Most defense contractors don't need to drag their entire network through 110 security controls. A secure enclave isolates the systems that actually touch Controlled Unclassified Information in a purpose-built, compliant environment — so the assessment boundary shrinks, the cost drops, and the timeline moves from years to weeks. Essendis designs, builds, and operates CMMC secure enclaves on Microsoft GCC High. One of them just carried a client to a perfect 110/110 Level 2 assessment.
Scope Your EnclaveA CMMC secure enclave is a segregated environment built specifically to store, process, and transmit Controlled Unclassified Information. Instead of applying the 110 NIST SP 800-171 controls to every laptop, server, and application you own, you concentrate CUI — and the controls that protect it — inside one well-instrumented boundary: encrypted at rest and in transit, gated by strict identity and access management, continuously logged and monitored. Everything outside the enclave stays out of your assessment scope. That's the entire strategy. For most contractors, enterprise-wide compliance means remediating years of accumulated IT decisions; an enclave means certifying a clean, purpose-built environment. Unless CUI genuinely flows through every corner of your business, the enclave wins on cost, speed, and audit surface.
Any organization in the DoD supply chain that handles CUI — primes and subcontractors alike — is the obvious candidate: CMMC Level 2 applies wherever that data lives, and an enclave is the fastest defensible way to contain it. But the same architecture serves anyone holding high-sensitivity data under strict compliance obligations: ITAR technical data, regulated health or financial information, criminal-justice data. If you face requirements under any of these frameworks, an enclave is worth a serious look:
HIPAA/HITECH
HITRUST
ISO/IEC 27001
SOC 1 (SSAE 16/SSAE 18)
Payment Card Industry Data Security Standard (PCI-DSS)
SOC 2 (AT-101)
California Consumer Privacy Act (CCPA)
Criminal Justice Information Services (CJIS)
Defense Federal Acquisition Regulation Supplement (DFARS)
NIST SP 800-171
Federal Information Security Management Act (FISMA)
Federal Risk and Authorization Management Program (FedRAMP)
General Data Protection Regulation (GDPR)
Personal Information Protection and Electronic Documents Act (PIPEDA)
NIST CyberSecurity Framework (CSF)
NIST SP 800-53
CMMC 2.0
International Traffic in Arms Regulations (ITAR)
You can build your own enclave: license GCC High, configure the tenant, harden every workload, write the policies, and generate the evidence. Contractors who go that route discover that the licensing alone is a specialty — GCC High is sold through a small circle of authorized partners, with eligibility validation and licensing rules that surprise first-timers — and the configuration work assumes deep familiarity with both Microsoft's government cloud and the assessment objectives a C3PAO will actually test. Budget a year or more of skilled internal effort, then plan for the permanent burden after go-live: patching, monitoring, evidence collection, and keeping configurations from drifting out of compliance. Buying a managed enclave compresses that into weeks, on an architecture that has already survived assessment scrutiny.
With the Essendis enclave, licensing is handled — we're a Microsoft Government Cloud reseller and AOS-G partner, so we procure and provision GCC High directly. The security stack arrives configured and mapped to the objectives assessors actually test. Policies, the System Security Plan, and evidence templates come with the environment instead of being written from scratch. And operations don't land on your IT team: our US-based 24x7 Secure Operations Center monitors the enclave, and our engineers keep it patched, tuned, and audit-ready between assessments. Your people keep their day jobs; your compliance program stops depending on whoever last touched the firewall.
Point solutions that promise "compliant CUI file sharing" solve one control family and leave the rest of your obligation untouched. CUI doesn't just sit in shared files — it moves through email, chat, project tools, and engineering systems, and NIST SP 800-171 applies to every system that stores, processes, or transmits it. A file-sharing tool bolted onto a commercial environment usually expands your assessment scope instead of shrinking it. An enclave addresses the whole data lifecycle inside one boundary.
CUI is unclassified information the government requires you to safeguard — in defense work, that's typically technical drawings, specifications, manufacturing data, and export-controlled information. Look at your contracts: DFARS 252.204-7012 clauses, distribution statements on documents, and CUI markings in the data you receive are the clearest signals. Many contractors underestimate what qualifies, then discover CUI scattered across email and file shares during their first scoping exercise. If you hold DoD contracts and aren't certain, assume you have it until a scoping review proves otherwise.
Ask three questions. How much of your business actually touches CUI — a program team, or everyone? What would it cost to bring your entire existing environment up to all 110 controls? And who will operate that compliance program year after year? If CUI is concentrated in a fraction of your operations, or your current network would need heavy remediation, isolating the data in a managed enclave is almost always faster and cheaper than an enterprise-wide retrofit.
Read more: Is a secure CMMC enclave right for your business?Commercial Microsoft 365 can technically hold some CUI, but it can't satisfy the DFARS 252.204-7012 paragraphs (c)–(g) incident-reporting and sovereignty obligations most defense contracts carry, and it isn't appropriate for ITAR data. GCC sits in the middle and fits some civilian-agency work. For most of the Defense Industrial Base, GCC High is the defensible answer: a US-sovereign Microsoft cloud operated by screened US persons, built to FedRAMP High-equivalent standards, and designed to support ITAR and DFARS 7012 requirements. That's why the Essendis enclave is built on GCC High by default. And no — you don't have to move your whole company. Your commercial tenant keeps running the business; the enclave handles the CUI.
Learn about Microsoft GCC High licensing and migrationLess than enterprise-wide compliance — that's the point. Pricing depends on user count, the workloads that must move (email, files, CAD, line-of-business systems), and how much of the operation you want managed. Because the enclave concentrates controls on a small footprint, licensing and remediation spend track the size of your CUI population rather than your whole headcount. A scoping conversation produces a real number quickly — we'd rather size it to your environment than quote a misleading average.
The Essendis Secure Enclave is a fully managed environment built on Microsoft 365 GCC High and Azure Government, engineered specifically for the 110 controls of CMMC Level 2. As a Microsoft Government Cloud reseller and AOS-G partner, we handle licensing, provisioning, and eligibility validation ourselves — no broker in the middle. Every component ships mapped to its NIST SP 800-171 requirements, and the environment is operated by the same team that built it. Here's what's inside:
A US-sovereign Microsoft cloud built for controlled data: FedRAMP High-equivalent infrastructure, US-persons support, and native support for ITAR and DFARS 7012 obligations. Your CUI lives in the environment DoD contracts assume.
Encryption, conditional access, endpoint management, logging, and threat detection arrive configured against NIST SP 800-171 assessment objectives — not as a pile of licenses your team has to figure out.
The documentation assessors sample — System Security Plan, policies, procedures, and evidence workflows — comes with the enclave. You inherit a working program, not a blank template.
Our US-based Secure Operations Center monitors the enclave around the clock, responds to incidents, and keeps the evidence trail current between assessments — so certification day is a review, not a scramble.
Email: CUI-bearing mail moves into GCC High Exchange with routing and data-loss-prevention rules that keep controlled data from leaking back into commercial mailboxes.
Files and collaboration: Program documents, drawings, and shared workspaces migrate into SharePoint and Teams inside the enclave, with access scoped to the people who actually need them.
CAD and technical data: Engineering files and export-controlled technical data get a protected home — including high-performance virtual desktop options for heavyweight design tools.
Identity and endpoints: Users, devices, and authentication policies are provisioned inside the enclave, so every login and laptop that touches CUI is controlled and accounted for.
Coexistence: Your commercial Microsoft 365 tenant keeps running day-to-day business. The enclave handles controlled work, and the two stay cleanly separated.
Cutover support: We sequence the migration so program work never stalls — users move in planned waves, with training and support through go-live.
Our client RPS Defense took its Essendis-built enclave and security program into a CMMC Level 2 assessment with A-LIGN, a certified C3PAO — and scored a perfect 110/110, with no POA&M required. Every control passed on the first attempt, on the same architecture described on this page. That isn't a marketing claim; it's an assessment outcome. And the operating model behind it is the one we've run for years for clients like AgilityHealth, who trusted us to overhaul how they manage security audits. When the assessor arrives, the difference between an environment built for assessment and one retrofitted to survive it is the whole ballgame.
Read the AgilityHealth case studyMost clients start with a readiness assessment to establish scope and their SPRS score, deploy the enclave as the remediation path, then move into Level 2 assessment preparation with our consultants beside them. If you're earlier in the process — still working out which level applies or where CUI actually lives — start with the full picture of our CMMC compliance services and come back to the enclave once scope is clear.
Start with a CMMC readiness assessmentExplore CMMC Level 2 compliance servicesSee all Essendis CMMC compliance servicesIf CMMC language is showing up in your contracts, the fastest next step is a scoping conversation: where your CUI lives, what an enclave would need to contain, and what your timeline realistically looks like. Talk to the team that designed, built, and operated a 110/110 enclave — and get a plan sized to your business, not a boilerplate pitch.