1. CUI footprint
Every additional user, endpoint, mailbox, file repository and service that handles CUI can expand what needs to be assessed and protected.
CMMC Level 2 readiness cost depends on which systems handle CUI, how much of NIST SP 800-171 is already implemented, whether supporting evidence exists, and which assessment type the contract requires. A useful estimate therefore starts by defining the CUI boundary and identifying the implementation gaps inside it.
The Department's current implementation is paused in Phase 1, where Level 1 Self and Level 2 Self may be required. Level 2 C3PAO remains in the regulatory model, but mandatory Phase II third-party requirements are suspended. Budgeting should therefore start with the applicable solicitation, contract or prime flow-down rather than an assumed certification path.
Every additional user, endpoint, mailbox, file repository and service that handles CUI can expand what needs to be assessed and protected.
Systems that provide security functions to the CMMC environment can be in scope even if they do not directly store CUI. Scoping only the obvious CUI systems can understate the boundary.
An organization with MFA, logging, configuration management, incident response, training and disciplined administration already operating generally requires less remediation than one beginning with policy documents alone.
A correct SSP, credible POA&M where allowed, asset inventory, network diagrams, procedures and final evidence all require effort. The cost increases when the environment and implementation history are poorly documented.
Logging, monitoring, vulnerability management, awareness, incident response and account governance continue after readiness. Operating cost should be included in the implementation plan.
Level 1 Self, Level 2 Self and Level 2 C3PAO are different assessment types. Current Phase 1 procurement policy centers the self-assessment paths; the contract determines which requirement applies.
If CUI flows through ordinary corporate email, shared drives and general-purpose endpoints, the environment can become broader than necessary. Where workflows permit, a secure CUI enclave can confine CUI handling to a smaller set of users and systems. That can reduce the number of assets requiring CMMC-specific implementation and evidence and can therefore reduce project and ongoing operating cost.
PreVeil is one option for that architecture. It provides end-to-end encrypted email and file sharing designed to run alongside existing Microsoft 365 or Google Workspace workflows. PreVeil publishes FedRAMP Moderate Equivalency and FIPS 140-3-validated cryptography information. Cyberneza can scope, deploy and document a PreVeil enclave when that architecture fits the contract and workflow.
Important: an enclave does not automatically exclude every surrounding system. CMMC Level 2 scoping under 32 CFR 170.19 includes defined asset categories such as Security Protection Assets and has specific rules for external service providers. The objective is to minimize unnecessary scope while accurately documenting the systems that remain in scope.
Cyberneza uses milestone-based, fixed-fee work where the scope can be defined. We establish the boundary, assess implementation against the applicable requirements, and then scope remediation based on the gaps that must be closed.
Use this engagement when the primary question is which systems, users and services belong in the CMMC environment.
Use this engagement when the boundary is known but implementation against NIST SP 800-171 is uncertain.
Implementation is scoped after the gaps are known, with technical and operational remediation separated from assessment preparation.
Send us the contract requirement, the users and systems that handle CUI, and your current security architecture. Cyberneza can identify the preliminary boundary and the implementation, documentation, evidence and operating workstreams that drive cost.