
The CUI cloud decision framework: GovCloud vs. Azure Government vs. commercial with a CUI enclave

A decision and operating framework for Defense Industrial Base contractors, across the full lifecycle: decide, scope, migrate, operate, prove
Executive summary
Choosing a compliant cloud is the easy part. Operating it under the obligations that come with Controlled Unclassified Information (CUI) is where defense contractors get stuck, and it is where architecture decisions made this quarter surface later as self-assessment deductions and assessment findings. This paper is a decision framework for the three realistic environment options in front of a Defense Industrial Base contractor: AWS GovCloud (US), Azure Government, and a commercial cloud region carrying a properly scoped CUI enclave. The decision input is not a price sheet; it is a one-page CUI data flow map, because the footprint decides which option fits and most contractors who skip the map over-buy. The framework then follows the decision through the four stages that come after it: scoping a boundary the 32 CFR Part 170 asset categories will support, migrating as an operating-model change run through five evidence-generating gates, operating with day-2 discipline where the real costs live, and proving the result as an honest NIST SP 800-171 self-assessment score in SPRS. The regulatory frame is what is enforced today, DFARS 252.204-7012, 7019, and 7020 and NIST SP 800-171 Rev 2, independent of third-party assessment scheduling. The paper closes with sequenced recommendations, starting with the map.

The decision is easy to buy and hard to operate
Every option on this menu can be purchased in an afternoon, and none of them can be operated by accident. The recurring failure pattern is not a wrong platform; it is a program that treats the platform choice as the finish line. The environment gets sized before the CUI footprint is mapped, the boundary gets drawn after the architecture is committed, the migration finishes without evidence, day-2 operations inherits whoever is left standing, and the score posted in the Supplier Performance Risk System (SPRS) describes an architecture that no longer exists.
The obligations, meanwhile, run continuously. DFARS 252.204-7012 protection and cyber incident reporting, the 110 security requirements of NIST SP 800-171 Rev 2, and the current-score posture required by DFARS 252.204-7019 and 7020 apply at every stage, including mid-migration.A decision framework for this environment therefore has to cover more than the purchase: it has to carry the contractor through decide, scope, migrate, operate, and prove, because the option that looks cheapest at the decision stage is frequently the one that costs the most at the operating stage.
The three options, and what each one actually is
AWS GovCloud (US) is a set of isolated AWS regions designed for sensitive workloads and regulated data, with their own access requirements. Azure Government is a physically and logically separated set of Microsoft Azure regions with its own compliance posture and eligibility requirements. Neither is the same thing as the vendor's commercial regions, and capability, service availability, and pricing differ from commercial in both.
The third option is a commercial cloud region carrying a CUI enclave: a segmented environment that holds all CUI so the rest of the network falls outside the assessment boundary. DFARS 252.204-7012 does not name a cloud; it requires that a cloud service provider storing, processing, or transmitting covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline, with incident reporting intact, so the enclave option lives or dies on the specific offering's status and on boundary discipline. The comparison table below is the decision surface; the rest of the paper is what each choice commits you to afterward.
| Option | What it is | Strongest fit | What to watch |
| AWS GovCloud (US) | Isolated AWS regions designed for sensitive workloads and regulated data, with their own access requirements | Pervasive CUI footprint in an AWS-centered estate; export-control considerations in play (route to counsel) | Region price premium, narrower service catalog, feature parity differences vs. commercial; verify against AWS documentation |
| Azure Government | Physically and logically separated Azure regions with their own compliance posture and eligibility requirements | Pervasive CUI footprint in a Microsoft-centered estate; alignment with government Microsoft 365 environments | Eligibility validation, parity and availability differences vs. commercial; verify against Microsoft documentation |
| Commercial region with a CUI enclave | A segmented environment holding all CUI so the rest of the network falls outside the assessment boundary, on a commercial platform meeting DFARS 252.204-7012's FedRAMP Moderate equivalency requirement | Contained CUI footprint: defined repositories, a program team, no contract term dictating a broader environment | Boundary discipline (a leak expands scope or becomes a finding); verifying the specific offering's equivalency status; endpoints, users, and identity remain in scope |
Decide: size the environment to the CUI footprint
The decision input is a data flow map: where CUI enters the organization, where it is stored and processed, who touches it, and where it leaves. A contained footprint, a defined set of repositories handled by a program team, points to the enclave option. A pervasive footprint, where engineering, manufacturing execution, quality, and program systems all process CUI, points to a full government cloud, because a boundary around the CUI part would enclose most of the company. Export-controlled data changes the calculus again and belongs with counsel before architecture. VSO runs this as a structured CUI data flow gap analysis, and the output is deliberately small: one page, with the people counted on it.
Most contractors who skip the map over-buy. The full government cloud quote arrives first, it is professionally assembled, and it solves a bigger problem than the one in the contract. Over-buying costs more than a price premium: it commits the whole estate to government-region operations, identity administration, logging, and patching that an enclave would have confined to a fraction of the environment.
Scope: a boundary the asset categories will support
Whichever option wins, the boundary has to hold up under 32 CFR Part 170. An asset is out of scope when it cannot process, store, or transmit CUI because it is physically or logically separated from the systems that do, and assets providing security functions for the environment are Security Protection Assets, assessed against the requirements relevant to what they provide. The endpoints, users, and identity systems that reach into the environment stay in scope no matter how the diagram is drawn.
Scope creep is the quiet cost multiplier. Every additional system CUI touches joins the boundary, and each one carries its share of implementing, documenting, and evidencing the 110 requirements. A CUI repository that syncs to an unscoped file server has not leaked data yet; it has already leaked scope. The stage-two artifact is the system security plan (SSP), updated to describe the boundary, the asset categories, and the controlled interfaces, with an asset inventory that matches it.
Migrate: an operating-model change run as five gates
A CUI migration is not a project with a cutover date; it is an operating-model change, and the obligations do not pause for it. Run it as five gates. Gate one: the CUI inventory and flow map approved before any server list. Gate two: the SSP updated for the target architecture before CUI moves into it. Gate three: the landing zone proven with a non-CUI pilot, meaning identity and multifactor authentication design settled, segmentation in place, FIPS-validated encryption configured for CUI at rest and in transit, and centralized logging on from the first account rather than retrofitted.
Gate four: workloads move in dependency waves, and each wave closes with evidence, encryption verified, access reviewed, logs flowing, change records complete, rollback tested, rather than a status update. Gate five: the source environment is decommissioned deliberately, including sanitization of media that held CUI per NIST SP 800-171 requirement 3.8.3, with the records kept. The characteristic failure is the evidence gap: a migration that finished cleanly and left nothing an assessor can read.

