Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
Manufacturing operations face intense competitive pressures, increasingly complex supply chains, and strict compliance requirements like CMMC and ITAR...
Healthcare providers face mounting pressures from ever-evolving technology...
Accounting firms handle sensitive financial data—from tax filings to audit...
Law firms operate under strict confidentiality obligations and face evolving...
Auto dealerships handle a wealth of customer information, from financing details...
In Oil & Gas, uptime, safety, and data integrity are paramount. Whether you’re managing offshore rigs,...
Financial institutions bear a heavy responsibility: they hold sensitive client information and manage...
In the insurance sector, safeguarding sensitive policyholder information is essential—not just to meet...
Auto dealerships handle a wealth of customer information, from financing details...
Small and medium-sized businesses are the backbone of our economy, but they often face...
A CMMC enclave separates the systems and people who handle Controlled Unclassified Information (CUI) from the rest of your network.
An enterprise-wide approach treats every workstation and every user as if they might touch CUI at some point. Which one you pick decides what gets assessed, what gets locked down, and as one shop found out the hard way whether the software you already run every day keeps working.
Related Topic: What Is a Passing CMMC Score and How Is It Calculated?
Somewhere early in the CMMC process, someone asks you a question that sounds simple: is your network enterprise or enclave?
Most owners answer it the way they’d answer almost any question about their shop. Honestly, quickly, and without much thought — because at that point in the process, it feels like a formality. A box to check before the real conversation starts.
It isn’t a formality. It’s one of the biggest decisions in the entire compliance process, and it gets made before most owners understand what it actually controls.
Here’s what happened to one manufacturer doing custom precision work, primarily for defense customers. They’d said “enterprise” without really weighing it — it matched how their network was actually built, one flat environment, no walls between departments. That answer meant every workstation in the shop, all of them, from the machinists running CNC programs to the front office running payroll, was now potentially in scope for CMMC. Not because CUI was actually on all of those machines. Because nothing separated the machines where it might show up from the machines where it definitely wouldn’t.
That single answer set off a chain of requirements nobody had walked them through yet. Nobody was being careless. The team running that shop knew their machines, their customers, and their production schedule better than anyone. What they didn’t have, going into that call, was a reason to think a scoping question would reach all the way down into their accounting software. Most owners wouldn’t. That’s not a knowledge gap you’re supposed to walk in with. It’s exactly the kind of thing a scoping conversation should catch before it becomes a problem, not after.
Related Topic: Department of War Suspends CMMC Phase II Certification: What It Means for Defense Contractors
Here’s the part that catches shops off guard. Once you’re scoped as an enterprise network, the assumption baked into the assessment is that CUI can move freely across your whole environment. Every user is a potential CUI user. Every device is a potential CUI device.
That assumption isn’t a technicality. It drives real requirements: FIPS-validated encryption on drives, tighter access controls, more devices to document, more people to train, more of your environment sitting inside the assessment boundary.
Related Topic: CMMC Readiness: Prepare Your Business for Compliance
An enclave approach — sometimes called a secure enclave for CMMC — flips that. Instead of assuming CUI touches everything, you build a defined, walled-off environment where CUI actually lives and gets worked on. Everything outside that boundary, the accounting desk, general office machines, anything that never needs to see a customer drawing or a technical data package, stays out of scope.
Same shop, same work, same customers. But a very different assessment, a very different set of controls, and in a lot of cases, a meaningfully smaller lift to get certified. That’s scope reduction in practice, not just a line item in a proposal.
This isn’t a decision you make once and forget. It shapes every control after it. Get it wrong, or answer it without understanding what it commits you to, and you end up applying enterprise-grade requirements to machines that never had any business being in scope in the first place.
The documentation burden moves with it too. Every device inside enterprise scope needs to show up in your System Security Plan. Every user inside that scope needs training records, access reviews, and a paper trail proving you’re managing them the way CMMC expects. None of that goes away because the CUI never actually touched that machine. Once you’ve said “enterprise,” the assessor isn’t grading what CUI actually did. They’re grading what your scope decision said could happen. If you want a closer look at how that documentation gets handled for the systems that fall outside CUI scope, we’ve written about documenting non-applicable controls in more depth.
Related Topic: CMMC Audit Preparation: Avoid Common Compliance Mistakes
Here’s a wrinkle that trips up almost every custom manufacturer at some point, enclave or enterprise.
Say your machinists work from what they call “tapes” — the programs and sequences that tell a CNC machine exactly how to cut a part. Those get built in-house, by your own people, on your own machines. Nobody handed them to you labeled CUI. So it’s tempting to assume they’re just your internal work product and none of this applies to them.
It’s rarely that simple. If those programs are derived from a customer’s technical data, drawings, or specs, and that source material is CUI, what you built from it usually inherits the same classification. The fact that your own team wrote the code doesn’t change where the underlying information came from.
