Secure CUI collaboration

Keep CUI in a deliberately protected workflow and minimize unnecessary CMMC scope.

When CUI use is concentrated in email and files, a secure enclave can reduce how widely controlled information spreads through the business. Cyberneza traces the information flow, defines the boundary, evaluates the supporting assets, deploys the selected enclave, and documents the resulting CMMC environment.

How the work gets done

Cyberneza provides architecture, implementation guidance, remediation planning, and documentation.

Cyberneza translates the applicable requirements into security architecture, control designs, remediation plans, implementation procedures, configuration guidance, and validation criteria. Your technical team executes approved production changes through its established change-management process.

An enclave can reduce CUI exposure, but it does not replace CMMC scoping.

32 CFR 170.19 defines Level 2 scope using asset categories that include CUI Assets and Security Protection Assets and gives specific treatment to Contractor Risk Managed Assets, Specialized Assets, external service providers and Out-of-Scope Assets. A secure enclave can help constrain where CUI is stored and transmitted, but it does not automatically exclude identity, endpoint, security, administration or external-service components that support the CMMC environment.

How CUI moves through an assessment boundary Controlled Unclassified Information arrives from a prime contractor or government system, passes through the assets that store, process or transmit it, and leaves as deliverables. Those assets, plus the security protection assets that defend them, sit inside the assessment boundary. Systems that never touch CUI — marketing, sales and general IT — sit outside it and are out of scope. CUI arrives Contract or flow-down clause Email from the prime Government portal or transfer Assessment boundary CUI assets Store Process Transmit The 110 requirements apply here. Security protection assets Identity & MFA Logging & monitoring Backup & encryption They defend CUI, so they are in scope too. Specialized assets Test equipment, IoT, OT, government property — documented and risk-managed, assessed differently. CUI leaves Deliverables to the prime Submission to the government Outside the boundary — out of scope Marketing site, CRM, general IT, personal devices — anything that never receives, stores, processes or transmits CUI.
Where CUI enters, is stored, processed, transmitted and leaves — and which assets that pulls into scope. Settling this is what decides how many of the 110 requirements apply to you.

Trace the CUI flow

Identify who receives CUI, where it is stored, who sends it externally, and which systems and services process or transmit it.

Design the protected workflow

Where possible, restrict CUI handling to approved users, protected email/file-sharing channels and controlled endpoints instead of ordinary company-wide collaboration.

Map supporting assets

Identify identity, security, administration and external-service components that remain relevant to the enclave and its CMMC scope.

Deploy and document

Implement the workflow, update diagrams and the SSP, and ensure procedures describe how users handle CUI in the operating environment.

PreVeil is one enclave option for protected email and file sharing.

PreVeil publishes FedRAMP Moderate Equivalency, end-to-end encrypted email/files, and FIPS 140-3-validated cryptography information. It is designed to operate alongside Microsoft 365 or Google Workspace so general business collaboration can remain on the existing platform while approved CUI workflows use the protected environment.

Cyberneza is a PreVeil referral partner. We recommend it only when the information flow, customer requirements and surrounding CMMC architecture make it appropriate.

What an enclave can support

  • Concentrating CUI email and files.
  • Reducing unnecessary CUI exposure.
  • Limiting the number of people routinely handling CUI.
  • Potentially lowering implementation and operating cost by reducing unnecessary scope.

What an enclave does not eliminate

  • The remaining NIST SP 800-171 requirements.
  • Endpoint, identity and security operations.
  • Incident response, training and governance.
  • The need to document and support the CMMC boundary.

Define the CUI boundary before selecting the collaboration platform.

Cyberneza can map the CUI workflow, identify supporting assets and external services, compare enclave and broader migration architectures, and document which components remain inside the CMMC environment.

Discuss CUI enclave planning