CMMC Enclave vs Enterprise: What 47 Assessments Show | Lazarus Alliance

CMMC Enclave vs Enterprise:
What 47 Assessments Show

Boundary Choice and Its Impact on Duration, Evidence, and Findings

Based on N = 47 completed formal Level 2 assessments  •  January 2025 – June 2026  •  Updated August 2026

66%
Enclave Boundary
(31 of 47)
34%
Enterprise Boundary
(16 of 47)
Faster
Enclave Assessments
on Average
Fewer
Residual Findings
in Enclaves
Quick Answer
In the Lazarus Alliance dataset of N = 47 formal CMMC Level 2 assessments, 66% (31) used a defined CUI enclave and 34% (16) assessed a full enterprise or multi-site boundary. Enclave assessments showed lower average duration, lower evidence volume, and fewer residual findings related to residual enterprise systems. Boundary definition remains one of the highest-leverage decisions an Organization Seeking Certification can make.
August 2026 Regulatory Context
On 13 July 2026 the Department of War suspended CMMC Phase II requirements pending a 60-day reform review. Phase I self-assessment requirements and DFARS 252.204-7012 remain in effect. Voluntary C3PAO assessments continue. Primary sources: DoW Release · Memo 26-P-1023 · DoD CIO CMMC.

1. Boundary Distribution in the Dataset

Boundary TypeCountShareTypical Profile
Defined CUI Enclave3166%Segmented network / system set limited to CUI processing
Enterprise / Multi-site1634%Broader organizational or multi-location boundary

Boundary Type (N = 47)

Relative Assessment Characteristics

2. What the Data Showed

Duration

Enclave assessments tended to complete the formal assessment phase faster. The overall median formal duration across all 47 assessments was 17 business days. Highly prepared enclave scopes frequently landed in the 25th percentile (around 11 business days). Enterprise and multi-site boundaries more often extended into the upper quartile (26+ days), especially when evidence was incomplete or segmentation was weakly documented.

Evidence volume

Average evidence volume across the full dataset was ~1,920 artifacts (range ~650–5,800). Enclave packages were generally more compact and better mapped. Enterprise packages more often required sampling strategies and generated more clarification requests.

Residual findings and POA&Ms

Enclave assessments showed fewer residual findings related to residual enterprise systems (access paths, logging consistency, policy application across locations). Enterprise assessments more frequently encountered issues with:

  • Consistent policy application across sites
  • Remote access paths into the broader environment
  • Multi-location logging and review
  • Boundary protection and external connections

Overall, 74% of assessments (35 of 47) had at least one POA&M item. Cleaner enclave boundaries correlated with more limited POA&M profiles.

3. Why Enclaves Tend to Perform Better

  1. Smaller, clearer scope — fewer systems, fewer users, fewer external connections to evidence.
  2. Defensible data flows — accurate diagrams make CUI paths visible and testable.
  3. Enforceable segmentation — technical controls that keep CUI inside the assessed boundary.
  4. Tighter evidence mapping — practice-to-artifact linkage is easier when the environment is bounded.
  5. Reduced residual risk surface — less “everything else” that assessors must still consider.

Success depends on the enclave being real, not merely documented. Assessors required strong evidence that CUI could not traverse uncontrolled paths into or out of the boundary.

4. When Enterprise Boundaries Are Appropriate

Enterprise assessments are sometimes unavoidable — for example when CUI is widely distributed, when business processes prevent meaningful segmentation, or when contractual scope requires broader coverage. In those cases the data suggest:

  • Invest early in consistent policy and control application across locations
  • Document sampling methodology clearly
  • Prioritize MFA, centralized logging, and baseline management — the areas that generated the most residual findings overall
  • Expect higher evidence volume and a higher likelihood of clarification rounds (89% of all assessments required additional evidence)

5. Practical Recommendations

  • Decide the boundary before heavy remediation. Scope drives cost, duration, and finding density.
  • Defend the enclave with diagrams and technical controls, not just a network drawing.
  • Treat boundary documentation as primary evidence — data flows, segmentation rules, and CUI inventories.
  • If enterprise is required, plan for more evidence and more assessor dialogue.
  • Use the same quality standard for enclave evidence that you would for a larger scope; small does not mean informal.

6. Related Benchmark Metrics (Full N = 47)

MetricValue
Median formal assessment duration17 business days
Assessments with ≥1 POA&M74% (35 of 47)
Required additional evidence89% (42 of 47)
Average evidence artifacts~1,920
Most frequent residual findingsMFA, logging, baselines

Aggregate CSV: 2026_CMMC_Benchmark_Aggregate_Data.csv

7. Authors & How to Cite

Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
Authorized CMMC C3PAO leadership; A2LA-accredited FedRAMP 3PAO; PCI DSS QSA firm principal.

How to Cite
Peters, M. D. (2026). CMMC Enclave vs Enterprise: What 47 Assessments Show. Lazarus Alliance, Inc. Data drawn from the 2026 CMMC Assessment Benchmark Report (N = 47).

8. About Lazarus Alliance

Lazarus Alliance is an authorized CMMC Third-Party Assessment Organization (C3PAO, CPN 10251), an A2LA-accredited FedRAMP 3PAO, a PCI DSS Qualified Security Assessor (QSA), and a veteran-owned small business headquartered in Scottsdale, Arizona.

Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580  •  [email protected]
https://lazarusalliance.com

© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Figures are observational aggregates from anonymized assessments and do not guarantee individual outcomes.

Data Source

This analysis is based on the 2026 CMMC Assessment Benchmark Report, Lazarus Alliance's aggregate analysis of 47 completed formal CMMC Level 2 C3PAO assessments conducted between January 2025 and June 2026.

Additional Analysis

  1. How Long Does a CMMC Level 2 Assessment Take?
  2. 7 Most Common CMMC Level 2 Assessment Findings
  3. How Much Evidence Does a CMMC Assessment Require?
  4. How Common Are CMMC POA&Ms?

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.