Linkedin
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Menu Categories
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool
Linkedin
Cart To use Cart please install WooCommerce plugin
Your Whole Office Doesn't Need to Be Level 2 | Overwatch Tools
The Enclave Build · Part 1 of 6

Your Whole Office Doesn't Need to Be Level 2

If your CUI lives on one or two contracts, a Level 1 workplace with a small Level 2 enclave is often the better build: easier to work in, cheaper to keep up, and smaller when something goes wrong.

By Rob Maupin · Author of the CMMC Practical Guides series

Published October 8, 2026. This article reflects the requirements in force at the time of writing, including DFARS 252.204-7012, NIST SP 800-171, 32 CFR Part 170, and Phase 1 CMMC self-assessment requirements, following the Department of War memorandum of July 13, 2026 and class deviation 2026-O0025 (Revision 3, September 3, 2026). The CMMC Reform Task Force's recommendations had not been made public at the time of writing; guidance may change, and we will update this article as it does.

Here's a pattern I see more than any other. A small company does most of its work for commercial customers and civilian agencies, and most of its defense work involves only Federal Contract Information (FCI), the information CMMC Level 1 covers. One subcontract, maybe two, carries Controlled Unclassified Information (CUI): a set of drawings, a technical data package, a handful of emails a month. Someone reads "CMMC Level 2," and the company sets out to bring the entire office up to it.

Every laptop. The front-desk PC. The shared printer. The owner's phone. The estimating software, the accounting system, the Wi-Fi the customers use in the conference room. All of it gets pulled into a 110-requirement program, because nobody stopped to ask a simpler question first.

The question isn't "are we Level 1 or Level 2?" It's "where does the CUI actually live?"

For a lot of small defense contractors, the honest answer is "in a very small place." When that's true, the better build is usually a Level 1 workplace with a Level 2 enclave. The whole business runs on a solid Level 1 foundation, and the CUI lives in a small, separate environment built to Level 2. This is Part 1 of The Enclave Build, and it makes the case for that design before the rest of the series shows how to finish one.

Two Levels, Two Different Jobs

Start with what each level actually covers, because the enclave idea falls out of the difference.

Level 1: Federal Contract Information

  • Protects FCI under FAR 52.204-21
  • 15 practices, scored MET / NOT MET
  • A system description and an annual affirmation
  • No POAM: every practice has to be met
  • Applies to essentially every company in the defense supply chain

Level 2: Controlled Unclassified Information

  • Protects CUI under DFARS 252.204-7012 and NIST SP 800-171
  • 110 practices across 14 domains
  • A System Security Plan (SSP), a POAM, and a Supplier Performance Risk System (SPRS) score
  • A self-assessment every three years, plus an affirmation every year
  • Applies wherever CUI is processed, stored, or transmitted

Level 2 always sits on top of Level 1. A company that holds CUI also holds FCI, so it carries both sets of obligations. That's a fact about what contractors owe, not a product decision. But notice the last line in each column. Level 1 follows the company. Level 2 follows the CUI. That difference is the whole opening for an enclave.

What an Enclave Actually Is

An enclave is a small, separate environment that exists to handle CUI and nothing else. In practice, that means:

  • Its own cloud workspace: a dedicated tenant on Google Workspace or Microsoft 365 GCC High, used only for CUI work
  • Its own devices: dedicated Windows laptops or Chromebooks that touch CUI and nothing else
  • Its own people: accounts only for the employees who actually handle CUI
  • A clear line around it: a documented boundary that the rest of the business stays outside of

Think of it as the locked file room, not a locked building. The building runs the way a well-managed small business should, which is Level 1. The file room gets the heavier lock.

The CMMC rule supports this design directly. Under 32 CFR 170.19, the Level 2 assessment scope is built around CUI assets, meaning assets that process, store, or transmit CUI, along with the assets that protect them. Assets that are physically or logically separated from CUI assets are out of scope for Level 2. They still carry Level 1 obligations if they handle FCI. Separation is a recognized, intended way to keep the Level 2 boundary small.

💡 The boundary only works if it holds

An enclave is a design and a discipline, not a label. If someone forwards a CUI drawing from their everyday email or saves it to the office file share, the boundary has moved. The enclave approach works because the rules are simple: CUI goes in the enclave, and the enclave stays separate. Your procedures say so, and your people follow them.

Advantage 1: How You Work and Communicate

Level 2 is not just more paperwork. Many of the 110 requirements change how a device behaves and how people use it. A few examples from NIST SP 800-171:

RequirementWhat it means day to day
3.13.11: FIPS-validated cryptographyCUI must be protected with validated encryption, which narrows which tools and settings qualify
3.1.10: Session lockScreens lock after inactivity, with the display hidden
3.8.7: Removable mediaUSB drives and other removable media are controlled
3.1.18 and 3.1.20: Mobile devices and external systemsPhones, personal devices, and outside systems connect only under defined rules
3.3.1: Audit loggingActivity is logged, kept, and reviewed
3.10.3: VisitorsVisitors are escorted and their activity monitored where CUI is handled

Every one of those is reasonable for a laptop holding controlled drawings. Applied to every device and every person in the company, they become friction everywhere: the shop-floor PC, the sales team's phones, the shared drive your commercial customers send files to, the conference room where a supplier drops by.

With an enclave, the Level 2 rules land where the CUI is. Your CUI users switch to the enclave for CUI work and back to the everyday environment for everything else. The rest of the business keeps communicating with customers, suppliers, and each other under Level 1 practices that are still real security, just right-sized for FCI. The friction lands on the few people and the few tasks that actually need it.

Advantage 2: The Cost of Keeping It Up

Most people price Level 2 as a project. It isn't one. Under 32 CFR 170.16, a Level 2 self-assessment is repeated every three years, affirmed every year in between, and backed by evidence kept for six years. What you build, you maintain.

The maintenance scales with the size of the boundary. Every asset inside it needs to be inventoried, configured to a baseline, patched, logged, reviewed, and evidenced, every year. Here's how that compares:

What you maintainWhole office at Level 2Level 1 office + Level 2 enclave
People with Level 2 accounts and trainingEveryoneOnly the people who handle CUI
Devices under Level 2 configurationEvery deviceDedicated CUI-only devices
Platform licensing at the CUI tierEvery userEnclave users only
New hire onboardingEvery hire enters the Level 2 boundaryOnly CUI users enter the enclave
Adding software or a vendor toolA Level 2 change-management decisionA Level 1 decision, unless it touches the enclave
Evidence collected each cycleFor the whole companyFor the enclave

None of this makes the enclave free. It still needs its own configuration, its own documentation, and its own evidence. But it's a bounded amount of work that doesn't grow every time the business hires someone or buys a new tool. For a company whose CUI is a small slice of its work, that difference compounds every year the program runs.

Not sure where your CUI actually lives?

Book a free 30-minute consultation. We'll talk through how CUI reaches you today, what your contracts require, and whether a Level 1 workplace with a Level 2 enclave fits the way your business runs.

Book a Free 30-Minute Consultation →

Advantage 3: The Size of the Question When Something Goes Wrong

Laptops get left in airports. Phones get dropped in parking lots. Accounts get phished. Every company will have a bad day eventually. What changes with an enclave is how big the question is on that day.

DFARS 252.204-7012 applies to any covered contractor information system, which it defines as an unclassified information system that processes, stores, or transmits covered defense information. When a cyber incident affects one of those systems, the clause requires a report within 72 hours of discovery, preservation of images of the affected systems for at least 90 days, and access for the Department to conduct forensic analysis if it asks.

If the whole office is in the CUI boundary, the whole office is that system. Every device that goes missing and every account that gets compromised has to be evaluated against those obligations.

With an enclave, the question gets smaller. A missing office laptop outside the boundary is handled under your Level 1 practices and your normal incident process. It isn't a question about CUI, because CUI was never on it. A missing enclave laptop is still taken seriously, but it's one of a small number of dedicated, encrypted, documented devices, so you know exactly what was on it and how it was configured. Whether a specific event is reportable depends on the facts. That's what your incident response plan and, where needed, your counsel are for. The point is how many events have to go through that evaluation at all.

Smaller boundary, smaller questions

An enclave doesn't make incidents less likely. It makes fewer of them CUI incidents, and it makes the ones that are easier to answer, because the boundary is small enough to know completely.

When an Enclave Isn't the Answer

This design fits a specific shape of business, and it's worth being honest about where it doesn't.

  • When CUI runs through most of the work. If most of your staff handle controlled data daily, the enclave ends up holding most of the company, and the separation stops paying for itself. A whole-environment build may be the more honest design.
  • When the boundary can't be held. If CUI keeps arriving through channels you don't control and can't redirect, the enclave will leak. Fix the intake first.
  • When your contract says otherwise. Your contract and your contracting officer or prime determine what is CUI and what's required. We help you design around the CUI you have. We don't decide what is or isn't CUI.

For the company with a small amount of defense work and a limited CUI footprint, though, these rarely apply. That company is usually doing far more work than it needs to.

💡 No CUI yet? The same design works in reverse.

Some of the best candidates for an enclave don't hold any CUI today. They're Level 1 companies that want to compete for work that carries it. When a contract requires a CMMC status, the contracting officer checks for it in SPRS before award, not after, so a small, documented Level 2 enclave built ahead of time lets you say "yes, we can handle that" without rebuilding the whole business around a contract you haven't won yet. That's Part 2 of this series, coming next.

The Foundation: A Level 1 Workplace Done Right

None of this works on a shaky base. In an enclave design, Level 1 isn't the lesser half. It's the environment your whole business lives in every day, it's what protects your FCI, and the enclave sits next to it. If the Level 1 side is thin, the separation that makes the enclave work isn't much of a line.

Building that foundation is exactly what Volume 1 of my CMMC Practical Guides walks through: the 15 practices, the system description, and the annual affirmation, written for a small business doing it themselves.

For the business that wants it built with us, the Turnkey CMMC Level 1 Package breaks all 15 practices into 142 defined artifacts, with platform-specific templates for Microsoft 365 or Google Workspace, 8 device and network configuration guides, an Evidence Locker, packaged and date-stamped self-assessment documentation, and 8 bi-weekly consulting sessions. $2,495/year (limited time, save $500 off the regular $2,995). Most clients complete their Level 1 assessment in 2–4 weeks, depending on existing infrastructure and responsiveness.

Our Analysis — not a commitment.

Not sure where your Level 1 baseline stands? Our free CMMC Assessment Tool checks all 15 practices in under 30 minutes.

📘 Building it yourself?

CMMC Practical Guides Volume 1: CMMC Level 1 book cover

Volume 1: CMMC Level 1: the Level 1 foundation your whole workplace runs on.

CMMC Practical Guides Volume 2: CMMC Level 2 book cover

Volume 2: CMMC Level 2: the Level 2 practices and documentation for the environment where your CUI lives.

Kindle from $12.99. See the full series →

The Enclave on Top: Your Choice of Platform

The L2 CUI Enclave Package builds the Level 2 side as a dedicated enclave on either Microsoft 365 GCC High or Google Workspace, with platform-specific configuration guides for each. It's designed for limited CUI needs: no Active Directory, no SIEM, no enterprise IT department. You get 110 practices mapped to 182 defined artifacts, a pre-filled SSP, a POAM framework, a Risk Register, an evidence checklist, and time estimates on every task so it can be done part-time. We provide the templates, configuration guides, and consulting. You implement, and the CUI-only devices are yours to buy.

$3,495/year, or $5,990/year combined with the Level 1 Turnkey Package for full FCI and CUI coverage.

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

And the Documentation: A Guided Path

A small enclave still needs a full Level 2 documentation set, and that's where most enclave projects stall. For qualifying self-assessment programs, there's now a named tier for that: L2 CUI Enclave — Guided Documentation.

Everything in the L2 CUI Enclave Package stays the same: the same practices, the same 182 artifacts, your consulting sessions, and your signature on the affirmation. What changes is the drafting. You answer structured questions about how your enclave is actually configured, and your answers become your documentation. We review it against what you built, and you sign. Three roles, and you hold the last one.

The tool runs outside your CUI boundary. No connection to your tenant, no access to your systems, and it never touches CUI. Its only inputs are your answers about how your environment is set up. It produces documentation about the enclave. It never operates inside it.

Before you buy, we confirm it fits your environment. Parts 3 and 4 of this series cover the guided path in full.

⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.

The Bottom Line

If your CUI lives in a small place, build a small place for it. Run the business on a Level 1 foundation done right, put the CUI in an enclave built to Level 2, and keep the line between them clear. You get a workplace that's easier to work in, a boundary that's cheaper to maintain, and smaller questions on the day something goes wrong.

Let's map your boundary.

In a free 30-minute consultation, we'll look at where your CUI comes from, who touches it, and what a Level 1 workplace with a Level 2 enclave would look like for your business on Google Workspace or Microsoft 365 GCC High.

