CUI Scoping and Enclaves: How to Shrink Your CMMC Boundary | Stealth Technology Group
Update — July 13, 2026: DoD paused CMMC Phase 2 certification. NIST 800-171 and your signed affirmation did not pause. See What Still Applies →
Compliance & Certification

CUI Scoping and Enclaves: How to Shrink Your CMMC Boundary (and Your Bill)

Michael Bannach, CISSP May 2026
~6 min read

Here's a number that surprises most defense contractors: the biggest driver of your CMMC compliance cost isn't which controls you implement. It's how much of your company those controls have to cover.

Every laptop, server, cloud service, and person that stores, processes, or transmits Controlled Unclassified Information — or that can affect the security of systems that do — is inside your assessment boundary. All 110 NIST 800-171 controls apply to everything inside that line. Draw the line around your whole company, and you're securing the marketing team's laptops to a federal standard. Draw it well, and you might be securing twelve machines instead of two hundred.

How Scoping Actually Works

Scoping starts with a deceptively simple question: where does CUI actually live? In practice, answering it means tracing data flows, not guessing:

  • Where does CUI enter the company — contract portals, prime contractor emails, government file transfers?
  • Who opens it, and on what devices?
  • Where is it saved — file shares, project folders, engineering tools, email archives?
  • Where does it leave — subcontractors, manufacturing partners, backups?

Most contractors discover their CUI footprint is both smaller and messier than expected: concentrated in a couple of programs and a handful of people, but leaked across email inboxes and shared drives where it was never supposed to be.

Asset Categories Matter

Under CMMC's scoping guidance, assets fall into categories — CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and out-of-scope assets. Each category carries different assessment treatment. Getting these classifications right, and being able to justify them with documented data flows and network diagrams, is a large part of what separates a smooth assessment from a painful one.

The Enclave Strategy

If your CUI footprint is a fraction of your business, the highest-leverage move available is an enclave: a purpose-built, isolated environment where all CUI lives, engineered to meet NIST 800-171 from day one.

Inside the enclave: hardened endpoints, controlled access, FIPS-validated encryption, monitored egress, compliant cloud services. Outside the enclave: your ordinary corporate IT, running the way it always has — because it never touches CUI.

What This Does to Your Compliance Problem

Factor Whole-Company Boundary Enclave Boundary
Systems in scope Every device and service company-wide Only the enclave environment
User impact Federal-grade controls on every employee Only CUI-handling staff affected
Timeline to compliant Typically 6–18 months of remediation ~60 days for a managed enclave deployment*
Evidence burden Sprawling, org-wide Concentrated and pre-documented
Ongoing cost Scales with the whole company Scales with the enclave

*Timeline varies based on scope and current posture.

When an Enclave Is the Wrong Answer

Honesty matters here: enclaves aren't universal. If CUI is woven through your core engineering or manufacturing workflow and most of your staff touch it daily, walling it off can create more friction than it removes. And an enclave only works if people actually use it — CUI that keeps flowing through regular email defeats the design and the compliance claim with it. Successful enclave deployments pair the technology with workflow changes and training, then verify the old paths actually closed.

Key Takeaway: Scope before you spend. A day spent mapping data flows routinely saves six figures in controls you didn't need to buy — and an enclave, done right, turns an 18-month compliance program into a 60-day deployment.

Where to Start

Before any remediation work, get three artifacts in place: a CUI data-flow map, a documented asset inventory with scoping categories, and a network diagram showing your intended boundary. These are the first things any assessor asks for — and they're the foundation for deciding whether an enclave, a full-environment approach, or a hybrid gets you to a defensible posture fastest.

Michael Bannach

Michael Bannach, CISSP

Michael Bannach is the President & CEO of Stealth Technology Group, a CyberAB Registered Provider Organization. He holds the Certified Information Systems Security Professional (CISSP) credential and brings 25+ years of enterprise IT and cybersecurity experience guiding defense contractors through NIST 800-171 implementation and CMMC readiness.

Wondering if an enclave is right for your environment?

We'll map where CUI actually lives in your business and show you the smallest defensible boundary — before you spend a dollar on controls.

Get Started Today