The enclave

The cheapest control is a smaller boundary.

Every system that touches CUI is in scope, and every system in scope has to meet 110 requirements, be documented, and be assessed. It follows that CUI should live in as few systems as possible.

Scope before and after an enclave

Before: every business system inside the assessment boundary. After: only the enclave inside it. Before 110 requirements applied to the whole company ERPEmail, all usersFile sharesEngineering / CADFinanceHRSales & CRMEvery laptopShared drives After 110 requirements applied to the enclave CUI file storeEnclave mailManaged devicesERPFinanceHRSales & CRMOther laptopsEngineering, non-CUI
The greyed systems are out of scope: not in the SSP, not assessed, and not paying for GCC High licenses. If they handle Federal Contract Information they still need the fifteen basic safeguards in FAR 52.204-21, but that is a much smaller job than 800-171.

What goes inside

The data, the people who handle it, and the devices they use

Data

Every document, drawing, message and dataset that is marked or reasonably identifiable as CUI. Finding all of it is the first task, and it is rarely where the org chart says it should be.

People

Only staff whose role requires access. Each gets an enclave identity, enclave email and training. Everyone else stays out, and the boundary documentation says so.

Devices

Managed, encrypted, and blocked if non-compliant. Conditional Access enforces it: an unenrolled or unhealthy device cannot reach the data. Personal devices are not admitted.

Choosing a tenant

GCC High is not automatic. The data decides.

If you hold
Why it matters
Usual answer
ITAR or EAR export-controlled data
Access must be limited to US persons, including the cloud provider's own support staff. Commercial tenants can't guarantee that.
GCC High and Azure Government
CUI under DFARS 7012, no export control
DFARS 7012 requires FedRAMP Moderate or equivalent for cloud services holding covered defense information, plus incident reporting and forensic obligations. Which tenants qualify has shifted with DoD guidance.
GCC High in most cases
[confirm against current DoD guidance]
FCI only, no CUI
FAR 52.204-21 lists fifteen basic safeguarding requirements. You may not need a separate enclave, just a properly configured tenant.
Commercial or GCC, hardened

Components

Each component is there because a control family requires it

Entra ID and Conditional Access

Access Control (AC)
Identification and Authentication (IA)
MFA, least privilege, session control

Intune

Configuration Management (CM)
Media Protection (MP)
Baselines, encryption, compliance enforcement

Defender

System and Information Integrity (SI)
Incident Response (IR)
Risk Assessment (RA): vulnerability scanning

Purview

Media Protection (MP): marking and handling
System and Communications Protection (SC): DLP
Labels, retention, eDiscovery

Sentinel or another SIEM

Audit and Accountability (AU)
Log retention, review and alerting
The evidence trail an assessor will ask for

The SSP

Every setting above maps to a requirement.
We write the SSP from the build,
not the build from the SSP.

Process

How the build runs

1. Discover

Locate all CUI, including copies nobody intended to make.

2. Design

Boundary, data flows, identities and devices, mapped to controls before anything is built.

3. Build

Tenant, policies, baselines and logging, configured from the design and documented as we go.

4. Migrate

Move the data and the people in. Train them. Cut over email and file access.

5. Remove

Purge CUI from the old systems and document that it's gone. Until then, those systems are still in scope.

Running costs

GCC High licensing costs more per user than commercial, and Microsoft validates eligibility before selling it. That's one more reason to keep the enclave small: you pay the premium for the people who need it rather than the whole company. We'll put real numbers on it during scoping.

Not sure where your CUI is?

Most organizations aren't. That's what the discovery phase is for.

Contact us