Here's a number that surprises most defense contractors: the biggest driver of your CMMC compliance cost isn't which controls you implement. It's how much of your company those controls have to cover.
Every laptop, server, cloud service, and person that stores, processes, or transmits Controlled Unclassified Information — or that can affect the security of systems that do — is inside your assessment boundary. All 110 NIST 800-171 controls apply to everything inside that line. Draw the line around your whole company, and you're securing the marketing team's laptops to a federal standard. Draw it well, and you might be securing twelve machines instead of two hundred.
How Scoping Actually Works
Scoping starts with a deceptively simple question: where does CUI actually live? In practice, answering it means tracing data flows, not guessing:
- Where does CUI enter the company — contract portals, prime contractor emails, government file transfers?
- Who opens it, and on what devices?
- Where is it saved — file shares, project folders, engineering tools, email archives?
- Where does it leave — subcontractors, manufacturing partners, backups?
Most contractors discover their CUI footprint is both smaller and messier than expected: concentrated in a couple of programs and a handful of people, but leaked across email inboxes and shared drives where it was never supposed to be.
Asset Categories Matter
Under CMMC's scoping guidance, assets fall into categories — CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and out-of-scope assets. Each category carries different assessment treatment. Getting these classifications right, and being able to justify them with documented data flows and network diagrams, is a large part of what separates a smooth assessment from a painful one.
The Enclave Strategy
If your CUI footprint is a fraction of your business, the highest-leverage move available is an enclave: a purpose-built, isolated environment where all CUI lives, engineered to meet NIST 800-171 from day one.
Inside the enclave: hardened endpoints, controlled access, FIPS-validated encryption, monitored egress, compliant cloud services. Outside the enclave: your ordinary corporate IT, running the way it always has — because it never touches CUI.
What This Does to Your Compliance Problem
| Factor | Whole-Company Boundary | Enclave Boundary |
|---|---|---|
| Systems in scope | Every device and service company-wide | Only the enclave environment |
| User impact | Federal-grade controls on every employee | Only CUI-handling staff affected |
| Timeline to compliant | Typically 6–18 months of remediation | ~60 days for a managed enclave deployment* |
| Evidence burden | Sprawling, org-wide | Concentrated and pre-documented |
| Ongoing cost | Scales with the whole company | Scales with the enclave |
*Timeline varies based on scope and current posture.
When an Enclave Is the Wrong Answer
Honesty matters here: enclaves aren't universal. If CUI is woven through your core engineering or manufacturing workflow and most of your staff touch it daily, walling it off can create more friction than it removes. And an enclave only works if people actually use it — CUI that keeps flowing through regular email defeats the design and the compliance claim with it. Successful enclave deployments pair the technology with workflow changes and training, then verify the old paths actually closed.
Key Takeaway: Scope before you spend. A day spent mapping data flows routinely saves six figures in controls you didn't need to buy — and an enclave, done right, turns an 18-month compliance program into a 60-day deployment.
Where to Start
Before any remediation work, get three artifacts in place: a CUI data-flow map, a documented asset inventory with scoping categories, and a network diagram showing your intended boundary. These are the first things any assessor asks for — and they're the foundation for deciding whether an enclave, a full-environment approach, or a hybrid gets you to a defensible posture fastest.