CMMC

CMMC Enclave vs Full GCC High Migration: The Six-Question Decision Tree

· 17 min read · Updated August 30, 2026

Bottom Line Up Front

CMMC Phase 2 was scheduled for November 10, 2026 and was suspended on July 13, 2026 [DoD CIO Memorandum 26-P-1023]. NIST SP 800-171 Rev 2 is still enforced and the SPRS score is still a live representation to the Government, so the enclave versus full GCC High decision still binds. What changed is that you now get to make it deliberately instead of under deadline panic. This article gives you the six-question decision tree, the licensing math, and the four mid-program switching scenarios that most contractors regret.

Updated July 30, 2026: On July 13, 2026 the Department of War suspended CMMC Phase II, which had been scheduled for November 10, 2026. Phase I self-assessment requirements, DFARS 252.204-7012, NIST SP 800-171 Rev 2, and SPRS score affirmation all remain in force. This analysis has been updated to reflect the suspension.

Cybersecurity Maturity Model Certification (CMMC) Phase 2, scheduled for November 10, 2026 per 32 CFR §170.3(e), was suspended on July 13, 2026 [DoD CIO Memorandum 26-P-1023]. It would have made third-party assessment by a Certified Third-Party Assessor Organization (C3PAO) the default for Level 2 contracts. Phase 3 and Phase 4 are suspended as well, with all milestones in abeyance until further notice. What survived the suspension is the part that actually drives this decision: NIST SP 800-171 Rev 2 is still enforced through self-assessment and select government-led assessments, DFARS 252.204-7012 is still in the contract, and the SPRS score is still a live representation to the Government. As of early 2026, fewer than 1,100 of the roughly 80,000 organizations the Department of Defense estimates need Level 2 certification had completed it. A deadline that moved 1.4 percent of the industrial base in eighteen months was never the thing driving readiness.

The decision that determines what a defense contractor spends on CUI compliance over the next five years is not the C3PAO selection, the System Security Plan draft, or the gap assessment. It is the CMMC enclave vs full GCC High migration decision, specifically whether to host Controlled Unclassified Information inside a scoped enclave or move the entire tenant to Government Community Cloud High. The decision shapes licensing cost, scope of audit, third-party SaaS dependence, and partner-collaboration mechanics for the next five years. Most contractors are still treating it as an information-technology decision. It is a financial-architecture decision with security-architecture consequences.

This article gives you the six-question decision tree, the licensing math, and the four mid-program switching scenarios that most contractors regret. It is written for the defense contractor holding a Level 2 clause whose Chief Information Officer and Chief Financial Officer cannot agree on the path. The suspension removed the time pressure on that argument. It did not settle it, and the cost of settling it wrong has not moved.

CMMC Phase 2 was scheduled for November 10, 2026 and was suspended on July 13, 2026 [DoD CIO Memorandum 26-P-1023]. NIST SP 800-171 Rev 2 is still enforced and the SPRS score is still a live representation to the Government, so the architecture decision still binds. What changed is that you now get to make it deliberately instead of under deadline panic. The decision is whether you put CUI behind an enclave or migrate the entire tenant to GCC High, and it still has to be locked before the migration RFP goes out. This article gives you the six-question decision tree, the licensing math, and the four mid-program switching scenarios that most contractors regret.

The Two Architectures in Plain Language

The full migration moves the entire Microsoft 365 tenant from commercial to Government Community Cloud High. Every user gets a GCC High license. Every email, file, Teams chat, and SharePoint document lives inside the GCC High boundary. The CMMC scope and the corporate scope become the same scope. The full migration is the simple architecture and the expensive one.

The enclave architecture keeps the corporate tenant in commercial Microsoft 365 and stands up a separate, smaller GCC High tenant or a dedicated CUI-scoped environment. Only the users who handle Controlled Unclassified Information are licensed for GCC High. The CMMC scope is the enclave; the corporate scope is everything else. The enclave is the surgical architecture and the operationally complex one.

