First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/CMMC Level 2 Enclave Design and Implementation
ImplementationComplianceSecurity and Protection

CMMC Level 2 Enclave Design and Implementation

A CMMC Level 2 enclave is the smallest Microsoft 365 environment that can hold your Controlled Unclassified Information and stand up to a NIST SP 800-171 assessment: only the people, devices, mailboxes and files that touch CUI live in it, and the rest of the company stays where it is. IT Partner designs and builds that enclave — normally a Microsoft 365 GCC High tenant, or GCC or a separate hardened commercial tenant where your contract's CUI category and your counsel allow it — and maps all 110 NIST SP 800-171 Rev 2 requirements to concrete settings: Entra ID Conditional Access and phishing-resistant MFA, Intune device baselines and BitLocker, Purview sensitivity labels and DLP for CUI, Defender for Endpoint and Defender for Office 365, and audit-log retention. We migrate the in-scope users and data into it, write the System Security Plan, the POA&M and an evidence index, hand over the four operating SOPs (user onboarding and offboarding, incident response, media handling, configuration change), train your administrators and finish with a pre-assessment readiness walkthrough. From $25,000 per project, quoted fixed-price in writing before work begins; about eight weeks of our work, on top of Microsoft's eligibility validation and tenant provisioning, which run on Microsoft's clock. GCC High licensing (bought through an AOS-G partner, not our CSP), C3PAO fees and any promise of certification are not part of this: we build and document, assessors assess.

Timeline 8 weeksService owner Roman SotnikMicrosoft 365 GCC HighMicrosoft Entra IDMicrosoft Intune

What this engagement is

If DFARS 252.204-7012 is in your contracts, you already owe the Department of Defense an implemented NIST SP 800-171 program, a score in SPRS under 252.204-7019 and -7020, and 72-hour cyber-incident reporting — none of that waited for CMMC. The DFARS CMMC rule (48 CFR) took effect on 10 November 2025 and put Level 1 and Level 2 self-assessments into new solicitations under Phase 1. The next step, third-party C3PAO certification for Level 2 from 10 November 2026 under Phase 2, was suspended by a 13 July 2026 memorandum from the Under Secretary of Defense for Acquisition and Sustainment, which also froze the later phases while a 60-day CMMC reform task force reviews the program. What did not change: the self-assessment path, the annual affirmation by your senior official, the False Claims Act exposure on an SPRS score you cannot back up, and the flowdowns your primes are already writing into subcontracts. The environment you need is the same either way — one you can defend on a self-assessment today and to an assessor whenever third-party assessment returns. Moving the whole company into GCC High is the clean answer and the expensive one: every seat pays the government-cloud premium, every application has to support government endpoints, and the assessment boundary becomes the entire business. An enclave is the alternative most 25-to-1,000-seat suppliers actually want. Only the users, devices, mail and files that create, receive, store or transmit CUI move into a separate environment built to the 110 requirements; the rest of the company keeps its commercial tenant, its tools and its licensing. Which cloud the enclave lives in is a contract question before it is a technology question. Microsoft's own guidance at the time of writing is direct: GCC is not suitable to hold CUI Specified — ITAR, nuclear and similar export-controlled categories — because that data requires US sovereignty, which only GCC High offers. For CUI Basic with no export-control element, GCC can be sufficient, and some contracts and primes accept a separately hardened commercial tenant. We design to the determination your contract and your counsel give us in writing; we do not make it for you, and if the paperwork looks thin we say so before you buy licenses. The build itself is where the 110 requirements stop being a spreadsheet. We split them the way our NIST SP 800-171 on GCC High guide does: requirements Microsoft 365 can enforce — Conditional Access, phishing-resistant MFA, privileged-role separation, Intune compliance and BitLocker, sensitivity labels with encryption, DLP, external-sharing restrictions, Defender policies, audit retention; requirements it can only evidence — access reviews, configuration exports, alert records, vulnerability reports; and organisational requirements that are procedures no matter what you buy — training, sanctions, visitor control, media handling, incident playbooks. Every setting is documented as built, every requirement in the SSP names the setting or the SOP that satisfies it, and every one we cannot honestly mark implemented goes on the POA&M with an owner and a date, in the structure the CMMC rule allows. Migration of the in-scope population into the enclave follows the discipline of our tenant-to-tenant work: inventory, pilot, staged content, a cutover the users are told about, and a reconciliation against the inventory. Two things we are honest about up front. Microsoft validates eligibility and provisions the GCC High tenant on its own timeline, and GCC High licensing flows through Microsoft's AOS-G partners (organisations under roughly 500 seats) or an Enterprise Agreement channel, not through our CSP — we coordinate with that partner, we are not it. And an enclave is a permanent two-environment operating model: the seam between the enclave and the rest of the company is real, and the SOPs we hand over exist to keep CUI on the right side of it. We operate in this world as a registered supplier ourselves — CAGE code 8BZ81 on SAM.gov — and everything we produce is yours to keep whoever runs the enclave next.

Success criteria

01The enclave boundary and data-flow design is signed off by the client before anything is built: contract clauses mapped, CUI categories named, every asset classed as CUI asset, security protection asset, contractor risk managed asset, specialized asset or out of scope, and the enclave population (users, devices, mailboxes, sites) listed by name.
02The enclave tenant is configured to the agreed baseline — Entra ID, Intune, Purview, Defender and audit logging — and the as-built configuration export matches the design.
03All 110 NIST SP 800-171 Rev 2 requirements are mapped, each marked Implemented, Partially Implemented or Not Applicable with the Microsoft setting, SOP or organisational control that satisfies it, with nothing claimed that the tenant cannot demonstrate.
04In-scope mailboxes, OneDrive content, SharePoint sites and Teams reach the enclave and reconcile against the migration inventory; in-scope devices are enrolled, compliant and able to reach CUI only from a compliant state.
05The System Security Plan, the POA&M and the evidence index are delivered in the client's own SharePoint, written to the structure a self-assessment and a C3PAO both expect.
06The four operating SOPs — user onboarding and offboarding, incident response, media handling, configuration change — are delivered and walked through with the people who will run them.
07The client's administrators can operate the enclave day to day after the handover session, and the DoD Assessment Methodology score is calculated and handed to the affirming official for SPRS submission.
08The pre-assessment readiness walkthrough is complete: for a sample of requirements the client can produce current evidence on demand, and every open item is on the POA&M with an owner and a date.

What you receive

Enclave boundary and data-flow design: contract clause map (DFARS 252.204-7012/-7019/-7020/-7021 and prime flowdowns), CUI inventory and category determination record, asset categorisation per the CMMC Level 2 scoping guidance, the enclave population, and the cloud decision record (GCC High, GCC, or a hardened commercial tenant) with its written justification.
Eligibility and licensing coordination: Microsoft's government-cloud validation form prepared with your CAGE code, SAM.gov registration and contract evidence; license mapping for the enclave population; purchase sequencing with the AOS-G partner or Enterprise Agreement channel you select.
Microsoft Entra ID build: Conditional Access policy set (compliant device, phishing-resistant MFA, session and location controls, legacy-authentication block), privileged-role model with Privileged Identity Management where licensed, guest and external-collaboration settings, and cross-tenant access settings toward the commercial tenant for what Microsoft supports across the seam.
Microsoft Intune build: Windows security baseline, device compliance policies, BitLocker enforcement and key escrow, Autopilot enrollment for enclave devices, removable-storage and USB controls, application control where licensed, and the mobile-device or app-protection pattern the design calls for.
Microsoft Purview build: a CUI sensitivity-label taxonomy with encryption and visual markings, DLP policies for Exchange, SharePoint, OneDrive and Teams (endpoint DLP where licensed), retention policies, external-sharing controls, and Purview Audit configured to the longest retention your licensing allows.
Microsoft Defender build: Defender for Endpoint onboarding for enclave devices with attack-surface-reduction and vulnerability-management baselines, and Defender for Office 365 policies for the enclave mail flow, with SPF, DKIM and DMARC for the enclave domain.
Logging and monitoring design: audit sources, retention periods, alert policies and review cadence documented; where the design needs longer retention or cross-source correlation, a Microsoft Sentinel workspace in Azure Government (Azure consumption is yours) or a handover to your MDR provider.
Migration of the in-scope population: mailboxes, OneDrive content, SharePoint sites and Teams standard channels staged with delta passes, device re-registration to the enclave tenant, a line-of-business application re-pointing plan, and a user communication pack for cutover.
System Security Plan (SSP) in NIST SP 800-171 Rev 2 structure: system description, boundary diagram, data flows, roles, and an implementation statement for each of the 110 requirements that names the setting, SOP or organisational control behind it.
Plan of Action and Milestones (POA&M) for every requirement not fully implemented at handover, with owner, milestone and target date, built to the structure and limits the CMMC rule allows; and an evidence index that maps each requirement to where its evidence lives and how it is refreshed.
Four operating SOPs written for your enclave, not a template pack: user onboarding and offboarding, incident response (including the 72-hour DoD reporting path), media handling (removable media, printing, sanitisation), and configuration change with an exception register.
Administrator handover training, the pre-assessment readiness walkthrough, and a DoD Assessment Methodology score worksheet for the affirming official's SPRS submission.

