Managed CUI enclave · Microsoft 365 GCC High
Built for the future.Ready for today.
Compliant by design.AI enabled by default.
One operated GCC High enclave for the people who handle CUI. The rest of the business stays outside the assessment.
- 60 days
- Standard, to ready
- 14 days
- Express, to ready
- 4 workloads
- Teams, Exchange, SharePoint, OneDrive
- CMMC L2
- Operator certified, 2025
A wide network is a wide assessment.
If CUI lands in everyday mail, shared drives, and shop-floor PCs, the boundary follows it. CUI Track pulls that work into one operated environment so the corporate network can stay out of scope.
Built for the future. Ready for today.
Two defaults, set on the first day.
COMPLIANT BY DESIGN
The controls are the build, not a layer on top of it.
- Identity, mail, files, and logging are configured for the enclave from the first station
- The System Security Plan is written with the build and kept current after it
- Only named people who handle CUI get access, and every change is a tracked request
- Operated by a firm that holds CMMC Level 2 on the same Microsoft stack
AI ENABLED BY DEFAULT
AI runs inside the boundary, not beside it.
- Purview labels and DLP are in place before any AI touches a file
- Nothing is sent to a commercial AI endpoint outside the boundary
- Access, prompts, and outputs are logged as evidence an assessor can test
- GCC High native, so AI work stays in the same federal cloud as the CUI
Every enclave is built AI-ready. Three add-on tiers turn AI on, starting with flows at $0 a month in Microsoft AI cost. See the AI tiers. Microsoft licensing, including any AI licensing, is billed by Microsoft.
Inside the enclave
Microsoft 365. Not a new application.
Microsoft 365 Business Premium on GCC High, plus the Defender and Purview add-on. The work happens in the apps your people already know.
Teams
The people who handle CUI, in one place.
Exchange
Mail that stays in scope.
SharePoint
The library the boundary owns.
OneDrive
Files that do not leave.
The path
Four stations. One boundary.
STATION 01
Draw the flow
We name where CUI is created, received, stored, and sent. If a system never sees it, it stays off the map.
Output: a CUI flow map and the list of people who actually handle it.
STATION 02
Build the boundary
The working environment sits on Microsoft 365 GCC High. Identity, mail, files, and logging are designed for that box, not bolted onto the corporate network.
Output: the enclave, configured and documented as one system.
STATION 03
Name the users
Only the people who handle CUI are onboarded. Everyone else keeps the tools they already use.
Output: named identities with access scoped to the work.
STATION 04
Hold the evidence
The System Security Plan and the remaining customer work stay current. The boundary does not replace policy, physical security, or your existing MSP.
Output: ready for an assessment or a self-attestation.
The edge
A defined edge, and a clear owner on each side.
INSIDE THE BOUNDARY · OPERATED BY US
- Microsoft 365 GCC High for the CUI workload
- Named user identities and access
- Encrypted mail, files, and retention for that environment
- Logging and backup designed with the boundary, not after it
STILL YOURS
- Systems that never see CUI
- Your MSP or internal IT for the corporate network
- Physical security and the policies outside the enclave
- The decision of who is allowed to handle CUI
Enclave Console
Managed where you already see your program.
Your enclave lives in the inDirectIT client portal, next to your SSP, POA&M, and evidence: the build station and day count, named users and seats, the four workloads, and every change request.
Module in build. Status stated honestly on the tour.
CUI Track enclave
ACME DEFENSE MFG · GCC HIGH
01
Draw the flow
02
Build the boundary
03
Name the users
04
Hold the evidence
- Named users
- 4
- 3 included · 1 added
- Business Premium
- 4
- GCC High seats
- Defender + Purview
- 4
- Add-on seats
- Change requests
- 1
- Add user · open
NAMED USERS
| Name | Role | MFA | Device |
|---|---|---|---|
| J. Reyes | Program manager | Authenticator | Compliant |
| A. Moss | Contracts | FIDO2 key | Compliant |
| K. Tran | Engineering lead | Authenticator | Compliant |
| L. Ortiz | Quality | Pending | Enrolling |
WORKLOADS
- TeamsCONFIGURED
- ExchangeCONFIGURED
- SharePointCONFIGURED
- OneDriveIN BUILD
The operator
Built by a firm that already holds CMMC Level 2.
inDirectIT builds and runs CUI Track. The same team runs its own Level 2 program on the Microsoft stack: GCC High, Intune, Defender, and Purview where the workload calls for them. The second engagement should look like the first.
- Level 2
- inDirectIT certification, 2025
- GCC High
- The stack we run ourselves
- Operator
- Not a replacement MSP
ONE OPERATOR · ONE BOUNDARY
Price
60 days. Or 14, with express.
Ready for an assessment or a self-attestation. Everything after setup is the same on both paces. Microsoft licensing is billed by Microsoft and is not in these figures.
STANDARD
$15,000
setup, once
Ready in 60 days
EXPRESS
FASTEST$50,000
setup, once
Ready in 14 days
THEN, ON BOTH
- $1,000
- each month, through 3 users
- $325
- each added user, each month
- $6,500
- compliance management, each year
We already have an MSP.
Good. CUI Track does not take over the corporate network. Your MSP keeps it.
Is this another product login?
No. It is an operated environment with a defined edge. People work in Microsoft 365.
We are not assessment-ready.
Start with the flow. The boundary comes after the map is honest.
Who sees the enclave’s status?
You do, in the inDirectIT client portal, next to your SSP, POA&M, and evidence.
Boundary review
Draw the flow first.
Thirty minutes on where CUI actually moves. We will tell you if CUI Track fits, and if it does not.