---
title: "What Is CUI Enclave? CMMC Definition"
description: "A CUI enclave is a segmented, hardened environment that isolates CUI so only that boundary, not the whole company, falls in CMMC scope."
url: https://policycortex.com/cmmc/glossary/enclave
sealed: 2026-07-02
amended: 2026-09-03
register: cmmc/glossary/enclave
records: 3
digest: sha3:52eff920c3863dc1274db389b0d00ef974afa03ad2d2a27e37c1b6b83158473f
---

# What is CUI Enclave?

Register / Glossary

A CUI enclave is a segmented, hardened environment that isolates CUI so only that boundary, not the whole company, falls in CMMC scope.

Sealed 2026-07-02 · Amended 2026-09-03

A CUI enclave is a deliberately scoped environment (often a dedicated cloud tenant or GCC High environment) where all CUI is stored, processed, and transmitted. Everything outside the enclave stays out of assessment scope.

Enclaves are the dominant cost-control strategy: rather than bringing an entire corporate network up to 110 controls, a contractor secures a much smaller boundary. Enclave seats commonly run $150–$300 per user per month.

Over-scoping — failing to segment CUI into an enclave — is the most common reason small contractors overspend on CMMC.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Related terms and reading

| Entry |
|---|
| [CUI: Controlled Unclassified Information](https://policycortex.com/cmmc/glossary/cui): CUI is government-created or -owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified. |
| [NIST SP 800-171](https://policycortex.com/cmmc/glossary/nist-800-171): NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2. |
| [DFARS 252.204-7012](https://policycortex.com/cmmc/glossary/dfars-7012): DFARS 7012 is the long-standing clause requiring contractors to safeguard covered defense information per NIST 800-171 and report cyber incidents within 72 hours. |
| [CMMC Cost Calculator](https://policycortex.com/tools/cmmc-cost-calculator) |

Know the term. Then see the record behind it. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2026-07-02
- **Last amended**: 2026-09-03
- **Record**: https://policycortex.com/cmmc/glossary/enclave

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | dfd33846de01 | b3097dbe21b8 |
| REC 0001 | DEFINITION | 244328c2bd3c | dfd33846de01 |
| REC 0002 | RELATED RECORDS | 52eff920c386 | 244328c2bd3c |

Head sha3:52eff920c3863dc1274db389b0d00ef974afa03ad2d2a27e37c1b6b83158473f. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
