This guide includes insights from a webinar hosted by GraVoc’s Director of Information Security, Brian Brunelle, alongside Joe Kurlanski of Monarch, a certified C3PAO.
When defense contractors begin preparing for CMMC Level 2, the most common point of confusion and errors is scoping. Under CMMC Level 2, there are two ways to scope your environment and define your CUI boundary: an enclave approach, which isolates a subset of your environment for CUI, and an enterprise approach, which brings your entire organization into scope.
In our experience guiding contractors through CMMC readiness, most organizations fall into one of two traps. Some default to the enterprise approach to “play it safe,” not realizing the cost and operational impact of pulling every user and system into scope. Others under-scope without fully mapping how CUI flows through their environment, which creates compliance gaps that surface during assessment. Over-scoping drives up unnecessary cost, which can be a concern for smaller defense contractors already stretched by compliance budgets. On the other hand, under-scoping puts your certification and your DoD contracts at risk.
In this post, we break down the difference between enclave and enterprise scoping for CMMC Level 2, the advantages and trade-offs of each, and how to decide which strategy fits your business.
If you're early in your CMMC journey and want to understand requirements, cloud strategy, and certification outcomes, start with our full CMMC Level 2 compliance guide.
What is the difference between CMMC Level 2 enterprise vs enclave scoping?
According to Brian, the enterprise approach brings your entire organization in scope. The enclave approach, on the contrary, puts a subset of your environment in scope.
The big difference is that in the enterprise approach, every user, system, and workflow across your business is subject to CMMC Level 2 controls. The enclave approach, however, isolates a defined subset of your environment where the Controlled Unclassified Information (CUI) will live, so only the systems, users, and processes inside that boundary are in scope.
Although the enclave approach can be more cost-effective, it’s important to note that your boundary will be thoroughly tested during an assessment to make sure CUI does not leak outside the enclave. Having conducted many CMMC Level 2 gap assessments, Brian says assessors don’t go easy on reviewing the boundary, "It's not just going to be, okay, you wrote down everything correctly. It's have you segmented your network correctly? We're going to test boundary controls, inbound and outbound firewall rules and connections, other network protocols. Those are all going to be tested to make sure that enclave really is that enclave and there’s no data leakage outside of that."
The thing you should remember is that enterprise pulls more of your organization in scope but keeps the operating model relatively simple. Enclave keeps the footprint smaller but demands more precision in how you maintain the boundary day to day.
Pros & cons of the enterprise approach
Joe says that the enterprise approach is what most contractors default to when they first start thinking about CMMC because they don’t want to worry about where their data or CUI will live. Going enterprise-wide simplifies a lot of things, but it also pulls every user, system, and process into the CMMC scope, which has real cost and operational consequences.
Where the enterprise approach works:
- One environment, one set of rules. Same controls and policies are applied across the entire business, which reduces complexity.
- Simpler day-to-day management: You’re not dividing your resources to manage two environments or two sets of documentation.
- Cleaner audit when CUI is everywhere: If most of your business is tied to CMMC contracts or all your users touch CUI, then an enterprise-wide approach is the best fit.
Where the enterprise approach gets expensive or complex:
- Higher cost: Every user, every endpoint, every system is in scope, which will drive up the cost of licensing, tooling, assessment, and more.
- More user disruption: Every employee operates under CMMC controls, even ones who never touch CUI. That has implications for productivity, training, and change management.
- Often chosen reactively, not strategically: This is the one we see most. Contractors pick enterprise-wide to “play it safe” without fully understanding the cost. Brian’s point is worth repeating here that contractors should look at scoping as a strategy decision. Going enterprise-wide because you didn’t want to think about scoping is the most expensive strategy.
Pros & cons of the enclave approach
The enclave approach is often the first thing defense contractors naturally gravitate toward once they realize the cost of going enterprise-wide. Enclave involves putting a subset of your environment in scope, so the lift feels smaller. But as Brian points out, “People hear subset and when you think about cost, you think, okay, cheaper, easier, more streamlined. That’s partially the case depending on the environment.” Whether an enclave is the right fit depends a lot on your team, your environment, and how disciplined you are about the boundary.
