Scoping is the decision that sets your budget
Before a single control gets implemented, you have to decide where CUI is allowed to live. Contractors who let CUI spread across their entire corporate network end up applying 110 controls to every laptop, server, and SaaS app they own. Contractors who build a defined enclave apply them to a much smaller boundary.
The enclave approach is usually dramatically cheaper and faster, but it only works if your business processes can actually be restructured to keep CUI inside it. That is an operational question as much as a technical one, and it is the first thing we work through.
- Full-boundary: every system in scope. Simplest to explain, most expensive to build and maintain.
- Enclave: a hardened, segmented environment where all CUI is created, stored, and processed.
- Hybrid: enclave for CUI workloads plus tightly controlled interfaces to corporate IT.
The 110 controls and your SPRS score
NIST SP 800-171 organizes 110 controls across 14 families — access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
The DoD Assessment Methodology converts your implementation status into a score submitted to SPRS. It starts at 110 and subtracts weighted points for every unimplemented control — 5, 3, or 1 point depending on severity. A contractor who has done nothing scores -203. Primes increasingly check SPRS scores before awarding subcontracts, which means your score is a commercial asset, not just a compliance artifact.
GCC High, enclaves, and the licensing question
Most Level 2 conversations arrive at Microsoft licensing quickly. GCC High is the common answer for CUI in Microsoft 365, but it is not the only answer and it is not automatically required — what matters is that your environment meets the control requirements, including FedRAMP-equivalent handling for cloud services storing CUI and, where ITAR applies, US-person access restrictions.
We work through the actual requirement rather than defaulting to the most expensive SKU. Sometimes GCC High is right. Sometimes a purpose-built enclave is cheaper and cleaner.
Where we fit — and where we do not
We do the implementation: scoping, remediation engineering, System Security Plan, POA&M, evidence packages, and the ongoing managed services that keep controls in place between assessments.
We do not perform your assessment. Under CMMC independence rules, an authorized C3PAO cannot assess an environment it built, so you need a separate implementation partner regardless. We will make C3PAO introductions when your environment is ready.

