Skip to content

Instantly share code, notes, and snippets.

@jgmac1106
Last active November 24, 2025 21:03
Show Gist options
  • Select an option

  • Save jgmac1106/1c8818fefce675b4e3be2c25a73ed134 to your computer and use it in GitHub Desktop.

Select an option

Save jgmac1106/1c8818fefce675b4e3be2c25a73ed134 to your computer and use it in GitHub Desktop.
CUI Enclave Options

CMMC Enclave Vendors

Secure File Sharing

A secure file share is never an enclave as the endpoints who access the file share are in scope, but when segmented off the secure file share can be part of an enclave. For example you can restrict managed devices accessing the secure file share with VLANs or create a DMZ. For companies who only handle document based CUI and need to flow these documents down to subcontractors you may be able to create an enclave with secure file sharing. Many companies with an Enterprise or enclave scope add secure file sharing as a way to flowdown CUI to subcontractors

  • Box.com
  • Cocoon Data
  • Egnyte
  • Exostar
  • PreVeil
  • Kiteworks PDN

Single Device Enclave

A hardened laptop, router, and firewall meant for small companies who need a way to receive, store, process, and transmit CUI in a very small scope

  • Totem Tech

Commercial VDI Enclaves

A commercial VDI is usually a hosted multi-tenant and managed enclave solution that smaller companies or those creating mainly digital assets such as code can use to create an Enclave

  • Island Systems
  • CUICKTrac
  • Exostar
  • Hypori

Commercial RDS/AMI or Virtual Machine Enclaves

  • Kiteworks PDN

Onprem RDS servers

A secure file sharing enclave for hybrid environments that have you run commercial software on your servers. Please note you no longer inherit many of the FedRAMP requirements that met 171 controls and need to consider FedRAMP Moderate/High solutions for HA/DR.

  • Exostar
  • Kiteworks PDN + SafeEdit

An MSP or Internal IT could run an Onprem RDS server.

Managed Security Service Provider GCCH Enclave

An External Service Provider that manages and maintains a Government Community Could Enclave in your Microsoft tenant.

  • Atomus
  • Axiom
  • Brea Networks
  • C3 Integrated Solutions
  • Cape Endeavors
  • Cybercecurity
  • inDirect IT
  • Kieri Solutions
  • Planet Technologies
  • Ridge IT
  • Rolle IT
  • SoundWat Consulting, Inc
  • Summit 7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment