If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
CMMC Compliance Options: Enclave, Environment or Service
Every set of CMMC compliance options eventually reduces to one question a finance leader can answer: are you paying to secure the whole company, or paying to secure a small part of it and keep the rest out of the way. That decision is worth more money than any product you will buy afterward, and most companies make it by accident.
This page compares the three paths side by side with real numbers. It exists because the market sells you tools before anyone helps you choose an architecture, and a tool bought before the architecture is decided is a tool you throw away.
What the July 2026 suspension changed about your CMMC compliance options
On July 13, 2026 the Department of War suspended the CMMC Phase 2 requirements that were due to take effect on November 10, 2026, and stood up a reform task force. Read the second half of that sentence carefully before you cancel anything.
| Obligation | Status today |
|---|---|
| Third party certification as a condition of award | Suspended |
| DFARS 252.204-7012 safeguarding and 72 hour incident reporting | In force, unchanged |
| NIST SP 800-171 Revision 2, all 110 requirements | In force, unchanged |
| Current SPRS score and annual senior official affirmation | In force, unchanged |
| Phase 1 self assessment requirements | In force. The Department stated these remain firmly in place |
| Government led DIBCAC assessments | Active, and they can arrive without much notice |
| C3PAO assessments | Still authorized and still being conducted, now voluntary rather than compelled |
The audit stopped being mandatory. The security requirement did not move at all. So the engineering and budget decisions on this page still matter, and the deadline pressure that used to force bad, fast choices is gone. That is a good year to make the architecture decision properly.
The three CMMC compliance options, priced honestly
Every credible approach is a variation on one of these three CMMC compliance options. The differences in cost between them are not marginal.
| Enclave | Full environment | Managed service | |
|---|---|---|---|
| What is in scope | A defined boundary holding controlled information, plus the people inside it | Every system, every laptop, every user | Whatever boundary the provider operates, plus your own residual assets |
| Who it suits | Defense is a minority of revenue, and a handful of people touch controlled data | Defense is most of your revenue and controlled data is everywhere | You have no internal security staff and no appetite to build one |
| Typical published range | Hosted micro enclaves run roughly $400 to $1,700 per month for a small group. Single seat products start near $400 per month | Licensing alone is the smaller half. Every endpoint becomes an assessed asset | Market reporting puts fully managed enclaves around $300 to $400 per user per month |
| Where it goes wrong | Data leaks out of the boundary and the scope quietly becomes the whole company again | Cost and calendar both run away, and nobody can say when it ends | You assume the provider owns the obligation. They do not |
Those enclave and managed figures come from market reporting and vendor published rates rather than from a government source, so treat them as planning ranges and get quotes. The point is the order of magnitude, and the order of magnitude is the whole argument.
The number the government publishes, and the number it leaves out
The Department published per entity cost estimates in the CMMC rulemaking. For a small entity, over a three year cycle, it estimated roughly $104,670 for a Level 2 certification assessment and roughly $37,196 for a Level 2 self assessment. A Level 1 self assessment came in near $5,977.
Now the part that matters more than any of those figures. The analysis explicitly assumes the cost of implementing the 110 requirements has already been spent, on the reasoning that DFARS 252.204-7012 has required it since 2017. So the published number is the cost of proving compliance. It is not the cost of becoming compliant, and for most of the industrial base the second number is far larger than the first.
If a board paper quotes the government estimate as the project budget, the project is already underfunded. Build the implementation line separately and defend it separately. How to Budget for CMMC covers the structure.
Four questions that pick the path for you
- How many people genuinely need to touch controlled information? Count names, not departments. In most small manufacturers the honest answer is between three and twelve, and that answer alone usually decides the architecture.
- Is any of it export controlled? ITAR and export controlled technical data restrict access to United States persons, which is a personnel and residency question rather than an encryption question. It narrows your product choices sharply. See GCC High vs GCC vs Commercial Microsoft 365 for CUI.
