Skip to content
CUI Enclaves for CMMC: The PreVeil + MAD Security CMMC Solution – August 2026

Watch the August MAD Security Town Hall Webinar replay 👇

 

 

Why Defense Contractors Should Understand CUI Enclaves

For defense contractors preparing for Cybersecurity Maturity Model Certification (CMMC), one question eventually becomes unavoidable: How are we going to protect Controlled Unclassified Information (CUI)?

Some organizations secure their entire enterprise. Others create completely separate environments. For many organizations, however, a CUI enclave can offer a more practical path by creating a defined security boundary around the people, systems, and data that need to handle CUI.

MAD Security’s August 2026 Town Hall explored how CUI enclaves can reduce CMMC scope and complexity, where PreVeil fits into an enclave strategy, and why secure technology must be combined with cybersecurity operations and compliance guidance to prepare for a successful CMMC assessment.

Leading the conversation were:

Drawing on their experience with CMMC, cybersecurity operations, and secure CUI environments, the speakers explained how organizations can approach enclave decisions without unnecessarily rebuilding their entire IT environment.

"There's no one-size-fits-all to CMMC. Every organization is different." 

- Adam Starnes, Customer Experience Manager


T
hroughout the discussion, several themes emerged around scope, technology, shared responsibility, and assessment readiness.

 

Key Takeaways from August Town Hall

MAD red 1 one

A CUI Enclave Can Reduce CMMC Assessment Scope 

At its core, a CUI enclave creates a defined, secure boundary for the subset of data, people, and systems that need to handle Controlled Unclassified Information.

Instead of applying the same CMMC requirements across an entire organization, an enclave can help isolate the CUI workflow and reduce the number of users and systems involved in the assessment boundary.

A smaller scope can mean lower costs, less disruption to existing business operations, easier evidence collection, and a more manageable CMMC implementation.

"An enclave simply reduces your CMMC assessment scope." 

- Erik Servinsky, Director of Sales, PreVeil

 

MAD red 2 two

An Enclave Does Not Require Rebuilding Your Entire Environment 

One common misconception is that implementing a CUI enclave means duplicating infrastructure or moving the entire organization into a new environment.

That is not necessarily the case.

For organizations that can clearly identify which users need CUI access, an enclave can allow much of the existing commercial infrastructure to remain in place while carving out where CUI is stored, processed, shared, and communicated.

This can provide an alternative for organizations evaluating options such as an enterprise-wide Microsoft GCC High implementation.

 

MAD red 3 three

PreVeil Provides More Than Secure File Storage  

PreVeil supports secure CUI communication and collaboration through end-to-end encryption, secure email, and secure file storage.

Users can receive an additional secure CUI email address that integrates directly into Outlook, helping them maintain familiar workflows. PreVeil also provides secure drive functionality for storing and collaborating on files, which can be accessed through Windows Explorer or a web application.

The platform can also support secure collaboration with primes, subcontractors, and other trusted third parties without requiring organizations to move their entire Microsoft environment.

"Only you as our customer and the sender of the data and a recipient would ever have access to the information." 

- Erik Servinsky, Director of Sales, PreVeil

 

MAD red 4 four

Technology Alone Does Not Make an Organization CMMC Compliant

One of the most important points from the Town Hall was that implementing an enclave does not automatically achieve CMMC compliance.

Organizations still need documentation, policies, procedures, evidence collection, security practices, training, System Security Plan updates, and clearly defined shared responsibilities.

Technology is one piece of the compliance program. People, processes, documentation, and evidence must support the technical implementation.

"Technology alone doesn't achieve compliance."  

- Jaclyn Jones, GRC Lead  

 

MAD red 5 five

Cybersecurity Operations and Compliance Guidance Complete the Picture

The partnership between PreVeil and MAD Security is designed around clearly defined responsibilities.

PreVeil provides the secure enclave technology, while MAD Security can provide CMMC gap assessments, Virtual Compliance Manager services, System Security Plan support, policy and procedure guidance, SOC and SIEM services, endpoint detection and response, vulnerability management, user awareness training, penetration testing, continuous monitoring, and assessment readiness guidance.

