There Can Only Be Two: The Single-User CMMC Company

A one-person company rarely wants two complete technology environments. Every additional device, mailbox, account, security tool, and login creates more work for the same person who already serves as owner, contracts manager, security officer, bookkeeper, and technical staff. It will always cost more to maintain two tenants and two devices.

Yet sometimes two devices make perfect sense. At KNC Strategic Services, we are not a single person company, but we are fully remote. We utilize a two device solution and a CUI Enclave. All of our assessors have two identities and two devices. One to access our commercial work in GCC and one to access assessor work in GCCH.

A single-user company may keep its existing commercial laptop for normal business and add one hardened laptop dedicated to Controlled Unclassified Information. Instead of pulling the entire company into the CMMC boundary, the owner creates a narrow enclave around the work that actually touches CUI. At face value, this makes little sense, but business use cases do exist for a single person company to maintain an enclave and two devices.

CMMC, the program to measure how your controls meet the NIST-SP-800-171 requirements, does not require two devices. In many cases, one properly configured device can handle the job. In total lifetime costs, an enterprise GCCH scope will set you back the least, but cost the most up front.

As your company were to scale carving out an enclave may makee more sense, but for the cost of a laptop you can control your CUI flow, and leave any commercial business out of scope. Buying a second device can protect the commercial business from the restrictions, cost, and operational friction that comes with a CUI environment.

Even as a single person company, you will want to ask:

When does a second laptop create an affordable and manageable CMMC boundary, and when does it create more trouble than it solves?

The Microbusiness Swivel Seat

For a one-person company, the swivel seat may be literal. We have reviewed, because of separation of duties, the need to have multiple licenses with multiple roles, which means instead of swivel seat we are talking swivel high-top.

If you want to have an enclave as a soloprenuer buying another computer is the easiet, and cheapest way to get the job done. The owner sits at a desk with two laptops. One handles ordinary business. The other handles protected contract work.

On the commercial laptop you read customer correspondence, prepares invoices, runs payroll, uses accounting software, joins commercial video calls, manages the company website, talks to potential customers, and handles every other part of the business.

On the protected laptop, the owner opens CUI drawings, reviews specifications, accesses approved government portals, connects to the authorized CUI repository, and performs contract work that requires the NIST-SP-800-171 environment.

Small contractors, especially those providing staffing or Defense Services, may receive email directly from the Government or a Prime that contains a file marked, or even the email, often incorrectly, is marked CUI. Think through what having two domains means.

You have to snag two identities and maintain two mailboxes. As a visual reminder you use two browser profiles, depending on the environment you need to access. or two collaboration environments depending on the architecture. Having a second device simplifies this into an easier to enforce boundary.

Why Would a One-Person Company Choose Two Devices?

Imagine that your company performs mostly commercial work and handles CUI only for one government contract. Your everyday computer may contain accounting software, CRM tools, commercial Microsoft 365 applications, marketing platforms, personal productivity tools, video conferencing software, browser extensions, and customer-specific applications.

You may also need local administrator privileges for specialized software or rely on an existing MSP that uses tools you do not want inside the CUI environment. If you turn that computer into your CUI endpoint, all of those applications and services suddenly deserve scrutiny.

It seems counter-intuitive, doubling the devices for ease, but you can understand.

This computer runs my business. That computer handles CUI.

That makes the boundary easier to explain and often easier to assess. You need to make the procedures useful for you. Just bifurcating behind boundaries allows you to understand and follow your own procedures. You can’t just have a plan. You need to follow the plan.

Left or Right. This device, that device. Easy to understand.

Two Devices Can Protect the Business From CMMC Restrictions

A properly hardened CUI laptop may restrict software installation. You do not give yourself local administrator privileges, USB devices and printing get blocked. You create technical settings or procedures to stop browser extensions, cloud storage, personal accounts, local network access, and unapproved collaboration applications.

Those restrictions make sense on the protected device.

They may create real problems on the computer you use to invoice customers, join sales calls, run payroll, manage banking, post to social media, edit the company website, or support commercial customers.

For a single-user business, breaking the owner’s primary computer can break the company. A dedicated CUI laptop isolates those restrictions from the systems that generate ordinary revenue.

Buy the Device When You Win the Work

A small contractor may not know whether an RFP will turn into an award. Building an entire enclave before the company knows whether it will ever receive CUI can create a large expense with no revenue behind it.

The company can instead design the enclave before award and provision the device after award.

The owner bids using commercial systems without receiving CUI. During proposal planning, the company identifies the expected CUI workflow and decides what the protected environment will look like. After award, the company purchases or assigns the laptop, applies the security baseline, creates the protected accounts, connects the approved security services, validates the device, and only then permits CUI access.

If CUI arrives before you know where it belongs, your scope problem has already started.

A Contract-Specific Device Can Make Cost Easier to Understand

A second laptop also gives a founder a clearer way to think about the cost of cybersecurity.

The protected environment may require the laptop itself, security licensing, a FedRAMP service, vulnerability management, monitoring, MSP support, logging, assessment preparation, and eventual secure retirement of the device.

When one government contract creates those costs, the company can at least identify them as costs associated with supporting that work. Whether the company can charge any particular expense directly to the contract depends on the contract and applicable cost rules, but the architecture makes the source of the cost easy to understand.

Instead of asking, “Why did our entire IT budget explode?” You can say, “This is what it costs us to operate the CUI environment.”

Just plan on a device refresh for every new contract.

Two Devices Work Best When CUI Work Stays Small

The model works particularly well when only the owner handles CUI and the protected workflow stays narrow. Without an ESP helping with IT, swivel seat, does mean multiple roles in each tenant. Third party file shares work well in these scenarioes.

Maybe CUI arrives a few times each month. Maybe the company works on short-duration defense contracts. Maybe the owner only needs a browser, PDF reader, Microsoft Office, or one approved engineering application.

In that situation, the hardened laptop sits in the enclave. You use it when you need to perform protected work and return to the commercial laptop for normal business. The more often you swivel, the greater the temptation to create shortcuts.

Separate Devices Also Solve Application Problems

Commercial businesses use messy software.

You may need consumer file sharing or want to use your commercial AI tools. Device may have remote-support software. You will accounting applications, payment processors, browser extensions, or an old engineering application that demands local administrator access. The earlier you can think about separating your logistics from third party data, the easier 171 will scale with you.

You may have perfectly legitimate reasons to use those applications for commercial business without wanting to approve them for CUI. A dedicated laptop gives you an easy answer. Keep those applications on the commercial device.

Keep the protected device boring. For CMMC, boring is beautiful.

A Smaller Device Boundary Can Simplify the Assessment

The second laptop does not remove any NIST SP 800-171 requirements. You still need to address the requirements that apply to the system.

Instead of inventorying every computer the company owns, you may have one CUI endpoint. Instead of reviewing dozens of applications, you maintain a short approved-software list. Instead of proving that several users follow the required configuration, you prove that one device does.

A narrow boundary can reduce the number of assets, applications, configurations, accounts, logs, and places where CUI might accidentally appear.

That does not make CMMC easy. It makes your CMMC problem smaller.

Two Devices Do Not Necessarily Mean Two Microsoft Tenants

People often jump jump from “two laptops” to “two complete cloud environments.” Getting M365 Commercial and GCCH. You do not always need that. The cloud storage boundary is a different problem than two devices.

A company may use one commercial tenant while keeping CUI in a protected repository. Another company may use a commercial tenant for ordinary business and GCC High for CUI. A third may keep the commercial laptop exactly as it works today and use a managed VDI enclave instead of a second physical CUI laptop. Each model creates a different boundary.

The question does not start with how many tenants you own. First you need to ask

Where does CUI enter, where can it travel, and which systems protect it?

Answer that first and then decide if an Enterprise or Enclave scope works better for you.

Two Mailboxes Create Their Own Problems

A second CUI environment often creates another mailbox or protected messaging identity.

This sounds trivial until you live with it. You may forget to check the protected mailbox. A customer may send information to the familiar commercial address. Suddenly things slip through the crack and a meeting invitation lands in the wrong tenant. The owner may respond from the wrong identity or attach a CUI file to the commercial message.

Automatic forwarding makes the problem worse because it can destroy the separation the company created in the first place.

A one person company needs a simple operating routine. Tell customers where they must send CUI. Use clearly different mailbox names and signatures. Do not automatically forward protected messages into the commercial mailbox. Check the protected mailbox every day when the contract remains active. Verify the active identity before attaching a file.

Small visual cues help too. Different desktop backgrounds, browser profiles, device labels, and signatures can prevent surprisingly expensive mistakes.