GCC High carries a premium of roughly 65 percent over commercial Microsoft 365 at the G3-equivalent tier and roughly 55 percent at the G5 tier, before adding any E5 security features. Treat that ratio as the durable number and the absolute prices as perishable. Microsoft raised Microsoft 365 E3 from $36.00 to $39.00 per user per month and E5 from $57.00 to $60.00 effective July 1, 2026, and raised G3 GCC 8 percent and G5 GCC 5 percent on the same date, with GCC High and DoD following their GCC counterparts. Microsoft does not publish GCC High list prices. Those come through a licensing partner, so get a current quote before building a business case on any published figure, this article included. What the price change does not touch is the shape of the decision. An enclave pays the premium only on the users who handle CUI. The full migration of a 50-user company runs $350,000 to $950,000 all-in across licensing, professional services, data migration, and the 14- to 22-week project timeline, per current operator estimates from GCC High migration consultancies including Summit 7, Agile IT, and Cyber Sheath. The 110 controls that define the CMMC Level 2 assessment scope, reviewed in the CMMC Level 2 assessment preparation guide, apply to whatever boundary the architecture commits to.

The Six-Question Decision Tree

The decision is not “enclave or full migration.” It is the answer to six discriminating questions, applied in order. Most contractors who get this wrong stop at question one because the answer feels obvious. The downstream questions are what determine whether the obvious answer is the right one. In my experience working through this decision, the revenue-share question has the lowest diagnostic value and the headcount question has the highest.

# Question Pulls Toward Enclave Pulls Toward Full Migration
1 What share of revenue comes from defense contracts? Less than 30 percent More than 60 percent
2 How many employees actually handle CUI? Less than 25 percent of headcount More than 50 percent of headcount
3 How dependent is the commercial side on third-party SaaS not supported in GCC High? High dependence on tools without GCC High parity Low dependence; primary stack is Microsoft
4 How frequent is collaboration with non-defense partners, vendors, and customers? Daily collaboration with commercial entities Collaboration is mostly with defense ecosystem
5 Can the budget absorb GCC High licensing across the entire workforce? No; budget is tight Yes; defense work funds the premium
6 What is the assessment cadence the contracting pipeline implies? One Level 2 assessment per audit cycle Multiple Level 2 contracts; some Level 3 trajectory

Question one is the headline. A contractor whose defense work is more than 60 percent of revenue almost always migrates fully because the corporate culture is already aligned to defense work and the cost of segregation outweighs the cost of full coverage. A contractor at less than 30 percent should default to the enclave because the cost of bringing 70 percent of a workforce that never touches CUI into GCC High is the largest line item on the bill of materials.

Question two is the discriminator. The 30 to 60 percent revenue band is where most contractors live, and revenue alone does not decide the architecture. Headcount that handles CUI is what does. A 200-employee company with 60 percent defense revenue may have only 35 employees who touch CUI; that is a textbook enclave case. The same company with 140 of 200 employees handling CUI is a textbook full migration. The CUI-handling headcount, not the revenue percentage, is the variable that drives the licensing math.

Question three is the operational kill switch. GCC High does not have parity with commercial Microsoft 365 across the third-party SaaS ecosystem. A commercial team that depends on Salesforce, HubSpot, Slack, Zoom, Asana, or specific industry-vertical applications often discovers post-migration that their workflow is broken because the GCC High versions of those tools either do not exist or have feature gaps. A contractor with deep third-party SaaS dependence on the commercial side should default to the enclave even at higher defense-revenue concentration.

Question four is the cultural test. A full migration changes the way a workforce communicates with the outside world. Email to commercial partners becomes a security-reviewed action. Teams meetings with commercial vendors require careful scoping. Companies whose business development depends on frequent commercial collaboration absorb operational friction in a full migration that an enclave avoids by keeping the commercial collaboration in the commercial tenant.

