Cybersecurity Journey: Building a Secure CMMC Enclave to Protect CUI
What’s New (Updated CUI Scoping & Enclave Requirements)
This blog reflects current CMMC enforcement following publication of the DFARS acquisition rule in September 2025, effective November 10, 2025. Organizations handling Controlled Unclassified Information (CUI) must now demonstrate compliant scoping, enclave design, and evidence-backed implementation at contract award. This post updates references to CMMC that previously described the program as imminent or upcoming.
Understanding CMMC Requirements in Today’s Compliance Environment
Get ready to take charge of your Cybersecurity Maturity Model Certification (CMMC) compliance journey by establishing a strong foundation for success in the evolving landscape of defense contracting. With CMMC now enforced through DoD solicitations, one of the crucial initial steps involves determining the scope of the systems responsible for handling controlled unclassified information (CUI).
This process often leaves organizations searching for clarity to define what’s within the boundaries for evaluation and what falls outside. Under active enforcement, improper scoping or unclear enclave boundaries can directly impact assessment outcomes and contract eligibility.
In a recent Exostar webinar with trusted partner RSM US LLP, we covered the essential skills required to confidently answer this critical question and properly scope and build your secure CUI enclave. Watch the recording for valuable insights and practical strategies to address CMMC compliance issues and support assessment-ready implementation.
This webinar can help elevate your organization’s cybersecurity posture and tackle NIST 800-171/CMMC compliance issues. Topics covered include:
- Identifying your boundary: Understand compliance scope, manage data flow efficiently, and gain practical techniques to achieve compliance
- Building your secure CUI enclave: Strengthen security with architectural principles, technical controls, and alignment with CMMC/NIST 800-171
- Enclave security design costs and considerations: Make informed design choices, optimize compliance, and streamline the process with expert insights on security and cost drivers and solutions.
With CMMC’ now in effect and requirements appearing in DoD solicitations, be prepared to meet compliance standards and thrive in the ever-evolving cybersecurity and compliance landscape. Under active CMMC enforcement, the consequences of non-compliance include ineligibility for contract award, operational disruption, and increased security risk.
What Is a CUI Enclave?
A CUI enclave is a defined, access-controlled environment where an organization stores, processes, or transmits Controlled Unclassified Information. Instead of allowing CUI to move across general business systems, an enclave limits that activity to approved users, applications, devices, and workflows.
For defense contractors, this matters because CMMC requirements and NIST SP 800-171 controls apply to the systems and components that handle CUI, as well as the systems that protect them. A secure CUI enclave helps establish a clear boundary around those assets, making it easier to document where CUI lives, who can access it, and which controls apply.
Your Relationship With CUI and Its Impacts on Your Business
External factors:
- Your Customers — agencies you work with
- Your Partners — your primes and subs as well as their requirements to work together
- Your Contracts — clauses that are already in your contracts
- Your Future — where your business will be in 2-3 years
Internal factors
- Your Data
- Do you have CUI?
- Do you have export-controlled data?
- Can you segment it from the rest of the organization?
- Your People
- Who directly interacts with CUI? Who indirectly interacts with CUI?
- Which systems store, process, or transmit data?
- Your Sources
- Where do you get CUI or send it inside and outside of your organization?
To better understand CUI, consider the following categories and examples:

CUI data flow diagrams demonstrate that the organization has a comprehensive understanding of the interconnected business processes handling CUI. This helps ensure that associated business processes are not missed and provides insight on where to apply relevant, mandated regulatory controls.
Drivers of your strategy include the level of knowledge of the business and the data, technical debt, documentation, any previous investments, resources, expertise, and availability.
Costs can be direct, such as internal resources and consultants, or indirect, such as organizational impact beyond IT and business process changes.
CMMC Enclave vs. Full-Environment Compliance: Understanding Your Options
One of the first CMMC scoping decisions defense contractors must make is whether to build a CMMC enclave for CUI or bring the full corporate environment into compliance. A CMMC enclave creates a defined, access-controlled environment for the systems, users, and workflows that store, process, or transmit CUI.
In contrast, full-environment compliance applies CMMC requirements across the broader enterprise ecosystem. There are benefits to this approach, but the trade-offs include greater implementation complexity, higher remediation costs, more systems and users in the assessment scope, and a longer path to documented compliance.
Turning to a managed, enclave-based solution like Exostar Managed on Microsoft 365™ can help mitigate potential risks associated with full-environment compliance.

Building Out a Secure CMMC Enclave and How to Best Protect Data
In the webinar recording, we go through the details of a secure enclave build-out, including the following steps:
- Discover — CMMC Readiness Assessment
- Design — POAM and SSP development
- Deploy — Training and organizing team members
- Optimize — Joint surveillance
You’ll also learn how to protect sensitive data using tools such as sensitivity labels, which classify and protect corporate documents and files without limiting user productivity or secure collaboration.
We go on to explore how different vendor capabilities fit into the enclave model, including identity and threat protection, device and application management, and information protection and governance. Finally, you’ll see how these elements work together within the Microsoft tools your organization may already use.
If your organization is unsure whether its CUI scoping or CUI enclave design will withstand assessment scrutiny under the Final Rule, now is the time to reassess. Explore structured approaches that help defense contractors define boundaries, document controls, and prepare assessment-ready evidence.
Schedule a conversation with a cybersecurity expert at Exostar® for information about the best solutions for your organization.
What Your Company Needs To Do Now
Organizations should confirm whether CMMC Level 2 requirements apply to their contracts, clearly document CUI scope and enclave boundaries, and ensure SSPs accurately reflect where CUI is stored, processed, and transmitted. Validate that enclave controls align with NIST SP 800-171, assign ownership for enclave governance, and prepare evidence demonstrating segmentation and access control. Proper scoping now reduces risk during self-assessment or C3PAO evaluation.