Your Whole Office Doesn't Need to Be Level 2
If your CUI lives on one or two contracts, a Level 1 workplace with a small Level 2 enclave is often the better build: easier to work in, cheaper to keep up, and smaller when something goes wrong.
By Rob Maupin · Author of the CMMC Practical Guides series
Here's a pattern I see more than any other. A small company does most of its work for commercial customers and civilian agencies, and most of its defense work involves only Federal Contract Information (FCI), the information CMMC Level 1 covers. One subcontract, maybe two, carries Controlled Unclassified Information (CUI): a set of drawings, a technical data package, a handful of emails a month. Someone reads "CMMC Level 2," and the company sets out to bring the entire office up to it.
Every laptop. The front-desk PC. The shared printer. The owner's phone. The estimating software, the accounting system, the Wi-Fi the customers use in the conference room. All of it gets pulled into a 110-requirement program, because nobody stopped to ask a simpler question first.
The question isn't "are we Level 1 or Level 2?" It's "where does the CUI actually live?"
For a lot of small defense contractors, the honest answer is "in a very small place." When that's true, the better build is usually a Level 1 workplace with a Level 2 enclave. The whole business runs on a solid Level 1 foundation, and the CUI lives in a small, separate environment built to Level 2. This is Part 1 of The Enclave Build, and it makes the case for that design before the rest of the series shows how to finish one.
Two Levels, Two Different Jobs
Start with what each level actually covers, because the enclave idea falls out of the difference.
Level 1: Federal Contract Information
- Protects FCI under FAR 52.204-21
- 15 practices, scored MET / NOT MET
- A system description and an annual affirmation
- No POAM: every practice has to be met
- Applies to essentially every company in the defense supply chain
Level 2: Controlled Unclassified Information
- Protects CUI under DFARS 252.204-7012 and NIST SP 800-171
- 110 practices across 14 domains
- A System Security Plan (SSP), a POAM, and a Supplier Performance Risk System (SPRS) score
- A self-assessment every three years, plus an affirmation every year
- Applies wherever CUI is processed, stored, or transmitted
Level 2 always sits on top of Level 1. A company that holds CUI also holds FCI, so it carries both sets of obligations. That's a fact about what contractors owe, not a product decision. But notice the last line in each column. Level 1 follows the company. Level 2 follows the CUI. That difference is the whole opening for an enclave.
What an Enclave Actually Is
An enclave is a small, separate environment that exists to handle CUI and nothing else. In practice, that means:
- Its own cloud workspace: a dedicated tenant on Google Workspace or Microsoft 365 GCC High, used only for CUI work
- Its own devices: dedicated Windows laptops or Chromebooks that touch CUI and nothing else
- Its own people: accounts only for the employees who actually handle CUI
- A clear line around it: a documented boundary that the rest of the business stays outside of
Think of it as the locked file room, not a locked building. The building runs the way a well-managed small business should, which is Level 1. The file room gets the heavier lock.
The CMMC rule supports this design directly. Under 32 CFR 170.19, the Level 2 assessment scope is built around CUI assets, meaning assets that process, store, or transmit CUI, along with the assets that protect them. Assets that are physically or logically separated from CUI assets are out of scope for Level 2. They still carry Level 1 obligations if they handle FCI. Separation is a recognized, intended way to keep the Level 2 boundary small.
💡 The boundary only works if it holds
An enclave is a design and a discipline, not a label. If someone forwards a CUI drawing from their everyday email or saves it to the office file share, the boundary has moved. The enclave approach works because the rules are simple: CUI goes in the enclave, and the enclave stays separate. Your procedures say so, and your people follow them.
Advantage 1: How You Work and Communicate
Level 2 is not just more paperwork. Many of the 110 requirements change how a device behaves and how people use it. A few examples from NIST SP 800-171:
| Requirement | What it means day to day |
|---|---|
| 3.13.11: FIPS-validated cryptography | CUI must be protected with validated encryption, which narrows which tools and settings qualify |
| 3.1.10: Session lock | Screens lock after inactivity, with the display hidden |
| 3.8.7: Removable media | USB drives and other removable media are controlled |
| 3.1.18 and 3.1.20: Mobile devices and external systems | Phones, personal devices, and outside systems connect only under defined rules |
| 3.3.1: Audit logging | Activity is logged, kept, and reviewed |
| 3.10.3: Visitors | Visitors are escorted and their activity monitored where CUI is handled |
Every one of those is reasonable for a laptop holding controlled drawings. Applied to every device and every person in the company, they become friction everywhere: the shop-floor PC, the sales team's phones, the shared drive your commercial customers send files to, the conference room where a supplier drops by.
With an enclave, the Level 2 rules land where the CUI is. Your CUI users switch to the enclave for CUI work and back to the everyday environment for everything else. The rest of the business keeps communicating with customers, suppliers, and each other under Level 1 practices that are still real security, just right-sized for FCI. The friction lands on the few people and the few tasks that actually need it.
Advantage 2: The Cost of Keeping It Up
Most people price Level 2 as a project. It isn't one. Under 32 CFR 170.16, a Level 2 self-assessment is repeated every three years, affirmed every year in between, and backed by evidence kept for six years. What you build, you maintain.
The maintenance scales with the size of the boundary. Every asset inside it needs to be inventoried, configured to a baseline, patched, logged, reviewed, and evidenced, every year. Here's how that compares:
| What you maintain | Whole office at Level 2 | Level 1 office + Level 2 enclave |
|---|---|---|
| People with Level 2 accounts and training | Everyone | Only the people who handle CUI |
| Devices under Level 2 configuration | Every device | Dedicated CUI-only devices |
| Platform licensing at the CUI tier | Every user | Enclave users only |
| New hire onboarding | Every hire enters the Level 2 boundary | Only CUI users enter the enclave |
| Adding software or a vendor tool | A Level 2 change-management decision | A Level 1 decision, unless it touches the enclave |
| Evidence collected each cycle | For the whole company | For the enclave |
None of this makes the enclave free. It still needs its own configuration, its own documentation, and its own evidence. But it's a bounded amount of work that doesn't grow every time the business hires someone or buys a new tool. For a company whose CUI is a small slice of its work, that difference compounds every year the program runs.
Not sure where your CUI actually lives?
Book a free 30-minute consultation. We'll talk through how CUI reaches you today, what your contracts require, and whether a Level 1 workplace with a Level 2 enclave fits the way your business runs.
Book a Free 30-Minute Consultation →Advantage 3: The Size of the Question When Something Goes Wrong
Laptops get left in airports. Phones get dropped in parking lots. Accounts get phished. Every company will have a bad day eventually. What changes with an enclave is how big the question is on that day.
DFARS 252.204-7012 applies to any covered contractor information system, which it defines as an unclassified information system that processes, stores, or transmits covered defense information. When a cyber incident affects one of those systems, the clause requires a report within 72 hours of discovery, preservation of images of the affected systems for at least 90 days, and access for the Department to conduct forensic analysis if it asks.
If the whole office is in the CUI boundary, the whole office is that system. Every device that goes missing and every account that gets compromised has to be evaluated against those obligations.
With an enclave, the question gets smaller. A missing office laptop outside the boundary is handled under your Level 1 practices and your normal incident process. It isn't a question about CUI, because CUI was never on it. A missing enclave laptop is still taken seriously, but it's one of a small number of dedicated, encrypted, documented devices, so you know exactly what was on it and how it was configured. Whether a specific event is reportable depends on the facts. That's what your incident response plan and, where needed, your counsel are for. The point is how many events have to go through that evaluation at all.
Smaller boundary, smaller questions
An enclave doesn't make incidents less likely. It makes fewer of them CUI incidents, and it makes the ones that are easier to answer, because the boundary is small enough to know completely.
When an Enclave Isn't the Answer
This design fits a specific shape of business, and it's worth being honest about where it doesn't.
- When CUI runs through most of the work. If most of your staff handle controlled data daily, the enclave ends up holding most of the company, and the separation stops paying for itself. A whole-environment build may be the more honest design.
- When the boundary can't be held. If CUI keeps arriving through channels you don't control and can't redirect, the enclave will leak. Fix the intake first.
- When your contract says otherwise. Your contract and your contracting officer or prime determine what is CUI and what's required. We help you design around the CUI you have. We don't decide what is or isn't CUI.
For the company with a small amount of defense work and a limited CUI footprint, though, these rarely apply. That company is usually doing far more work than it needs to.
💡 No CUI yet? The same design works in reverse.
Some of the best candidates for an enclave don't hold any CUI today. They're Level 1 companies that want to compete for work that carries it. When a contract requires a CMMC status, the contracting officer checks for it in SPRS before award, not after, so a small, documented Level 2 enclave built ahead of time lets you say "yes, we can handle that" without rebuilding the whole business around a contract you haven't won yet. That's Part 2 of this series, coming next.
The Foundation: A Level 1 Workplace Done Right
None of this works on a shaky base. In an enclave design, Level 1 isn't the lesser half. It's the environment your whole business lives in every day, it's what protects your FCI, and the enclave sits next to it. If the Level 1 side is thin, the separation that makes the enclave work isn't much of a line.
Building that foundation is exactly what Volume 1 of my CMMC Practical Guides walks through: the 15 practices, the system description, and the annual affirmation, written for a small business doing it themselves.
