Skip to main content

CUI Enclave Setup

Written by Brady Price

What a CUI enclave is

A CUI enclave is a secure, isolated environment where your organization stores and accesses Controlled Unclassified Information (CUI). Instead of CUI living across your entire company, it stays in one contained environment, which keeps your CMMC scope small and contained: fewer systems to secure, less documentation to maintain, and a faster, more affordable path to compliance.

The CUI Enclave Setup module in Navigator is where you choose what your enclave is built on and Secureframe sets it up: the cloud platform where CUI is stored, and the technology your team uses to work with it. Standing up a compliant CUI environment is traditionally a weeks-long project requiring dedicated IT resources or outside consultants; Secureframe applies the configuration automatically.


Your environment, your data

Secureframe builds your enclave inside cloud environments that your organization owns. Secureframe never hosts your CUI in a Secureframe-owned environment. Your data stays in your Microsoft, Google, or Azure tenant, and the environment remains yours.

Because the infrastructure runs in your tenant, cloud infrastructure costs are usage-based and are your responsibility, separate from your Secureframe subscription.


Cloud environment (required)

Choose the cloud platform where your organization's CUI will live. You need one to continue:

  • Microsoft 365 GCC High: Secureframe configures your GCC High tenant into a CMMC-compliant environment: a designated CUI SharePoint site with role-based access groups, multi-factor authentication (MFA), conditional access policies, CUI sensitivity labeling with data loss prevention, audit logging, and locked-down sharing on your CUI site.

  • Google Workspace: Secureframe configures your Google Workspace into a CMMC-compliant environment: a designated CUI area in Drive with role-based access groups, MFA, logging, sharing restrictions, and role separation so admin privileges and CUI access stay apart.

Connecting your cloud environment also syncs your personnel into Secureframe. Personnel are pulled automatically from your tenant, and as people join or leave your organization, Secureframe stays in sync. Connecting is also what unlocks the rest of Navigator. The later modules (roles, background checks, training, policies, and invitations) become available once your cloud environment is connected, and they work from your real, current personnel list.

Note: New to GCC High? You need a GCC High tenant before licenses can be purchased and applied to your organization. Start with Microsoft GCC High Tenant Eligibility for CMMC, which walks you through Microsoft's eligibility approval process.


Workspaces and endpoints

Choose how your personnel will access and manage CUI. You can set this up now or save it for later:

  • Azure Government VDI (Secureframe Virtual Desktops): Secureframe provisions and manages CMMC-compliant virtual desktops in your Azure Government environment. CUI work happens inside the desktops, so the computers connecting to them stay out of scope.

  • Secureframe Federal MDM: Secureframe's federally hosted device management enforces CMMC-required settings on your team's own Windows, macOS, and Linux computers. Enabled through your account manager.

Some organizations use one, and some use both for different teams. Your Customer Success Manager (CSM) can help you choose based on how your people actually work.


How setup works

Every component follows the same model:

  1. Connect: You authorize your environment with the required permissions through a guided setup flow.

  2. Configure: Secureframe applies the CMMC-compliant configurations automatically and walks you through the few steps that must be done manually with exact guided instructions.

  3. Validate: Configuration evidence flows into automated tests, so you can see your environment's compliance status on your dashboard.

For what Secureframe configures in your Microsoft GCC High environment, see What Secureframe configures in your Microsoft GCC High tenant. Deep configuration inventories may be limited to signed-in Help Center access.

Setup itself is a one-time process, but Secureframe's work does not end there. After your enclave is configured, Secureframe continuously syncs your personnel and configuration data, runs automated tests against your actual configuration, and flags anything that drifts out of compliance.


Frequently Asked Questions (FAQ)

Does setting up the enclave make me CMMC compliant?

  • It is the environment piece, and a significant one, but not the whole program. Policies, training, personnel processes, and documentation complete the picture, and the rest of Navigator walks you through them.

Who pays for the cloud infrastructure?

  • You do. The environment runs in your own tenant and the infrastructure costs are separate from your Secureframe subscription.

Can I use both Virtual Desktops and Federal MDM?

  • Yes. Some teams work from managed endpoints while others use virtual desktops. Choose per team based on how people work.

I already have a GCC High tenant. Can I use it?

Did this answer your question?