sha3:52eff920c3863dc1274db389b0d00ef974afa03ad2d2a27e37c1b6b83158473fIntactdfd33846de014038b41b5e8afb5a0a5a190efafd5ddaff0b447cbeaa9a0839feprev:b3097dbe21b8RegisterGlossary
What is CUI Enclave?
A CUI enclave is a segmented, hardened environment that isolates CUI so only that boundary, not the whole company, falls in CMMC scope.
244328c2bd3cb73159e77cb312d1a768f7de75cea68aed09acb94d0fd934b957prev:dfd33846de01A CUI enclave is a deliberately scoped environment (often a dedicated cloud tenant or GCC High environment) where all CUI is stored, processed, and transmitted. Everything outside the enclave stays out of assessment scope.
Enclaves are the dominant cost-control strategy: rather than bringing an entire corporate network up to 110 controls, a contractor secures a much smaller boundary. Enclave seats commonly run $150–$300 per user per month.
Over-scoping — failing to segment CUI into an enclave — is the most common reason small contractors overspend on CMMC.
52eff920c3863dc1274db389b0d00ef974afa03ad2d2a27e37c1b6b83158473fprev:244328c2bd3cRelated records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Related terms and reading
Know the term. Then see the record behind it.
- Sealed
- Last amended