How the work unfolds

Week 1 — Kickoff, boundary and data-flow design

We read the contract clauses and prime flowdowns with your contracts owner, inventory where CUI actually enters, lives and leaves today, class every asset per the CMMC scoping guidance, list the enclave population by name and settle the cloud decision on the written determination your counsel and contracting officer provide. The signed design closes the week and fixes the scope the quote covers.

Weeks 1–3 — Eligibility and licensing track (Microsoft-dependent, runs in parallel)

If the enclave tenant does not exist yet, Microsoft's government-cloud eligibility validation and the AOS-G or Enterprise Agreement purchase start on day one. Microsoft decides eligibility and provisions the tenant on its own timeline, measured in weeks; this track sits outside our eight-week clock and the plan below assumes a provisioned tenant by the start of week 3. If you already hold a GCC High or GCC tenant, this track is a license-mapping exercise.

Weeks 2–4 — Enclave tenant build

Entra ID, Intune, Purview and Defender are configured to the baseline in the design, in that order, with each policy exported as built. Audit retention, alert policies and the monitoring design are set before any CUI arrives, so the first evidence the assessor sees is the enclave's own birth certificate.

Weeks 4–6 — Pilot and migration

A pilot group of enclave users goes end to end — device enrollment, sign-in under Conditional Access, mail, files, Teams, a labelled CUI document that DLP handles correctly — and the runbook is corrected before the rest follow. In-scope mailboxes, OneDrive, SharePoint and Teams content are staged with delta passes, cutover runs to the communicated window, and the result is reconciled against the inventory.

Weeks 5–7 — SSP, POA&M, evidence index and SOPs

With the tenant built and populated, the documentation is written from what exists rather than from a template: each of the 110 requirements gets its implementation statement, every gap becomes a POA&M line with an owner and a date, the evidence index points at the real artefacts, and the four SOPs are drafted with the people who will execute them.

Week 8 — Readiness walkthrough, handover and training

We run the pre-assessment walkthrough the way an assessor would: pick requirements, ask for current evidence, time how long it takes to produce. Administrators are trained on operating the enclave and the seam with the commercial tenant, the DoD Assessment Methodology score worksheet goes to your affirming official, and you sign off on delivery before the invoice.

Prerequisites

Contracts with DFARS 252.204-7012 (and, where present, -7019, -7020 or -7021) or a prime's flowdown in hand, and a contracts owner who can answer which CUI categories the work involves.
A written determination of your CUI category and export-control position from counsel or the contracting officer — it decides GCC High versus GCC versus a hardened commercial tenant, and we design to it rather than make it.
Eligibility evidence for Microsoft's government-cloud validation where GCC High or GCC is the destination: a CAGE code and SAM.gov registration, or contract documentation evidencing CUI or export-controlled data obligations.
A licensing path: engagement with an AOS-G partner (typically under roughly 500 seats) or an Enterprise Agreement channel for the enclave's GCC High licenses, with license costs on your side; for a GCC enclave, Microsoft 365 GCC licensing can be quoted through us.
A named executive owner for the enclave boundary decision and a named affirming official for the CMMC self-assessment — both are business roles, not IT roles.
Global administrator access to the commercial tenant and, once provisioned, to the enclave tenant; read access to the identity, device and file estate for discovery.
A starting inventory: the people and roles who handle CUI, their devices and management state, the mailboxes, sites and Teams where CUI lives today, and the line-of-business applications enclave users depend on.
Where a readiness assessment already exists — ours or another firm's — its report, boundary analysis and any draft SSP, so the build starts from your findings instead of repeating them.