Schedule Your Free 30 Minutes →

Coming Up in The Enclave Build

  • Part 2: Ready Before the Contract. No CUI yet? How a Level 1 company gets ready to compete for CUI work with a small enclave.
  • Part 3: The Self-Assessment Path Is Open. Finishing Is the Hard Part. Why Level 2 self-assessments stall on the documentation, not the technology.
  • Part 4: Same Practices, Same Artifacts, Same Signature. The guided documentation tier in full.
  • Part 5: Building a Level 2 CUI Enclave, Start to Signature. One enclave, phase by phase, with both platforms side by side.
  • Part 6: We'll Tell You If It Isn't the Right Fit. Who the guided tier is for, and where everyone else should go.

About the author

Rob Maupin is the founder of Overwatch Tools and the author of the CMMC Practical Guides series: Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2. He helps small defense contractors reach CMMC Level 1 and Level 2 self-assessments with templates, configuration guides, and expert consulting.

Rob offers the L2 CUI Enclave — Guided Documentation tier for qualifying self-assessment programs.

Sources & Further Reading

  • 32 CFR 170.19: CMMC Scoping
  • 32 CFR 170.16: CMMC Level 2 Self-Assessment and Affirmation Requirements
  • DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting
  • FAR 52.204-21: Basic Safeguarding of Covered Contractor Information Systems
  • NIST SP 800-171 Rev. 2
  • DoD CIO: About CMMC
  • NARA CUI Registry: Category List

This article is general information, not legal advice. Whether your contracts require a Level 2 self-assessment, and whether information you hold is CUI, is determined by your contract and your contracting officer or prime. Questions of contract interpretation should go to your attorney.

Tags: cmmc, FCI_vs_CUI, Google, L1, L2, Level 1, Level 2, MS365, NIST, templates
Share Post
  • Twitter
  • Facebook
  • Pinterest
  • Linkedin
What a Task Force Report Can a...
What a Task Force Report Can and Cannot Change

Related posts

What a Task Force Report Can and Cannot Change
Read more

What a Task Force Report Can and Cannot Change

What a Task Force Report Can and Cannot Change | Overwatch Tools Reference · The Deviation, Part 3 What a Task Force Report Can and Cannot Change The report will be read as a verdict. It is closer to an opening argument. Here is how to read it when it arrives, and the three documents that actually... Continue reading
The Department Asked Seven Questions. Read Them Closely.
Read more

The Department Asked Seven Questions. Read Them Closely.

The Department Asked Seven Questions. Read Them Closely. | Overwatch Tools Analysis · The Deviation, Part 2 The Department Asked Seven Questions. Read Them Closely. The Task Force report isn’t public. The questions that shaped it have been public since July — and almost nobody has read them carefully. By Rob Maupin, Overwatch Tools — author of... Continue reading
"Suspended" Is the Wrong Word. So Is "Cancelled."
Read more

“Suspended” Is the Wrong Word. So Is “Cancelled.”

“Suspended” Is the Wrong Word. So Is “Cancelled.” | Overwatch Tools Industry Update · The Deviation, Part 1 “Suspended” Is the Wrong Word. So Is “Cancelled.” The CMMC pause stopped living in a memo in July. And the September document that half the industry read as the end of the program did not change the CMMC text... Continue reading
Rev. 2 to Rev. 3: What Changes for a Small Enclave
Read more

NIST Rev. 2 to Rev. 3: What Changes for a Small Enclave

Rev. 2 to Rev. 3: What Changes for a Small Enclave | Overwatch Tools The Second Front · Part 3 of 4 Rev. 2 to Rev. 3: What Changes for a Small Enclave The Department of War enforces one revision of NIST SP 800-171. The proposed FAR CUI rule reaches for the next one. If both touch... Continue reading
Do You Actually Hold CUI on a Civilian Contract?
Read more

Do You Actually Hold CUI on a Civilian Contract?

Do You Actually Hold CUI on a Civilian Contract? | Overwatch Tools The Second Front · Part 2 of 4 Do You Actually Hold CUI on a Civilian Contract? Sensitive, proprietary, and export-controlled are three different things. None of them is automatically Controlled Unclassified Information — and the difference decides your scope. By Rob Maupin, founder of... Continue reading

Comments are closed

Company Address

  • Overwatch Tools, Inc.
  • 300 Woodards Ford Road
  • Chesapeake Virginia 23322
  • E-Mail: info@overwatchtools.com
  • Outervision Capitol Company
  • Privacy Policy

,Copyright © 2025 Overwatch Tools, Inc.

Home
Shop
Contact us
More
More
  • Home
  • Demo & Video
  • Blog
  • About Us
  • Try Free Self-Assessment Tool