Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

Build vs Buy Enclave: What In House Actually Costs

The build vs buy enclave decision usually gets made on a single number, the monthly subscription, compared against a hardware estimate someone put together in an afternoon. That comparison is wrong in a specific and predictable way: it prices the build at the moment of construction and prices the buy across three years.

What follows is the line by line version, including the costs that never appear in the internal estimate and the one regulatory deadline that quietly moved the economics this year. This page belongs to How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.

Start with the number the government publishes, and what it leaves out

The Department’s own cost analysis put a small entity Level 2 certification assessment at roughly $104,670 across a three year cycle, and a Level 2 self assessment at roughly $37,196. Useful anchors, and widely quoted.

Now the sentence that changes how you read them. The analysis explicitly assumes the cost of implementing the 110 requirements has already been incurred, on the reasoning that DFARS 252.204-7012 has required it since 2017. Levels 1 and 2 carry no implementation estimate at all, deliberately.

So the published figure is the cost of proving compliance. The enclave, the licences, the tooling and the labor to build and run it are all outside that number. If your board paper uses the government estimate as the project budget, the enclave is unfunded and nobody has noticed yet. How to Budget for CMMC covers building the rest of the line.

Build vs buy enclave: what you commit to when you build

An enclave is not a server. It is a set of capabilities that must exist, be documented, and keep working for as long as you hold the contract.

CapabilityWhat building it actually means
Identity and multifactor authenticationA separate directory boundary, conditional access, and a joiner and leaver process somebody owns
Validated encryptionNot just encryption. Validated modules, verified per component, revisited as certificates age
Logging and retentionCollection, storage, and a named person who actually reviews it. Retention with nobody reading satisfies nothing
Endpoint detectionLicensing, deployment, tuning, and someone to answer alerts outside business hours
Vulnerability and patch managementScanning, prioritisation, a maintenance window, and evidence it happened
Backup and recoveryEncrypted, tested, and restorable. Untested backup is an assumption, not a control
Incident responseA plan, a rehearsal, and the medium assurance certificate needed to report to DIBNet within 72 hours, obtained before you need it
Media preservation capacityThe clause requires preserving images and monitoring data for at least 90 days after an incident report. That is storage and process you must fund
DocumentationSystem Security Plan, policies, Plan of Action and Milestones, kept current as the environment changes

Look at the incident response and media preservation rows. Neither is a product you buy once. Both are standing operational commitments requiring somebody reachable and prepared. A commercial provider funds equivalent retention as part of the service. A self builder funds it out of their own budget and staffs it out of their own team.

The deadline that shifted the maths this year

Cryptographic modules validated to FIPS 140-2 are accepted through September 21, 2026, after which they move to the historical list and remain usable for existing systems only.

Read the practical consequence carefully, because it lands squarely on builders. Anyone selecting modules now should be requiring FIPS 140-3 certificates. A 140-2 certificate bought today has very little non historical life left and cannot support a new deployment afterward.

For a self builder that means chasing certificate status across every component in the stack, the operating system cryptography, the virtual private network, disk encryption, backup, database encryption, and re verifying as certificates roll over. That recurring verification burden is a genuine build cost and it appears in nobody’s spreadsheet. Major cloud providers have already moved their platform modules and publish the status. This deadline asymmetrically favours buying.

Three year totals, the only fair build vs buy enclave comparison

BuildBuy
Year oneFront loaded. Market reporting puts build and migration between roughly $5,000 and $30,000 or more, before licences and before laborPredictable. Market reporting puts fully managed enclaves around $300 to $400 per user per month
Years two and threeLooks cheap, and is not. Operations, monitoring, patching, evidence, documentation upkeep and certificate re verificationSame subscription, plus whatever remains yours
DocumentationYours. Roughly $12,000 to $60,000 if outsourced, or several weeks of skilled internal timeSometimes bundled. Ask, because assumption is expensive here
Key person riskHigh. The person who built it holds knowledge that is rarely written downTransferred, in exchange for provider dependence
ExitYou own itAsk about data export before signing, not at renewal

Those cost ranges come from market reporting and vendor rates rather than a government source, so use them for shape rather than precision and collect real quotes. The pattern holds regardless of the exact figures: build concentrates spend at the front and hides it afterward, buy spreads it evenly and makes it visible.

When building is the right call

It genuinely is, in three situations. When you already employ people who operate secure infrastructure competently, and have their hours. When your controlled workload is something you built rather than email and documents, in which case you are choosing a hosting platform anyway, covered in Azure Government vs AWS GovCloud for CUI workloads. And when defense is enough of the business that the capability is worth owning permanently.

It is also worth checking the boundary decision first, in enclave vs full remediation, because a smaller boundary makes building far more tractable. It is the wrong call when the plan depends on one person, when nobody has answered who reviews logs on a Tuesday in eighteen months, or when the internal estimate contains hardware and licences but no line for operations. That last one is the tell. An enclave with no operating budget is not a cheaper enclave, it is an enclave that will drift out of compliance quietly and be discovered by somebody else.

Five questions to settle before you decide build vs buy enclave

  1. Who operates this in eighteen months, by name? If the answer is a role that does not exist yet, you are buying whether you know it or not.
  2. What happens at two in the morning? The 72 hour reporting clock starts at discovery, not at the next business day.
  3. Who tracks module certificate status? With FIPS 140-2 going historical in September 2026, this is now a standing job rather than a one time check.
  4. What does year three look like? Price both routes across three years including labor, or the comparison is not a comparison.
  5. If we buy, what do we still own? Get the responsibility matrix in writing. No provider absorbs your affirmation, and none of them own your scope decision.

Frequently asked

Questions about this topic

In build vs buy enclave, is building cheaper?
In year one it usually looks cheaper, and across three years it frequently is not. Build concentrates spend in architecture and engineering labor at the front, then carries operations, monitoring, evidence and documentation upkeep that rarely appear in the original estimate. Compare three year totals including labor or the comparison is meaningless.
What does the government estimate cover?
Planning, the assessment itself, reporting and affirmation labor. Roughly $104,670 for a small entity Level 2 certification across three years and roughly $37,196 for a self assessment. It explicitly excludes implementing the 110 requirements, because the analysis assumes that was already done under DFARS 252.204-7012. Your enclave is entirely outside that number.
How many people does it take to run an enclave?
There is no published figure, and any vendor quoting one is estimating. The better question is which named person owns identity, patching, log review and incident response, and whether their hours are protected. If those four have no owner, the enclave will drift regardless of headcount.
What changes with FIPS 140-2 in September 2026?
Modules validated to FIPS 140-2 are accepted through September 21, 2026, then move to the historical list for existing systems only. Anyone selecting modules now should require FIPS 140-3. For a self builder this creates a recurring obligation to verify certificate status across the whole stack, which is a build cost most estimates omit.
Does buying transfer our compliance obligation?
No. It transfers work, not accountability. The annual affirmation is signed by your senior official, the obligation sits with the contract holder, and your provider’s relationship to you must be documented in your System Security Plan. Any contract implying otherwise is describing something that does not exist.
Can we build now and buy later, or the reverse?
Moving from bought to built is straightforward if you designed for it. Moving from built to bought means migrating data and unwinding decisions, which is slower. If genuinely undecided, buy first. It is the reversible direction and it buys you a working environment while you learn what you actually need.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents