CMMC Level 2: shrinking the assessment boundary
The largest cost driver in a CMMC engagement is not the controls. It is how much of your environment you let into scope.
When a defence supplier asks us what CMMC Level 2 will cost, the honest answer is that we cannot say until we know where Controlled Unclassified Information goes. Two companies of identical size routinely differ by a factor of five, and the variable is scope.
Why the boundary dominates
Every system that stores, processes or transmits CUI is in scope for all 110 NIST SP 800-171 requirements. Systems that provide security functions to those systems are in scope too. If CUI has been allowed to spread into general-purpose file shares, email, and every engineer’s laptop, you have effectively scoped your entire company.
The enclave pattern
- A defined set of systems where CUI is permitted to exist, with everything else explicitly out of bounds
- Controlled entry and exit points, logged, with data transfer procedures people can actually follow
- Separate identity where practical, or at minimum separate privileged access
- Documented and enforced — an enclave that exists only in the System Security Plan will not survive assessment
What this costs you
Enclaves impose friction. Engineers cannot use their normal tooling for CUI work, and that is unpopular. The trade is real: friction for a small number of people against 110 requirements applied to your entire estate. In every engagement we have run, the enclave has been cheaper — but the decision belongs to the business, and it should be made explicitly rather than by drift.
Sequencing
Map CUI flows first, design the boundary second, implement controls third. Suppliers who implement controls before scoping invariably re-do work, because the control set that makes sense for an enclave is not the one that makes sense for a whole company.
