enclave?
Not automatically. The requirement that drives a specific hosting choice is not CMMC itself but DFARS 252.204-7012, which obliges the contractor to ensure that any external cloud service storing, processing, or transmitting covered defense information meets security requirements equivalent to the FedRAMP Moderate baseline. That can be satisfied in more than one way. Export-controlled technical data is the separate factor that most often forces a specific tenant, because personnel and data-residency obligations under ITAR or EAR run in parallel with CMMC and are not discharged by meeting Level 2.
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.