Operate: the real cost is operational overhead, not the list price
Government-region list pricing gets the attention, but the cost that determines the outcome is operational: identity and access administration, audit logging with deliberate retention and actual review, guest OS and workload patching, configuration baselines with drift detection, and incident response readiness. The platform authorization covers the platform, and neither a workload nor a managed service inherits it; the customer side of the shared responsibility split is a daily discipline with no finish line.
This is also where the three options genuinely diverge. A full government cloud applies that overhead, and the region price premium, to the entire estate; an enclave confines it to the boundary. The operating cadence that keeps either honest is a quarterly review with four agenda items: baseline and drift status, logging coverage against the account list, a parity watchlist for services the roadmap depends on, and cost against the asset inventory. An environment run this way generates its assessment evidence as a byproduct of operations.
Prove: architecture decisions set the self-assessment score
The proof obligation enforced today is the self-assessment: DFARS 252.204-7019 requires a current NIST SP 800-171 assessment score posted in SPRS to be considered for award, and 252.204-7020 gives the government verification access and flows the requirement down the subcontract chain. [EXT: acquisition.gov; confirm current clause text and currency window before publication] The scoring methodology in 32 CFR 170.24 starts at 110 and subtracts five, three, or one point per unimplemented requirement; the score may go negative, and a plan of action and milestones documents a fix without restoring points.
The heavy deductions land exactly where the architecture decision landed. Multifactor authentication coverage across consoles, command line, API, and break-glass paths costs five points if absent for all users and three if limited to remote and privileged users. Encryption costs five points if absent and three if present but not FIPS-validated, the one above-one-point gap the rule permits on a POA&M. An accurate lower score with a credible remediation record is a defensible position; an inflated score is a representation made to the government. If the posted score predates the migration, that is the first finding.

The framework on one page
The comparison table settles which environment; the stage grid below is what any of the three commits you to. One owner question, one primary artifact, and one characteristic failure per stage, small enough to run as a standing agenda.
Two boundaries on this paper's claims. Platform authorizations belong to the platforms: Azure Government and AWS GovCloud (US) carry authorizations that cover the platform and are not inherited by customer workloads or by any managed service operating on them. And third-party assessment timing is out of scope by design: the CMMC program's certification assessment schedule has moved, and nothing in this framework depends on it, because the obligations it is built on are in contracts now.
| Stage | The owner question | Primary artifact | Characteristic failure |
| 1. Decide | Does the CUI footprint justify a full government cloud, or does an enclave contain it? | One-page CUI data flow map | Over-buying: full-estate cost for a containable footprint |
| 2. Scope | Can this boundary be defended under the 32 CFR Part 170 asset categories? | SSP and asset inventory describing the boundary | Scope creep: every system CUI touches joins the boundary |
| 3. Migrate | Does each wave close with evidence an assessor can read? | Per-wave evidence packages; sanitization records | The evidence gap: a clean cutover with nothing to show |
| 4. Operate | Does the environment still match the SSP that describes it? | Quarterly operating review: drift, logging, parity, cost | Silent degradation: drift with no incident to mark it |
| 5. Prove | Is the posted score describing the environment we run today? | Current SPRS score with POA&M for open gaps | The stale score: a number older than the architecture |
Conclusion and recommendations
Recommendations, in sequence. First, draw the CUI data flow on one page and count the people on it; the map decides among the three options and costs an afternoon. Second, test the boundary against the 32 CFR Part 170 asset categories and fix the SSP before fixing anything else. Third, if a migration is ahead, adopt the five gates and make evidence a column in the project plan. Fourth, if the migration is behind you, run the first quarterly operating review this quarter: drift, logging coverage, parity, cost. Fifth, re-run the scoring methodology against the environment as it exists today, close the five-point items first, and post the honest number. A contractor that works this sequence has done more than choose a cloud; it has built the operating model the choice was always going to require.
CTA
VSO designs, migrates, and operates all three environment models for Defense Industrial Base contractors, from scoped CUI enclaves on commercial platforms to full Azure Government and AWS GovCloud estates. If you want the framework run against your environment, start with the data flow conversation.