- Can the work actually be done inside a boundary? A quoting team living in email and a document library can. An engineering group pushing models to machines on the shop floor often cannot, and that changes the answer. Enclave vs full remediation works through the test.
- Do you have anyone to run it on Monday morning? Controls are bought once and operated forever. If nobody owns logging review, patching and incident response by name, you are buying a managed service whether you call it that or not.
The distinction the market deliberately blurs
There are two entirely different things being sold as CMMC compliance options, and conflating them is the most expensive mistake in this category.
Documentation tooling produces a System Security Plan, a Plan of Action and Milestones, policies and a score. It changes your paperwork. It changes nothing about your actual security posture.
An environment is a compliant place for controlled information to live. It changes your posture. It does not write your documentation, and it covers nothing outside its own boundary.
Most small manufacturers need one of each, or a provider who bundles both. Buying one and believing you are finished is the single most common failure in this market. A beautifully generated plan describing controls you have not implemented is not a plan, it is a Plan of Action and Milestones, and unimplemented requirements subtract from your SPRS score no matter how well they are written up. CMMC platform vs consultant vs doing it in house maps the market properly.
Compare the options that fit your situation
| The decision in front of you | Where to go next |
|---|---|
| Which Microsoft tenant your data is allowed to live in | GCC High vs GCC vs Commercial Microsoft 365 for CUI |
| Whether to shrink the boundary or fix everything | Enclave vs full remediation |
| Whether an encrypted overlay can replace a government tenant | PreVeil vs GCC High for small defense contractors |
| Who should do the work: software, an outside firm, or your own team | CMMC platform vs consultant vs doing it in house |
| Which credential actually means something when you hire | RPO vs C3PAO vs independent consultant |
| Which product to buy if you have decided to buy software | CMMC compliance software for small manufacturers |
| Where to host a CUI workload you build yourself | Azure Government vs AWS GovCloud for CUI workloads |
| Whether to take laptops out of scope entirely | Virtual desktop enclave vs managed laptops |
| Whether the free government tooling is enough for you | Free NIST 800-171 tools vs paid platforms |
| What building it yourself really costs over three years | Build vs buy: what an in house enclave actually costs |
How to compare CMMC compliance options without wasting a quarter
Give this to whoever owns the decision and ask for it back in three weeks.
- Inventory the data before you price anything. Where controlled information actually is today, who put it there, and how it arrives. Every quote you request is guesswork until this exists.
- Decide the boundary. Write down which systems will hold controlled information going forward and which will not. This is a management decision, not an IT decision, and it is the largest cost lever available to you.
- Price three architectures against the same boundary, not against each other’s marketing. Include year one and years two and three, because subscription models and build models cross over somewhere around month eighteen.
- Ask every vendor the same four questions. Which of the 110 requirements do you cover, in writing. What do I still own. What happens in an incident and who reports to DIBNet within 72 hours. What does the exit look like if I leave you.
- Name the internal owner before you sign. Not the vendor. Yours.
Frequently asked
Questions about this topic
Which CMMC compliance options are cheapest for a small manufacturer?
Does the Phase 2 suspension mean we can stop spending?
Is a compliance platform the same thing as an enclave?
How much should we budget in total?
Can we change our mind later?
Who inside the company should own this decision?
Keep reading
More in Comparisons & Alternatives
- Azure Government vs AWS GovCloud for CUI Workloads →
- Build vs Buy Enclave: What In House Actually Costs →
- CMMC Compliance Software for Small Manufacturers →
- CMMC Platform vs Consultant vs Doing It In House →
- Enclave vs Full Remediation: Which CMMC Path Fits →
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps →
- GCC High vs GCC vs Commercial Microsoft 365 for CUI →
- PreVeil vs GCC High for Small Defense Contractors →
- RPO vs C3PAO vs Consultant: Who Does What in CMMC →
- Virtual Desktop Enclave vs Managed Laptops for CUI →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5