Being told that a CMMC enclave means virtual desktops for everyone is common, and it is wrong. That is the core CMMC VDI assumption: compliance forces your CAD team onto a laggy remote session. No rule says so.
A secure enclave can manage physical workstations alongside virtual desktops. Heavy design work runs on real hardware and stays fully inside the compliance boundary.
This guide explains where the assumption comes from and where virtual desktops genuinely struggle. It also shows how physical machines fit inside a CMMC boundary.
It is written for IT leads and engineering managers at defense subcontractors. That includes architecture and engineering firms, MEP, manufacturing, GIS and survey, and R&D shops whose power users live in 3D models all day.
A CMMC secure enclave is a segregated environment built to store, process, and transmit Controlled Unclassified Information (CUI). Concentrating CUI in one boundary shrinks the assessment scope. The 110 NIST SP 800-171 controls apply to the enclave, not to every laptop your company owns.
Most enclaves are built on a government cloud such as Microsoft GCC High. Because the data lives in the cloud, the default way to reach it is a virtual desktop. The session runs inside the boundary, and the user's own device only displays it.
That default exists for a good reason. When the local device never stores or processes CUI, it stays out of scope and the boundary shrinks. For email, documents, and line-of-business work, a virtual desktop is often the right call: simple to provision, easy to replace, and friendly to remote work.
The problem starts when the default hardens into a rule. Teams hear "enclave" and assume every workload, including CAD, must run in a remote session. That assumption created the compliance-versus-performance dilemma, and the dilemma is optional.
Modern virtual desktops handle far more than they used to, including GPU-backed sessions for design tools. Many engineering teams run them happily. An honest assessment still has to name the friction points for the heaviest users:
The pattern repeats across tools. Parametric CAD assemblies, BIM coordination models, photogrammetry point clouds, and simulation runs all reward local horsepower. If your engineers already push their workstation specs, a remote session will not make them happier.
None of this makes virtual desktops wrong. It makes them wrong for some users. The fix is matching the delivery model to the workload instead of forcing one model on everyone.
Nothing in CMMC or NIST SP 800-171 requires virtualization. The frameworks describe controls: access control, encryption, monitoring, configuration management. They stay silent on whether the machine that meets them is virtual or physical.
What CMMC cares about is scope. A system that stores, processes, or transmits CUI is in scope wherever it sits. A cloud tenant, a rack server, and a machine on a desk are judged the same way.
A virtual desktop keeps the local device out of scope. A physical workstation that touches CUI is in scope and must be managed accordingly. That is the real trade-off: not compliance versus speed, but which machines you bring inside the boundary and who manages the controls on them.
The Essendis Secure Enclave supports both delivery models side by side. Virtual desktops serve the users they fit. Physical, enclave-managed workstations serve the users they do not.
An enclave-managed workstation is a real machine under the enclave's controls. It is enrolled in the enclave's identity and device management, encrypted, locked to enclave policies, and monitored like every other asset inside the boundary. CUI on that machine stays governed by the same 110 controls that protect the cloud side.
Day-to-day upkeep does not land on your IT team. Essendis engineers keep enclave assets patched, tuned, and audit-ready between assessments. The workstation's evidence feeds the same System Security Plan as the rest of the boundary.
The result for your engineers is ordinary local computing. Models open from enclave storage, render on local hardware, and never leave the governed environment. The person at the workstation notices nothing unusual, which is the point.
Most organizations land on a mix. A practical split looks like this:
The split is a scoping decision as much as a technical one. Each physical workstation added to the boundary is one more asset to manage and assess. That is why the decision belongs in your enclave design, not as an afterthought.
Settle the workstation count early, because it shapes licensing, hardware budget, and the evidence your assessor will sample. Changing the mix later is possible, but planning it up front is cheaper.
Five questions surface the right delivery model for each team. Answer them before licensing anything:
Worked through in that order, the answers usually sort your users cleanly. Document-centric staff land on virtual desktops, and a smaller group of power users justifies managed physical hardware. If one team's answers conflict, split the team: the delivery model is chosen per user, not per company.
Essendis designs, builds, and operates CMMC secure enclaves on Microsoft GCC High. High-performance virtual desktops and enclave-managed physical workstations are supported options in one boundary. Our engineers run the environment, and our US-based 24x7 Secure Operations Center monitors it, workstations included.
The architecture has held up under scrutiny. One client, RPS Defense, earned a perfect 110/110 on its CMMC Level 2 assessment with C3PAO A-LIGN, with no POA&M. To talk through how your design tools would run inside an enclave, connect with an Essendis expert.
No: CMMC and NIST SP 800-171 define security controls, not delivery architectures. CMMC VDI deployments are popular because they keep local devices out of assessment scope. A physical workstation managed inside the boundary satisfies the same controls. Every system touching CUI must be governed; the delivery model is your design choice.
Yes, in two ways: design tools can run on GPU-backed virtual desktops inside the enclave, or on physical workstations the enclave manages. The second option keeps rendering and model work on local hardware. That matters for large assemblies, point clouds, and other latency-sensitive workloads.
Yes: a physical workstation that stores or processes CUI is an in-scope asset, like any server or virtual machine. It must be enrolled in the boundary's device management, encrypted, monitored, and covered by the System Security Plan. Managed that way it is fully assessable, and nothing in the framework prefers virtual hardware.
It can: a local device that only displays a remote session, and never stores or processes CUI, can stay outside the boundary. That is a genuine advantage of the CMMC VDI pattern for document-centric users. For power users the math changes: the workstation joins the boundary, and the enclave provider absorbs the added management burden.
Export-controlled technical data belongs in an environment that meets its sovereignty demands, which is one reason Essendis builds enclaves on Microsoft GCC High. An enclave-managed workstation holding ITAR data is governed by the same boundary controls. Access stays limited to authorized users under the enclave's identity rules.

