Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

Enclave vs Full Remediation: Which CMMC Path Fits

The enclave vs full remediation decision is the only one in this whole programme that changes the cost by a factor rather than a percentage. Everything downstream, the licences, the tooling, the consulting hours, the assessment itself, is priced off the number of assets inside your boundary. Choose the boundary badly and you will spend the next two years paying for that choice in every invoice.

The rule that governs it is short and it is worth internalising before any vendor conversation. You are not assessed on your company. You are assessed on your assessment scope. This article sits under How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.

How the regulation categorises what you own

32 CFR 170.19 sorts every asset into one of five buckets, and the bucket determines how much work it costs you. This table is the entire economic argument in enclave vs full remediation.

CategoryWhat it isWhat it costs you
CUI AssetsAnything that processes, stores or transmits controlled informationThe most expensive category. Documented in your inventory, plan and network diagram, and assessed against all Level 2 requirements
Security Protection AssetsThings that provide security functions to the scope, such as your logging platform or identity systemAssessed against the relevant requirements, not all of them
Contractor Risk Managed AssetsAssets that could hold controlled information but are not intended to, because policy and practice prevent itDocumented in the plan. The assessor reviews it and spot checks only if the documentation raises questions
Specialized AssetsOperational technology, industrial control systems, test equipment, government furnished equipment, restricted systemsDocumented and risk managed. Not assessed against the other requirements
Out of Scope AssetsCannot process, store or transmit controlled information and provide no security protection for itNothing

Read the Specialized Assets row twice if you run a shop floor. The machine controller nobody can patch, the coordinate measuring machine on an operating system from 2009, the test rig the vendor will not let you touch: these are documented and risk managed rather than assessed against 110 requirements. A great deal of anxiety in small manufacturing is spent on equipment the rule already accommodates.

The arithmetic behind enclave vs full remediation

Take your headcount and ask how many of those people genuinely need to open a controlled document. Not how many are curious, not how many are in the department. How many need it to do the job.

EnclaveFull remediation
Users inside the boundaryTypically three to fifteen at a small manufacturerEveryone
Endpoints assessed against all 110 requirementsOnly those inside, and with a properly configured virtual desktop, potentially noneEvery laptop and workstation in the company
Government cloud licencesBought for the people who need themBought for everyone
Time to a defensible positionWeeks to a few monthsSix to eighteen months, and often longer
Ongoing operating burdenContained and predictableGrows with headcount and every new device
What it demands of youProcess discipline. Data must genuinely stay insideCapital and patience

The trade in enclave vs full remediation is real and it is not free. An enclave converts a technology problem into a behaviour problem. The boundary only holds if people actually use it, which means a written instruction, training and somebody checking. Full remediation asks nothing of behaviour and everything of the budget.

When an enclave genuinely will not work

Honest disqualifiers, because a boundary that fails in practice is worse than no boundary at all. You will have paid for it and still be out of scope discipline.

  • Controlled data drives production. If a model has to leave the boundary to reach a machine, the boundary has a hole in it by design. Sometimes solvable with a controlled transfer process, sometimes not.
  • Most of your revenue is defense. If eighty percent of the company touches this work, an enclave containing eighty percent of the company is just your network with extra steps and a second licence bill.
  • Controlled information arrives through channels you do not control. Customers who email drawings to whoever they spoke to last will defeat a boundary unless you change how they send. That is a customer conversation, and it is winnable, but it has to happen first.
  • Nobody will enforce it. If leadership will not back a rule that says this work happens over here, the rule will not survive its first deadline.

Where full remediation is the correct answer

It is not always wrong. It is the right call when defense work is the business rather than a line of it, when controlled information is genuinely pervasive across engineering, quality, purchasing and production, or when your customers are pushing you toward higher assurance and you would rather build once than migrate twice. Companies in that position who force an enclave usually end up paying for both.

If you are heading that way, the tenant decision comes with it, and that is covered in GCC High vs GCC vs Commercial Microsoft 365 for CUI. The mistake is defaulting into it. Full remediation should be a decision someone made deliberately, not the result of never having drawn a boundary.

What an enclave does not do

Shrinking scope shrinks the assessment. It does not eliminate the requirements that have nothing to do with where files live.

Policy, awareness training, personnel screening, physical protection, media handling and incident response apply to your organisation regardless of how narrow your technical boundary is. So does the System Security Plan, and so does the annual affirmation signed by a senior official. Your external providers do not disappear either. The rule requires that the use of an external service provider, its relationship to you and the services it provides are documented in your plan, and that a cloud service provider holding controlled information meets the FedRAMP requirements in DFARS 252.204-7012.

If you want the mechanics of the documentation that follows either choice, start with How to Write a CMMC System Security Plan.

A sequence that does not waste money

  1. Find the data first. Mail, file shares, endpoints, the engineering drive, the quoting mailbox, the machine that runs the CAM software. You cannot draw a boundary around something you have not located, and every quote you collect before this is fiction.
  2. Name the people, not the departments. The list is nearly always shorter than anyone expects, and it is the input to every licence count you will buy.
  3. Decide the boundary and write it down. One page. Which systems hold controlled information going forward, and which explicitly do not.
  4. Stop the inflow before you clean up. Tell customers in writing where to send controlled material from now on. Free, and it stops the pile growing while you work.
  5. Move the data, then remove the originals with a record. Mailboxes and retention policies are where this work is most often left half finished.
  6. Then buy. Licences, tooling and consulting all price off the boundary. Buying first is how companies end up with shelfware.

If a delivery date is already committed and you are doing this under pressure, 90 days to get compliant covers what fits in a quarter. For what an enclave costs to build rather than rent, see build vs buy: what an in house enclave actually costs.

Frequently asked

Questions about this topic

In enclave vs full remediation, is an enclave a shortcut?
It is legitimate and it is anticipated by the rule. 32 CFR 170.19 defines the asset categories precisely so that organisations can scope an assessment to the systems that handle controlled information. Reducing scope is the intended use of the framework, not a way around it.
How small can the boundary be?
As small as your work genuinely allows. Some manufacturers run a defensible enclave for three or four people. The constraint is not a minimum size, it is whether controlled information can actually be kept inside it without breaking how the business operates.
What happens to our shop floor equipment?
Machine controllers, test equipment and other operational technology fall under Specialized Assets. They are documented in your plan and inventory and risk managed, and they are not assessed against the other requirements. This is far less alarming than most manufacturers assume before they read it.
Do our laptops stay in scope with an enclave?
It depends on how people reach the enclave. A laptop that stores or opens controlled information is a CUI Asset assessed against all 110 requirements. A laptop restricted by policy from holding it is at best a Contractor Risk Managed Asset, still documented and still reviewed. A properly locked down virtual desktop client can be genuinely out of scope, which is the largest single scope reduction available.
Can we start narrow and expand later?
Yes, and that is the recommended direction of travel. Expanding a boundary is straightforward. Contracting one after controlled information has spread across the company is slow and expensive, because every copy has to be found and removed. If you are undecided, narrow is the reversible choice.
Does an enclave reduce what we have to document?
It reduces how much you assess, not whether you document. You still need a System Security Plan, a Plan of Action and Milestones, policies, training records and an annual affirmation. What shrinks is the number of systems each of those has to account for, which is where most of the labor sits.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents