If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Build vs Buy Enclave: What In House Actually Costs
The build vs buy enclave decision usually gets made on a single number, the monthly subscription, compared against a hardware estimate someone put together in an afternoon. That comparison is wrong in a specific and predictable way: it prices the build at the moment of construction and prices the buy across three years.
What follows is the line by line version, including the costs that never appear in the internal estimate and the one regulatory deadline that quietly moved the economics this year. This page belongs to How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.
Start with the number the government publishes, and what it leaves out
The Department’s own cost analysis put a small entity Level 2 certification assessment at roughly $104,670 across a three year cycle, and a Level 2 self assessment at roughly $37,196. Useful anchors, and widely quoted.
Now the sentence that changes how you read them. The analysis explicitly assumes the cost of implementing the 110 requirements has already been incurred, on the reasoning that DFARS 252.204-7012 has required it since 2017. Levels 1 and 2 carry no implementation estimate at all, deliberately.
So the published figure is the cost of proving compliance. The enclave, the licences, the tooling and the labor to build and run it are all outside that number. If your board paper uses the government estimate as the project budget, the enclave is unfunded and nobody has noticed yet. How to Budget for CMMC covers building the rest of the line.
Build vs buy enclave: what you commit to when you build
An enclave is not a server. It is a set of capabilities that must exist, be documented, and keep working for as long as you hold the contract.
| Capability | What building it actually means |
|---|---|
| Identity and multifactor authentication | A separate directory boundary, conditional access, and a joiner and leaver process somebody owns |
| Validated encryption | Not just encryption. Validated modules, verified per component, revisited as certificates age |
| Logging and retention | Collection, storage, and a named person who actually reviews it. Retention with nobody reading satisfies nothing |
| Endpoint detection | Licensing, deployment, tuning, and someone to answer alerts outside business hours |
| Vulnerability and patch management | Scanning, prioritisation, a maintenance window, and evidence it happened |
| Backup and recovery | Encrypted, tested, and restorable. Untested backup is an assumption, not a control |
| Incident response | A plan, a rehearsal, and the medium assurance certificate needed to report to DIBNet within 72 hours, obtained before you need it |
| Media preservation capacity | The clause requires preserving images and monitoring data for at least 90 days after an incident report. That is storage and process you must fund |
| Documentation | System Security Plan, policies, Plan of Action and Milestones, kept current as the environment changes |
Look at the incident response and media preservation rows. Neither is a product you buy once. Both are standing operational commitments requiring somebody reachable and prepared. A commercial provider funds equivalent retention as part of the service. A self builder funds it out of their own budget and staffs it out of their own team.
The deadline that shifted the maths this year
Cryptographic modules validated to FIPS 140-2 are accepted through September 21, 2026, after which they move to the historical list and remain usable for existing systems only.
Read the practical consequence carefully, because it lands squarely on builders. Anyone selecting modules now should be requiring FIPS 140-3 certificates. A 140-2 certificate bought today has very little non historical life left and cannot support a new deployment afterward.
For a self builder that means chasing certificate status across every component in the stack, the operating system cryptography, the virtual private network, disk encryption, backup, database encryption, and re verifying as certificates roll over. That recurring verification burden is a genuine build cost and it appears in nobody’s spreadsheet. Major cloud providers have already moved their platform modules and publish the status. This deadline asymmetrically favours buying.
Three year totals, the only fair build vs buy enclave comparison
| Build | Buy | |
|---|---|---|
| Year one | Front loaded. Market reporting puts build and migration between roughly $5,000 and $30,000 or more, before licences and before labor | Predictable. Market reporting puts fully managed enclaves around $300 to $400 per user per month |
| Years two and three | Looks cheap, and is not. Operations, monitoring, patching, evidence, documentation upkeep and certificate re verification | Same subscription, plus whatever remains yours |
| Documentation | Yours. Roughly $12,000 to $60,000 if outsourced, or several weeks of skilled internal time | Sometimes bundled. Ask, because assumption is expensive here |
| Key person risk | High. The person who built it holds knowledge that is rarely written down | Transferred, in exchange for provider dependence |
| Exit | You own it | Ask about data export before signing, not at renewal |
Those cost ranges come from market reporting and vendor rates rather than a government source, so use them for shape rather than precision and collect real quotes. The pattern holds regardless of the exact figures: build concentrates spend at the front and hides it afterward, buy spreads it evenly and makes it visible.
When building is the right call
It genuinely is, in three situations. When you already employ people who operate secure infrastructure competently, and have their hours. When your controlled workload is something you built rather than email and documents, in which case you are choosing a hosting platform anyway, covered in Azure Government vs AWS GovCloud for CUI workloads. And when defense is enough of the business that the capability is worth owning permanently.
It is also worth checking the boundary decision first, in enclave vs full remediation, because a smaller boundary makes building far more tractable. It is the wrong call when the plan depends on one person, when nobody has answered who reviews logs on a Tuesday in eighteen months, or when the internal estimate contains hardware and licences but no line for operations. That last one is the tell. An enclave with no operating budget is not a cheaper enclave, it is an enclave that will drift out of compliance quietly and be discovered by somebody else.
Five questions to settle before you decide build vs buy enclave
- Who operates this in eighteen months, by name? If the answer is a role that does not exist yet, you are buying whether you know it or not.
- What happens at two in the morning? The 72 hour reporting clock starts at discovery, not at the next business day.
- Who tracks module certificate status? With FIPS 140-2 going historical in September 2026, this is now a standing job rather than a one time check.
- What does year three look like? Price both routes across three years including labor, or the comparison is not a comparison.
- If we buy, what do we still own? Get the responsibility matrix in writing. No provider absorbs your affirmation, and none of them own your scope decision.
Frequently asked
Questions about this topic
In build vs buy enclave, is building cheaper?
What does the government estimate cover?
How many people does it take to run an enclave?
What changes with FIPS 140-2 in September 2026?
Does buying transfer our compliance obligation?
Can we build now and buy later, or the reverse?
Keep reading
More in Comparisons & Alternatives
- Azure Government vs AWS GovCloud for CUI Workloads →
- CMMC Compliance Options: Enclave, Environment or Service →
- CMMC Compliance Software for Small Manufacturers →
- CMMC Platform vs Consultant vs Doing It In House →
- Enclave vs Full Remediation: Which CMMC Path Fits →
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps →
- GCC High vs GCC vs Commercial Microsoft 365 for CUI →
- PreVeil vs GCC High for Small Defense Contractors →
- RPO vs C3PAO vs Consultant: Who Does What in CMMC →
- Virtual Desktop Enclave vs Managed Laptops for CUI →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5