If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Enclave vs Full Remediation: Which CMMC Path Fits
The enclave vs full remediation decision is the only one in this whole programme that changes the cost by a factor rather than a percentage. Everything downstream, the licences, the tooling, the consulting hours, the assessment itself, is priced off the number of assets inside your boundary. Choose the boundary badly and you will spend the next two years paying for that choice in every invoice.
The rule that governs it is short and it is worth internalising before any vendor conversation. You are not assessed on your company. You are assessed on your assessment scope. This article sits under How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.
How the regulation categorises what you own
32 CFR 170.19 sorts every asset into one of five buckets, and the bucket determines how much work it costs you. This table is the entire economic argument in enclave vs full remediation.
| Category | What it is | What it costs you |
|---|---|---|
| CUI Assets | Anything that processes, stores or transmits controlled information | The most expensive category. Documented in your inventory, plan and network diagram, and assessed against all Level 2 requirements |
| Security Protection Assets | Things that provide security functions to the scope, such as your logging platform or identity system | Assessed against the relevant requirements, not all of them |
| Contractor Risk Managed Assets | Assets that could hold controlled information but are not intended to, because policy and practice prevent it | Documented in the plan. The assessor reviews it and spot checks only if the documentation raises questions |
| Specialized Assets | Operational technology, industrial control systems, test equipment, government furnished equipment, restricted systems | Documented and risk managed. Not assessed against the other requirements |
| Out of Scope Assets | Cannot process, store or transmit controlled information and provide no security protection for it | Nothing |
Read the Specialized Assets row twice if you run a shop floor. The machine controller nobody can patch, the coordinate measuring machine on an operating system from 2009, the test rig the vendor will not let you touch: these are documented and risk managed rather than assessed against 110 requirements. A great deal of anxiety in small manufacturing is spent on equipment the rule already accommodates.
The arithmetic behind enclave vs full remediation
Take your headcount and ask how many of those people genuinely need to open a controlled document. Not how many are curious, not how many are in the department. How many need it to do the job.
| Enclave | Full remediation | |
|---|---|---|
| Users inside the boundary | Typically three to fifteen at a small manufacturer | Everyone |
| Endpoints assessed against all 110 requirements | Only those inside, and with a properly configured virtual desktop, potentially none | Every laptop and workstation in the company |
| Government cloud licences | Bought for the people who need them | Bought for everyone |
| Time to a defensible position | Weeks to a few months | Six to eighteen months, and often longer |
| Ongoing operating burden | Contained and predictable | Grows with headcount and every new device |
| What it demands of you | Process discipline. Data must genuinely stay inside | Capital and patience |
The trade in enclave vs full remediation is real and it is not free. An enclave converts a technology problem into a behaviour problem. The boundary only holds if people actually use it, which means a written instruction, training and somebody checking. Full remediation asks nothing of behaviour and everything of the budget.
When an enclave genuinely will not work
Honest disqualifiers, because a boundary that fails in practice is worse than no boundary at all. You will have paid for it and still be out of scope discipline.
- Controlled data drives production. If a model has to leave the boundary to reach a machine, the boundary has a hole in it by design. Sometimes solvable with a controlled transfer process, sometimes not.
- Most of your revenue is defense. If eighty percent of the company touches this work, an enclave containing eighty percent of the company is just your network with extra steps and a second licence bill.
- Controlled information arrives through channels you do not control. Customers who email drawings to whoever they spoke to last will defeat a boundary unless you change how they send. That is a customer conversation, and it is winnable, but it has to happen first.
- Nobody will enforce it. If leadership will not back a rule that says this work happens over here, the rule will not survive its first deadline.
Where full remediation is the correct answer
It is not always wrong. It is the right call when defense work is the business rather than a line of it, when controlled information is genuinely pervasive across engineering, quality, purchasing and production, or when your customers are pushing you toward higher assurance and you would rather build once than migrate twice. Companies in that position who force an enclave usually end up paying for both.
If you are heading that way, the tenant decision comes with it, and that is covered in GCC High vs GCC vs Commercial Microsoft 365 for CUI. The mistake is defaulting into it. Full remediation should be a decision someone made deliberately, not the result of never having drawn a boundary.
What an enclave does not do
Shrinking scope shrinks the assessment. It does not eliminate the requirements that have nothing to do with where files live.
Policy, awareness training, personnel screening, physical protection, media handling and incident response apply to your organisation regardless of how narrow your technical boundary is. So does the System Security Plan, and so does the annual affirmation signed by a senior official. Your external providers do not disappear either. The rule requires that the use of an external service provider, its relationship to you and the services it provides are documented in your plan, and that a cloud service provider holding controlled information meets the FedRAMP requirements in DFARS 252.204-7012.
If you want the mechanics of the documentation that follows either choice, start with How to Write a CMMC System Security Plan.
A sequence that does not waste money
- Find the data first. Mail, file shares, endpoints, the engineering drive, the quoting mailbox, the machine that runs the CAM software. You cannot draw a boundary around something you have not located, and every quote you collect before this is fiction.
- Name the people, not the departments. The list is nearly always shorter than anyone expects, and it is the input to every licence count you will buy.
- Decide the boundary and write it down. One page. Which systems hold controlled information going forward, and which explicitly do not.
- Stop the inflow before you clean up. Tell customers in writing where to send controlled material from now on. Free, and it stops the pile growing while you work.
- Move the data, then remove the originals with a record. Mailboxes and retention policies are where this work is most often left half finished.
- Then buy. Licences, tooling and consulting all price off the boundary. Buying first is how companies end up with shelfware.
If a delivery date is already committed and you are doing this under pressure, 90 days to get compliant covers what fits in a quarter. For what an enclave costs to build rather than rent, see build vs buy: what an in house enclave actually costs.
Frequently asked
Questions about this topic
In enclave vs full remediation, is an enclave a shortcut?
How small can the boundary be?
What happens to our shop floor equipment?
Do our laptops stay in scope with an enclave?
Can we start narrow and expand later?
Does an enclave reduce what we have to document?
Keep reading
More in Comparisons & Alternatives
- Azure Government vs AWS GovCloud for CUI Workloads →
- Build vs Buy Enclave: What In House Actually Costs →
- CMMC Compliance Options: Enclave, Environment or Service →
- CMMC Compliance Software for Small Manufacturers →
- CMMC Platform vs Consultant vs Doing It In House →
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps →
- GCC High vs GCC vs Commercial Microsoft 365 for CUI →
- PreVeil vs GCC High for Small Defense Contractors →
- RPO vs C3PAO vs Consultant: Who Does What in CMMC →
- Virtual Desktop Enclave vs Managed Laptops for CUI →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5