Case Study 04 - Mid-Sized Aerospace Supplier

PreVeil enclave design instead of a full GCC High rollout.

Microsoft GCC High is the well-publicized path to CMMC compliance. It is also the most expensive and disruptive path, and it is the wrong answer for many manufacturers. For an aerospace supplier with a narrow CUI footprint and an established Microsoft 365 commercial environment, a scoped PreVeil enclave was the architecturally correct choice - and the consultancy work was about getting the scoping decision right, not about selling tooling.

Industry: Aerospace and defense supplier with mixed commercial and DoD business Geography: Southern California CMMC scope: Level 2
Industry context

An aerospace supplier with a narrow CUI scope was being pushed toward an organization-wide GCC High deployment.

The organization at the center of this case study is a mid-sized aerospace supplier in Southern California whose business is a mix of commercial aviation work and Department of Defense subcontracts. Roughly seventy people work at the company. The DoD portion of the business runs through a defined subset of the workforce - engineers and quality personnel who interface directly with customer-supplied technical data - while the rest of the company supports commercial customers whose data is not subject to CUI handling requirements.

When the engagement began, the company was operating on a commercial Microsoft 365 tenant, the standard environment most small and mid-sized businesses use. Email, file sharing, and collaboration all ran through Microsoft 365 Business or E-series licensing. Endpoint protection, multi-factor authentication, and the rest of the standard hygiene stack were in place. The environment was capable, but it was not built to satisfy the requirements of NIST SP 800-171 across a CUI-handling boundary, and the existing Microsoft 365 tenant was not authorized to host CUI under the FedRAMP Moderate baseline the Final Rule requires for cloud service providers handling CUI.

The company's existing IT advisor had recommended a Microsoft GCC High migration. GCC High is Microsoft's government-community cloud environment, certified at FedRAMP High and explicitly authorized to host CUI and even more sensitive data. It is the most-recommended platform in the CMMC ecosystem, and for organizations with broad, deep CUI exposure across most of the workforce, it is often the correct answer. For this organization - with CUI confined to a defined subset of users and processes - it was not.

The challenge

GCC High is well-marketed, expensive, and disruptive - and it is often the wrong fit for narrow-scope CUI manufacturers.

The economics of a GCC High deployment for a mid-sized manufacturer are documented across multiple vetted industry sources. The licensing premium relative to commercial Microsoft 365 is substantial. The deployment scope frequently expands to organization-wide rather than CUI-user-only, because GCC High is a distinct cloud tenant with different licensing, different identity infrastructure, and limited interoperability with the commercial tenant. Migration timelines for organization-wide deployments typically run six to twelve months. The Redspin 2025 readiness survey found that contractors reporting more than $250,000 in CMMC preparation spend made up 31 percent of the surveyed population - and platform-migration cost is one of the largest single line items for organizations that go that route.

HSToday's November 2025 industry guide notes that total CMMC Level 2 certification costs typically run $100,000 to $200,000 for small and mid-sized contractors requiring third-party assessment - and that figure assumes platform decisions have already been right-sized. Adding an unnecessary organization-wide cloud migration on top of that base cost is one of the most expensive mistakes in CMMC implementation, particularly because the cost is not just the licensing - it is the workforce disruption, the change-management overhead, the email-address transitions, the third-party integrations that have to be rebuilt, and the lost productivity during the transition window.

The framework itself does not require GCC High. NIST SP 800-171 and the CMMC Final Rule specify the security outcomes required for CUI handling - FedRAMP Moderate-equivalent for cloud service providers, FIPS-validated cryptography where applicable, the full 110-control set in NIST 800-171 Rev 2 - but they are platform-agnostic. Multiple paths can satisfy these requirements. A scoped enclave architecture, in which CUI is isolated in a separate, properly-authorized environment while the rest of the business continues to operate on commercial infrastructure, is one of those paths and is explicitly supported by The Cyber AB's scoping guidance.

PreVeil, by publicly available figures, is used by over 1,600 defense contractors and has supported many of those contractors through successful CMMC assessments, including a notable number of perfect 110/110 SPRS scores. The platform deploys alongside an existing Microsoft 365 or comparable email environment rather than replacing it. Per published industry references, contractors have reported six-figure savings versus GCC High deployments. Those figures come from PreVeil's published customer materials and should be read with the standard awareness that they are vendor-sourced; the underlying point - that an enclave architecture costs materially less than an organization-wide cloud migration when the scope is narrow - is well-established in the broader industry literature.

The challenge in this engagement was not selling PreVeil. The challenge was running the scoping analysis honestly, demonstrating that the company's CUI footprint genuinely justified an enclave rather than an organization-wide migration, and then designing the enclave to satisfy the full set of CMMC controls, not just the cloud-platform piece.

