Platform
One box for CUI.
Nothing else in it.
CUI Track is an operated Microsoft 365 GCC High environment for the people who handle Controlled Unclassified Information. The rest of the business keeps its tools, its network, and its MSP.
- Tenant
- Microsoft 365 GCC High
- Licensing
- Business Premium + Defender and Purview
- Workloads
- Teams, Exchange, SharePoint, OneDrive
- Users
- Named, CUI handlers only
- Ready
- 60 days, or 14 express
- AI
- Enabled, inside the boundary
- Operator
- inDirectIT, CMMC Level 2
The architecture
The boundary follows the data. So we move the data.
CUI arrives from primes and the DoD through one managed edge. Inside, it lives in four Microsoft 365 workloads on GCC High, used only by named people. The corporate network, everyday email, shop-floor PCs, and your MSP never see it, so they stay out of the assessment.
Designed as one system
Microsoft 365 Business Premium on GCC High.
Plus the Defender and Purview add-on. Every layer is configured for the enclave, and documented as part of it.
- Identity
- Named identities for the people who handle CUI, with access scoped to the work. Nobody else is onboarded.
- Exchange inside the boundary, so CUI mail stays in scope instead of spreading the assessment.
- Files
- SharePoint and OneDrive as the only home for CUI files, with retention set for that environment.
- Collaboration
- Teams for the people and the programs that carry CUI.
- Protection
- The Defender and Purview add-on on top of Business Premium for the enclave’s users.
- Logging and backup
- Designed with the boundary from the first day, not added after it.
01
02
03
04
05
06
The path
Four stations, on a clock.
STATION 01
Draw the flow
We name where CUI is created, received, stored, and sent. If a system never sees it, it stays off the map.
Output: a CUI flow map and the list of people who actually handle it.
STATION 02
Build the boundary
The working environment sits on Microsoft 365 GCC High. Identity, mail, files, and logging are designed for that box, not bolted onto the corporate network.
Output: the enclave, configured and documented as one system.
STATION 03
Name the users
Only the people who handle CUI are onboarded. Everyone else keeps the tools they already use.
Output: named identities with access scoped to the work.
STATION 04
Hold the evidence
The System Security Plan and the remaining customer work stay current. The boundary does not replace policy, physical security, or your existing MSP.
Output: ready for an assessment or a self-attestation.
STANDARD
60 days
$15,000 setup. The pace most contractors take.
EXPRESS
14 days
$50,000 setup. Same enclave, same stations, on a two-week clock.
Shared responsibility
Who owns what, written down before the build.
| Responsibility | CUI Track | You |
|---|---|---|
| Map where CUI is created, received, stored, and sent | Leads | Provides access and people |
| Build and configure the GCC High enclave | Owns | Approves |
| Decide who handles CUI | Advises | Owns |
| Onboard and remove named users | Owns | Requests |
| Keep the SSP and enclave evidence current | Owns | Reviews |
| Corporate network, devices outside the enclave | Out of scope | Owns, with your MSP |
| Physical security and policies outside the enclave | Out of scope | Owns |
The enclave does not replace your policies, your physical security, or your existing MSP. The final matrix is agreed per customer during the first station.
Boundary review
Draw the flow first.
Thirty minutes on where CUI actually moves. We will tell you if CUI Track fits, and if it does not.