Question five is the budget reality. Some companies cannot absorb GCC High licensing across the entire workforce. The math is direct, and it scales with headcount rather than with the price list. A 200-employee company pays the GCC High premium on 200 seats under a full migration and on 50 seats under an enclave, so the enclave carries one quarter of the licensing exposure. At the rates quoted before July 2026, GCC High G3 at $60 against commercial E3 at $36, that was a $24 per user per month premium: $57,600 a year across 200 users against $14,400 across 50. Both numbers rose with the July 1, 2026 increase. The quarter stayed a quarter, and the quarter is what the Chief Financial Officer is actually deciding.

Question six is the strategic question. A contractor whose pipeline implies multiple Level 2 contracts each with different scopes, or a trajectory toward Level 3, gains administrative simplicity from a full migration because the CMMC boundary becomes the corporate boundary. A contractor whose pipeline is one or two Level 2 assessments per audit cycle gets nothing from full migration that an enclave does not provide more cheaply.

The Licensing Math, Worked

The honest comparison requires four cost categories: licensing, migration project, ongoing operations, and assessment scope. Most vendor blogs cite only the licensing differential, which understates the full migration cost by 40 to 60 percent.

Licensing

Commercial Microsoft 365 E3 lists at $39.00 per user per month and E5 at $60.00, both effective July 1, 2026 (Microsoft 365 pricing and packaging updates). For the government SKUs Microsoft publishes percentage changes rather than list prices: Microsoft 365 G3 GCC rose 8 percent and G5 GCC rose 5 percent on the same date, with GCC High and DoD following their GCC counterparts. Absolute GCC High pricing is quoted through licensing partners, not published. Work the comparison as a premium per CUI-handling seat and the arithmetic survives any repricing. Before the July 2026 increase, GCC High G3 quoted at $60 against $36 commercial E3, a $24 per user per month premium, or $288 per user per year. Across 200 users that came to $57,600 a year. Across a 50-user enclave, $14,400. The difference was $43,200 a year in pure licensing. At the G5 tier the premium ran $32 per user per month. Substitute your own quoted rate into the same structure: the ratio holds even though every dollar figure above has moved.

Migration Project

A full migration of a 50-user contractor runs $350,000 to $950,000 all-in over 14 to 22 weeks, per current operator estimates from GCC High migration consultancies including Summit 7, Agile IT, and Cyber Sheath. The variability is driven by data volume, custom application count, and third-party integration complexity. The same data, migrated into a smaller enclave, runs $80,000 to $240,000 over 6 to 12 weeks because the scope is smaller and the application portfolio is smaller. The enclave migration is roughly one-third the cost and half the duration of the full migration on a 50-user footprint.

Ongoing Operations

The full migration’s operating cost is one tenant administrator team, one set of GCC High-aware tooling, and one identity-management surface. The enclave’s operating cost is two tenants, two sets of tooling, and a cross-tenant identity strategy that has to be designed and maintained. The enclave saves on licensing and pays back some of the savings in operations. The net annual operations differential on a 200-user company with a 50-user enclave is typically $40,000 to $80,000 per year in favor of the enclave once the licensing savings are applied against the higher operations cost (current operator estimates; varies by organization complexity).

Assessment Scope

The CMMC Level 2 assessment covers the boundary that handles CUI. Scoping is governed by 32 CFR §170.19, which sorts in-scope assets into CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets. In a full migration, that boundary is the entire tenant. In an enclave, it is the enclave only. The C3PAO scopes the assessment based on the boundary; the smaller boundary is the cheaper assessment. A 200-user full migration assessment typically runs $80,000 to $180,000, per current operator estimates. The same company with a 50-user enclave assessment runs $40,000 to $90,000. The enclave saves on assessment scope by roughly 50 percent.

The Four Mid-Program Switching Scenarios Contractors Regret

The decision has to happen before migration planning begins. Switching from one architecture to the other mid-program creates rework, delays, and budget overruns that proper upfront planning avoids. Four switching scenarios are common enough to merit explicit warning.