Who does what

IT Partner

  • Design the enclave boundary and data flows, and document the cloud decision against the determination you provide.
  • Prepare the eligibility submission and coordinate licensing sequence with your AOS-G partner or EA channel.
  • Build the enclave tenant to the agreed baseline across Entra ID, Intune, Purview and Defender, and export every policy as built.
  • Map all 110 NIST SP 800-171 Rev 2 requirements to settings, SOPs or organisational controls, honestly.
  • Plan and execute the migration of the in-scope population and reconcile it against the inventory.
  • Write the SSP, POA&M, evidence index and the four SOPs from the environment as built.
  • Run the readiness walkthrough, train your administrators, and state every Microsoft-controlled dependency and every licensing limitation in writing before it can surprise you.

Your team

  • Provide the contracts, the CUI category and export-control determination, and the eligibility evidence, and own their accuracy.
  • Purchase the enclave's licensing through the AOS-G partner or EA channel on the sequence the plan requires, and pay any Azure Government consumption directly.
  • Name the executive owner, the affirming official, the SOP owners and a project coordinator.
  • Grant tenant access, supply the inventory inputs and make application owners available for re-pointing.
  • Communicate with staff using the cutover pack, and execute the organisational controls — training, sanctions, screening, physical security — that no tenant setting can perform.
  • Submit the SPRS score, make the annual affirmation, engage a C3PAO if and when required, and own every assessment outcome.
  • Operate the enclave after handover, or contract someone to — the SOPs and evidence index are written so that either works.

What's not included

The readiness or gap assessment itself. If you have not yet had one, the CMMC and NIST 800-171 Compliance Readiness Assessment, the CMMC and FedRAMP Readiness Assessment or the lighter CMMC Self-Assessment Assistance come first; this service builds what they recommend.
A full-tenant move of the whole company into GCC High — that is the Microsoft 365 Commercial to GCC High Migration, and the boundary design will tell you honestly if it is the better shape for you.
GCC High licensing, or acting as your GCC High reseller. GCC High licenses flow through Microsoft's AOS-G partners or Enterprise Agreement channels, not our CSP; we coordinate with that partner. Azure Government consumption for Sentinel or any other workload is billed by Microsoft to you.
C3PAO engagement, assessor fees, DIBCAC interaction, or any guarantee of a self-assessment score, a conditional or final CMMC status, a certification outcome, or Microsoft's eligibility decision.
Legal determinations that data is or is not CUI, CUI Specified, ITAR- or EAR-controlled — that is counsel's work, and we design to what counsel and your contracting officer put in writing. IT Partner is not a law firm, a CPA firm, a QSA, a C3PAO or a certification body of any kind.
Ongoing evidence operations after handover — monthly evidence refresh, drift checks, policy review calendar and questionnaire support are the Compliance Evidence and Audit Readiness Retainer; security-program leadership and the risk register are the Virtual CISO.
Managed detection and response, 24/7 monitoring, a SOC or incident handling after handover — available separately through MDR or our security managed service; the incident-response SOP we deliver assumes you have named who watches the alerts.
Non-Microsoft systems inside the boundary — ERP, CAD/PLM, engineering file servers, manufacturing or operational technology, third-party SaaS — beyond re-pointing enclave users to them and recording them in the SSP. Bringing those systems to the 110 requirements is scoped separately.
On-premises work: Active Directory restructuring, network segmentation, firewalls, physical access controls, or hardware purchases — the design records what the enclave needs from them; delivering it is separate.
Endpoint refresh or at-scale device reimaging — enclave devices are enrolled and re-registered in the plan; replacing hardware is not.
Security awareness training delivery, background screening, sanctions processes, visitor logs and the other organisational controls: we write the procedure, you run it.
Enclave changes after handover — new user populations, additional workloads, Microsoft 365 Copilot or other AI features, or a later move from GCC to GCC High — are change requests quoted from the plan.

Limitations & technical notes

!Regulatory timing honesty: the 13 July 2026 memorandum suspended CMMC Phase 2's third-party certification requirement and froze the later phases pending the reform task force's recommendations; the self-assessment requirements of Phase 1, DFARS 252.204-7012, SPRS scoring and the annual affirmation remain in force. We build to the contract in hand, not to a headline, and we will tell you when the program moves again.
!NIST SP 800-171 Rev 2 is the assessed baseline: DoD's class deviation keeps contractors on Revision 2 even though NIST has published Revision 3, and the CMMC rule points at Rev 2. The SSP is written to the 110 Rev 2 requirements; a Rev 3 crosswalk is a future change, not something we pre-empt.
!Timeline honesty: Microsoft's eligibility validation and tenant provisioning are Microsoft-controlled steps measured in weeks, and reported lead times vary widely. The eight-week figure is our work with a provisioned tenant from week 3; we sequence around Microsoft's gates and cannot compress them.
!GCC High is not feature-identical to commercial Microsoft 365, and GCC is not identical to either. Some services and features arrive later, behave differently or are absent, external collaboration is deliberately more restricted, and some Microsoft 365 Copilot and AI capabilities have reached the government clouds after commercial. We confirm availability in your target cloud before writing a control into the SSP, and the initial baseline leaves AI features out unless your contract position and availability are settled.
!An enclave creates a seam. Users who live in the enclave and also work with the rest of the company will feel it — separate sign-in, restricted sharing, a different Teams. Entra cross-tenant access settings and Teams external access give you what Microsoft supports across the seam; the rest is procedure, and the SOPs say so.
!Audit-log retention depends on licensing: at the time of writing Purview Audit (Standard) keeps records for 180 days, Audit (Premium) for one year with the qualifying license, and a separate add-on extends to ten years; longer retention or correlation across sources means Microsoft Sentinel in Azure Government at your consumption cost. The monitoring design states which you have and why.
!Line-of-business applications must support government-cloud endpoints and the enclave's identity; some vendors do not. Discovery flags them, vendor roadmaps are outside our control, and an application that cannot follow its users into the enclave is a POA&M line, not a surprise.
!The 'from $25,000' floor covers a small enclave — a few dozen users and their devices, mail and files, a single cloud destination and no existing-SSP rework. Enclave seat count, device count, data volume, GCC versus GCC High, the number of applications to re-point, the state of any prior assessment and the length of coexistence move the price, and the fixed quote precedes any commitment.
!An enclave built and documented is not, by itself, compliance. Compliance is the posture you maintain and the evidence you can produce on the day you are asked; we hand over the starting state, the SOPs and the evidence index, and the retainer, the vCISO and your own team take it from there.

Frequently asked questions

What is a CMMC enclave, and why not just move everyone to GCC High?

An enclave is a separate, purpose-built Microsoft 365 environment holding only the users, devices, mailboxes and files that touch CUI, so the assessment boundary is small and the rest of the company keeps its commercial tenant and licensing. A full move is simpler to operate and to assess, but prices every seat at government-cloud rates and drags every application into scope. For most 25-to-1,000-seat suppliers with a defined defense workload, the enclave is the better economics; where the boundary design shows CUI is everywhere, we will say so and point you at the full migration instead.

GCC High, GCC or a commercial tenant — which one does the enclave need?

It depends on the CUI category in your contracts, and the answer has to come from your counsel or contracting officer in writing. Microsoft's guidance at the time of writing is that GCC is not suitable for CUI Specified — ITAR, nuclear and similar export-controlled data — because it requires US sovereignty, which only GCC High offers. For CUI Basic with no export-control element, GCC can be sufficient, and some primes accept a separately hardened commercial tenant. We design and build to the determination you give us; our decision guide walks through the questions that produce it.

What happened to the 10 November 2026 CMMC deadline?

Phase 2 of the DFARS CMMC rule would have put Level 2 third-party (C3PAO) certification into applicable solicitations from 10 November 2026. On 13 July 2026 the Under Secretary of Defense for Acquisition and Sustainment suspended that requirement and froze the later phases while a 60-day CMMC reform task force reviews the program. Phase 1 — Level 1 and Level 2 self-assessments in solicitations since 10 November 2025 — remains, as do DFARS 252.204-7012, SPRS scoring and the annual affirmation. The enclave you need for a defensible self-assessment is the same one an assessor would examine, so the work is not wasted whichever way the review lands; we cite the memorandum and the rule, and we do not tell anyone they 'must be certified by' a date.

Which version of NIST SP 800-171 do you build to?

Revision 2 — the 110 requirements the CMMC rule points at and that DoD's class deviation keeps in force for DFARS 252.204-7012 contractors, even though NIST has published Revision 3. The SSP, the POA&M and the control mapping are all in Rev 2 structure. When DoD moves to Rev 3 through rulemaking, the crosswalk is a scoped change to the documentation, not a rebuild of the tenant.

Do we buy the GCC High licenses from you?

No. GCC High licensing is not sold through the commercial CSP channel we operate. Organisations under roughly 500 seats buy through Microsoft's authorised AOS-G partners; larger ones typically use an Enterprise Agreement. We map your enclave population to the right GCC High SKUs, sequence the purchase against provisioning and coordinate with the partner you choose — we are the engineers, not the reseller. For a GCC enclave, Microsoft 365 GCC licensing can be quoted through us.

What exactly moves into the enclave?

The population named in the boundary design: the people who handle CUI, their mailboxes, their OneDrive content, the SharePoint sites and Teams where CUI lives, and their devices, which are re-registered to the enclave tenant and enrolled in its Intune. Content is staged ahead of cutover with delta passes and reconciled against the inventory afterwards. Hard cases — Teams private chat history, Planner, Forms, per-app settings — are dispositioned explicitly before cutover, so nothing is discovered missing after it.

How do enclave users work with the rest of the company?

Across a seam we design deliberately rather than leave to chance. Entra cross-tenant access settings and Teams external access cover what Microsoft supports between the enclave and your commercial tenant; sensitivity labels and DLP stop CUI crossing it; and the onboarding SOP tells a new enclave user how the two identities relate. Users will notice the separation — that is the point — and we would rather show you the friction in the pilot than promise it away.

What is in the SSP and the POA&M you deliver?

The SSP describes the enclave as built — boundary, data flows, roles, and an implementation statement for each of the 110 requirements naming the Entra, Intune, Purview or Defender setting, the SOP or the organisational control that satisfies it. The POA&M lists every requirement not fully implemented at handover with an owner, milestone and target date, built to the structure the CMMC rule permits, which limits which requirements may sit on a POA&M and sets a 180-day window to close them for a conditional status to become final. The evidence index maps each requirement to where its evidence lives and how it is refreshed.

Does this get us CMMC certified?

No, and nothing we sell does. Certification, when it is required, is issued by a C3PAO on its own judgment; the self-assessment score and the annual affirmation are yours to submit. What this service produces is an enclave whose controls are actually implemented, documentation that describes it truthfully, and evidence you can produce on demand — the things an assessor examines. We are Microsoft 365 engineers, not assessors, and the page says so on purpose.

What moves the price from $25,000?

Six things, all visible in the boundary design before we quote: the number of users in the enclave, the number of devices to enroll, the volume of mail and files to migrate, whether the destination is GCC High, GCC or a hardened commercial tenant, how many line-of-business applications need re-pointing, and whether a usable SSP or readiness report already exists. The floor covers a small enclave with a single destination and no rework; the fixed quote comes in writing before you commit.

Why eight weeks, and what is not inside them?

Eight weeks is our work: design, build, pilot, migration, documentation and handover, with a provisioned tenant by week 3. Microsoft's eligibility validation and tenant provisioning are Microsoft's, run in parallel from day one, and take a number of weeks that we can plan around but not promise. If you already hold a GCC High or GCC tenant, that dependency disappears; if you do not, expect the calendar to be longer than eight weeks even though our effort is not.

We already had a readiness assessment. Does that shorten the work?

Yes, if it produced a boundary analysis and a usable draft SSP. We start from its findings rather than repeating discovery, the control mapping inherits its gap list, and the price reflects it. If it was a questionnaire-style review with no boundary work, the week-1 design still has to happen, and we will tell you which of the two you have.

What about personal devices and phones?

CUI is reached only from a compliant, enclave-managed device — that is what the Conditional Access and Intune baseline enforce, and it is what the SSP claims. For phones, the design chooses between fully managed devices and app-protection policies with no local CUI storage, and personal computers are out unless the boundary design explicitly admits a managed-virtual-desktop pattern. 'Bring your own device' and CUI do not mix well, and we would rather scope the devices than dilute the control.

Our engineering and ERP systems hold CUI too. Are they covered?

They are recorded in the boundary and the SSP, and enclave users are re-pointed to them, but bringing a CAD, PLM, ERP or file-server platform to the 110 requirements is its own project, scoped after the boundary design shows what each system does with CUI. Where a system cannot follow its users into the enclave — a vendor with no government-cloud support, say — it becomes a POA&M line with a plan, not a footnote.

What happens after handover?

You operate the enclave, or someone you contract does; the SOPs and evidence index are written so either works, and nothing we deliver locks you to us. Most clients pair it with the Compliance Evidence and Audit Readiness Retainer for the monthly evidence refresh and drift checks, and some add the Virtual CISO for program leadership. If you buy your commercial Microsoft 365 licensing through IT Partner, our included business-hours break-fix support covers that tenant; support for the GCC High tenant is a separate agreement, because its licensing does not flow through us.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

From $25,000 per project
8 weeks
Book an enclave scoping call