The goal is to bring technology, cybersecurity operations, and compliance expertise together so organizations understand who owns each responsibility and what evidence will be required during an assessment.

 

Q&A Highlights

Do I have to move my entire Microsoft environment into PreVeil?

No. Organizations can maintain their existing commercial Microsoft environment and limit PreVeil access to the individuals who need to handle CUI.

Does implementing an enclave automatically make us CMMC compliant?

No. An enclave can protect CUI and reduce scope, but organizations must still implement the required documentation, policies, procedures, training, evidence collection, and security practices.

When should an organization begin planning for an enclave?

As early as possible. Organizations should begin identifying where CUI exists, who needs access, and what the assessment boundary should include well before scheduling a CMMC certification assessment.

What does an enclave look like for the end user?

PreVeil users can have a secure email inbox integrated into Outlook and a secure drive for storing and collaborating on CUI. Endpoints, audit logging, user awareness training, HR controls, incident response, risk assessments, and other organizational responsibilities still need to be considered within the broader CMMC program.

 

What a CUI Enclave Can Look Like in Practice

The concepts discussed during the webinar are not purely theoretical. The Town Hall also highlighted how this approach has worked in a real-world CMMC environment.

The Town Hall highlighted Logical Systems, Inc. (LSI) as a real-world example of this approach.

LSI maintained its existing Microsoft environment, implemented a PreVeil enclave, and partnered with MAD Security as its managed security service provider and CMMC readiness partner.

According to the Town Hall, LSI moved from an SPRS score of -171 to a perfect 110 and successfully completed a CMMC Level 2 assessment.

Rather than rebuilding the entire environment, the organization narrowed its CUI scope and combined secure technology with cybersecurity operations, documentation, evidence collection, and compliance guidance.

 "They didn't try to rebuild their entire environment."  

- Adam Starnes, Customer Experience Manager 


The example demonstrates why enclave decisions should be driven by how an organization actually handles CUI, not by the assumption that every system and employee must be treated the same way.

 

Why Organizations Should Start With Their CUI

Organizations evaluating an enclave should begin by identifying where CUI lives, who needs to handle it, and how that information moves through the business.

Defining those elements early can help establish a clear system boundary, reduce unnecessary components within scope, and make policies, procedures, and evidence easier to manage.

 "Identify your CUI, where it lives, who needs to handle it."  

- Erik Servinsky, Director of Sales, PreVeil

 

Waiting until a CMMC assessment is scheduled can create unnecessary pressure. CUI identification, scope definition, documentation, and evidence collection should begin well before assessment day.

Early preparation gives organizations more time to address gaps, refine processes, and ensure the technical environment matches what is documented in policies, procedures, and the System Security Plan.

 

Free Resources and Next Steps 

Once organizations understand their CUI scope and potential compliance gaps, the next step is turning that knowledge into an actionable readiness plan.

Whether your organization is evaluating a CUI enclave or already preparing for a CMMC assessment, MAD Security offers several free resources to help you understand where you stand and what comes next.

Available resources include:

  Free CMMC Pre-Assessment
  CMMC Master Bundle
  Free Consultation with MAD Security
  MAD Security Town Hall Webinars

These resources can help organizations better understand their current CMMC posture, identify potential gaps, and develop a practical strategy for protecting CUI and preparing for assessment.

 

Final Thoughts 

A successful CMMC strategy starts with understanding how your organization actually handles CUI and building the security and compliance program around that reality.

For many defense contractors, a properly designed CUI enclave can reduce complexity and help create a more manageable path to protecting sensitive information. But technology is only part of the solution.

Combining secure enclave technology from PreVeil with MAD Security’s cybersecurity operations and CMMC compliance guidance can help organizations build a program designed not only for assessmentreadiness, but for long-term cybersecurity and compliance success.

 "The more preparation you do up front, the smoother the assessment process is going to be for you."  

- Jaclyn Jones, GRC Lead


If your organization is evaluating a CUI enclave or trying to determine the right approach for CMMC, MAD Security can help you assess your environment, define your scope, identify gaps, and develop a practical path forward.