The Architecture Decision Hiding Under CMMC’s Price Tag
In the coming weeks, the CMMC Reform Task Force delivers its recommendations to the Department of War’s CIO. The charge she gave it in July was blunt: replace “prohibitive, third-party compliance models with scalable, realistic security measures,” because on CMMC’s cost to small business, “the math just simply doesn’t math.”
She’s right about the math. So before the report lands, we want to put one idea in front of the Task Force, the program offices, and the members and staff on the Hill who will judge what it recommends:
CMMC’s cost problem was decided by architecture long before it was decided by pricing. Fix the pricing without understanding the architecture, and the market will drift right back.
Two weeks ago we shared a milestone that provoked this argument: more than 115 small businesses, CMMC Level 2 certified on our shared enclave, verified by eleven different independent C3PAOs, at $299 per user per month. The question we heard most in response was some version of how is that even possible? In this market, “affordable” usually means something got cut
Here is the honest answer. Part of it is choices we made. But the biggest part is a choice someone else made, fifteen years ago.
More than 115 small businesses are CMMC Level 2 certified on ATX’s secure enclave, CMMC Space.
A breach, and what came after
In late 2009, Google discovered it had been breached by Chinese state actors. What matters for the DIB today is not the breach but the response. Rather than bolt a “secure tier” onto what already existed, Google rebuilt its security architecture from the ground up: no trusted internal network, every user and device verified on every access, encryption everywhere. Google published that model years later under the name BeyondCorp. Most of the world now calls it zero trust: the same architecture the federal government itself would eventually mandate across every agency.
The consequence, years later, is one of the most underappreciated facts in the defense market. Google Workspace (the same Gmail, Drive, and Docs your dry cleaner uses) holds a FedRAMP High authorization from the Joint Authorization Board and a DoD Impact Level 4 provisional authorization for CUI. Not a separate government edition of the product. The product. The environment built for billions of consumers and the environment the government trusts for its most sensitive unclassified data are the same environment, because the security was built into the foundation instead of sold as an upgrade.
There is no separate “govcloud” with Google, because there doesn’t need to be one.
The govcloud tax
Now consider the path most of the DIB has been steered down for the past seven years. Under that model, the commercial platform is not considered sufficient for government data, so a parallel government enclave exists: separately built, separately licensed, separately supported, and priced accordingly. The “compliant” version of the same productivity suite costs multiples of the commercial version before a single additional security control is implemented, before a single consultant is hired, before the first assessment is scheduled.
Call it the govcloud tax. It isn’t a security control. It’s a licensing structure, and it lands hardest on exactly the companies the Department’s own reform campaign says are being priced out: the 10-person machine shop, the 5-person engineering firm, the small business making less than $100,000 a year for whom, as one of the Department’s own posts put it, CMMC costs “are not feasible.”
When we built CMMC Space, we didn’t make compliance affordable by cutting scope. The enclave covers 307 of 320 assessment objectives and runs on Google Cloud’s IL5 Assured Workloads for the ITAR and export-controlled work our clients carry. Independent assessors have certified more than 115 of our clients at a 100% pass rate. We made it affordable by refusing to pass through a tax that the underlying architecture had already made unnecessary. Security built in at the foundation doesn’t need to be bought again at a premium.
Independent assessors have certified more than 115 of our clients at a 100% pass rate. We made it affordable by refusing to pass through a tax that the underlying architecture had already made unnecessary.
But my prime is Microsoft
The most common objection is interoperability, and it’s legitimate. The DIB runs heavily on Microsoft, and no small business can afford to be unreachable by its prime or its government customer.
So we engineered for both worlds. CMMC Space clients get web-based Microsoft 365 GCC High for under $200 per user per year so they can join the Teams call, open the Office attachment, and work with whoever the mission requires, while their CUI lives inside an environment with commercial-grade economics on infrastructure rebuilt, from the ground up, to survive nation-state attack.
This is not a Google-versus-Microsoft argument. It’s an argument about what happens when a platform’s security story begins with “we were attacked and rebuilt everything” instead of “we sell a more secure version at a higher tier.” One produces an affordability curve small businesses can live on. The other produces the market the Task Force was chartered to fix.
Three things the Task Force should carry into its report
Affordability is an architecture problem before it is a pricing problem.
No subsidy, waiver, or trimmed control set can fully compensate for a cost structure in which the compliant baseline is priced at a premium by design. Whatever the report recommends on price (we have argued for hard affordability ceilings and fixed-fee assessments) it should reward providers whose foundations make compliance inherently cheap, and it should say so explicitly.
Stop treating expensive as a proxy for secure.
For seven years, the unspoken assumption in this market has been that a six-figure compliance bill signals seriousness. More than 115 certifications at a fraction of that price, verified by eleven different independent assessment organizations, say otherwise. Assessed, third-party, auditable outcomes are the only honest measure, and the Department should admit and retain solutions on that basis alone.
The hard engineering is already done, so recognize it.
FedRAMP-authorized commercial infrastructure, shared-responsibility enclaves, and control inheritance are not future concepts. They exist, they’re certified, and they are protecting CUI today on the Department’s highest-priority programs, including Golden Dome for America. The Task Force does not need to invent an affordable model. It needs to formally recognize the one already running and let the cost curve follow.
The requirement to protect defense information isn’t going away, because the theft isn’t going away. The breach that started this story proved that a long time ago. The only question is whether the DIB pays for security once, in the architecture, or forever, in the licensing.
The report is due in the coming weeks. We’d welcome the chance to walk any Task Force member, program office, or congressional staff through the numbers before it lands.