Where the enclave approach works:
- Lower cost in most environments: You’re applying CMMC Level 2 controls to a smaller surface or subset of your environment, which usually translates to lower costs and user disruption.
- Less user disruption: Only the people who touch CUI must operate under the stricter controls. The rest of your organization keeps working the way it always has.
Where the enclave approach gets harder than people expect:
- You’re now managing two environments: That’s two sets of controls, two user experiences, and two operational workflows to maintain.
- It demands a mature IT and security operation: Whether it’s your internal team or your managed service provider (MSP), someone must be able to maintain the controls inside the enclave and outside of it without letting CUI leak across the boundary.
- Documentation gets heavier: You’ll need a clearly scoped system security plan (SSP), a formal boundary statement, a CUI asset inventory, network and data flow diagrams, and often separate incident response and business continuity plans for the enclave itself.
- There’s a risk of under-coping: We’ve seen contractors get halfway through readiness and realize the enclave wasn’t scoped correctly, or that CUI flows through more of the business than they thought. At that point, you’re either expanding the enclave or rethinking your approach altogether.
Want to hear how CMMC experts think about scoping?
Watch this clip from our webinar with Monarch ISC's Joe Kurlanski and GraVoc's Brian Brunelle, where they discuss enclave vs enterprise scoping, the most common mistakes assessors see, and how to build a scoping strategy.
Enterprise vs enclave: Which approach is right for your organization?
Both Brian and Joe stress that CMMC Level 2 scoping should be driven by strategy, not price. The right approach depends on how much of your business touches CUI, how mature your team and security program is, and how central CMMC contracts are to your revenue.
Brian explained, “If you are a fifteen-person manufacturing company and every person in your in your operation works on a CMMC contract, okay, great. You’re clearly going to go with an enterprise-wide approach. If you’re a much larger organization and you have one department that works on CMMC contracts, that’s certainly a different decision.”
Here are a few questions to ask as you decide between enclave vs enterprise:
Enterprise tends to be the right call when:
- CMMC contracts drive a significant share of your revenue or headcount
- Most or all of your employees interact with CUI in some form
- You don’t have the internal or MSP-backed capacity to maintain two parallel environments
- You’d rather absorb the higher cost than manage the ongoing complexity of a boundary
An enclave tends to be the right choice when:
- Only a specific team, department, or system handles CUI
- You have a lower percentage of CMMC-related revenue relative to the rest of the business
- Budget is a real constraint, and you need to keep scope tight
- Your team or your MSP has the operational maturity to run and defend two environments
Brian sums it up perfectly, “If you have a lower percent of users, less of a budget and your operational security or maturity might be lower, maybe an enclave is more appropriate. And again, you know, vice versa, it’s true, of course, if most of your business is tied to CMMC, then you want to go with that enterprise approach.”
Key takeaways
- Scoping is a strategy decision, not a price decision. The enclave-vs-enterprise call shapes your cost, your operational complexity, and your assessment experience. Making it based on budget alone is the most expensive way to end up in scope.
- Enterprise-wide fits when CMMC is core to your business. If most of your users, revenue, or operations touch CMMC contracts, or if you don't have the internal capacity to run two parallel environments, enterprise gives you a simpler operating model and a uniform security posture.
- Enclave fits when CUI lives in a defined subset. If only a specific team or system handles CUI, and you or your MSP have the maturity to maintain a segmented boundary, an enclave keeps your footprint smaller, your cost lower, and your attack surface tighter.
- An enclave demands more precision, not less. Smaller scope doesn't mean less work. You'll need a defensible boundary, tighter documentation, and the operational discipline to manage two environments in parallel.
- Your boundary will be tested rigorously. Assessors don't just read your plan. They test firewall rules, network segmentation, and data flow to confirm CUI isn't leaking outside the enclave.
- CUI flow mapping should come before your scoping decision. Email, desktops, printed documents, cloud storage, third-party sharing — every path CUI takes has to be accounted for before you make the enclave-vs-enterprise decision. If you haven't done CUI mapping yet, a CMMC gap assessment will give you a clear picture of where CUI lives and how to scope your environment.