Scoping out Costs of Solution Archietecture
For many small entrepreneurs the cost of CMMC drives your scope. You may engineer a solution that allows you to buy inherited solutions so you do not have to build every security control yourself. Microsoft GCCH will always have lower lifetime costs, but not every contractor can live by five year plans.
This is the third post in the series on the soloprenuer and CMMC. You can find the first post here and the second post here.
You may live TO by TO even after winning a spot on an IDIQ. Maybe you make it from RFP response to response and need to survive lean times between awards. Paying for the costly migration of a Microsoft tenant may not be in the cards until after award. So you utilize a FedRAMP Fileshare until then.
No matter what the interwebz say, no one way exists to engineer a NIST-SP-800-171 environment for a single employee company. You have to right fit your solution to your business needs.
What do I actually need to buy?
A tiny contractor does not need one product for every NIST SP 800-171 requirement. Really the first question you need to ask, the most important thing to interview is Time and not money. How much time do you want to spend on IT, and does this have an impact on time available for Direct work?
Really try to see if your Prime will bring you in scope and provide you a device, but when they say no, four practical strategies emerge:
-
Keep Microsoft 365 Commercial and add a dedicated CUI repository.
-
Build a Microsoft 365 GCC High environment.
-
Rent a fully managed VDI enclave.
-
Use an MSP to take recurring security work off your plate.
The products may change, but the business question will not.
Cheap does not simply mean the smallest monthly bill.
A founder needs to look at the first-year check, five-year cost, implementation labor, inherited controls, and the amount of time the company must spend running the environment.
First, Set a Common Budgeting Baseline
We need an apples-to-apples starting point before comparing CUI solutions.
For this article, every architecture except GCC High starts with the same commercial Microsoft baseline:
$32 per user per month for Microsoft 365 Business Premium/E3 plus the P2 add-on.
That gives us:
- $384 per user per year
- $1,920 per year for five users
This baseline gives the company the Microsoft identity, endpoint-management, and Defender capabilities that support the managed endpoint. Defender handles vulnerability management, and Huntress remains the monitoring/SIEM platform.
You might be a Google Workspace customer, and of so just skip ahead to the Managed VDI section. Explaining the difference in what a Google versus Microsoft stack brings goes way beyond the scope of this post. Google shops will need a managed VDI.
The important budgeting rule looks like this:
File sharing and VDI add to the commercial Microsoft baseline. GCC High replaces the commercial Microsoft baseline.
We do not buy Business Premium/E3 + P2 and then stack equivalent GCC High licensing on top of it for the same CUI users. A one person company would rarely need a CUI enclave. You would not maintain two tenants unless you made significant commercial money overseas.
Strategy One: Keep Commercial Microsoft 365 and Add a CUI Repository
You have all seen the commercials. Heard the channel sales pitch. Building a CUI enclave, meaning logical boundaries, around a FedRAMP High File share is quite common. Many business owners will pay more to keep Microsoft 365 Commercial for ordinary business and FCI while placing CUI in a separate FedRAMP High file-sharing service. This introduces less change to how business already gets done
For this example, we budget $12,000 per year for a product-agnostic FedRAMP High file-sharing service. We also assume that price includes five CUI users.
You always need more than one user, even as a single user company.
The business still controls the laptop, approves access, reviews vulnerabilities, handles remediation, manages CUI, and keeps evidence. The cloud provider handles the infrastructure inside the CUI repository.
For one user let us assume:
$12,000 file share + $384 Microsoft baseline = $12,384 per year
| One-User File-Share Model | Cost |
|---|---|
| Commercial M365 + P2 baseline | $384.00/year |
| FedRAMP High file share | $12,000.00/year |
| Annual recurring cost | $12,384.00 |
| Five-year cost | $61,920.00 |
This architecture has one easy rule:
CUI goes in the CUI repository. Commercial business information stays in commercial Microsoft 365.
For a tiny contractor, that clarity has real value. Many contractors also want to pay less up front and might start with a file-share and then move to GCCH once they win award. You gamble with less, and hope you win the award.
Strategy Two: Replace the Commercial Stack With GCC High
The second strategy moves the CUI users into Microsoft 365 GCC High. GCC High can provide CUI email, SharePoint, OneDrive, Teams, identity, device management, and related security capabilities inside one Microsoft government environment. Defender still handles endpoint vulnerability management, and Huntress still supports monitoring.
The key budget difference matters:
GCC High replaces the $32-per-user commercial Microsoft baseline for those CUI users.
We do not add $384 per user to the GCC High number.