Architecture comparison

Three CUI architectures compared for CMMC Level 2

Three CUI architectures compared for CMMC Level 2 Side-by-side comparison of three architectures for handling CUI under CMMC Level 2: A) GCC High org-wide for all 70 users, B) GCC High scoped tenant (10) + commercial M365 (60), C) PreVeil enclave (10) inside existing M365 tenant (60) - recommended. ARCHITECTURE A GCC High organization-wide GCC HIGH TENANT All 70 users in CUI cloud No commercial M365 alongside Deployment time 6-12 months License premium Highest Identity model Single Org disruption Org-wide ARCHITECTURE B GCC High scoped tenant GCC HIGH 10 users CUI tenant COMMERCIAL M365 60 users separate tenant Deployment time 4-8 months License premium Medium Identity model Dual Org disruption Two tenants ARCHITECTURE C - RECOMMENDED PreVeil enclave COMMERCIAL M365 TENANT 60 users ENCLAVE 10 users Deployment time Weeks License premium Lowest Identity model Single Org disruption Minimal CUI-controlled environment Commercial M365 environment SOURCES: NIST SP 800-171 - 32 CFR 170 - DFARS 7012 - CYBER AB MARKETPLACE

Reading this diagram: color encodes the CUI boundary. Architecture A places all users in a single CUI cloud. Architecture B uses two separate tenants. Architecture C wraps a small CUI enclave inside the existing commercial tenant - typically the lowest-cost option when the CUI footprint is narrow. Sources: NIST SP 800-171, 32 CFR 170, DFARS 7012, Cyber AB Marketplace.

How we approached this

Scope first, choose tooling second. Then build the enclave to the scope.

The right answer to 'GCC High or PreVeil or neither' depends entirely on how much CUI you have, where it lives, who handles it, and what business processes touch it. We start with the scope before we recommend the tool. For this organization, the scope decision drove the tooling decision, and the tooling decision saved the company a substantial deployment cost and disruption window.

Run the CUI footprint analysis before recommending any platform

We mapped every CUI handling event in the business - every workflow where a customer-supplied controlled drawing, a CUI-marked technical specification, or a derivative work product (estimating data, engineering analysis, supplier package, quality record) enters, transforms, or exits the organization. The analysis identified a tightly bounded user population: engineering and program management staff who interface with DoD customers, plus a small number of quality and inspection personnel on those programs. The commercial customer base, which represented the majority of company revenue and headcount, did not touch CUI in any form. This footprint analysis is what justifies an enclave architecture rather than an organization-wide migration.

Present the platform decision framework honestly, with the tradeoffs visible

Three architectures were on the table. Architecture A: full organization-wide GCC High migration. Strengths: single-platform simplicity, full Microsoft ecosystem integration, comfortable for IT teams already on Microsoft. Weaknesses: significant licensing premium, six-to-twelve-month deployment window, disruption to commercial-side operations, email-address transitions for the entire workforce. Architecture B: scoped GCC High enclave for the CUI-handling subset. Strengths: smaller licensing footprint than option A. Weaknesses: cross-tenant collaboration friction, identity duplication, persistent operational drag from running two parallel Microsoft tenants. Architecture C: PreVeil enclave alongside existing commercial Microsoft 365. Strengths: deploys in weeks rather than months, preserves existing email addresses, FedRAMP Moderate Equivalent posture per published documentation, FIPS 140-2 validated cryptography, lower licensing cost for the narrow user base, designed for collaboration with third parties outside the enclave at no additional license cost. Weaknesses: a separate platform staff need to learn, dependent on PreVeil's continued operation and authorization status. The company chose Architecture C after reviewing the analysis.

Design the enclave boundary precisely

The PreVeil enclave is the system that holds and handles CUI. The boundary between the enclave and the surrounding commercial Microsoft 365 environment had to be defined and documented. We specified which users belong inside the enclave, which workflows transit the boundary (for example, when an engineer pulls a customer drawing from PreVeil to perform analysis), what controls govern those workflow transitions, and what data is explicitly prohibited from leaving the enclave. The boundary diagram became part of the System Security Plan and the artifact the C3PAO will reference during the assessment Examine phase.

Configure the supporting infrastructure to NIST 800-171 standards

An enclave is not just an email and file platform - it is a control environment. We configured multi-factor authentication using a method that satisfies the CMMC requirement and integrates with the staff workflow. We established the audit logging configuration that supports the AU.L2 control family. We documented the FIPS-validated cryptography in use. We confirmed the platform's FedRAMP Moderate Equivalency documentation and incorporated it into the Shared Responsibility Matrix the SSP references. We defined the device management approach for endpoints that access the enclave, including the use of compliant Windows endpoints and the role of mobile device controls.

Migrate existing CUI into the enclave and decommission residual copies

Historical CUI scattered across the commercial environment had to be identified, migrated into the enclave, and removed from the commercial systems. We ran a systematic search across email, file shares, and endpoint storage for indicators of CUI presence - distribution statement markings, customer-specific keywords, contract numbers, technical specifications belonging to DoD programs. Identified content was migrated into the enclave. Residual copies in commercial systems were removed using sanctioned methods. The migration log itself became an assessor artifact: it demonstrates that the organization understood where its CUI was and took deliberate action to consolidate it into the controlled environment.

