RELIABLE INTEGRATION Book a scoping call

REV A  A prime just told you that you need CMMC.

Your CUI gets one room. We build the room in thirty days.

Reliable Integration builds compliant Microsoft GCC High and Azure Government enclaves for small defense contractors. Fixed price. Fixed schedule. The NIST 800-171 controls actually implemented, not just written down — plus the System Security Plan and POA&M an assessor will ask to see.

Book a 20-minute scoping call See the price Or call 1-919-717-2707 — you get the engineer.
Build price
$45,000
Schedule
30 days
Target
Level 2
Platform
GCC High

The situation

You didn't go looking for this. It arrived in an email.

Usually it's a letter from a prime — L3, Lockheed, BAE, or a tier-one you've supplied for eleven years without a single quality escape. It says you need CMMC. It names a date. It does not explain what any of it means.

Then you call around. A national compliance firm quotes you $150,000 and an eighteen-month program. Your IT provider, who is very good at keeping the shop running, says they'll look into it. Neither answer helps, because neither one tells you the thing you actually need to know first: whether the data you receive is even CUI.

A lot of suppliers who get these letters turn out to hold only Federal Contract Information. That's Level 1, it's a self-assessment, and it does not require any of this. Finding that out costs you a phone call.

Where the program actually stands

DateStatus
Nov 10, 2025Phase 1 live. Covered DoD contracts require a current Level 1 or Level 2 self-assessment in SPRS plus an annual affirmation, at time of award.
Jul 13, 2026Phases 2 and 3 suspended pending program review. Third-party C3PAO assessment expansion is on hold.
NowSelf-assessment obligations remain in force. Primes continue flowing requirements down on their own timelines, which are frequently earlier than the government's.

The suspension paused the auditor. It did not pause the controls. A self-assessment still requires that the controls genuinely exist, and a false affirmation carries False Claims Act exposure.

Deliverables

What you get, and what you don't

The scope is written down before we start and doesn't move. If something outside this list turns out to be necessary, we tell you before we do it, not after.

In scope

  • GCC High or Azure Government tenant, provisioned and hardened
  • Entra ID identity design, conditional access, phishing-resistant MFA
  • Network segmentation and the CUI boundary — where the fence goes and why
  • Device compliance and endpoint policy for in-scope machines
  • Encryption at rest and in transit, FIPS-validated modules
  • Centralized logging, alerting, and 90-day retention
  • Data-flow map showing every path CUI takes through your business
  • System Security Plan covering all 110 NIST 800-171 controls
  • POA&M for anything not fully met at handover, with owners and dates
  • SPRS score calculation and submission walkthrough
  • Two hours of admin training, recorded, so you can rewatch it

Not in scope

  • Certification. We're not a C3PAO and can't assess our own work
  • Microsoft licensing — billed by Microsoft directly, to you
  • Physical security controls at your facility
  • Rewriting your ERP or MES to move CUI out of it
  • Legal opinions on contract language — that's your counsel
  • Day-to-day helpdesk for your commercial environment
  • Migrating non-CUI workloads for the sake of tidiness
CUI enclave boundary diagram Commercial environment on the left sits outside the assessment boundary. A dashed boundary on the right contains the GCC High tenant with identity, segmented workload network, encrypted storage, and centralized logging. A single controlled path connects them. OUTSIDE BOUNDARY Commercial M365 Shop floor / MES Accounting, HR General email NOT ASSESSED ONE PATH CUI ASSESSMENT BOUNDARY — GCC HIGH Entra ID + Conditional Access AC / IA control families Managed endpoints CM / SI control families Segmented workload VNet SC control family Encrypted CUI storage MP / SC control families Centralized logging + alerting · 90-day retention · AU control family 110 CONTROLS APPLY HERE ONLY
Fig. 1 — The fence is the whole point. Everything outside it stays out of the assessment.

Schedule

Thirty days, four phases

The clock starts at kickoff. It assumes you can give us an org chart, a rough data inventory, and one person who can answer a question within a business day. If that person goes on vacation in week two, the schedule moves. We'll say so out loud.

Days 1–5

Find the CUI

Interviews, a data-flow map, and a decision on where the fence goes. This is the phase that determines everything downstream, so it gets real time rather than a template.

Days 6–14

Build the tenant

GCC High or Azure Government provisioning, identity design, conditional access, network segmentation. The enclave exists and is empty by the end of week two.

Days 15–24

Implement controls

Endpoint policy, encryption, logging and alerting, and the specific technical controls your gap report flagged. Each one gets evidence captured as it's built, not reconstructed later.

Days 25–30

Document and hand over

SSP, POA&M, SPRS score, admin training, and a walkthrough with whoever owns this after we leave. You end the month able to explain your own environment.

Pricing

Published, fixed, and not a range

If a firm won't tell you the price before a discovery call, the price depends on what they think you'll pay. Here's ours.

Gap analysis

$7,500

Two weeks · credited toward a build
  • CUI data-flow map
  • Recommended enclave boundary
  • Current SPRS score, calculated
  • Gap report, prioritized by risk and cost
  • Platform recommendation with the reasoning shown
Start here

Enclave build · most common

$45,000

Fixed price · 30 days · includes gap analysis
  • Everything in the gap analysis
  • GCC High or Azure Government tenant built
  • All 110 controls implemented or documented
  • System Security Plan and POA&M
  • Evidence package for your assessor
  • Admin training and handover
Book a scoping call

Managed retainer

$2,000 /mo

Optional · month to month, no term
  • Monitoring and alert triage
  • Configuration drift remediation
  • SPRS score kept current
  • Annual affirmation support
  • POA&M items driven to closed
  • Assessor liaison when your turn comes
Ask about it

Microsoft licensing is separate and billed to you by Microsoft — budget roughly $50–70 per user per month for GCC High, for in-scope users only, which is usually far fewer people than you'd guess. We don't resell licenses and we don't take a margin on them. Travel, if a site visit is genuinely required, is billed at cost.