Related Topic: C3PAO: What It Is and How to Choose One for CMMC Level 2
This matters for scoping either way you go. In an enterprise environment, it barely changes anything, since everything’s already assumed in scope. But if you’re building an enclave specifically to keep it small, this is exactly the kind of detail that decides whether a workstation belongs inside the boundary or outside it. Guess wrong here and you either leave real CUI unprotected or drag machines into scope that never needed to be there.
When you’re not sure, the fastest path isn’t guessing. It’s asking the customer directly whether the source material is CUI, and treating anything they’ve labeled as such accordingly, whether or not you’d have called it that yourself.
Related Topic: DIBCAC: What Defense Contractors Need to Know
Here’s where it gets real, not theoretical.
That same manufacturer ran QuickBooks Enterprise on their network, the way plenty of shops do. Nothing unusual about that. But once they were scoped as an enterprise network, FIPS-validated encryption became a requirement across their devices, including the machines running QuickBooks.
The moment FIPS mode got turned on, QuickBooks stopped opening. Not slower. Not glitchy. Closed.
Picture that call with your bookkeeper. Payroll’s due Friday, invoices need to go out, and the accounting software just won’t launch, because a compliance requirement that has nothing to do with accounting collided with software that has nothing to do with CUI.
That collision only exists because of the enterprise scoping decision. If that shop’s accounting team and their QuickBooks machines had been outside the CUI enclave from the start, FIPS never needed to touch those devices. The people running payroll don’t need access to technical drawings. There was no reason for their software to be caught in the blast radius of a requirement meant for a completely different part of the business.
Related Topic: Why Every Business Needs an IT Risk Assessment?
The fix, once you catch it, is manageable. You identify exactly who needs QuickBooks and confirm they never touch CUI. If that’s true, those specific machines can be treated as an exception and kept off FIPS. If someone genuinely needs both QuickBooks and CUI access on the same machine, you’re looking at a different setup entirely, usually a segmented one.
But that’s a fix you’re making after the software already broke. An enclave built correctly from the start means that question never comes up, because accounting was never inside the boundary to begin with.
Related Topic: Why Your Small Business Network Setup Matters More Than You Think?
Before you answer “enterprise” or “enclave” on a scoping call, walk through this with whoever actually understands your network.
Not “who might, eventually.” Who, today, actually opens customer drawings, technical data packages, or anything derived from them. If that’s a defined group and not your whole staff, an enclave is probably worth serious consideration.
Accounting software, ERP systems, quality management tools, anything your team depends on daily. Some of it may not play well with FIPS-validated encryption or other enclave-adjacent controls. Better to find that out on paper than after the requirement is already live on your machines.
This is really a build vs. buy decision, not just a technical one. A well-designed enclave is not a one-time project. It needs monitoring, maintenance, and someone who understands where its boundary actually sits, day to day, not just on the day it was built. New hires get added on the wrong side of that boundary. New software gets installed without anyone checking whether it belongs inside or outside. Without ongoing ownership, an enclave that was correctly scoped on day one can quietly drift back toward enterprise-wide risk within a year, and nobody notices until an assessor does. A managed enclave, where a provider owns that upkeep, is often the more realistic path for a shop without a dedicated internal IT security team. If you’re not sure your current provider can support that, here’s how to tell whether your MSP is actually equipped for CMMC Level 2.
Related Topic: Windows 10 ESU Cost: What Delaying Your Upgrade Will Really Cost
You do not need to figure this out alone, and you should not be answering “enterprise or enclave” on a scoping call without someone in your corner who’s seen what happens on both sides of that decision.
Start with a conversation before that question gets asked, not after. A CMMC-certified team can walk your actual network, your actual software, and your actual CUI flow, and tell you which approach protects your contracts without dragging every machine in your shop into scope. That’s a very different conversation than answering “enterprise or enclave” on the spot during an assessor’s scoping call, with no chance to weigh what either answer actually commits you to.
Schedule a free consultation with our CMMC-certified team before that scoping question gets asked on your next call. If you’re already working through CMMC compliance services, this is exactly the kind of decision that conversation should cover early.
Related Topic: How to Build a Ransomware Backup Strategy That Works?
An enterprise approach scopes your entire network for CMMC, assuming CUI can appear anywhere. An enclave scopes only a defined, walled-off portion of your network where CUI actually lives, keeping everything outside that boundary out of the assessment.
In most cases, yes. Fewer in-scope systems and users means fewer controls to implement, document, and get assessed against, which typically translates into a smaller Level 2 assessment and lower ongoing compliance cost compared to scoping the whole enterprise.
Both models exist. Some shops build and maintain their own enclave internally. Others use a managed enclave, where a provider builds, monitors, and maintains the boundary and its controls on an ongoing basis, which is often the better fit for a shop without a dedicated internal IT security team.
A CMMC enclave separates the systems and people who handle Controlled Unclassified Information (CUI)…
An IT risk assessment identifies where client data actually lives, who can reach it, and…
A small business network setup includes more than a router and a Wi-Fi password.…