CMMC Enclave vs Enterprise:
What 47 Assessments Show
Table of Contents
ToggleBoundary Choice and Its Impact on Duration, Evidence, and Findings
Based on N = 47 completed formal Level 2 assessments • January 2025 – June 2026 • Updated August 2026
(31 of 47)
(16 of 47)
on Average
in Enclaves
On 13 July 2026 the Department of War suspended CMMC Phase II requirements pending a 60-day reform review. Phase I self-assessment requirements and DFARS 252.204-7012 remain in effect. Voluntary C3PAO assessments continue. Primary sources: DoW Release · Memo 26-P-1023 · DoD CIO CMMC.
1. Boundary Distribution in the Dataset
| Boundary Type | Count | Share | Typical Profile |
|---|---|---|---|
| Defined CUI Enclave | 31 | 66% | Segmented network / system set limited to CUI processing |
| Enterprise / Multi-site | 16 | 34% | Broader organizational or multi-location boundary |
Boundary Type (N = 47)
Relative Assessment Characteristics
2. What the Data Showed
Duration
Enclave assessments tended to complete the formal assessment phase faster. The overall median formal duration across all 47 assessments was 17 business days. Highly prepared enclave scopes frequently landed in the 25th percentile (around 11 business days). Enterprise and multi-site boundaries more often extended into the upper quartile (26+ days), especially when evidence was incomplete or segmentation was weakly documented.
Evidence volume
Average evidence volume across the full dataset was ~1,920 artifacts (range ~650–5,800). Enclave packages were generally more compact and better mapped. Enterprise packages more often required sampling strategies and generated more clarification requests.
Residual findings and POA&Ms
Enclave assessments showed fewer residual findings related to residual enterprise systems (access paths, logging consistency, policy application across locations). Enterprise assessments more frequently encountered issues with:
- Consistent policy application across sites
- Remote access paths into the broader environment
- Multi-location logging and review
- Boundary protection and external connections
Overall, 74% of assessments (35 of 47) had at least one POA&M item. Cleaner enclave boundaries correlated with more limited POA&M profiles.
3. Why Enclaves Tend to Perform Better
- Smaller, clearer scope — fewer systems, fewer users, fewer external connections to evidence.
- Defensible data flows — accurate diagrams make CUI paths visible and testable.
- Enforceable segmentation — technical controls that keep CUI inside the assessed boundary.
- Tighter evidence mapping — practice-to-artifact linkage is easier when the environment is bounded.
- Reduced residual risk surface — less “everything else” that assessors must still consider.
Success depends on the enclave being real, not merely documented. Assessors required strong evidence that CUI could not traverse uncontrolled paths into or out of the boundary.
4. When Enterprise Boundaries Are Appropriate
Enterprise assessments are sometimes unavoidable — for example when CUI is widely distributed, when business processes prevent meaningful segmentation, or when contractual scope requires broader coverage. In those cases the data suggest:
- Invest early in consistent policy and control application across locations
- Document sampling methodology clearly
- Prioritize MFA, centralized logging, and baseline management — the areas that generated the most residual findings overall
- Expect higher evidence volume and a higher likelihood of clarification rounds (89% of all assessments required additional evidence)
5. Practical Recommendations
- Decide the boundary before heavy remediation. Scope drives cost, duration, and finding density.
- Defend the enclave with diagrams and technical controls, not just a network drawing.
- Treat boundary documentation as primary evidence — data flows, segmentation rules, and CUI inventories.
- If enterprise is required, plan for more evidence and more assessor dialogue.
- Use the same quality standard for enclave evidence that you would for a larger scope; small does not mean informal.
6. Related Benchmark Metrics (Full N = 47)
| Metric | Value |
|---|---|
| Median formal assessment duration | 17 business days |
| Assessments with ≥1 POA&M | 74% (35 of 47) |
| Required additional evidence | 89% (42 of 47) |
| Average evidence artifacts | ~1,920 |
| Most frequent residual findings | MFA, logging, baselines |
Aggregate CSV: 2026_CMMC_Benchmark_Aggregate_Data.csv
7. Authors & How to Cite
Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
Authorized CMMC C3PAO leadership; A2LA-accredited FedRAMP 3PAO; PCI DSS QSA firm principal.
How to Cite
Peters, M. D. (2026). CMMC Enclave vs Enterprise: What 47 Assessments Show. Lazarus Alliance, Inc. Data drawn from the 2026 CMMC Assessment Benchmark Report (N = 47).
8. About Lazarus Alliance
Lazarus Alliance is an authorized CMMC Third-Party Assessment Organization (C3PAO, CPN 10251), an A2LA-accredited FedRAMP 3PAO, a PCI DSS Qualified Security Assessor (QSA), and a veteran-owned small business headquartered in Scottsdale, Arizona.
Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580 • [email protected]
https://lazarusalliance.com
© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Figures are observational aggregates from anonymized assessments and do not guarantee individual outcomes.
Scottsdale, Arizona • 1-888-896-7580 • lazarusalliance.com
Data Source
This analysis is based on the 2026 CMMC Assessment Benchmark Report, Lazarus Alliance's aggregate analysis of 47 completed formal CMMC Level 2 C3PAO assessments conducted between January 2025 and June 2026.
Additional Analysis
- How Long Does a CMMC Level 2 Assessment Take?
- 7 Most Common CMMC Level 2 Assessment Findings
- How Much Evidence Does a CMMC Assessment Require?
- How Common Are CMMC POA&Ms?
Talk with one of our experts
Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.
We're here to answer any questions you may have.