The first regret is enclave-to-full migration triggered by a contracting-officer challenge. A contractor stands up an enclave, completes a Level 2 assessment, wins a contract, and then has the contracting officer challenge the enclave boundary on the basis that CUI flows are happening outside the assessed scope. The contractor migrates the whole tenant under deadline pressure, paying for a second migration and delaying contract performance. The prevention is rigorous boundary documentation in the System Security Plan and disciplined enforcement of CUI flow controls before assessment.

The second regret is full-migration-to-enclave triggered by a workforce mutiny. A contractor migrates fully, the commercial side of the business loses access to third-party SaaS tools they depended on, and within nine months business development complains that they cannot collaborate with commercial customers. The contractor stands up a commercial tenant alongside the GCC High tenant, paying for both, and effectively converting the architecture to an enclave-equivalent at twice the cost. The prevention is question-three discipline at the decision point. I call this the SaaS-dependency blind spot. It rarely surfaces at decision time, and it always surfaces in the budget once the company is paying for two tenants.

The third regret is full-migration cost overrun. A contractor commits to a full migration, the project budget is set at the low end of the $350,000 to $950,000 range, and the actual project lands at the high end because of data-volume and custom-application complexity that surfaces during discovery. The contractor finishes the migration $400,000 over budget. The prevention is a discovery-first project plan that establishes the actual scope before committing to a budget number, plus a 30 percent contingency on the initial estimate.

The fourth regret is the enclave-then-no-Level-2-contracts scenario. A contractor stands up an enclave at $200,000 in project cost, completes the Level 2 assessment, and then the anticipated Level 2 contract pipeline does not materialize. The contractor is paying the enclave’s ongoing operations cost, including the higher GCC High licensing on the enclave seats, against zero defense revenue from those seats. The prevention is contract-pipeline validation before architecture commitment; if the pipeline is uncertain, the question-one and question-six answers should pull harder toward a phased approach with an enclave that can be retired without strand cost.

The Sequence That Works

The sequence that works has six steps. With Phase 2 suspended, no external date drives it, so the forcing function is your own contract pipeline.

Step one is the contract-pipeline analysis. List every active contract and active solicitation that includes Level 2 requirements. List every prospective contract within the next 18 months. Categorize each by FedRAMP-equivalent impact and CUI-handling intensity. The output is the demand profile that questions one, four, and six in the decision tree need.

Step two is the workforce-handling analysis. Identify the employees who will handle CUI. Be precise: program managers, engineers in CUI-marked technical work, finance personnel processing CUI-marked invoices, executives in CUI briefings. Most contractors overstate this number by including employees who could handle CUI rather than those who do. The output feeds question two.

Step three is the third-party SaaS audit. List every third-party application the workforce uses. Confirm whether each has GCC High parity. Classify each as critical, important, or convenience. The number of critical applications without GCC High parity is the answer to question three.

Step four is the decision-tree application. Apply the six questions in order. Document the answer. Present to the joint Chief Information Officer and Chief Financial Officer review for sign-off. The decision-tree answer is the architecture commitment.

Step five is the System Security Plan boundary draft. Draft the SSP boundary based on the chosen architecture. The boundary must be defensible against a contracting-officer challenge. The boundary determines C3PAO scope, assessment cost, and ongoing-monitoring cost. Enclave architecture scoping, the discipline of drawing the CUI boundary precisely, is covered in detail separately.

Step six is the migration-project plan. Discovery first, then budget commitment, with a 30 percent contingency. Discovery is now the forcing function rather than the assessment queue. With Phase 2 suspended, book a C3PAO when a specific solicitation requires one, not on speculation, and keep the 6- to 9-month booking lead in the plan for when that day comes.

Frequently Asked Questions

Is the enclave approach DoD-approved?

