CMMC Level 2 Enclave Design and Implementation
A CMMC Level 2 enclave is the smallest Microsoft 365 environment that can hold your Controlled Unclassified Information and stand up to a NIST SP 800-171 assessment: only the people, devices, mailboxes and files that touch CUI live in it, and the rest of the company stays where it is. IT Partner designs and builds that enclave — normally a Microsoft 365 GCC High tenant, or GCC or a separate hardened commercial tenant where your contract's CUI category and your counsel allow it — and maps all 110 NIST SP 800-171 Rev 2 requirements to concrete settings: Entra ID Conditional Access and phishing-resistant MFA, Intune device baselines and BitLocker, Purview sensitivity labels and DLP for CUI, Defender for Endpoint and Defender for Office 365, and audit-log retention. We migrate the in-scope users and data into it, write the System Security Plan, the POA&M and an evidence index, hand over the four operating SOPs (user onboarding and offboarding, incident response, media handling, configuration change), train your administrators and finish with a pre-assessment readiness walkthrough. From $25,000 per project, quoted fixed-price in writing before work begins; about eight weeks of our work, on top of Microsoft's eligibility validation and tenant provisioning, which run on Microsoft's clock. GCC High licensing (bought through an AOS-G partner, not our CSP), C3PAO fees and any promise of certification are not part of this: we build and document, assessors assess.
What this engagement is
If DFARS 252.204-7012 is in your contracts, you already owe the Department of Defense an implemented NIST SP 800-171 program, a score in SPRS under 252.204-7019 and -7020, and 72-hour cyber-incident reporting — none of that waited for CMMC. The DFARS CMMC rule (48 CFR) took effect on 10 November 2025 and put Level 1 and Level 2 self-assessments into new solicitations under Phase 1. The next step, third-party C3PAO certification for Level 2 from 10 November 2026 under Phase 2, was suspended by a 13 July 2026 memorandum from the Under Secretary of Defense for Acquisition and Sustainment, which also froze the later phases while a 60-day CMMC reform task force reviews the program. What did not change: the self-assessment path, the annual affirmation by your senior official, the False Claims Act exposure on an SPRS score you cannot back up, and the flowdowns your primes are already writing into subcontracts. The environment you need is the same either way — one you can defend on a self-assessment today and to an assessor whenever third-party assessment returns. Moving the whole company into GCC High is the clean answer and the expensive one: every seat pays the government-cloud premium, every application has to support government endpoints, and the assessment boundary becomes the entire business. An enclave is the alternative most 25-to-1,000-seat suppliers actually want. Only the users, devices, mail and files that create, receive, store or transmit CUI move into a separate environment built to the 110 requirements; the rest of the company keeps its commercial tenant, its tools and its licensing. Which cloud the enclave lives in is a contract question before it is a technology question. Microsoft's own guidance at the time of writing is direct: GCC is not suitable to hold CUI Specified — ITAR, nuclear and similar export-controlled categories — because that data requires US sovereignty, which only GCC High offers. For CUI Basic with no export-control element, GCC can be sufficient, and some contracts and primes accept a separately hardened commercial tenant. We design to the determination your contract and your counsel give us in writing; we do not make it for you, and if the paperwork looks thin we say so before you buy licenses. The build itself is where the 110 requirements stop being a spreadsheet. We split them the way our NIST SP 800-171 on GCC High guide does: requirements Microsoft 365 can enforce — Conditional Access, phishing-resistant MFA, privileged-role separation, Intune compliance and BitLocker, sensitivity labels with encryption, DLP, external-sharing restrictions, Defender policies, audit retention; requirements it can only evidence — access reviews, configuration exports, alert records, vulnerability reports; and organisational requirements that are procedures no matter what you buy — training, sanctions, visitor control, media handling, incident playbooks. Every setting is documented as built, every requirement in the SSP names the setting or the SOP that satisfies it, and every one we cannot honestly mark implemented goes on the POA&M with an owner and a date, in the structure the CMMC rule allows. Migration of the in-scope population into the enclave follows the discipline of our tenant-to-tenant work: inventory, pilot, staged content, a cutover the users are told about, and a reconciliation against the inventory. Two things we are honest about up front. Microsoft validates eligibility and provisions the GCC High tenant on its own timeline, and GCC High licensing flows through Microsoft's AOS-G partners (organisations under roughly 500 seats) or an Enterprise Agreement channel, not through our CSP — we coordinate with that partner, we are not it. And an enclave is a permanent two-environment operating model: the seam between the enclave and the rest of the company is real, and the SOPs we hand over exist to keep CUI on the right side of it. We operate in this world as a registered supplier ourselves — CAGE code 8BZ81 on SAM.gov — and everything we produce is yours to keep whoever runs the enclave next.
Success criteria
What you receive
How the work unfolds
We read the contract clauses and prime flowdowns with your contracts owner, inventory where CUI actually enters, lives and leaves today, class every asset per the CMMC scoping guidance, list the enclave population by name and settle the cloud decision on the written determination your counsel and contracting officer provide. The signed design closes the week and fixes the scope the quote covers.
