For defense contractors pursuing CMMC Level 2 certification, the concept of the "Secure Enclave" is the gold standard. It represents a walled garden where Controlled Unclassified Information (CUI) lives, safe from the open internet and unauthorized users.
But in the Defense Industrial Base (DIB), business doesn’t happen in a vacuum. You have to email partners, share files with subcontractors, and collaborate with government agencies. The challenge has always been: How do you share CUI out of your secure enclave without breaking compliance or expanding your audit scope?
Recent guidance from the Department of Defense (specifically CMMC FAQ Rev 2.2) has provided much-needed clarity on this issue, and it validates a data-centric approach to security — the exact architecture Virtru is built on.
Here is how the new guidance impacts your secure enclave strategy and how Virtru helps you stay compliant. For more detail on how Virtru supports CMMC Level 2 compliance according to these updated standards, download our datasheet, Supporting CMMC Level 2 Certifications with Data-Centric Security.
The recent CMMC FAQ Rev 2.2 reinforces a clear path for secure collaboration. The DoD clarified four major principles regarding CUI data flows:
Virtru allows you to share CUI via email and file transfer while satisfying the DoD’s definition of "Logical Separation." By treating the data object as its own secure enclave (hosted on a FedRAMP authorized cloud, with encryption and granular access control applied), you can allow data to travel outside your network boundaries without losing control.
Here is how Virtru aligns with the new FAQ guidance:
The guidance is clear: Cloud services storing CUI must meet FedRAMP Moderate standards. Virtru for Email and Virtru Secure Share utilize a FedRAMP Moderate authorized cloud environment. This satisfies DFARS 252.204-7012 and CMMC requirements for cloud services, meaning you don’t need to implement separate FedRAMP controls for the Virtru environment itself. It’s important to note that there’s a big difference between “FedRAMP equivalent” and “FedRAMP authorized” in terms of how much risk you’re assuming.
Recommended Reading: Feedback From the Front Lines: Where 'FedRAMP Equivalent' Falls Short
The DoD requires that you demonstrate adequate protection for CUI at all times. Virtru employs a "Split-Knowledge" architecture. While encrypted CUI files may be stored in Virtru’s FedRAMP cloud, the encryption keys are managed separately.
The result is that Virtru (the vendor) cannot decrypt, view, or access your plaintext CUI. This creates the distinct "Logical Separation" the DoD looks for. It ensures that CUI remains unusable to unauthorized parties, effectively reducing risk without introducing uncontrolled third-party access.Recommended Reading: Why We Should Give a $@*# About Secure Cloud Computing
How does this look in practice when your teams are working?
When you send a proposal or schematic via an email attachment, Virtru encrypts the file containing CUI and stores it in the FedRAMP Moderate cloud. The recipient must authenticate (via Google/Microsoft credentials) to view it.
For larger files, Secure Share offers a controlled environment for collaboration. Files are encrypted individually, and you retain the ability to revoke access or audit activity at any time.
For organizations looking to demonstrate the highest level of logical separation — particularly for strict interpretations of the new guidance — there’s Virtru Private Keystore. This allows you to host your own private encryption keys on-premises, in an HSM, or in a private cloud.
Virtru’s CMMC customers are continually passing their C3PAO assessments for CMMC Level 2. One recent example is Maya HTT, a 3D simulation software engineering company that works closely with enterprise customers as well as government agencies in the U.S. and Canada.
Here’s a clip from a recent conversation with Maya HTT’s CISO, Jonathan Bieber, where he shares about their path to achieving a perfect SPRS score on their first CMMC assessment.
The new DoD guidance affirms that compliance isn't just about where data sits; it must also account for how data is controlled. By combining FedRAMP Moderate authorization with strong, data-centric encryption and split-knowledge key management, Virtru enables you to extend the security of your enclave to wherever your business takes you.
Ready to align your external communication with CMMC Level 2? Book a demo with our team to learn more.
Juan is the Manager of Solutions Engineering at Virtru. As a Solutions Engineering leader, he's spent his career helping teams and customers translate complexity into clarity. His work centers on making data protection practical, translating complex security, privacy, and compliance requirements into solutions that enable trust, collaboration, and scale.
View more posts by Juan SalinasSee Virtru In Action
Sign Up for the Virtru Newsletter




/blog%20-%20EEOC/EEOC.webp)


/blog%20-%20marquis%20exploit/Marquise-Zero-Day.webp)
/blog%20-%20the%20data%20layer/geode.webp)

Contact us to learn more about our partnership opportunities.