We also need to remember that one employee does not mean one GCC High identity. Our one-person company needs a licensed daily-use account, a separate licensed privileged-administrator account, and two cloud-only emergency-access identities. The architecture comparison uses this same separation because the founder should not use the account that reads email and browses the web to administer the entire tenant.
| Identity | Purpose | Daily Use? |
|---|---|---|
| Daily user | Email, Teams, SharePoint, OneDrive, and CUI work | Yes |
| Privileged administrator | Tenant and security administration | No |
| Emergency access 1 | Tenant recovery | No |
| Emergency access 2 | Tenant recovery | No |
Our current planning model puts that GCC High stack at approximately $7,871.88 per year for the one-person environment.
Then we have to build it.
GCC High Has a First-Year Problem
Let us assume a qualified Microsoft provider charges an average of $150 per hour.
A greenfield GCC High deployment requires about 100 hours of engineering. The provider needs to configure the tenant, identities, administrative accounts, device management, Defender, Conditional Access, logging, SharePoint, OneDrive, security settings, testing, and documentation.
That creates a $15,000 setup project.
| One-User Greenfield GCC High | Cost |
|---|---|
| Annual GCC High stack | $7,871.88 |
| 100-hour implementation at $150/hour | $15,000.00 |
| Year-one cost | $22,871.88 |
| Five-year cost | $54,359.40 |
GCC High costs less over five years than the dedicated file-share model, but the founder has to absorb a much larger first-year bill.
That creates the cash-flow problem.
Migrating an Existing Tenant Costs Even More Up Front
A founder who already runs a commercial Microsoft tenant faces a larger project. The provider now needs to build GCC High and move identities, mail, files, permissions, devices, DNS, and configurations.
We will budget 150 hours for that work.
At $150 per hour, the migration costs $22,500.
If you know how to all the Microsoft stuff you can knock down these costs, but it will still take time. If you are in between awards time may not be scarce, if you have Direct hours to bill your time gets expensive.
| One-User GCC High Migration | Cost |
|---|---|
| Annual GCC High stack | $7,871.88 |
| 150-hour migration at $150/hour | $22,500.00 |
| Year-one cost | $30,371.88 |
| Five-year cost | $61,859.40 |
Notice what happened.
The five-year cost of migrating into GCC High gets close to commercial Microsoft and adding the $12,000 file share. Two to Five users, if you can get an affordable file-share package is the sweet spot.
The business decision now depends much more on cash flow, workflow, and how much infrastructure the founder wants to manage.
Strategy Three: Rent a Managed CUI Workspace
A fully managed VDI enclave takes another path.
A service such as CuickTrac, ATX, or Midwatch moves much of the technical operation into the managed enclave. You get access to a VDI solution that keeps your endpoint out of scope. Suddenly more of your security requirements get inherited. This is as close as turn key getd
For this comparison we will assume three users. Just like the Fileshare and M365 a single person company needs multiple identities to fill roles of least privilege.
For this compliance story we will use $325 per user per month, with a three-user minimum, plus a $5,000 one-time setup fee.
The commercial Microsoft baseline still applies because this model does not replace the company’s Business Premium/E3 + P2 environment.You still need to pay for your commercial side of the business.
3 × $325 = $975 per month for Managed Enclave
Then we add our one-user Microsoft baseline:
$975 + $32 = $1,007 per month
| One-User Model | Cost |
|---|---|
| Commercial M365 + P2 baseline | $384.00/year |
| Three-seat minimum | $11,700.00/year |
| Annual recurring cost | $12,084.00 |
| One-time setup | $5,000.00 |
| Year-one cost | $17,084.00 |
| Five-year cost | $65,420.00 |
Now the fully managed VDI model sits in an interesting position.
It costs less in year one than either GCC High approach, and its five-year cost stays reasonably close to both the dedicated file share and a GCC High migration.
The founder pays a premium over greenfield GCC High but buys much more operational help.
Compare the One-Person Company
| One-Person Architecture | Year One | Five Years |
|---|---|---|
| Commercial M365 + P2 + FedRAMP High file share | $12,384.00 | $61,920.00 |
| Cuick Trac + Commercial M365 + P2 | $17,084.00 | $65,420.00 |
| GCC High — greenfield | $22,871.88 | $54,359.40 |
| GCC High — migrate existing tenant | $30,371.88 | $61,859.40 |
The dedicated file share creates the lowest first-year cost.
Greenfield GCC High creates the lowest five-year cost.
Managed Enclaves have the highest lifetime cost but the lowest level of effort.
Migrating into GCC High costs almost exactly the same over five years as the dedicated file-share model, but the founder has to fund much more of that cost during year one.
None of those choices are right or wrong. They solve different problems.
Scale Changes the Answer
Now let the company grow from one CUI user to five.
Our commercial Microsoft baseline follows the number of users:
5 × $32 × 12 = $1,920 per year
The file-share service still costs $12,000 because our planning assumption includes five licenses.