If the enclave tenant does not exist yet, Microsoft's government-cloud eligibility validation and the AOS-G or Enterprise Agreement purchase start on day one. Microsoft decides eligibility and provisions the tenant on its own timeline, measured in weeks; this track sits outside our eight-week clock and the plan below assumes a provisioned tenant by the start of week 3. If you already hold a GCC High or GCC tenant, this track is a license-mapping exercise.
Entra ID, Intune, Purview and Defender are configured to the baseline in the design, in that order, with each policy exported as built. Audit retention, alert policies and the monitoring design are set before any CUI arrives, so the first evidence the assessor sees is the enclave's own birth certificate.
A pilot group of enclave users goes end to end — device enrollment, sign-in under Conditional Access, mail, files, Teams, a labelled CUI document that DLP handles correctly — and the runbook is corrected before the rest follow. In-scope mailboxes, OneDrive, SharePoint and Teams content are staged with delta passes, cutover runs to the communicated window, and the result is reconciled against the inventory.
With the tenant built and populated, the documentation is written from what exists rather than from a template: each of the 110 requirements gets its implementation statement, every gap becomes a POA&M line with an owner and a date, the evidence index points at the real artefacts, and the four SOPs are drafted with the people who will execute them.
We run the pre-assessment walkthrough the way an assessor would: pick requirements, ask for current evidence, time how long it takes to produce. Administrators are trained on operating the enclave and the seam with the commercial tenant, the DoD Assessment Methodology score worksheet goes to your affirming official, and you sign off on delivery before the invoice.
Prerequisites
Who does what
IT Partner
- Design the enclave boundary and data flows, and document the cloud decision against the determination you provide.
- Prepare the eligibility submission and coordinate licensing sequence with your AOS-G partner or EA channel.
- Build the enclave tenant to the agreed baseline across Entra ID, Intune, Purview and Defender, and export every policy as built.
- Map all 110 NIST SP 800-171 Rev 2 requirements to settings, SOPs or organisational controls, honestly.
- Plan and execute the migration of the in-scope population and reconcile it against the inventory.
- Write the SSP, POA&M, evidence index and the four SOPs from the environment as built.
- Run the readiness walkthrough, train your administrators, and state every Microsoft-controlled dependency and every licensing limitation in writing before it can surprise you.
Your team
- Provide the contracts, the CUI category and export-control determination, and the eligibility evidence, and own their accuracy.
- Purchase the enclave's licensing through the AOS-G partner or EA channel on the sequence the plan requires, and pay any Azure Government consumption directly.
- Name the executive owner, the affirming official, the SOP owners and a project coordinator.
- Grant tenant access, supply the inventory inputs and make application owners available for re-pointing.
- Communicate with staff using the cutover pack, and execute the organisational controls — training, sanctions, screening, physical security — that no tenant setting can perform.
- Submit the SPRS score, make the annual affirmation, engage a C3PAO if and when required, and own every assessment outcome.
- Operate the enclave after handover, or contract someone to — the SOPs and evidence index are written so that either works.
What's not included
Limitations & technical notes
Frequently asked questions
What is a CMMC enclave, and why not just move everyone to GCC High?
An enclave is a separate, purpose-built Microsoft 365 environment holding only the users, devices, mailboxes and files that touch CUI, so the assessment boundary is small and the rest of the company keeps its commercial tenant and licensing. A full move is simpler to operate and to assess, but prices every seat at government-cloud rates and drags every application into scope. For most 25-to-1,000-seat suppliers with a defined defense workload, the enclave is the better economics; where the boundary design shows CUI is everywhere, we will say so and point you at the full migration instead.
GCC High, GCC or a commercial tenant — which one does the enclave need?
It depends on the CUI category in your contracts, and the answer has to come from your counsel or contracting officer in writing. Microsoft's guidance at the time of writing is that GCC is not suitable for CUI Specified — ITAR, nuclear and similar export-controlled data — because it requires US sovereignty, which only GCC High offers. For CUI Basic with no export-control element, GCC can be sufficient, and some primes accept a separately hardened commercial tenant. We design and build to the determination you give us; our decision guide walks through the questions that produce it.
What happened to the 10 November 2026 CMMC deadline?
Phase 2 of the DFARS CMMC rule would have put Level 2 third-party (C3PAO) certification into applicable solicitations from 10 November 2026. On 13 July 2026 the Under Secretary of Defense for Acquisition and Sustainment suspended that requirement and froze the later phases while a 60-day CMMC reform task force reviews the program. Phase 1 — Level 1 and Level 2 self-assessments in solicitations since 10 November 2025 — remains, as do DFARS 252.204-7012, SPRS scoring and the annual affirmation. The enclave you need for a defensible self-assessment is the same one an assessor would examine, so the work is not wasted whichever way the review lands; we cite the memorandum and the rule, and we do not tell anyone they 'must be certified by' a date.
Which version of NIST SP 800-171 do you build to?