Train the enclave user population and integrate the workflow

Enclave users received targeted training on how the new workflow operates - when to use the enclave versus when to use commercial systems, how to share CUI-bearing files with external customers without taking it outside the enclave, how to handle the inevitable edge cases (a customer who insists on emailing a CUI-marked drawing to a commercial address, for example). The training was short, role-specific, and tied to the documented Information Security Policies and Standards. Adoption was high because the platform genuinely makes the workflow easier than the workarounds the engineering team had been using.

Outcomes

A defensible CUI enclave, deployed in weeks rather than months, at a fraction of the GCC High cost.

The enclave was operational in a fraction of the time a comparable GCC High deployment would have required. The commercial side of the business - the larger part of headcount and revenue - was completely undisturbed. Email addresses for the entire workforce stayed the same. Existing commercial Microsoft 365 customers, vendors, and partners experienced no change. The CUI-handling user population transitioned into the enclave with a manageable training and adoption curve.

The cost differential versus a full organization-wide GCC High deployment was substantial. Specific savings figures vary by environment, but the published industry references - including PreVeil's own customer materials, which should be read as vendor-sourced but are corroborated by multiple independent industry sources - consistently indicate six-figure savings on platform migration alone for organizations that fit the enclave model. For an organization that does fit the model, the math is not subtle.

From a CMMC assessment posture, the enclave architecture is fully defensible. The CUI scope is documented, the boundary is documented, the platform's FedRAMP Moderate Equivalency posture is documented, the Shared Responsibility Matrix between Consilien's client and the enclave platform is documented, and the controls implemented inside the enclave are documented against the 110 NIST 800-171 Rev 2 requirements. The C3PAO assessor's Examine phase has clear, complete, current artifacts to review. The Interview phase has personnel who understand the architecture they work inside. The Test phase has demonstrable controls.

This is the model the framework was designed to support. NIST 800-171 and CMMC do not require GCC High. They require defensible controls for handling CUI. When the CUI footprint is narrow enough to support an enclave architecture, the enclave is often the cheaper, faster, less-disruptive path.

Standards and controls touched

The published controls and authorities behind this work.

Every Consilien engagement maps to specific, citeable controls and publications. This is the regulatory and standards footprint of the work described above.

Standard / Control
Why it applies here
AC.L2-3.1.1 through 3.1.22
Access Control family - the enclave's identity and authorization controls form the foundation of this family.
IA.L2-3.5.1 through 3.5.11
Identification and Authentication - including multi-factor authentication for accessing CUI and FIPS-validated cryptographic mechanisms.
SC.L2-3.13.8 / 3.13.11
System and Communications Protection - FIPS-validated cryptography to protect the confidentiality of CUI, both at rest and in transit.
AU.L2-3.3.1 through 3.3.9
Audit and Accountability - the enclave platform's audit logging satisfies most of this family; the Shared Responsibility Matrix documents which controls the platform implements and which the customer does.
CA.L2-3.12.4
System Security Plan - must accurately reflect the enclave boundary and the controls operating inside it.
FedRAMP Moderate (or Moderate Equivalency)
Required posture for cloud service providers handling CUI under the CMMC Final Rule. Both Microsoft GCC High and PreVeil hold defensible positions in this regard, with documentation supporting their respective claims.
DFARS 252.204-7012
Underlying contractual requirement that establishes the safeguarding obligations that the CMMC framework operationalizes.
Why this matters for similar manufacturers

If your CUI footprint is narrow, GCC High is probably not your answer.

The decision between GCC High and a PreVeil-style enclave is one of the most consequential architectural choices in a manufacturer's CMMC program - and it is one of the most frequently mis-handled. The defaulting bias in the consulting market runs toward GCC High because Microsoft's partner ecosystem is enormous, because most CMMC consultants come from Microsoft-centric backgrounds, and because the GCC High licensing model is the path of least resistance for a consulting firm that has to make a recommendation quickly. None of those are reasons that match your organization's actual CUI footprint.

The right question is structural: where does your CUI actually live, who actually handles it, and what fraction of your workforce is that? If the answer is "across most of the company, most of the workforce, deeply integrated with our daily operations," GCC High may genuinely be the right answer. If the answer is "a defined subset of users, a defined subset of workflows, a bounded portion of the business," an enclave architecture is worth a serious analysis - and the cost difference is large enough to matter to your CFO.

The Cyber AB scoping guidance explicitly supports enclave architectures. The CMMC framework was designed to allow this. The contractors who are paying the most for CMMC compliance are the ones who skipped the scoping analysis and went straight to the platform decision. The contractors with the cleanest CMMC programs are the ones who did the scoping analysis first and let it drive every downstream choice - tooling, controls, documentation, and the size of the deployment effort.

Sources and references

Sources & references

Should your CUI live in GCC High, in PreVeil, or somewhere else?

We will scope your CUI footprint against your business model and recommend the tooling architecture that matches it. We work with both Microsoft GCC High and PreVeil. We are not paid by either vendor.