REV A A prime just told you that you need CMMC.
Your CUI gets one room. We build the room in thirty days.
Reliable Integration builds compliant Microsoft GCC High and Azure Government enclaves for small defense contractors. Fixed price. Fixed schedule. The NIST 800-171 controls actually implemented, not just written down — plus the System Security Plan and POA&M an assessor will ask to see.
- Build price
- $45,000
- Schedule
- 30 days
- Target
- Level 2
- Platform
- GCC High
The situation
You didn't go looking for this. It arrived in an email.
Usually it's a letter from a prime — L3, Lockheed, BAE, or a tier-one you've supplied for eleven years without a single quality escape. It says you need CMMC. It names a date. It does not explain what any of it means.
Then you call around. A national compliance firm quotes you $150,000 and an eighteen-month program. Your IT provider, who is very good at keeping the shop running, says they'll look into it. Neither answer helps, because neither one tells you the thing you actually need to know first: whether the data you receive is even CUI.
A lot of suppliers who get these letters turn out to hold only Federal Contract Information. That's Level 1, it's a self-assessment, and it does not require any of this. Finding that out costs you a phone call.
Where the program actually stands
| Date | Status |
|---|---|
| Nov 10, 2025 | Phase 1 live. Covered DoD contracts require a current Level 1 or Level 2 self-assessment in SPRS plus an annual affirmation, at time of award. |
| Jul 13, 2026 | Phases 2 and 3 suspended pending program review. Third-party C3PAO assessment expansion is on hold. |
| Now | Self-assessment obligations remain in force. Primes continue flowing requirements down on their own timelines, which are frequently earlier than the government's. |
The suspension paused the auditor. It did not pause the controls. A self-assessment still requires that the controls genuinely exist, and a false affirmation carries False Claims Act exposure.
Deliverables
What you get, and what you don't
The scope is written down before we start and doesn't move. If something outside this list turns out to be necessary, we tell you before we do it, not after.
In scope
- GCC High or Azure Government tenant, provisioned and hardened
- Entra ID identity design, conditional access, phishing-resistant MFA
- Network segmentation and the CUI boundary — where the fence goes and why
- Device compliance and endpoint policy for in-scope machines
- Encryption at rest and in transit, FIPS-validated modules
- Centralized logging, alerting, and 90-day retention
- Data-flow map showing every path CUI takes through your business
- System Security Plan covering all 110 NIST 800-171 controls
- POA&M for anything not fully met at handover, with owners and dates
- SPRS score calculation and submission walkthrough
- Two hours of admin training, recorded, so you can rewatch it
Not in scope
- Certification. We're not a C3PAO and can't assess our own work
- Microsoft licensing — billed by Microsoft directly, to you
- Physical security controls at your facility
- Rewriting your ERP or MES to move CUI out of it
- Legal opinions on contract language — that's your counsel
- Day-to-day helpdesk for your commercial environment
- Migrating non-CUI workloads for the sake of tidiness
Schedule
Thirty days, four phases
The clock starts at kickoff. It assumes you can give us an org chart, a rough data inventory, and one person who can answer a question within a business day. If that person goes on vacation in week two, the schedule moves. We'll say so out loud.
Days 1–5
Find the CUI
Interviews, a data-flow map, and a decision on where the fence goes. This is the phase that determines everything downstream, so it gets real time rather than a template.
Days 6–14
Build the tenant
GCC High or Azure Government provisioning, identity design, conditional access, network segmentation. The enclave exists and is empty by the end of week two.
Days 15–24
Implement controls
Endpoint policy, encryption, logging and alerting, and the specific technical controls your gap report flagged. Each one gets evidence captured as it's built, not reconstructed later.
Days 25–30
Document and hand over
SSP, POA&M, SPRS score, admin training, and a walkthrough with whoever owns this after we leave. You end the month able to explain your own environment.
Pricing
Published, fixed, and not a range
If a firm won't tell you the price before a discovery call, the price depends on what they think you'll pay. Here's ours.
Gap analysis
$7,500
Two weeks · credited toward a build- CUI data-flow map
- Recommended enclave boundary
- Current SPRS score, calculated
- Gap report, prioritized by risk and cost
- Platform recommendation with the reasoning shown
Enclave build · most common
$45,000
Fixed price · 30 days · includes gap analysis- Everything in the gap analysis
- GCC High or Azure Government tenant built
- All 110 controls implemented or documented
- System Security Plan and POA&M
- Evidence package for your assessor
- Admin training and handover
Managed retainer
$2,000 /mo
Optional · month to month, no term- Monitoring and alert triage
- Configuration drift remediation
- SPRS score kept current
- Annual affirmation support
- POA&M items driven to closed
- Assessor liaison when your turn comes
Microsoft licensing is separate and billed to you by Microsoft — budget roughly $50–70 per user per month for GCC High, for in-scope users only, which is usually far fewer people than you'd guess. We don't resell licenses and we don't take a margin on them. Travel, if a site visit is genuinely required, is billed at cost.
Hardware, and being straight about it. Reliable Integration also operates a value-added reseller arm that supplies servers, endpoints and network gear. If your build needs hardware, we can source it — or you can buy it anywhere you like. The build price is the same either way, the specification doesn't change based on who fills the order, and we'll tell you plainly when a cheaper part meets the same control. You should know we sell the equipment before you take a recommendation from us about it.
Who builds it
One engineer, and it's the one you talk to.
Most CMMC vendors are compliance-paperwork shops. They're good at documentation and they subcontract the engineering to whoever's available. I'm the opposite of that: I've spent my career inside Azure networking and security, including migrating U.S. Treasury financial systems into Azure Government, where the compliance boundary isn't a diagram in a deck — it's the thing that has to hold.
So the person on your scoping call is the person who designs the boundary, writes the conditional access policies, and signs the SSP. When something in your environment is genuinely weird, that's a conversation, not a change order.
Reliable Integration LLC is registered in North Dakota and carries general liability and errors & omissions coverage. Certificates available on request, before you sign anything.
Arday Ardayfio, MBA — Principal Engineer
| Ref | Detail |
|---|---|
| AZ-700 | Azure Network Engineer Associate |
| AZ-305 | Azure Solutions Architect Expert |
| SC-500 | Microsoft Security Operations |
| AZ-104 | Azure Administrator Associate |
| AWS-SAA | AWS Solutions Architect – Associate |
| PRIOR | Microsoft — Senior Cloud Solutions Architect; Azure Network Support Engineer |
| PRIOR | Fiserv Government Solutions — Senior Azure InfraOps Network & Security Engineer, U.S. Treasury systems to Azure Government |
| MBA | UNC Kenan-Flagler Business School |
| INS | General liability + errors & omissions, active |
Questions
The seven things everyone asks
Is CMMC actually required right now, or was it delayed?
Phase 1 has been in force since November 10, 2025. Covered new DoD contracts require a current Level 1 or Level 2 self-assessment posted in SPRS, plus an annual affirmation, to be eligible for award.
What changed is Phase 2 — the expansion of third-party C3PAO assessments — which was suspended on July 13, 2026 pending a program review. That suspension paused the auditor. It didn't pause the obligation to implement the controls, and it hasn't slowed primes down at all; several are flowing requirements to suppliers on schedules earlier than the government's.
What is a CUI enclave, and why not just secure the whole company?
An enclave is a fenced-off environment that holds all of your Controlled Unclassified Information, so only that environment falls inside the assessment boundary.
The alternative is pulling every laptop, server, and shared drive into scope. That costs more to build, far more to maintain, and turns every future assessment into a company-wide event. For a shop of 40 people where six of them touch CUI, the enclave is usually a fraction of the cost.
Do I need GCC High, or is commercial Microsoft 365 enough?
It depends on whether your CUI includes export-controlled data. Commercial M365, configured correctly, satisfies NIST 800-171 for many CUI categories. If ITAR or EAR data is in play, the data residency and personnel screening commitments in GCC High or Azure Government are usually what decides it.
This is one of the first questions the gap analysis answers, because getting it wrong is expensive in both directions — over-buying GCC High for data that never needed it is a common and permanent tax.
Can you certify my company?
No. Certification assessments are performed by a C3PAO, and we're not one.
We build and document the environment an assessor evaluates, and we get your team ready for that conversation. Keeping the builder separate from the assessor is how the program is meant to work, and any firm offering to do both should give you pause.
What does it cost, all in?
$45,000 for the build, fixed. $7,500 if you only want the gap analysis, credited in full if you go on to build. $2,000 a month afterward if you want it monitored and maintained, with no term commitment.
Microsoft licensing is on top and goes straight to Microsoft — roughly $50–70 per in-scope user per month for GCC High. We don't mark it up.
How long does it really take?
Thirty days from kickoff to handover, across four phases. That's the schedule we hold ourselves to.
The two things that reliably break it are a decision-maker who can't be reached and a CUI data flow nobody mentioned in scoping — usually a shared drive, or an engineer emailing drawings to a vendor. We ask hard about both in week one for exactly this reason.
My prime sent a flow-down letter with a deadline. What do I do first?
Read it for two things: which level it names, and whether it says self-assessment or certification. Those two answers set your entire budget.
Then figure out whether you actually receive CUI or only Federal Contract Information. A real share of the suppliers who get these letters hold only FCI, which is Level 1, a self-assessment, and nothing like this project. That's a twenty-minute conversation and we don't charge for it.
Resources
Written for the week the letter arrives
No gated PDFs, no email wall. If one of these answers your question and you never call us, that's a fine outcome.
Next step
Twenty minutes. Bring the letter.
The call has one job: work out whether you have a CUI problem, an FCI problem, or no problem. Sometimes the honest answer is that you don't need us, and you'll get that answer on the call rather than after an invoice.