Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

CMMC Compliance Options: Enclave, Environment or Service

Every set of CMMC compliance options eventually reduces to one question a finance leader can answer: are you paying to secure the whole company, or paying to secure a small part of it and keep the rest out of the way. That decision is worth more money than any product you will buy afterward, and most companies make it by accident.

This page compares the three paths side by side with real numbers. It exists because the market sells you tools before anyone helps you choose an architecture, and a tool bought before the architecture is decided is a tool you throw away.

What the July 2026 suspension changed about your CMMC compliance options

On July 13, 2026 the Department of War suspended the CMMC Phase 2 requirements that were due to take effect on November 10, 2026, and stood up a reform task force. Read the second half of that sentence carefully before you cancel anything.

ObligationStatus today
Third party certification as a condition of awardSuspended
DFARS 252.204-7012 safeguarding and 72 hour incident reportingIn force, unchanged
NIST SP 800-171 Revision 2, all 110 requirementsIn force, unchanged
Current SPRS score and annual senior official affirmationIn force, unchanged
Phase 1 self assessment requirementsIn force. The Department stated these remain firmly in place
Government led DIBCAC assessmentsActive, and they can arrive without much notice
C3PAO assessmentsStill authorized and still being conducted, now voluntary rather than compelled

The audit stopped being mandatory. The security requirement did not move at all. So the engineering and budget decisions on this page still matter, and the deadline pressure that used to force bad, fast choices is gone. That is a good year to make the architecture decision properly.

The three CMMC compliance options, priced honestly

Every credible approach is a variation on one of these three CMMC compliance options. The differences in cost between them are not marginal.

EnclaveFull environmentManaged service
What is in scopeA defined boundary holding controlled information, plus the people inside itEvery system, every laptop, every userWhatever boundary the provider operates, plus your own residual assets
Who it suitsDefense is a minority of revenue, and a handful of people touch controlled dataDefense is most of your revenue and controlled data is everywhereYou have no internal security staff and no appetite to build one
Typical published rangeHosted micro enclaves run roughly $400 to $1,700 per month for a small group. Single seat products start near $400 per monthLicensing alone is the smaller half. Every endpoint becomes an assessed assetMarket reporting puts fully managed enclaves around $300 to $400 per user per month
Where it goes wrongData leaks out of the boundary and the scope quietly becomes the whole company againCost and calendar both run away, and nobody can say when it endsYou assume the provider owns the obligation. They do not

Those enclave and managed figures come from market reporting and vendor published rates rather than from a government source, so treat them as planning ranges and get quotes. The point is the order of magnitude, and the order of magnitude is the whole argument.

The number the government publishes, and the number it leaves out

The Department published per entity cost estimates in the CMMC rulemaking. For a small entity, over a three year cycle, it estimated roughly $104,670 for a Level 2 certification assessment and roughly $37,196 for a Level 2 self assessment. A Level 1 self assessment came in near $5,977.

Now the part that matters more than any of those figures. The analysis explicitly assumes the cost of implementing the 110 requirements has already been spent, on the reasoning that DFARS 252.204-7012 has required it since 2017. So the published number is the cost of proving compliance. It is not the cost of becoming compliant, and for most of the industrial base the second number is far larger than the first.

If a board paper quotes the government estimate as the project budget, the project is already underfunded. Build the implementation line separately and defend it separately. How to Budget for CMMC covers the structure.

Four questions that pick the path for you

  1. How many people genuinely need to touch controlled information? Count names, not departments. In most small manufacturers the honest answer is between three and twelve, and that answer alone usually decides the architecture.
  2. Is any of it export controlled? ITAR and export controlled technical data restrict access to United States persons, which is a personnel and residency question rather than an encryption question. It narrows your product choices sharply. See GCC High vs GCC vs Commercial Microsoft 365 for CUI.
  3. Can the work actually be done inside a boundary? A quoting team living in email and a document library can. An engineering group pushing models to machines on the shop floor often cannot, and that changes the answer. Enclave vs full remediation works through the test.
  4. Do you have anyone to run it on Monday morning? Controls are bought once and operated forever. If nobody owns logging review, patching and incident response by name, you are buying a managed service whether you call it that or not.

The distinction the market deliberately blurs

There are two entirely different things being sold as CMMC compliance options, and conflating them is the most expensive mistake in this category.

Documentation tooling produces a System Security Plan, a Plan of Action and Milestones, policies and a score. It changes your paperwork. It changes nothing about your actual security posture.

An environment is a compliant place for controlled information to live. It changes your posture. It does not write your documentation, and it covers nothing outside its own boundary.

Most small manufacturers need one of each, or a provider who bundles both. Buying one and believing you are finished is the single most common failure in this market. A beautifully generated plan describing controls you have not implemented is not a plan, it is a Plan of Action and Milestones, and unimplemented requirements subtract from your SPRS score no matter how well they are written up. CMMC platform vs consultant vs doing it in house maps the market properly.

Compare the options that fit your situation

The decision in front of youWhere to go next
Which Microsoft tenant your data is allowed to live inGCC High vs GCC vs Commercial Microsoft 365 for CUI
Whether to shrink the boundary or fix everythingEnclave vs full remediation
Whether an encrypted overlay can replace a government tenantPreVeil vs GCC High for small defense contractors
Who should do the work: software, an outside firm, or your own teamCMMC platform vs consultant vs doing it in house
Which credential actually means something when you hireRPO vs C3PAO vs independent consultant
Which product to buy if you have decided to buy softwareCMMC compliance software for small manufacturers
Where to host a CUI workload you build yourselfAzure Government vs AWS GovCloud for CUI workloads
Whether to take laptops out of scope entirelyVirtual desktop enclave vs managed laptops
Whether the free government tooling is enough for youFree NIST 800-171 tools vs paid platforms
What building it yourself really costs over three yearsBuild vs buy: what an in house enclave actually costs

How to compare CMMC compliance options without wasting a quarter

Give this to whoever owns the decision and ask for it back in three weeks.

  1. Inventory the data before you price anything. Where controlled information actually is today, who put it there, and how it arrives. Every quote you request is guesswork until this exists.
  2. Decide the boundary. Write down which systems will hold controlled information going forward and which will not. This is a management decision, not an IT decision, and it is the largest cost lever available to you.
  3. Price three architectures against the same boundary, not against each other’s marketing. Include year one and years two and three, because subscription models and build models cross over somewhere around month eighteen.
  4. Ask every vendor the same four questions. Which of the 110 requirements do you cover, in writing. What do I still own. What happens in an incident and who reports to DIBNet within 72 hours. What does the exit look like if I leave you.
  5. Name the internal owner before you sign. Not the vendor. Yours.

Frequently asked

Questions about this topic

Which CMMC compliance options are cheapest for a small manufacturer?
A narrow enclave covering only the people who genuinely handle controlled information is almost always the lowest total cost, because cost scales with the number of assets inside the assessment boundary rather than with headcount. The cheapest option on a per seat basis is frequently the most expensive overall once you count every endpoint it drags into scope.
Does the Phase 2 suspension mean we can stop spending?
No. The suspension paused third party certification as a condition of award. DFARS 252.204-7012, NIST SP 800-171, the SPRS score and the annual affirmation are all still in force, and government led assessments continue. What changed is the deadline, not the obligation.
Is a compliance platform the same thing as an enclave?
No, and this is the most costly confusion in the market. A platform generates documentation and tracks your position. An enclave is a compliant place to put controlled information. They solve different halves of the problem and most companies need both.
How much should we budget in total?
Treat the published government estimate of roughly $104,670 for a small entity Level 2 certification as the cost of proving compliance over three years, then budget the implementation separately, because the government analysis assumes implementation is already done. Depending on your starting point the implementation line is often the larger of the two.
Can we change our mind later?
Moving from an enclave to a full environment is straightforward. Moving the other way is painful, because controlled information will have spread across systems and every copy has to be found and removed. If you are genuinely undecided, start narrow. Narrow is the reversible choice.
Who inside the company should own this decision?
Someone with authority over both budget and process, which usually means the chief operating officer or the chief financial officer rather than the IT manager. The largest cost lever is scope, and scope is decided by telling people where they may and may not do certain work. That is a management instruction, not a configuration setting.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents