Your CMMC Enclave Protects CUI. It Won't Stop Ransomware.
CMMC enclave strategies protect confidentiality, not availability. Here's the risk manufacturers overlook when they treat an enclave as a complete security program.
An enclave is the default scoping strategy for most defense contractors going through CMMC Level 2 right now, and for good reason. It's cheaper, faster to stand up, and easier to maintain than applying every control across an entire enterprise. That part isn't wrong.
What's wrong is treating the enclave as the whole security program instead of one piece of it. An enclave is built to protect the confidentiality of CUI. It was never built to keep your business running. For most organizations, that gap doesn't matter much. For manufacturers, it's the gap that actually gets exploited.
What a CMMC Enclave Actually Protects
A CMMC enclave is a defined, access-controlled boundary around the people, systems, and locations that touch Controlled Unclassified Information. Everything inside the boundary gets the full weight of NIST SP 800-171 controls. Everything outside it doesn't, at least not as a compliance requirement.
That's the appeal. Instead of applying 110 controls across every workstation, server, and account in the company, you apply them to a contained segment. Smaller footprint, lower cost, shorter audit trail.
But scope down the boundary and you scope down what the assessment is actually measuring. CMMC Level 2 and the underlying 800-171 controls exist to protect one thing: the confidentiality of CUI. That's the stated purpose of the publication. It is not a general-purpose security certification, and it was never designed to be one.
| Typically Inside the Enclave | Typically Outside the Enclave | |
|---|---|---|
| Systems | Servers and workstations that store, process, or transmit CUI | Shop floor equipment, general office systems, non-CUI business applications |
| Controls applied | Full 110 controls from NIST SP 800-171 | Baseline IT hygiene, not formally assessed under CMMC |
| What's measured | Confidentiality of CUI | Not part of the CMMC assessment scope |
The Blind Spot: Confidentiality Isn't the Whole Risk Picture
Security has three legs: confidentiality, integrity, and availability. NIST 800-171 is explicit about which one it's built around. Confidentiality is the mandate. Integrity often comes along for the ride, since a lot of controls that protect confidentiality (like cryptography) protect integrity at the same time. Availability is scoped out on purpose.
For a lot of organizations in the DIB, that's a reasonable trade-off. If your primary risk is a foreign adversary getting access to sensitive program data, confidentiality is exactly where your attention should go.
Manufacturers are a different case. If a ransomware event takes down production systems, the immediate damage isn't a data leak. It's that parts stop shipping. For a company building components for a weapons platform or a critical subsystem, availability isn't a secondary concern. It's the primary one.
An enclave that perfectly protects CUI confidentiality does nothing to stop that. The systems that keep the plant running are, by design, often outside the compliance boundary entirely.
Why Manufacturers Over-Optimize for the Enclave
Vicky Pillitteri, NIST — The Watchers Podcast, Episode 43
Vicky Pillitteri, who leads security engineering and risk management at NIST, breaks down this exact blind spot in the clip above.
Her point isn't that enclaves are a bad strategy. She's clear that an enclave can be a genuinely cost-effective way to isolate CUI, especially for smaller organizations without a dedicated security team. The problem shows up when a company leans so heavily into the enclave that it loses sight of everything the enclave doesn't cover. In manufacturing specifically, she points to availability as the lever nobody's watching, since ransomware taking down a production environment is a far more common and immediate threat than a confidentiality breach. DoD's use of CMMC and 800-171 gives contractors one lever to focus on. It was never meant to be the only lever a manufacturer pulls.
For more conversations like this, subscribe to Sentinel Blue on YouTube.
Where This Goes Wrong in Practice
Here's the scenario that plays out more often than it should. A manufacturer builds a tightly scoped enclave, passes their assessment with a perfect score, and moves on. Six months later, ransomware hits the systems that run production, systems that were never inside the enclave boundary because they never touched CUI.
Nothing about that event is a compliance failure. The enclave did exactly what it was certified to do. But the business still can't ship parts, and the certification on file doesn't reflect that risk at all.
This is the same gap we cover in our breakdown of CMMC compliance requirements: passing an assessment proves your controls existed and were documented on the day the assessor showed up. It doesn't prove your organization can absorb a real attack. Applied to enclave scoping specifically, that means the boundary decision that gets you certified and the boundary decision that keeps your business running are not automatically the same decision.
How to Scope an Enclave Without Creating a Blind Spot
An enclave should be a scoping decision for compliance, not a substitute for a security strategy. Whatever sits outside the boundary still needs baseline protection, particularly the controls that address availability rather than confidentiality.
Before finalizing an enclave boundary, it's worth asking:
- What happens to production, shipping, or service delivery if the systems outside the enclave go down?
- Do the out-of-enclave systems have backup and recovery in place, tested and not just documented?
- Is there network segmentation between the enclave and the rest of the environment, so an incident on one side doesn't spread to the other?
- Does incident response cover the whole business, or only the systems inside the compliance boundary?
- Who is monitoring the systems that fall outside the assessment scope?
None of these questions have anything to do with whether you pass your next CMMC assessment. All of them determine whether your business is still operating the week after an incident.
This is where Sentinel Blue's approach differs from a pure compliance engagement. Citadel builds the CMMC-ready enclave in GCC High. Shield extends coverage, monitoring, and incident response across the parts of the business the enclave doesn't touch, so the boundary that satisfies an assessor isn't the same boundary that determines whether operations survive a ransomware event.
Enclave or Enterprise-Wide? It Depends on What You're Actually Protecting
The enclave-versus-enterprise decision usually gets framed as a cost question, and cost is a real factor. But the more useful question is what risk you're actually managing. If confidentiality of CUI is genuinely your top concern, a well-scoped enclave is a sound, defensible strategy. If operational uptime is what keeps you up at night, and for most manufacturers it should, your security program needs to extend past the enclave boundary even though your CMMC compliance obligation stops there.
For a deeper comparison of when each approach makes sense, see our breakdown of Enterprise vs. Enclave Solutions.
Need Help Scoping Your Environment?
Sentinel Blue helps defense contractors build enclave and enterprise-wide environments that satisfy CMMC and actually hold up against real-world threats.
Talk to Sentinel BlueFrequently Asked Questions
Does a CMMC enclave protect against ransomware?
Not by itself. A CMMC enclave is built to protect the confidentiality of CUI, which is the mandate under NIST SP 800-171. Ransomware is primarily an availability threat, and availability is intentionally outside the scope of what CMMC assesses. Systems outside the enclave boundary need their own protection against ransomware, since they aren't covered by the compliance requirement.
Is an enclave enough for CMMC Level 2 compliance?
A properly scoped enclave can satisfy CMMC Level 2 certification requirements. Whether it's enough as a full security strategy depends on what else is at risk in your business. Manufacturers in particular should treat the enclave as one part of a broader security program, not the entire program.
What outside a CMMC enclave still needs security controls?
Any system that isn't formally protecting the confidentiality of CUI. In practice, that often includes production and shop floor systems, general business applications, and everyday office infrastructure. These systems fall outside the CMMC assessment scope, but they still need baseline security hygiene, especially backup, recovery, segmentation, and monitoring.
Why does NIST 800-171 only address confidentiality?
NIST SP 800-171 is derived from the moderate confidentiality baseline in NIST SP 800-53. Its stated purpose is protecting the confidentiality of Controlled Unclassified Information specifically, not general enterprise security. Integrity is often addressed as a byproduct of confidentiality controls, but availability is intentionally scoped out and left to the organization's broader risk management program.