For the business that wants it built with us, the Turnkey CMMC Level 1 Package breaks all 15 practices into 142 defined artifacts, with platform-specific templates for Microsoft 365 or Google Workspace, 8 device and network configuration guides, an Evidence Locker, packaged and date-stamped self-assessment documentation, and 8 bi-weekly consulting sessions. $2,495/year (limited time, save $500 off the regular $2,995). Most clients complete their Level 1 assessment in 2–4 weeks, depending on existing infrastructure and responsiveness.
Our Analysis — not a commitment.
Not sure where your Level 1 baseline stands? Our free CMMC Assessment Tool checks all 15 practices in under 30 minutes.
📘 Building it yourself?
Volume 1: CMMC Level 1: the Level 1 foundation your whole workplace runs on.
Volume 2: CMMC Level 2: the Level 2 practices and documentation for the environment where your CUI lives.
Kindle from $12.99. See the full series →
The Enclave on Top: Your Choice of Platform
The L2 CUI Enclave Package builds the Level 2 side as a dedicated enclave on either Microsoft 365 GCC High or Google Workspace, with platform-specific configuration guides for each. It's designed for limited CUI needs: no Active Directory, no SIEM, no enterprise IT department. You get 110 practices mapped to 182 defined artifacts, a pre-filled SSP, a POAM framework, a Risk Register, an evidence checklist, and time estimates on every task so it can be done part-time. We provide the templates, configuration guides, and consulting. You implement, and the CUI-only devices are yours to buy.
$3,495/year, or $5,990/year combined with the Level 1 Turnkey Package for full FCI and CUI coverage.
⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.
And the Documentation: A Guided Path
A small enclave still needs a full Level 2 documentation set, and that's where most enclave projects stall. For qualifying self-assessment programs, there's now a named tier for that: L2 CUI Enclave — Guided Documentation.
Everything in the L2 CUI Enclave Package stays the same: the same practices, the same 182 artifacts, your consulting sessions, and your signature on the affirmation. What changes is the drafting. You answer structured questions about how your enclave is actually configured, and your answers become your documentation. We review it against what you built, and you sign. Three roles, and you hold the last one.
The tool runs outside your CUI boundary. No connection to your tenant, no access to your systems, and it never touches CUI. Its only inputs are your answers about how your environment is set up. It produces documentation about the enclave. It never operates inside it.
Before you buy, we confirm it fits your environment. Parts 3 and 4 of this series cover the guided path in full.
⚠️ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope.
The Bottom Line
If your CUI lives in a small place, build a small place for it. Run the business on a Level 1 foundation done right, put the CUI in an enclave built to Level 2, and keep the line between them clear. You get a workplace that's easier to work in, a boundary that's cheaper to maintain, and smaller questions on the day something goes wrong.
Let's map your boundary.
In a free 30-minute consultation, we'll look at where your CUI comes from, who touches it, and what a Level 1 workplace with a Level 2 enclave would look like for your business on Google Workspace or Microsoft 365 GCC High.
Schedule Your Free 30 Minutes →Coming Up in The Enclave Build
- Part 2: Ready Before the Contract. No CUI yet? How a Level 1 company gets ready to compete for CUI work with a small enclave.
- Part 3: The Self-Assessment Path Is Open. Finishing Is the Hard Part. Why Level 2 self-assessments stall on the documentation, not the technology.
- Part 4: Same Practices, Same Artifacts, Same Signature. The guided documentation tier in full.
- Part 5: Building a Level 2 CUI Enclave, Start to Signature. One enclave, phase by phase, with both platforms side by side.
- Part 6: We'll Tell You If It Isn't the Right Fit. Who the guided tier is for, and where everyone else should go.
About the author
Rob Maupin is the founder of Overwatch Tools and the author of the CMMC Practical Guides series: Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2. He helps small defense contractors reach CMMC Level 1 and Level 2 self-assessments with templates, configuration guides, and expert consulting.
Rob offers the L2 CUI Enclave — Guided Documentation tier for qualifying self-assessment programs.
Sources & Further Reading
- 32 CFR 170.19: CMMC Scoping
- 32 CFR 170.16: CMMC Level 2 Self-Assessment and Affirmation Requirements
- DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting
- FAR 52.204-21: Basic Safeguarding of Covered Contractor Information Systems
- NIST SP 800-171 Rev. 2
- DoD CIO: About CMMC
- NARA CUI Registry: Category List
This article is general information, not legal advice. Whether your contracts require a Level 2 self-assessment, and whether information you hold is CUI, is determined by your contract and your contracting officer or prime. Questions of contract interpretation should go to your attorney.
