CUI Enclave Architecture. On-Premise Alternative to GCC High.
Most defense contractors do not need every employee in GCC High. They need a smaller, on-premise space that protects CUI work and the OT systems behind it. Deployed in 3-6 weeks, no organization-wide Microsoft migration.
Last updated:
You are evaluating how to protect Controlled Unclassified Information for CMMC Level 2. The default answer in 2026 is GCC High- Microsoft's government cloud tenant. For some contractors, that is the right call. For most, it is overkill. GCC High forces every CUI-touching user into a separate Microsoft tenant with separate licenses, separate identity, and a migration project that takes 9-18 months. And it does not cover the legacy OT, PLCs, CNCs, or specialized assets that produce or consume CUI on the shop floor.
The alternative, an on-premise CUI enclave, protects CUI workflows where they actually live: in your engineering systems, your OT segments, your CAD/CAM applications. The enclave is bounded by network controls, identity gates, and audit logging. It covers what GCC High covers (NIST 800-171 controls), adds what GCC High does not (OT, specialized assets), and deploys in weeks instead of months.
Per user / month GCC High
GCC High G5 license. Multiply by every user who handles CUI, even occasionally. For 200-user contractors, that is $120k-$216k/year before professional services.
GCC High migration timeline
Tenant procurement, license negotiation, identity migration, mailbox migration, application rehost. CMMC Phase II is suspended, but the NIST 800-171 obligation to protect CUI is not.
Of OT covered by GCC High
GCC High is an IT productivity stack. It does not cover PLCs, HMIs, CNCs, SCADA, or any specialized asset on the production floor. Those still need a separate solution.
The ten dimensions that matter at the architecture decision
| Dimension | GCC High | On-Premise Enclave (Trout Access Gate) | Edge |
|---|---|---|---|
| Time to deploy | 9-18 months (tenant procurement, license negotiation, identity migration, app rehost) | 3-6 weeks (appliance install, network integration, policy config) | ON-PREMISE |
| License cost (per user, annual) | $50-90 per user / month for G5 GCC High suite | Flat annual subscription per appliance, no per-seat fees | ON-PREMISE |
| OT and specialized asset coverage | Limited, designed for IT productivity, not industrial control systems | Native, protects PLCs, HMIs, CNCs, SCADA at the network layer | ON-PREMISE |
| Identity backbone | Entra ID (Azure AD) only, single vendor lock | Entra, Okta, AD on-prem, or local, bring your IdP | ON-PREMISE |
| CUI control coverage (NIST 800-171) | about 80% of 110 controls via M365 + GCC High services | 87% via network enforcement + audit-ready evidence packs | EVEN |
| Email and collaboration | Native. Exchange, Teams, SharePoint, OneDrive in CUI-compliant tenant | Not provided, use existing IT email if CUI flows are bounded by enclave | GCC HIGH |
| Compatibility with existing IT | Forces all CUI users into the GCC High tenant, migration of email, identity, files | Coexists with existing M365 commercial, only the CUI flows traverse the enclave | ON-PREMISE |
| Air-gap / disconnected deployment | Cloud-dependent, requires persistent internet to Azure GCC High region | Air-gap supported, appliance runs locally, no outbound cloud calls required | ON-PREMISE |
| FCI vs CUI scope flexibility | All-or-nothing, once in GCC High, all org IT flows through it | Enclave-scoped, protect only the CUI workflows, leave the rest in commercial | ON-PREMISE |
| C3PAO assessment evidence | Microsoft shared responsibility matrix + customer SSP | Per-session logs, policy configs, segmentation baselines, all auditor-ready | EVEN |
9-18 months (tenant procurement, license negotiation, identity migration, app rehost)
3-6 weeks (appliance install, network integration, policy config)
$50-90 per user / month for G5 GCC High suite
Flat annual subscription per appliance, no per-seat fees
Limited, designed for IT productivity, not industrial control systems
Native, protects PLCs, HMIs, CNCs, SCADA at the network layer
Entra ID (Azure AD) only, single vendor lock
Entra, Okta, AD on-prem, or local, bring your IdP
about 80% of 110 controls via M365 + GCC High services
87% via network enforcement + audit-ready evidence packs
Native. Exchange, Teams, SharePoint, OneDrive in CUI-compliant tenant
Not provided, use existing IT email if CUI flows are bounded by enclave
Forces all CUI users into the GCC High tenant, migration of email, identity, files
Coexists with existing M365 commercial, only the CUI flows traverse the enclave
Cloud-dependent, requires persistent internet to Azure GCC High region
Air-gap supported, appliance runs locally, no outbound cloud calls required
All-or-nothing, once in GCC High, all org IT flows through it
Enclave-scoped, protect only the CUI workflows, leave the rest in commercial
Microsoft shared responsibility matrix + customer SSP
Per-session logs, policy configs, segmentation baselines, all auditor-ready
Dimensions where on-prem wins
GCC High wins on email/collab and shared responsibility maturity. On-premise wins on speed, cost, OT coverage, identity flexibility, scope efficiency, and deployment topology. For most small-to-mid defense contractors, on-premise is the better starting architecture. For very large primes, the hybrid model is increasingly the answer.
The right answer depends on your size, your OT footprint, and your existing Microsoft posture.
Small-to-mid defense contractor
10-500 employees, holding 1-5 DoD contracts with CUI. Currently on M365 commercial. Cannot afford the all-org migration to GCC High.
Recommended: On-premise enclaveNext step
Scope the enclave to the engineering/project teams that handle CUI. Leave the rest of the org in commercial M365. 90% cost reduction vs full GCC High migration.
Defense manufacturer with legacy OT
Job-shop CNCs, PLCs, HMIs that handle CUI drawings and production files. GCC High does not cover any of these, wrong product category.
Recommended: On-premise enclaveNext step
Enclave wraps the OT segment plus the engineering workstations that push files to it. CUI never leaves the on-premise boundary. CMMC Level 2 path is enclave-only, no GCC High needed.
Large prime contractor
5,000+ employees, dozens of CUI-handling teams across multiple subsidiaries. Already on GCC High or migrating. Email/collab needs are real.
Recommended: HybridNext step
GCC High for collaboration. On-premise enclave for OT and specialized assets that GCC High cannot cover. Each handles what it's designed for, no architectural compromise.
Air-gap / classified-adjacent operator
Sites that operate offline by policy, naval shipyards, research labs, certain defense plants. Cannot maintain persistent cloud connection.
Recommended: On-premise onlyNext step
GCC High is structurally incompatible. On-premise enclave is the only option that meets both CUI protection and operational reality.
Enclave deployed, C3PAO-ready evidence.
Week 1: asset discovery + scope confirmation. Week 2: install + identity. Week 3: policies + audit logging. Evidence packs delivered every week.
3-6 weeks to enclave-live
Compare to 9-18 months for a GCC High tenant migration with identity and mailbox migration overhead. The CUI protection obligation stands whether or not the CMMC audit is enforced.
Covers what GCC High cannot
PLCs, HMIs, CNCs, SCADA, and any specialized asset on the shop floor. GCC High is an IT productivity stack, it does not reach the production network.
Building toward CMMC Level 2 certification?
The on-premise enclave is one piece of a CMMC L2 architecture. See our CMMC compliance for defense manufacturers with legacy OT for the broader solution, the Respect Your Elders manufacturing-specific landing, and what is CMMC compliance for the framework primer. For the control-layer mechanics, see what is an industrial proxy and PLC security. For the specialized-asset path, see the CMMC enduring exception for OT and replacing a VPN for CMMC compliance.
CUI enclave architecture
NIST 800-171 controls covered
It depends on your data type and your footprint. GCC High is mandatory for ITAR and export-controlled (EAR) data, and it fits organizations already all-in on Microsoft 365. An on-premise CUI enclave fits when you have a manufacturing or OT footprint, want to keep CUI off the cloud, need coverage for specialized and legacy assets that GCC High cannot reach, and want a faster, lower-friction path: it deploys in 3 to 6 weeks and covers roughly 87 of the 110 NIST SP 800-171 controls. Trout's Access Gate delivers the on-premise enclave, enforcing those controls at the network layer, including the OT and specialized assets GCC High cannot reach. Many contractors run both: GCC High for office productivity, Trout's on-premise enclave for the plant floor and specialized assets.
A CUI enclave is a logically separated environment within an organization's network that contains all systems and data subject to NIST SP 800-171 control requirements. The enclave is bounded by network controls, identity controls, and audit logging, only authorized users and processes can enter, and all traffic is recorded. The rest of the organization's IT environment can remain on commercial-grade infrastructure. The enclave approach is recognized in DoD CMMC guidance as a valid scope-reduction strategy: instead of treating the entire org as CUI-handling, you treat only the enclave that way.
GCC High is Microsoft's government-cloud tenant for Department of Defense contractors. It runs M365 (Exchange, Teams, SharePoint, OneDrive) in a dedicated infrastructure that meets DFARS 7012 and supports CUI workflows. It became the default CMMC path because it solves the email/collaboration side of CUI handling, but it forces the entire CUI user population into the GCC High tenant, with license, identity, and operational consequences that many small-to-mid contractors find prohibitive.
Four scenarios. (1) When your CUI flows include OT, PLCs, CNCs, or specialized assets that GCC High does not cover. (2) When most of your organization does not handle CUI, paying GCC High licenses for hundreds of non-CUI users is wasted budget. (3) When you operate disconnected or air-gapped sites that cannot maintain cloud connectivity. (4) When the migration cost and timeline to GCC High is incompatible with the contract deadline driving CMMC certification.
Yes, and for many large primes this is the practical answer. GCC High handles email, Teams, and collaboration for the CUI-handling user population. The on-premise enclave handles OT, specialized assets, and CUI flows that originate or terminate outside of M365 productivity tools. The two architectures coexist; the C3PAO assesses each scope against the relevant controls. This is increasingly the dominant architecture for primes with both modern IT and traditional manufacturing footprints.
Access Gate enforces 87 of the 110 controls directly at the network layer: access control (AC), audit and accountability (AU), identification and authentication (IA), system and communications protection (SC), system integrity (SI). The remaining ~23 controls require organizational measures (personnel security, physical, training) or customer-owned process controls. Every covered control generates auditor-ready evidence on demand, session logs, policy configurations, segmentation baselines, denied-access records.
3-6 weeks for a single-site enclave. Week 1: asset discovery and scope confirmation (which workflows, which users, which OT assets are in scope). Week 2: appliance installation and network integration, identity provider connection. Week 3: policy configuration, MFA enforcement, audit logging activation. Week 4: evidence package generation, SSP draft alignment, internal review. Weeks 5-6: remediation cycles and pre-C3PAO walkthrough. Compare to 9-18 months for a GCC High tenant migration with identity and data migration overhead.
GCC High is the safer default for ITAR and export-controlled EAR technical data, because it provides US-person-only access controls and a data-residency guarantee inside a DoD-authorized cloud boundary. An on-premise enclave can hold ITAR/EAR data as well, but the burden shifts to you: the enclave must enforce US-person access at the identity layer, keep the data physically on US soil under your control, and log every access for the export-control record. Access Gate binds every session to a named identity from your IdP and records it, which supplies the access-control and audit evidence an export-compliance program needs. Many contractors keep ITAR email and collaboration in GCC High and use the on-premise enclave for the ITAR-marked drawings that live on the shop floor and in the machine-tool workflow, where GCC High cannot reach.
Not directly, and it does not need to be. FedRAMP Moderate is an authorization framework for cloud service offerings; an on-premise enclave is not a cloud service, so FedRAMP does not apply to it. What a C3PAO actually assesses for CMMC Level 2 is whether the NIST SP 800-171 controls are met, and DFARS 252.204-7012 requires that any cloud service used to store or process CUI meet the FedRAMP Moderate baseline or equivalent. Keeping CUI inside an on-premise enclave keeps those flows out of the cloud entirely, so the FedRAMP-equivalence question narrows to only the specific cloud services you still use. This is a scope-reduction move, not a FedRAMP substitute.
Scope reduction works by drawing the CUI boundary as small as defensibly possible. Assets fall into categories the CMMC scoping guidance recognizes: CUI assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets such as OT and IoT. Anything that does not store, process, or transmit CUI, and is separated from the CUI enclave by Access Gate enforcement, is out of the CUI assessment scope. In practice you place the engineering workstations, the machine tools that receive CUI drawings, and the CUI file share inside the enclave, and everything else stays on commercial M365 as out-of-scope. Fewer in-scope assets means fewer controls to prove and a smaller, cheaper, faster assessment.
You do not retire it, and you do not pretend it complies. Machine tools are Specialized Assets under the CMMC scoping guidance, and the recognized path is a compensating control documented as an enduring exception with a Plan of Action and Milestones (POA&M) entry in your System Security Plan. Access Gate is the compensating control: it sits in front of the control, enforces identity, allowlists the specific commands the workflow needs, denies the rest, and logs every session, so the asset that cannot itself do access control, audit, or identification gets those controls applied at its boundary. A CNC control cannot run an MFA client, so nothing is installed on it: Access Gate brokers the operator or vendor session and performs the MFA, and the controller never sees the authentication and is never modified.
Yes, and that is usually the first thing it removes. A VPN extends your network to a person; the enclave extends one authorized action to one asset and nothing else. A remote engineer or an OEM vendor authenticates through Access Gate, gets a time-bound session to exactly the one control or workstation the job requires, at the command level, and the session is recorded. There is no flat tunnel into the CUI segment and no standing vendor account waiting to be harvested.