CMMC Level 2 · Defense Industrial Base · Leesburg, VA+1 571 410-3066
Capital Cyber Compliance

CUI enclave design

Where CUI lives, written down.

Advisory design for a Controlled Unclassified Information boundary on Microsoft GCC High and Azure Virtual Desktop, for contractors building or keeping their own. Design and documentation only.

Advisory CUI enclave design on Microsoft GCC High and Azure Virtual Desktop: where Controlled Unclassified Information lives, who reaches it, and how that is evidenced.

Where CUI actually lives

A boundary is not a wall. It is a wall with exactly one gate, and knowing where that gate is, and who is allowed through it, is most of the design work.

REST OF YOUR NETWORKWorkstationsGeneral emailBusiness appsNO PATH TO CUICUI ENCLAVESecure CUI emailFile share and storageActivity logsBackupsAuthorizedusersTHE ONEGATEIsolated browserand MFANothing is savedto the PC

Scroll sideways to see the whole diagram.

Is this the right service?

SCOPED, NOT PRICED

Who it is for

A contractor building its own CUI environment, or reshaping one it already has, who wants the boundary designed before money is spent on licensing and build.

How it starts

With where CUI enters your business today: which contracts bring it in, which people handle it, and which systems it touches.

How it differs

The gap assessment reviews the boundary you already have. Enclave design draws a new one. CMMC In A Container gives you an enclave we provide and manage, already FedRAMP Moderate Authorized, so there is nothing to design; this service is for when you are building or keeping your own.

What you receive

A written boundary: which systems handle CUI, and which are kept out of scope and why.An access design: who reaches CUI, from where, and how that access is evidenced.The scoping documentation that goes with it, such as the CUI flow diagram and network boundary diagram, written against your environment.

What this is not

This is design and documentation only. We do not hold your CUI, we do not operate the environment under this engagement, and we are not an Authorized C3PAO.

Book a 30-minute call.

BOOK A CALL

Scoped per client, so the first step is a conversation. Pick a time.

What happens in 30 minutes

  1. We read your contract's CMMC and DFARS clauses with you.
  2. We confirm which level applies and how it will be assessed.
  3. We tell you the first step, whether or not it involves us. No slides.

Talk to us about it.

This is scoped per client, not priced on a page. Tell us what you have and we will tell you what it takes.

Book a 30-minute call

Defense supplier under 25 people? Start with the grant.

Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.

Apply for a CGA grant