Hardware, and being straight about it. Reliable Integration also operates a value-added reseller arm that supplies servers, endpoints and network gear. If your build needs hardware, we can source it — or you can buy it anywhere you like. The build price is the same either way, the specification doesn't change based on who fills the order, and we'll tell you plainly when a cheaper part meets the same control. You should know we sell the equipment before you take a recommendation from us about it.

Who builds it

One engineer, and it's the one you talk to.

Most CMMC vendors are compliance-paperwork shops. They're good at documentation and they subcontract the engineering to whoever's available. I'm the opposite of that: I've spent my career inside Azure networking and security, including migrating U.S. Treasury financial systems into Azure Government, where the compliance boundary isn't a diagram in a deck — it's the thing that has to hold.

So the person on your scoping call is the person who designs the boundary, writes the conditional access policies, and signs the SSP. When something in your environment is genuinely weird, that's a conversation, not a change order.

Reliable Integration LLC is registered in North Dakota and carries general liability and errors & omissions coverage. Certificates available on request, before you sign anything.

Arday Ardayfio, MBA — Principal Engineer

RefDetail
AZ-700Azure Network Engineer Associate
AZ-305Azure Solutions Architect Expert
SC-500Microsoft Security Operations
AZ-104Azure Administrator Associate
AWS-SAAAWS Solutions Architect – Associate
PRIORMicrosoft — Senior Cloud Solutions Architect; Azure Network Support Engineer
PRIORFiserv Government Solutions — Senior Azure InfraOps Network & Security Engineer, U.S. Treasury systems to Azure Government
MBAUNC Kenan-Flagler Business School
INSGeneral liability + errors & omissions, active

Questions

The seven things everyone asks

Is CMMC actually required right now, or was it delayed?

Phase 1 has been in force since November 10, 2025. Covered new DoD contracts require a current Level 1 or Level 2 self-assessment posted in SPRS, plus an annual affirmation, to be eligible for award.

What changed is Phase 2 — the expansion of third-party C3PAO assessments — which was suspended on July 13, 2026 pending a program review. That suspension paused the auditor. It didn't pause the obligation to implement the controls, and it hasn't slowed primes down at all; several are flowing requirements to suppliers on schedules earlier than the government's.

What is a CUI enclave, and why not just secure the whole company?

An enclave is a fenced-off environment that holds all of your Controlled Unclassified Information, so only that environment falls inside the assessment boundary.

The alternative is pulling every laptop, server, and shared drive into scope. That costs more to build, far more to maintain, and turns every future assessment into a company-wide event. For a shop of 40 people where six of them touch CUI, the enclave is usually a fraction of the cost.

Do I need GCC High, or is commercial Microsoft 365 enough?

It depends on whether your CUI includes export-controlled data. Commercial M365, configured correctly, satisfies NIST 800-171 for many CUI categories. If ITAR or EAR data is in play, the data residency and personnel screening commitments in GCC High or Azure Government are usually what decides it.

This is one of the first questions the gap analysis answers, because getting it wrong is expensive in both directions — over-buying GCC High for data that never needed it is a common and permanent tax.

Can you certify my company?

No. Certification assessments are performed by a C3PAO, and we're not one.

We build and document the environment an assessor evaluates, and we get your team ready for that conversation. Keeping the builder separate from the assessor is how the program is meant to work, and any firm offering to do both should give you pause.

What does it cost, all in?

$45,000 for the build, fixed. $7,500 if you only want the gap analysis, credited in full if you go on to build. $2,000 a month afterward if you want it monitored and maintained, with no term commitment.

Microsoft licensing is on top and goes straight to Microsoft — roughly $50–70 per in-scope user per month for GCC High. We don't mark it up.

How long does it really take?

Thirty days from kickoff to handover, across four phases. That's the schedule we hold ourselves to.

The two things that reliably break it are a decision-maker who can't be reached and a CUI data flow nobody mentioned in scoping — usually a shared drive, or an engineer emailing drawings to a vendor. We ask hard about both in week one for exactly this reason.

My prime sent a flow-down letter with a deadline. What do I do first?

Read it for two things: which level it names, and whether it says self-assessment or certification. Those two answers set your entire budget.

Then figure out whether you actually receive CUI or only Federal Contract Information. A real share of the suppliers who get these letters hold only FCI, which is Level 1, a self-assessment, and nothing like this project. That's a twenty-minute conversation and we don't charge for it.

Resources

Written for the week the letter arrives

No gated PDFs, no email wall. If one of these answers your question and you never call us, that's a fine outcome.

Next step

Twenty minutes. Bring the letter.

The call has one job: work out whether you have a CUI problem, an FCI problem, or no problem. Sometimes the honest answer is that you don't need us, and you'll get that answer on the call rather than after an invoice.

Prefer to just call? 1-919-717-2707. We reply within one business day. No drip sequence, no newsletter — one human, one reply. Don’t send CUI or anything export-controlled through this form.