3 min read

CMMC Enclave or Enterprise Scope, and What SPRS Shows

An enclave reduces the assets assessed, not the 110 requirements. And SPRS records CAGE codes plus an SSP pointer, not your boundary. Why the SSP is the only document that says what you certified.
SPRS records CAGE codes and an SSP pointer. Not your boundary. 32 CFR 170.17

Quick answer: yes, you can certify an enclave rather than the whole company, but SPRS will not describe it. The record carries CAGE codes and a pointer to your System Security Plan. The boundary itself lives only in the SSP. That makes the SSP the single document that defines what your certification actually covers.

Can you certify just an enclave?

Yes. 32 CFR 170.19 states that "the CMMC Assessment Scope is the set of all assets in the OSA's environment that will be assessed against CMMC security requirements." The scope is a set you define, not your whole company by default.

The CMMC Assessment Scope Level 2 guide is explicit in its section on enclaves: "this does not mean all assets across the entire OSA enterprise are automatically part of a CMMC Assessment Scope."

The DoD CIO CMMC FAQ adds a useful point for anyone worried that traffic leaving the enclave drags the network back in. So long as the enclave is logically separated from the wider enterprise, transmitting properly encrypted CUI does not extend the assessment scope to the enterprise networking components.

One drafting note. The word enclave is not defined in the definitions at 32 CFR 170.4, even though the Scoping Guide uses it. Define what you mean by it in your own documentation rather than assuming a shared meaning.

Does an enclave reduce the 110 requirements?

No. This is the most common misreading of scoping, and it is worth stating flatly.

An enclave reduces the number of assets assessed. It does not reduce the number of requirements. The Scoping Guide is direct: within the enclave, the organisation determines which requirements are implemented and which are inherited, and all requirements must be MET.

So a Mac-only shop that stands up a tightly bounded enclave still answers for all 110 requirements inside it. What shrinks is the hardware and headcount in scope, and the amount of the business that has to be re-engineered. That is a real and often decisive saving. It is not a discount on the standard.

What does SPRS actually record?

Less than most people assume. Under 32 CFR 170.17(a)(1), a C3PAO submits results into the CMMC instantiation of eMASS, which transmits to SPRS. The submitted fields include the date and level of the assessment, the C3PAO name, an assessment identifier, and assessor contact details. Two more matter here. The record captures "all industry CAGE codes associated with the information systems addressed by the CMMC Assessment Scope," and "the name, date, and version of the SSP."

Read the last two together. SPRS gets the CAGE codes tied to your scope and a reference to the SSP by name, date, and version. It does not get a narrative description of your boundary. The scope definition lives in the SSP, and the SSP is not in SPRS.

What will a prime see when they check you?

A CMMC status against CAGE codes, with dates. Not a boundary diagram, not a list of what was excluded, and not whether the certified environment is the one that will perform their work.

That gap has a practical consequence under DFARS 252.204-7021(f), which requires a prime to ensure a subcontractor holds a current certificate or status at the appropriate level before award. The prime can verify that you hold a status. They cannot verify from SPRS that your certified enclave covers the work they are about to send you.

Expect that question to arrive by email instead, and expect it to arrive late in a bid. Having a clean one-paragraph scope statement ready is cheap insurance.

Why does this make the SSP load-bearing?

Because it is the only artifact in the chain that says what was certified.

32 CFR 170.20 makes the same point from another direction, stating for converted DIBCAC assessments that "the scope of the Level 2 certification assessment is identical to the scope of the DCMA DIBCAC High Assessment." Scope is an attribute of the assessment, and the assessment is described by the plan.

Three things follow for how you write it. Describe the boundary precisely enough that a reader who has never seen your network can tell what is inside it. Version it, because SPRS records a version and a date. And keep the asset inventory consistent with it, because an assessor who finds Macs in the inventory and no Macs in the narrative has found a documentation gap rather than a security one.

If you are deciding which assets belong inside the boundary in the first place, start with Mac asset classification for CMMC, and for the platform layer see the Mac-based SSP narrative.

Sources

  • 32 CFR 170.17(a)(1)(i)(E) and (F), 170.19, 170.20
  • CMMC Assessment Scope Level 2, v2.13, Use of Enclaves
  • DoD CIO CMMC FAQ v6
  • DFARS 252.204-7021(f)

Verified against primary sources on August 1, 2026. This is not legal advice.