Yes. The CMMC framework does not specify an architecture; it specifies a control set (32 CFR §170.14(c)(3)) that must be implemented within an assessment scope drawn under 32 CFR §170.19. Both enclave and full-migration architectures can satisfy Level 2 if the boundary is defensible and the 110 NIST SP 800-171 Rev 2 controls are implemented. The DoD program management office has not endorsed one over the other. C3PAOs assess both regularly.

What is the cost difference for a 200-user company?

For a 200-user company with a 50-user CUI-handling footprint, the enclave architecture is typically $200,000 to $400,000 cheaper in the first 18 months than full migration, accounting for licensing, project, and assessment costs. The annual ongoing differential is roughly $40,000 to $80,000 in favor of the enclave (current operator estimates). The licensing component alone came to $43,200 per year at the G3 rates quoted before the July 1, 2026 increase, and scales with whatever rate your partner quotes today. These numbers vary widely by data volume, application complexity, and third-party SaaS dependence.

Can I use a hybrid architecture?

Yes, with caution. A hybrid architecture pairs an enclave for the highest-sensitivity CUI with a partial migration of certain corporate functions to GCC High. Hybrid architectures are operationally complex and expensive to assess because the boundary is composite. Most contractors are better served by a clean enclave or a clean full migration.

Phase 2 is suspended. Does this decision still matter?

Yes. The suspension removed the award-eligibility cliff that was scheduled for November 10, 2026. It removed nothing about the underlying obligation. The operational cybersecurity clause, DFARS 252.204-7012, remains in force regardless of which architecture is chosen, and the 110 NIST SP 800-171 Rev 2 controls still have to be implemented inside whatever boundary you commit to. The architecture determines the cost of meeting that obligation, and it is the same architecture either way.

Should I start the enclave now or wait for clarity?

Decide now, and let the migration follow your pipeline. The suspension bought calendar room that did not exist in May 2026, when the same work backed against a November 10 date was a 9- to 13-month scramble. Use it on discovery and on the third-party SaaS audit, which are the two steps contractors skip under deadline pressure and regret later. A CMMC Reform Task Force reports in mid-September 2026, and waiting for it to decide your architecture hands the decision to a schedule you do not control.

Does the architecture decision affect Level 3?

Yes. Level 3 imposes a substantially larger control set and stricter boundary requirements. Enclaves can scale to Level 3 but the operational complexity rises sharply. Contractors with a credible Level 3 trajectory should weight question six more heavily toward full migration, because the administrative simplicity of a tenant-wide boundary becomes more valuable as the control burden grows.

The verdict. In my view, the enclave-versus-full-migration decision is the highest-leverage architectural choice a defense contractor makes during CMMC implementation. It is reversible, but reversal is expensive enough to be treated as irreversible once the migration RFP is signed. The contractors who land on the right side of that decision do it before the migration project starts, with the six-question decision tree applied to honest data, with the contract-pipeline analysis grounded in actual solicitations rather than aspirational ones, and with the budget written against the high end of the cost range plus a 30 percent contingency. Treat attestation as the legal obligation it is: the senior official affirmation required under 32 CFR §170.22 carries False Claims Act exposure under 31 U.S.C. §3729, the same exposure that makes an accurate SPRS score a legal document rather than a planning tool. The contractors who land on the wrong side of the decision usually got there by skipping question two or question three. The 30-to-60-percent revenue band is the trap; CUI-handling headcount and third-party SaaS dependence are the way out.

Discipline in preparation. Confidence in the room.

Josef Kamara, CPA, CISSP, CISA, Security+
Josef Kamara
Josef Kamara
CPA · CISSP · CISA · Security+ · MBA

15+ years in Technology Risk Consulting, External and Internal Audit across KPMG (Financial Audit), BDO (Senior Manager across the Third-Party Risk Management practice and IS Assurance, leading technology assurance audits of public and private companies), and Stryker (Head of SOX IT Audit). Founded The Audit Defense Library in 2024 after 50+ SOC 1, SOC 2, HITRUST, and HIPAA attestation engagements plus multiple SOX and IT assurance projects.

The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.