Everyone’s selling the CMMC tax. Here’s who actually does the work.

Three of these were built for SOC 2 and had CMMC added. Garde1 was built for CMMC and nothing else: CUI scope, SPRS, POA&M eligibility and all 320 objectives are the product, not a framework in a dropdown. Four routes, one table, every number from the vendor’s own page, a published range, or a quote made to us.

“During the roundtable, one participant aptly described this ecosystem as a “CMMC tax.””

Comment letter to the Department of War on reforming CMMC · SBA Office of Advocacy, August 2026

Who does the work, what it costs, and who’s on the hook when you sign.

Hire a consultantStep by stepBuy compliance softwareVanta · Secureframe · Drata · DelveDo it yourselfFutureFeed · PreVeilHow it works
Who does the workA firm, by the hour. They leave. The binder stays.You. You scope, you write, you fix. Then you hire an RPO anyway.You. All 320 statements. Then you grade your own homework.The product, from your own tenant. You review. You approve.
What it costs, first year$50K–$200K+, and the meter keeps running.$20K to $75K+ by quote. Plus the firm. Sometimes plus a new tenant.$2,196 to $5,400. Plus whoever ends up doing the work.$23,988, published. Then the C3PAO and the Microsoft or Google you already pay for.
Who vouches for your scoreThem, grading their own work.You, ticking boxes. The tests check the vendor’s defaults, not your policy.You, marking yourself Met.The evidence. Missing evidence is Not Met, and nobody can override it.
After you passThe engagement ends. The binder starts drifting that day.Tests keep failing. Fixing them is yours.You keep the SSP current by hand. Forever.Garde1 keeps watching, and only pulls you back when something breaks.

Whichever route, the score is signed under the False Claims Act. The Department of Justice has been collecting.

Every route ends with a senior official affirming a NIST SP 800-171 score in SPRS. A self-marked “met” and a template SSP are what these settlements are made of.

SettlementWhat the release saysSource
Raytheon and Nightwing$8.4 millionAlleged to have “failed to develop and implement a system security plan.” The whistleblower received $1,512,000.Press release, U.S. Department of Justice, May 2025
MORSECORP$4.6 millionSubmitted a score of 104. A consultant later found it was actually -142. The score was not corrected until after a subpoena.Press release, U.S. Department of Justice, March 2025
Honeywell Aerospace$2,042,518Allegedly “failing to comply with cybersecurity requirements specified in NIST SP 800-171” on one network from April 2020 through December 2023. The whistleblower received $375,823.Press release, U.S. Department of Justice, September 2026
Aero Turbine and Gallant Capital$1.75 millionA contractor and its private-equity owner. They “provided the government with multiple written self-disclosures” and still paid.Press release, U.S. Department of Justice, July 2025
Georgia Tech Research Corporation$875,000A summary score of 98 “premised on a ‘fictitious’ or ‘virtual’ environment.”Press release, U.S. Department of Justice, September 2025
LOGZONE$507,144A DCMA assessment produced “a score of -170, at the low end of the possible score range of -203 to 110.”Press release, U.S. Department of Justice, June 2026
Demo

See your SPRS score this week.

Give us 30 minutes. We'll show you where you stand against all 110 requirements, what's missing, and what it costs to close the gap, using your own environment instead of a slide deck.

Only handle FCI? See Level 1, $150 a monthOr start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE
readiness · sample tenantlive
61%
Ready
Pass67
Partial5
Fail19
None19
SPRS SCORE
39
CONNECTED
3
CADENCE
4 days a week
TREND
↑ improving