A CMMC enclave is a segmented portion of a defense contractor’s network built specifically to process, store, and transmit Controlled Unclassified Information under the Department of Defense’s Cybersecurity Maturity Model Certification program. Instead of hardening an entire corporate network to meet the 110 security requirements in NIST SP 800-171, you draw a boundary around only the systems that touch CUI and leave everything else out of scope. For most small and mid-size contractors chasing CMMC Level 2, this is the most cost-effective route to certification.
Why Contractors Build an Enclave
The CMMC program, codified at 32 CFR Part 170, requires defense contractors to protect CUI at a level matching the sensitivity of the information they handle.1Federal Register. Cybersecurity Maturity Model Certification (CMMC) Program Without an enclave, every workstation, server, printer, and mobile device on your network potentially falls within an assessor’s review if there is any chance it touches CUI. With a well-defined enclave, the assessment boundary shrinks to only the systems inside the perimeter plus the security tools protecting them.
That scope reduction is the whole point. A smaller boundary means fewer controls to implement, fewer devices to document, and a shorter, cheaper assessment. C3PAO fees for small to mid-size contractors with a well-defined scope generally start around $30,000 to $40,000 and can exceed $100,000 for larger environments. Every asset you can push out of scope is one you do not have to harden, document, or defend.
Enclaves matter most at Level 2. Level 1 contracts involve only Federal Contract Information and require 15 basic practices plus a self-assessment, which most contractors can meet on their existing network. Level 2 covers contracts involving CUI and requires all 110 requirements from NIST SP 800-171 Revision 2.2National Institute of Standards and Technology. NIST Special Publication 800-171 Revision 2 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations Depending on the contract, Level 2 calls for either a self-assessment or a certification assessment by a Certified Third-Party Assessment Organization; the contract itself will specify.3eCFR. 32 CFR 170.17 – CMMC Level 2 Certification Assessment and Affirmation Requirements Level 3 covers the most sensitive programs, adds requirements beyond 800-171, and is assessed by DIBCAC.
Defining the Enclave Boundary
Before you build anything, you have to define the CMMC Assessment Scope: which assets sit inside the boundary and which stay outside. Scoping is governed by 32 CFR 170.19 and the DoD’s Level 2 Scoping Guidance, and every asset in your environment gets sorted into one of five categories.4eCFR. 32 CFR 170.19 – CMMC Scoping
- CUI Assets process, store, or transmit CUI. They form the core of the enclave and are assessed against all 110 Level 2 requirements.
- Security Protection Assets provide security functions for the enclave, such as firewalls, SIEM tools, or authentication servers. They are assessed against the requirements relevant to the capabilities they provide, even if they never touch CUI directly.
- Contractor Risk Managed Assets could potentially handle CUI but are not intended to, kept in check by your own policies. They must appear in the System Security Plan, but the assessor reviews only the documentation unless something raises a red flag.
- Specialized Assets include IoT sensors, operational technology, and government-furnished equipment that handle CUI but cannot be fully secured. They require documented management procedures.
- Out-of-Scope Assets have no ability to process, store, or transmit CUI and are physically or logically separated from assets that do. They are not assessed.5Department of Defense Chief Information Officer. CMMC Assessment Scope Level 2
The separation must be real. Assessors look specifically for bridges between the enclave and the general network: shared file servers, email accounts, printers, or administrative credentials that cross the boundary. A single overlooked connection can pull your entire corporate network back into scope.
When Outside Providers Sit Inside Your Scope
Most contractors run their enclave with help from managed service providers or cloud platforms. Both arrangements are viable, but both add scoping complexity that catches people off guard.
If your MSP processes, stores, or transmits CUI or security protection data on your behalf, the services they provide fall within your assessment scope.6U.S. Department of Defense Chief Information Officer. Technical Application of CMMC Requirements: ESPs, Asset Categories, SPA/SPD, and VDI Your SSP must describe which requirements the MSP handles and how. Even if the MSP voluntarily undergoes its own C3PAO assessment, its services remain part of your scope. Staff augmentation counts too: if MSP technicians hold administrative passwords to your equipment, they are handling security protection data and must be included.
Cloud-hosted enclaves carry an additional requirement. Under DFARS 252.204-7012, any cloud service provider that stores, processes, or transmits covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline.7Acquisition.GOV. 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting A FedRAMP Moderate or High authorization satisfies this. Without a full authorization, the DoD’s FedRAMP Equivalency memo requires an independent assessment by a FedRAMP-recognized 3PAO confirming 100% of the moderate baseline controls are met, with no open remediation items.8U.S. Department of Defense Chief Information Officer. FedRAMP Authorization and Equivalency
Two common mistakes. Hosting your application on FedRAMP-authorized infrastructure does not make your application FedRAMP compliant; you may inherit some controls, but your own software and configuration still need independent evaluation. And “FedRAMP Ready” status is not equivalency. It means the provider has started the process, not finished it.
Controls the Enclave Must Actually Enforce
The 110 requirements in NIST SP 800-171 Rev 2 span 14 control families. A handful of them shape how the enclave has to be built.
Network Segmentation
The enclave has to be logically or physically separated from the general corporate network. Logical separation typically uses firewalls with strict access control lists that deny all traffic by default and permit only what is explicitly needed, with VLANs keeping internal enclave traffic in authorized zones. Physical separation goes further, using dedicated hardware in a restricted area with badge or biometric access. Most organizations combine both.
Encryption
All CUI at rest and in transit inside the enclave must be protected using FIPS-validated cryptographic modules. Requirement 3.13.11 specifically mandates FIPS-validated cryptography to protect the confidentiality of CUI.9National Institute of Standards and Technology. NIST SP 800-171 Revision 2 Your encryption solutions must hold a current FIPS 140-2 or FIPS 140-3 validation certificate. A strong algorithm that has not been FIPS-validated does not count, and this is a common assessment failure point.
Multi-Factor Authentication
Requirement 3.5.3 requires multi-factor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.9National Institute of Standards and Technology. NIST SP 800-171 Revision 2 Password-only access to anything inside the boundary is a guaranteed finding.
Audit Logging
Requirement 3.3.1 requires you to create and retain audit logs sufficient to enable monitoring, analysis, investigation, and reporting of unauthorized activity.9National Institute of Standards and Technology. NIST SP 800-171 Revision 2 The standard does not set an exact retention period, but individual contracts or DFARS clauses may. Centralizing logs in a SIEM that is itself a Security Protection Asset keeps everything under one assessment umbrella.
Training
All users need security awareness training covering the risks tied to their activities and the policies governing the enclave. Administrators need role-specific training tailored to their duties. Everyone in the organization, including managers and executives, must complete insider threat awareness training.10Department of Defense Chief Information Officer. CMMC Assessment Guide Level 2 Assessors look for evidence that training is current and that the people maintaining the controls understand what those controls do.
Documentation the Assessor Will Demand
The backbone document is the System Security Plan. The SSP describes your operational environment, the in-scope assets, how CUI flows through the enclave, and how each of the 110 requirements is implemented. A thin or outdated SSP is one of the fastest ways to stall an assessment.
Before you build, gather four things:
- A data inventory identifying every type of CUI you receive or generate, mapping where it enters the enclave, where it is stored, who accesses it, and where it exits.
- An asset inventory cataloging every piece of hardware and software that will operate inside the boundary, including servers, workstations, network equipment, and security tools.
- A user access roster documenting every person who needs enclave access, their role, and their required privilege level.
- A network diagram showing how traffic flows between internal assets, external services, and the broader corporate network, with the enclave boundary clearly marked.
If you have previously submitted a NIST SP 800-171 self-assessment score to the Supplier Performance Risk System, pull it as your baseline.11Supplier Performance Risk System. Supplier Performance Risk System It tells you which controls you were already meeting and where the gaps live. Closing gaps before the formal assessment is much cheaper than discovering them during one.
The Assessment and What Happens After
For contracts requiring certification, you present the functional enclave to an accredited C3PAO. The assessor conducts interviews, reviews documentation, examines technical evidence, and tests controls to confirm they actually work. A successful assessment results in a CMMC status valid for three years from the status date.12Department of Defense Chief Information Officer. About CMMC
You do not need a perfect score to move forward. If some requirements are not fully met at the time of assessment, the assessor can assign a Conditional status, provided the gaps are documented in a Plan of Action and Milestones. You then have 180 days to close every item on the POA&M and undergo a closeout assessment by the same C3PAO.10Department of Defense Chief Information Officer. CMMC Assessment Guide Level 2 Miss the window and you lose the Conditional status.
Discrepancies between the SSP and the live environment are among the most common assessment problems, usually because someone changed a firewall rule or added a device without updating the paperwork. Internal validation before the C3PAO shows up is worth the time.
Staying Compliant After Certification
Certification is not the finish line. DFARS 252.204-7021 requires contractors to complete an annual affirmation of continued compliance in the Supplier Performance Risk System.13Acquisition.GOV. 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Program A designated Affirming Official must legally assert that the organization still meets the required CMMC level. The obligation flows down: every subcontractor handling CUI must maintain its own affirmation. Letting the affirmation lapse affects your eligibility to perform on the contract.
Treat the SSP as a living document. When a firewall rule changes or a new server joins the enclave, update the plan before the change goes into production, not six months later.
72-Hour Incident Reporting
If your enclave experiences a cyber incident, DFARS 252.204-7012 requires you to report it to the DoD within 72 hours of discovery through the DIBNet portal.7Acquisition.GOV. 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting The clock starts when you discover the incident, not when you finish investigating. Delayed reporting is itself a compliance violation, separate from whatever the underlying breach involved.
False Claims Act Exposure
Misrepresenting compliance carries consequences beyond losing certification. The Department of Justice has pursued False Claims Act cases against organizations that claimed to meet cybersecurity requirements but did not. Raytheon and its affiliates paid $8.4 million to resolve allegations of cybersecurity noncompliance on DoD contracts.14United States Department of Justice. Raytheon Companies and Nightwing Group to Pay 8.4M to Resolve False Claims Act Allegations Relating to Non-Compliance With Cybersecurity Requirements in Federal Contracts Penn State settled similar allegations for $1.25 million.15United States Department of Justice. The Pennsylvania State University Agrees to Pay 1.25M to Resolve False Claims Act Allegations Relating to Non-Compliance With Cybersecurity Requirements Every year, a named official signs a compliance assertion that carries legal weight. Building the enclave correctly is expensive. Building it poorly and signing anyway is far more so.