Revision 2 — the 110 requirements the CMMC rule points at and that DoD's class deviation keeps in force for DFARS 252.204-7012 contractors, even though NIST has published Revision 3. The SSP, the POA&M and the control mapping are all in Rev 2 structure. When DoD moves to Rev 3 through rulemaking, the crosswalk is a scoped change to the documentation, not a rebuild of the tenant.
Do we buy the GCC High licenses from you?
No. GCC High licensing is not sold through the commercial CSP channel we operate. Organisations under roughly 500 seats buy through Microsoft's authorised AOS-G partners; larger ones typically use an Enterprise Agreement. We map your enclave population to the right GCC High SKUs, sequence the purchase against provisioning and coordinate with the partner you choose — we are the engineers, not the reseller. For a GCC enclave, Microsoft 365 GCC licensing can be quoted through us.
What exactly moves into the enclave?
The population named in the boundary design: the people who handle CUI, their mailboxes, their OneDrive content, the SharePoint sites and Teams where CUI lives, and their devices, which are re-registered to the enclave tenant and enrolled in its Intune. Content is staged ahead of cutover with delta passes and reconciled against the inventory afterwards. Hard cases — Teams private chat history, Planner, Forms, per-app settings — are dispositioned explicitly before cutover, so nothing is discovered missing after it.
How do enclave users work with the rest of the company?
Across a seam we design deliberately rather than leave to chance. Entra cross-tenant access settings and Teams external access cover what Microsoft supports between the enclave and your commercial tenant; sensitivity labels and DLP stop CUI crossing it; and the onboarding SOP tells a new enclave user how the two identities relate. Users will notice the separation — that is the point — and we would rather show you the friction in the pilot than promise it away.
What is in the SSP and the POA&M you deliver?
The SSP describes the enclave as built — boundary, data flows, roles, and an implementation statement for each of the 110 requirements naming the Entra, Intune, Purview or Defender setting, the SOP or the organisational control that satisfies it. The POA&M lists every requirement not fully implemented at handover with an owner, milestone and target date, built to the structure the CMMC rule permits, which limits which requirements may sit on a POA&M and sets a 180-day window to close them for a conditional status to become final. The evidence index maps each requirement to where its evidence lives and how it is refreshed.
Does this get us CMMC certified?
No, and nothing we sell does. Certification, when it is required, is issued by a C3PAO on its own judgment; the self-assessment score and the annual affirmation are yours to submit. What this service produces is an enclave whose controls are actually implemented, documentation that describes it truthfully, and evidence you can produce on demand — the things an assessor examines. We are Microsoft 365 engineers, not assessors, and the page says so on purpose.
What moves the price from $25,000?
Six things, all visible in the boundary design before we quote: the number of users in the enclave, the number of devices to enroll, the volume of mail and files to migrate, whether the destination is GCC High, GCC or a hardened commercial tenant, how many line-of-business applications need re-pointing, and whether a usable SSP or readiness report already exists. The floor covers a small enclave with a single destination and no rework; the fixed quote comes in writing before you commit.
Why eight weeks, and what is not inside them?
Eight weeks is our work: design, build, pilot, migration, documentation and handover, with a provisioned tenant by week 3. Microsoft's eligibility validation and tenant provisioning are Microsoft's, run in parallel from day one, and take a number of weeks that we can plan around but not promise. If you already hold a GCC High or GCC tenant, that dependency disappears; if you do not, expect the calendar to be longer than eight weeks even though our effort is not.
We already had a readiness assessment. Does that shorten the work?
Yes, if it produced a boundary analysis and a usable draft SSP. We start from its findings rather than repeating discovery, the control mapping inherits its gap list, and the price reflects it. If it was a questionnaire-style review with no boundary work, the week-1 design still has to happen, and we will tell you which of the two you have.
What about personal devices and phones?
CUI is reached only from a compliant, enclave-managed device — that is what the Conditional Access and Intune baseline enforce, and it is what the SSP claims. For phones, the design chooses between fully managed devices and app-protection policies with no local CUI storage, and personal computers are out unless the boundary design explicitly admits a managed-virtual-desktop pattern. 'Bring your own device' and CUI do not mix well, and we would rather scope the devices than dilute the control.
Our engineering and ERP systems hold CUI too. Are they covered?
They are recorded in the boundary and the SSP, and enclave users are re-pointed to them, but bringing a CAD, PLM, ERP or file-server platform to the 110 requirements is its own project, scoped after the boundary design shows what each system does with CUI. Where a system cannot follow its users into the enclave — a vendor with no government-cloud support, say — it becomes a POA&M line with a plan, not a footnote.
What happens after handover?
You operate the enclave, or someone you contract does; the SOPs and evidence index are written so either works, and nothing we deliver locks you to us. Most clients pair it with the Compliance Evidence and Audit Readiness Retainer for the monthly evidence refresh and drift checks, and some add the Virtual CISO for program leadership. If you buy your commercial Microsoft 365 licensing through IT Partner, our included business-hours break-fix support covers that tenant; support for the GCC High tenant is a separate agreement, because its licensing does not flow through us.