Keep the Office Network Out of the CUI Workflow

You may want the protected laptop to use the same internet connection as the commercial computer without turning every device in the house or office into part of the CUI environment. As a single person company defining your physical boundary at your endpoint, provides you the ability to easily meet the physical security requirements,

Keeping things out of scope in the home requires deliberate design.The protected endpoint should not talk to local printers, shared folders, media servers, NAS devices, or other commercial computers. The endpoint firewall can block local communication while allowing approved outbound services. The company can disable network discovery, peer-to-peer services, local printing, and removable media.

A dedicated cellular or other isolated connection can make the separation even clearer when the business model supports it.

You can keep your him office router or network outside scope simply because you can demonstrate that CUI stays encrypted while in transit. You are going from an hardened and encrypted endpoint, over TLS, up to a FedRAMP Moderate or High environment. Your second laptop creates one anchor of “the enclave.” with the cloud being the other.

The Desk Becomes Part of the Boundary

Two laptops sitting next to each other create another category of risk: shared stuff.

Think about the innocent things sitting on your desk.

A docking station. A USB keyboard. A mouse. A monitor with a USB hub. A scanner. A printer. A flash drive. A phone charging cable. Bluetooth headphones. Every shared peripheral creates a question about whether information can move between the two environments.

For a one-person enclave, the simplest answer often uses dedicated accessories for the protected device. Label the laptop. Give it a visibly different desktop background. Keep removable media disabled. Do not connect it to the commercial printer. Lock the device when you walk away.

The Hidden Cost of the Second Laptop

The laptop may cost $1,500.

The laptop rarely represents the expensive part.

You also have to configure it, license it, monitor it, patch it, vulnerability scan it, support it, maintain its accounts, collect evidence, document the environment, replace it eventually, and securely retire it.

Then add the cost no spreadsheet captures particularly well:

your time.

A one-person company has no spare security officer sitting in another office. Every hour you spend fixing the enclave represents an hour you cannot bill to a customer. This is one reason I keep encouraging microbusinesses to consider an MSP or managed enclave. You should understand your security program, but you do not need to spend your life administering Microsoft.

Know When the Two-Device Model Starts to Break

The second laptop works when it behaves like a specialized tool.

It starts to fail when the owner constantly moves between devices just to complete ordinary work. Warning signs appear when you repeatedly retype information from one machine into another, need the protected laptop to reach commercial applications, start moving USB devices between systems, regularly need to print CUI, or find yourself emailing information between environments just to get work done.

The architecture also becomes harder to sustain when every new customer introduces another portal, another security configuration, or another identity.

At that point, the friction itself becomes a security risk.

People design workarounds around systems that get in the way. If your two-device architecture constantly encourages you to bypass your own rules, you no longer have a good architecture. You have an argument with your laptop.

One Protected Device or One Per Contract?

A single-user company may eventually work on several government contracts.

That does not automatically mean you need a laptop for every contract.

A separate device for each contract can make sense when customers impose incompatible requirements, contracts require unique applications, the company must prevent cross-contract access, or the customer supplies or reimburses the equipment. But if every contract can use the same security baseline, the same authorized applications, and the same protected repository, one properly managed CUI laptop may support several contracts.

Use access controls and repository separation to keep project data apart. Do not create hardware sprawl simply because another award arrives.

The Decision Test

A second laptop makes sense when most of your revenue comes from commercial work, only one person needs CUI, the protected workflow uses a small number of applications, and you can prohibit printing, removable media, and local sharing.

It also works well when the CUI need starts and stops with particular awards and you want to protect your existing commercial environment from CMMC restrictions.

The model makes less sense when CUI drives almost everything you do. If you spend all day moving between environments, need commercial systems to complete protected work, constantly transfer information, or require several people to work simultaneously, you may have outgrown the two-device model.

At that point, a broader GCC High environment, managed VDI enclave, or more integrated architecture may create less friction and less risk.

There Can Only Be Two

For a one-person company, two devices should not mean building two complete enterprises.

Your commercial laptop keeps the company alive. It handles sales, accounting, ordinary email, customer support, marketing, commercial production, and everything else that does not require the CUI enclave.

Your protected laptop does one job. It handles CUI. That narrow purpose creates the value. It fails when every ordinary business process forces you to swivel back and forth between two computers.

Keep the enclave boring. Keep the data flow narrow. Keep the commercial business outside it.

Sometimes the easiest way to make one tiny company meet CMMC is to accept one simple rule:

There can only be two.

“Mr. Hardcast’s Seal of Approval Bar Stool” flickr photo by Hardcast65 flickr.com/photos/ca… shared under a Creative Commons (BY 2.0) license