Updated September 29, 2026
Someone has pitched you an enclave as the cheap way through CMMC, the Defense Department's cybersecurity check for its suppliers. Someone else says you'll end up including everything anyway. Both can be right.
First, the two words. Your scope is the set of people, computers, and accounts the assessor examines. Everything inside it has to meet the security requirements; everything outside it doesn't. An enclave is a walled-off corner of your IT, with its own accounts, laptops, and file storage, where only a few people do the sensitive work, so the scope stays small.
Build an enclave when a small team handles CUI (controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive) and can do their entire job inside it. Include the whole company when drawings routinely reach estimating, purchasing, and the shop floor. The enclave is only cheaper if nobody has to climb out of it to get work done. If they do, you pay for the enclave and still fail the assessment, because the leak is the thing the assessor finds.
The test is one question. Can the CUI team receive a drawing, edit it, review it, send it to a supplier, and restore it from backup without touching anything outside the enclave? If yes, build it; a CAD/CAM programming shop is a typical fit. Five engineers working in GCC High (Microsoft's government version of Microsoft 365) on company-managed laptops is a common design and a sound one (which Microsoft cloud). An encrypted add-on such as PreVeil is the other common way to build one. If the answer is "yes, except every week when," count the exceptions. Each one is either a hole or another person you have to bring inside.
What Tuesday looks like
Here is how enclaves usually fail. The estimator needs the drawing to quote a job, so every Tuesday an engineer forwards it to his regular company mailbox. Nobody thinks of this as moving CUI; it's just how quotes get done. The diagram shows a clean enclave. The real setup includes the estimator's mailbox, his laptop, and whatever he prints. An assessor who asks "how do quotes get made?" finds it in about four minutes.
So before you commit, try the shortcuts with a dummy file. Forward it by email. Download it. Copy and paste out of the session. Print it. Drop it in a personal OneDrive. Attach it to a support ticket. Ask an admin on the business side to restore it from backup. Each one should fail because of a setting you can show, or be covered by a written procedure someone follows. A sentence in a policy doesn't stop a forward.
The three holes we find most
A 40-person company proposed a separate workspace for six engineers. On the first test, three things leaked. The company's IT admin could get into the enclave's control panel from the same laptop he used for everyday email. Engineers could still save files to the regular company file share. And the design-software vendor's support team shared one login with full access.
A separate subscription doesn't make a wall until those close. The fixes, in the terms your MSP (managed service provider, the outside IT company many shops use) will recognize: give admins dedicated accounts with multi-factor login (required for privileged accounts under 3.5.3), used only from managed admin workstations. Block downloads and sharing outside the enclave in the tenant's sharing settings, then test it. Give each vendor technician a named account with an expiry date.
Some things cross the wall on purpose. The enclave usually shares logins, antivirus and threat detection, the MSP, and backup with the rest of the company, and sometimes with a second plant or a sister company that has its own CAGE code (the government's ID number for a contractor). Those shared systems count as Security Protection Assets, the government's term for the tools that protect the enclave, and they get assessed too (32 CFR 170.19). That doesn't drag every business laptop in. It does drag in the admin accounts and control panels that can change the enclave (which admin paths count).
Compare the running cost
Get real quotes for both designs, then add what the quotes leave out: separate accounts and devices to maintain, the handoffs on every job, and someone's time reviewing exceptions. Five enclave seats do not cost one-eighth of forty. The per-person overhead is higher, and every handoff is somewhere a drawing can leak.
Our rule: pick the smallest boundary your people can work inside without a weekly workaround, and write down why you rejected the other option. If the enclave needs an escape hatch every Tuesday, it's the wrong enclave. For a design that held up, see a small CUI team's boundary.
