CMMC Enclaves for University
& Federally Funded Research

Federally funded research brings CUI onto a campus network built for open collaboration, not federal compliance. An enclave separates the two without shutting down the collaboration that makes the research possible.

Agile IT builds Microsoft-based enclaves that isolate CUI from the rest of campus IT. Faculty, students, and outside research partners keep working together. The compliance boundary sits around the data, not around the university. 
Sanity-check whether an enclave is the right way to scope your CUI.

AOS-G

Microsoft Partner

Cyber AB

Registered Practitioner Organization 

GCC High

Focused, Nit General-Purpose IT

What Is a CMMC Enclave for Universities?

A CMMC enclave is a dedicated, secure environment that isolates and manages Controlled Unclassified Information (CUI) in accordance with Cybersecurity Maturity Model Certification (CMMC) standards. In higher education, enclaves allow institutions to: 

Isolate DoW or federally funded research from general campus systems

Enable secure collaboration for faculty, students, and external research partners 

Maintain compliance with DFARS, CMMC, NIST 800-171 and ITAR

Why a CMMC-Compliant Enclave?

Academic networks are designed for collaboration, not regulation. When research involves CUI, those same open systems create risk. A CMMC enclave minimizes that exposure by: 

  • Segregating regulated data from general academic systems 
  • Reducing CMMC audit scope and overall compliance effort 
  • Enabling rapid provisioning of secure environments for research projects 
  • Simplifying documentation and audit readiness 

Four Areas Where Research Compliance Gets Complicated

Identity and Access Management 

  • Enclave creates separate identities, ensuring the logical separation required by CMMC 
  • Apply role-based access control across departments and research groups 
  • Enforce MFA and session management for all enclave users 

Data Protection and Controls 

  • Store sensitive data securely in SharePoint, OneDrive, and Azure Files 
  • Enforce DLP and labeling through Microsoft Purview policies 
  • Enable full audit logging and control-family reporting 

Isolated Collaboration Spaces 

  • Create project-based Teams and SharePoint sites for each research project 
  • Manage guest access for external collaborators with governance policies 
  • Integrate approved research tools inside the secure boundary 

Licensing and Deployment Help 

  • Simplify GCC High onboarding and tenant configuration 
  • Right-size licensing for faculty, staff, and researchers 
  • Plan and execute infrastructure migration with minimal downtime 

Who We Serve and What to Expect

Who We Serve:

Expected Outcomes:

Why Agile IT

Agile IT is a Microsoft AOS-G partner and Cyber AB Registered Practitioner Organization, working specifically in Microsoft GCC High environments for regulated research. 

GCC High Enclave

Migrate .edu environments into GCC High enclaves designed for regulated research. This starts with a readiness assessment, then enclave design, tenant provisioning, and a phased data migration that minimizes downtime and user disruption. 

Hybrid and Federated Identity

Support hybrid Entra ID configurations that unify academic and research identity ecosystems. Researchers and staff get secure access to both on-premises and cloud resources through one identity, not separate logins for each system. 

CMMC Alignment

Work with research IT and compliance teams to define and map CMMC control ownership. Templates, SSP guidance, and technical configuration recommendations inside Microsoft 365 GCC High support certification readiness. 

Book a University CMMC Enclave Consultation

Connect with Agile IT’s higher education specialists to scope an enclave for your research environment.