TroutTrout

CUI enclave: protect CUI from cloud to machine.

On-premise, GCC High, or both, for CMMC Level 2.

A CUI enclave is a bounded part of your network that holds every system handling CUI. Access control, encryption and audit logging guard its edge, so only the enclave is in CMMC Level 2 assessment scope. Access Gate builds the on-premise enclave in a day.

Last updated:

CUI enclave, defined

What is a CUI enclave?

A CUI enclave is a scoped security boundary inside your network. Everything inside it handles Controlled Unclassified Information and must meet the 110 requirements of NIST SP 800-171 Rev. 2. Everything outside it does not handle CUI.

The enclave works because CMMC does not ask you to apply 800-171 to the whole company. The DoD CMMC Level 2 Scoping Guide lets a contractor take its certification assessment on a specific enclave rather than the entire enterprise. Assets kept apart from it by logical or physical separation fall out of scope.

An enclave is an architecture, not a product. It can live in the cloud, on site, or both. CMMC Phase II audits are suspended, but the obligation to protect CUI under DFARS 252.204-7012 and NIST SP 800-171 still stands.

Scope

What goes inside a CUI enclave?

Every system that stores, processes or transmits CUI goes inside. Your ERP, corporate email, guest Wi-Fi and general IT network can stay outside, unless they touch CUI too. The asset categories come from 32 CFR 170.19, the CMMC scoping rule.

Engineering workstations

The machines that open technical data packages, ITAR drawings and specifications.

CUI file storage

The file server or NAS where CUI rests on site.

Machines that receive CUI

CNC controls, printers and test rigs that load drawings or NC programs.

The boundary and its logs

The enforcement point at every entry, and the audit trail it writes.

Diagram showing GCC High covering cloud collaboration tools and an on-premise CUI enclave covering the engineering workstation, CNC machine, network printer and file server, with an Access Gate on the enclave boundary
GCC High ends at the browser. The enclave picks CUI up where it lands: on paper, on a machine, on a local disk.
NIST SP 800-171 mapping

Which controls does the enclave enforce?

Five technical components build the enclave. None of them is exotic, and each maps to a NIST SP 800-171 family. Encryption must use modules listed by the NIST Cryptographic Module Validation Program. Access Gate enforces 87 of the 110 controls at the network layer.

Component800-171 familyRequirementEvidence for the assessor
Network separationSC 3.13.1, 3.13.6A distinct segment. Traffic in or out crosses one controlled boundary; deny by default.Segmentation baseline, boundary policy, denied-connection records.
Access control and identityAC 3.1.x, IA 3.5.xNamed accounts, MFA at the boundary, least privilege per role and per machine.Per-session identity, MFA events, access policy per asset.
EncryptionSC 3.13.8, 3.13.11CUI encrypted in transit and at rest with FIPS-validated cryptography.Module certificate on the NIST CMVP list, tunnel configuration.
Audit loggingAU 3.3.xLogins, file access, connections and admin changes recorded, protected and reviewed.Session logs and recordings, exportable on demand.
Hardening or compensating controlCM 3.4.x, SI 3.14.xSecure baselines on every system. Where a machine cannot be hardened, the boundary compensates.Baseline records, or an enduring exception documented in the SSP.

Legacy machines that cannot be patched still fit. A 20-year-old PLC or a proprietary HMI cannot be hardened, but it can be isolated and monitored. The enclave boundary becomes its compensating control, documented as a CMMC enduring exception for OT.

On-premise enclave vs GCC High

On-premise or GCC High enclave?

Most defense manufacturers need both. GCC High protects CUI while people collaborate on it. An on-premise enclave protects it once it reaches a printer, a CNC machine or a local file server. Read the table as a map of what each one reaches.

What it covers

GCC High

CUI in email, Teams, SharePoint and OneDrive, while people work on it.

On-premise enclave

CUI on engineering workstations, machine tools, printers, file servers and the OT network.

Both

The whole path, from the cloud tenant to the machine and back.

Where CUI lives

GCC High

Microsoft Azure Government data centers.

On-premise enclave

On your premises, under your physical control.

Both

In the tenant for collaboration, on site once it reaches the plant.

Cost model

GCC High

A licence per user, per month, for everyone in the tenant.

On-premise enclave

A flat annual subscription per appliance. No per-seat fees.

Both

User licences only for the people who collaborate on CUI, one appliance per plant.

Time to deploy

GCC High

A tenant migration. Mailboxes, files and identities move, and users learn new tools.

On-premise enclave

Access Gate is installed in a day. The enclave is complete in a week.

Both

Access Gate in a day, connected to a managed tenant such as CUI Vault.

Machines and legacy OT

GCC High

Out of reach. GCC High stops at the browser.

On-premise enclave

Covered at the network layer. Nothing is installed on the machine.

Both

Jobs travel from the tenant to the machine over a FIPS 140-3 validated tunnel.

Connectivity

GCC High

Needs a steady internet link to Azure Government.

On-premise enclave

Runs air-gapped. No outbound cloud calls required.

Both

The tenant needs internet. The plant side runs locally.

Who runs it

GCC High

Microsoft runs the platform. You configure the tenant.

On-premise enclave

You or your MSSP run the appliance and its physical security.

Both

A managed provider runs the tenant. You run the appliance.

Assessment evidence

GCC High

Microsoft shared responsibility matrix plus your SSP.

On-premise enclave

Session logs, policy configs and segmentation baselines, on demand.

Both

One System Security Plan covering the tenant, the tunnel and the plant.

What GCC High does well.

Microsoft runs and patches the platform, and the cloud carries physical and infrastructure controls for you. Backup and recovery are built in. For CUI that lives in email and documents, it is the natural home.

What the on-premise enclave asks of you.

You or your MSSP keep the appliance updated and physically secure. Backup follows the strategy your plant already runs. In return, CUI never leaves your control and the floor is covered.

Decision criteria

Which signals point to each one?

Match your environment row by row. If you match rows on both sides, you need both layers.

SignalPoints to GCC HighPoints to an on-premise enclave
Where CUI livesEmail, SharePoint, Teams and Microsoft 365 documents.Engineering workstations, machine tools, printers and local file servers.
Who touches itPeople collaborating, reviewing and approving.Machines executing, and the operators loading work onto them.
Systems in scopeModern, cloud-capable systems.Legacy systems that cannot migrate or be patched, like 20-year-old PLCs.
ConnectivityReliable internet to Azure Government.Air-gapped, intermittent or deliberately isolated plant networks.
Headcount in scopeA small, defined group of people handles CUI.CUI reaches the floor, whatever the headcount.

Small-to-mid defense contractor

10 to 500 employees, one to five DoD contracts with CUI, on Microsoft 365 commercial today.

Recommended: On-premise enclave

Next step

Scope the enclave to the engineering and project teams that handle CUI. Everyone else stays on commercial Microsoft 365, with no per-seat fees for people who never touch CUI.

Defense manufacturer with legacy OT

CNCs, PLCs and HMIs that receive CUI drawings and production files. No cloud tenant can reach them.

Recommended: On-premise enclave

Next step

The enclave wraps the OT segment and the workstations that push files to it. If CUI never needs cloud collaboration, the enclave carries the whole scope.

Large prime contractor

Thousands of employees and many CUI-handling teams. Already on GCC High or moving there.

Recommended: Both

Next step

GCC High for collaboration. The on-premise enclave for OT and specialized assets. One SSP covers both.

Air-gapped or isolated plant

Shipyards, research labs and plants that run offline by policy and cannot hold a cloud connection.

Recommended: On-premise only

Next step

A cloud tenant cannot reach these networks. The on-premise enclave runs locally, with no outbound cloud calls.

Cloud enclave plus plant enclave

How do GCC High and the enclave work together?

The common gap is stopping after the cloud half. A manufacturer moves email and SharePoint to GCC High and covers collaboration. Technical data packages still land on a shared drive and reach machine tools by USB.

GCC High covers the desk. The on-premise enclave covers the floor. When CUI is printed, exported or loaded onto a machine, the enclave authenticates the person, limits what they reach, encrypts the path and records the session.

Trout and CUI Vault connect the two. CUI Vault, from NtelSec, runs a managed GCC High enclave. It connects to Access Gate over a FIPS 140-3 validated site-to-site tunnel. A job goes from the enclave to the printer or CNC without landing on a workstation, and machine output returns the same way. Both sides report to one System Security Plan. Read the Trout and CUI Vault announcement and how the last hop works.

3-week pilot

The pilot delivers C3PAO-ready evidence.

Week 1: asset discovery and scope confirmation. Week 2: install and identity. Week 3: policies and audit logging. Evidence packs every week.

Done

Installed in a day, complete in a week.

The enclave wraps existing systems instead of migrating them. Nothing moves and no workflow changes.

The enclave covers what GCC High cannot reach.

PLCs, HMIs, CNCs, SCADA and every specialized asset on the shop floor.

Related reading

Building toward CMMC Level 2?

The enclave is one piece of a CMMC Level 2 architecture. See CMMC compliance for defense manufacturers with legacy OT and what CMMC compliance requires. For the control layer, see what an industrial proxy is and PLC security. For remote access into the enclave, see a FIPS-validated VPN for CMMC.

Sources: NIST SP 800-171 Rev. 2, DoD CMMC Level 2 Scoping Guide, 32 CFR 170.19, DFARS 252.204-7012, NIST CMVP.

CUI enclave questions

Common questions about CUI enclaves.

87/110

NIST 800-171 controls covered

A CUI enclave is a bounded part of your network that holds every system that stores, processes or transmits Controlled Unclassified Information. Access control, encryption and audit logging guard its boundary, and only authorized people and processes get in. The DoD CMMC Level 2 Scoping Guide lets a contractor take its certification assessment on a specific enclave rather than the whole enterprise, so the rest of the company stays out of scope.

Yes, and for most suppliers that is the realistic shape. GCC High holds CUI on the IT side: email, documents and collaboration. It cannot enforce anything once that CUI has to reach a plant. An NC program going to a machine tool, a drawing opened on an operator station, or a print job on a shop-floor printer all leave the cloud boundary. The on-premise enclave picks up the flow there. Trout and CUI Vault connect a managed GCC High environment to Access Gate over a FIPS 140-3 validated site-to-site tunnel, so a job goes from the enclave to the machine without landing on a workstation.

Four cases. When CUI reaches OT, PLCs, CNCs or other specialized assets, which no cloud tenant can reach. When most of the company never handles CUI, so tenant-wide licences buy nothing for most users. When plants run air-gapped or offline. And when the CMMC timeline cannot wait for a tenant migration. In the first case the enclave usually runs alongside a GCC High tenant rather than replacing it.

GCC High is Microsoft's government cloud for defense contractors. It runs Exchange, Teams, SharePoint and OneDrive in dedicated infrastructure that supports DFARS 252.204-7012 and CUI workflows. It became the default because it solves the email and collaboration side of CUI. It also moves every CUI user into the GCC High tenant, with the licence, identity and migration work that implies.

Access Gate enforces 87 of the 110 NIST SP 800-171 controls at the network layer, across access control (AC), audit and accountability (AU), identification and authentication (IA), system and communications protection (SC) and system integrity (SI). The remaining controls are organizational: personnel security, physical protection, training and your own processes. Every covered control produces evidence on demand: session logs, policy configurations, segmentation baselines and denied-access records.

Access Gate is installed in a day, and a single-site enclave is complete in a week. Day 1: install the appliance, connect it to the network and to your identity provider. Days 2 and 3: confirm scope (which workflows, users and machines), then configure policy, MFA and audit logging. Days 4 and 5: assemble the evidence package, align the SSP and review internally. Nothing migrates, so no workflow changes.

32 CFR 170.19 sorts assets into CUI assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope Assets. An asset that cannot store, process or transmit CUI, and is logically or physically separated from the enclave, is out of scope. In practice the engineering workstations, the machines that receive CUI drawings and the CUI file share sit inside the enclave. Everything else stays outside. Fewer assets in scope means fewer controls to prove and a smaller assessment.

You do not retire it, and you do not pretend it complies. Machine tools are Specialized Assets under CMMC scoping, documented in the SSP and managed under your risk-based policies. Access Gate is the compensating control. It sits in front of the controller, enforces identity, allows only the commands the job needs and logs every session. A CNC control cannot run an MFA client, so Access Gate performs the MFA and nothing is installed on the controller.

GCC High is the common default for ITAR and EAR technical data, because it offers US-person support and US data residency inside a DoD-authorized cloud. An on-premise enclave can hold ITAR and EAR data too, but the burden is yours. It must enforce US-person access at the identity layer, keep the data on US soil under your control, and log every access. Access Gate binds each session to a named identity from your IdP and records it. Many contractors keep ITAR email in GCC High and use the enclave for the ITAR drawings that live on the shop floor.

It does not need to be. FedRAMP is an authorization program for cloud services, and an on-premise enclave is not a cloud service. DFARS 252.204-7012 requires a cloud service that stores or processes CUI to meet the FedRAMP Moderate baseline or equivalent. Keeping CUI inside an on-premise enclave keeps those flows out of the cloud, so the question narrows to the cloud services you still use. It is a scope decision, not a FedRAMP substitute.

It replaces the flat VPN route into the CUI segment. The encrypted link stays: Access Gate CMMC Edition includes a FIPS-certified VPN that ends at the gate. A remote engineer or vendor authenticates through Access Gate and gets a time-bound session to the one machine the job requires, and the session is recorded. There is no flat tunnel into the CUI segment and no standing vendor account.