If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Virtual Desktop Enclave vs Managed Laptops for CUI
A virtual desktop enclave can remove your entire laptop fleet from the assessment. Not reduce it. Remove it. That single sentence is why this comparison is worth an executive hour, and why the detail underneath it deserves more care than most vendors give it.
The regulation is precise, and the precision is the whole point. Get the configuration wrong and you keep the cost of the virtual desktop enclave while keeping every laptop in scope as well, which is the worst of both approaches. This page sits under How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.
The rule, quoted, because the wording is the value
32 CFR 170.19 lists among out of scope assets the following: an endpoint hosting a virtual desktop client configured to not allow any processing, storage, or transmission of controlled information beyond the keyboard, video and mouse sent to that client.
Three things follow, and executives should understand all three.
- Out of scope is the strongest category there is. Not a contractor risk managed asset, not a specialized asset. Out of scope means the laptop is not assessed at all.
- It is conditional, and the condition is a configuration. Keyboard, video and mouse only. Nothing else may cross.
- “Configured to not allow” is a control you must enforce and evidence. Intent does not qualify. A policy asking people not to copy files does not qualify. The block has to be in place and demonstrable.
What breaks the exemption
Every one of these is a channel that can move controlled information onto the endpoint, and enabling any of them puts the laptop back in scope.
| Redirection | Why it breaks the exemption | What people use it for |
|---|---|---|
| Clipboard, in either direction | Controlled text reaches the local clipboard | Copying a part number into a quote |
| Local drive and USB storage | Controlled files written to the laptop | Moving a file to a customer portal |
| Printer redirection | The document is rendered on the endpoint | Printing a drawing at home |
| Screenshots and local recording | Not addressed by the rule and a practical leak | Sharing a view in a meeting |
Turn these off centrally rather than relying on client settings, because the more restrictive configuration wins wherever it is applied. Then document that you did, because the exemption is only worth what you can evidence.
The comparison that actually matters
| Virtual desktop enclave | Managed laptops | |
|---|---|---|
| Endpoint status | Out of scope, if properly configured | CUI Asset assessed against all 110 requirements, or at best a contractor risk managed asset |
| What grows with headcount | A per seat subscription | The assessment boundary itself |
| Indicative cost | Commercial cloud desktops list from $41 per user per month at entry specification. Government equivalents are not publicly priced | No per seat subscription, but every device needs validated encryption, endpoint detection, patching evidence and inventory |
| Where the saving really comes from | Assessor scope and operational labor, not hardware | None. The saving is capital, and the cost is recurring compliance work |
| Biggest risk | A redirection channel quietly enabled, forfeiting the exemption | A lost device becomes a potential reportable incident with a 72 hour clock |
Note the honest framing, because vendors usually get this wrong. The virtual desktop seat is additive to the licence, and users still need a physical machine to run the client. You are not saving hardware. You are removing an entire class of asset from the assessment and removing the recurring labor of proving those assets are compliant. That is the return, and for a company with thirty endpoints it is substantial.
Where the virtual desktop approach breaks
Be honest about these before you commit, because they are the reasons projects fail after purchase.
Latency, and geography. Microsoft guidance treats round trip times up to about 150 milliseconds as fine, 150 to 200 as workable for text, and beyond 200 as affecting the experience. Graphics has its own budget where beyond 300 milliseconds end to end is bad. The government cloud has only three United States regions, which is fewer placement options than commercial, so a rural facility should measure before it buys.
Engineering workloads. Computer aided design is a rendering workload and lands in the graphics budget, not the text budget. It needs graphics capable session hosts from a specific supported list, and the commercial list price for a graphics tier cloud desktop is $537 per user per month. That number is what kills virtual desktop for everyone strategies in engineering firms. It does not kill it for the contracts and quoting team.
USB devices, which is the sharpest constraint. Low level USB redirection is designed for local network conditions under about 20 milliseconds, which effectively means on site. Encrypted USB storage, USB network adapters and USB displays are blocked outright, and scanner redirection has no support for the common scanning standard. Licence dongles, probes, calibration devices and programming cables are exactly what a machine shop depends on, and every redirection channel you enable to support them is a channel that threatens the out of scope status. This is the central tension of the approach and there is no way to design around it, only to decide it deliberately.
Printing. Redirected printing renders the document on the endpoint, which is the boundary the exemption depends on. Print inside the enclave to a printer inside the enclave, or do not print.
Offline work. There is no offline mode. A cloud desktop requires connectivity by construction. Field service engineers and travelling staff are the population this approach does not serve, and the workaround people reach for, syncing files locally, is precisely what forfeits the exemption.
What neither approach fixes
Shop floor equipment, which is covered further in CMMC for Machine Shops. A machine controller, a coordinate measuring machine or a test rig is a specialized asset under the rule, documented and risk managed rather than assessed against the other requirements, and that is true whichever endpoint strategy you pick. Virtual desktop does not touch it. Neither do managed laptops. Do not let a vendor imply otherwise.
One further trap on the licensing side. Cloud desktop products are sold in variants tied to different tenants, and the variant tied to the standard government community tenant sits at a lower impact level than the one tied to the high tenant. Buying the wrong variant and assuming it covers controlled information is a common and entirely avoidable error. Confirm the impact level of the specific product you are quoted, in writing.
For how this fits the wider boundary decision, see enclave vs full remediation. For where the desktops are hosted, see Azure Government vs AWS GovCloud for CUI workloads.
Frequently asked
Questions about this topic
Does a virtual desktop really take our laptops out of scope?
What settings do we have to disable?
Can engineers run CAD in a virtual desktop enclave?
What about USB dongles and measurement devices?
Is it cheaper than managing compliant laptops?
Does this help with our shop floor machines?
Keep reading
More in Comparisons & Alternatives
- Azure Government vs AWS GovCloud for CUI Workloads →
- Build vs Buy Enclave: What In House Actually Costs →
- CMMC Compliance Options: Enclave, Environment or Service →
- CMMC Compliance Software for Small Manufacturers →
- CMMC Platform vs Consultant vs Doing It In House →
- Enclave vs Full Remediation: Which CMMC Path Fits →
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps →
- GCC High vs GCC vs Commercial Microsoft 365 for CUI →
- PreVeil vs GCC High for Small Defense Contractors →
- RPO vs C3PAO vs Consultant: Who Does What in CMMC →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5