That gives the five-user file-share model a major scaling advantage.
| Five-User File-Share Model | Cost |
|---|---|
| Five Commercial M365 + P2 users | $1,920.00/year |
| FedRAMP High file share with five included users | $12,000.00/year |
| Annual recurring cost | $13,920.00 |
| Five-year cost | $69,600.00 |
At one user, the company pays for file-sharing capacity it does not use. At five users, the company finally uses all five included licenses while the $12,000 repository cost stays flat.
Five Users in GCC High
A five-person GCC High company also needs more than five identities.
Our design uses five licensed daily-use accounts, one separate licensed privileged-administrator account, and two cloud-only emergency-access identities.
That gives the company eight identities, with six licensed identities in our planning model.
The current planning figure puts the five-user GCC High stack at approximately $12,335.88 per year.
GCC High still replaces the commercial Microsoft baseline. We do not add another $1,920 for Business Premium/E3 + P2.
| Five-User GCC High | Year One | Five Years |
|---|---|---|
| Greenfield — 100-hour setup | $27,335.88 | $76,679.40 |
| Migration — 150 hours | $34,835.88 | $84,179.40 |
GCC High now loses the five-year price advantage it had at one user because our file-share service includes five seats for the same $12,000 annual price. File-share pricing model scales unusually well from one to five users.
Five Users in Managed Enclave
Managed Enclaves scale differently because they charge per user.
Using our earlier estimage Five users cost:
5 × $325 × 12 = $19,500 per year
We then add the five-user commercial Microsoft baseline:
$19,500 + $1,920 = $21,420 per year
| Five-User Cuick Trac Model | Cost |
|---|---|
| Five Commercial M365 + P2 users | $1,920.00/year |
| Five users | $19,500.00/year |
| Annual recurring cost | $21,420.00 |
| One-time setup | $5,000.00 |
| Year-one cost | $26,420.00 |
| Five-year cost | $112,100.00 |
The managed VDI looks much more attractive at one user than at five because the three-seat minimum already forces the tiny company to buy unused capacity.
Once the company reaches five people, every new VDI user increases recurring cost.
The Five-User Comparison
| Five-User Architecture | Year One | Five Years |
|---|---|---|
| Commercial M365 + P2 + FedRAMP High file share | $13,920.00 | $69,600.00 |
| Cuick Trac + Commercial M365 + P2 | $26,420.00 | $112,100.00 |
| GCC High — greenfield | $27,335.88 | $76,679.40 |
| GCC High — migrate existing tenant | $34,835.88 | $84,179.40 |
The file-share model wins the five-user price comparison because the $12,000 subscription already includes five CUI users.GCC High costs more over five years at this size, but it provides a much broader collaboration environment. The company gains CUI email, Teams, SharePoint, OneDrive, identity, device management, and other services under one ecosystem.
Managed Enclaves cost substantially more at five users, but price does not tell the whole story. The company pays the provider to operate much more of the environment. A founder who does not want to build or maintain the technical stack may still value that trade.
What Are You Really Buying?
The three architectures sell different kinds of inheritance.
With the FedRAMP High file-share model, you buy a controlled place for CUI while keeping the commercial Microsoft security stack.
With GCC High, the founder replaces the commercial Microsoft stack with a government cloud environment and pays a substantial engineering cost to build it correctly.
With *Managed Enclave, the founder keeps the commercial Microsoft baseline and pays a managed-enclave provider to take much more responsibility for the CUI workspace.
The cheapest choice depends on the size of the company and the kind of inheritance the founder values.
Strategy Four: Buy Back the Founder’s Time
An MSP can support the commercial Microsoft and GCC High models by reviewing Defender findings, monitoring Huntress, coordinating remediation, managing endpoint configuration, reviewing accounts, gathering evidence, and preparing reports.
The founder still owns the CMMC program, but the founder does not need to spend every Friday staring at security dashboards.
That time has value.
If a founder spends five hours each month managing cybersecurity, the company loses 60 hours per year. At a $200 billable rate, that represents $12,000 of potential revenue.
A spreadsheet that ignores the founder’s time does not show the true cost of the architecture.
Inheritance Does Not Make Responsibility Disappear
Microsoft can operate the cloud. A FedRAMP provider can secure the repository. Defender can identify vulnerabilities. Huntress can monitor security events. CuickTrac can operate a managed enclave. An MSP can review alerts.
The founder still approves users, decides who may access CUI, maintains the system boundary, manages company procedures, reviews provider responsibilities, makes risk decisions, and keeps the SSP accurate.
That gives us the real lesson behind inheritance:
You do not need to build every security control yourself. You need to understand which controls you own and which controls you bought from somebody else.
So What Should Our Founder Choose?
For a one-person company, the dedicated file-share architecture provides the lowest first-year cost, while greenfield GCC High produces the lowest five-year cost under these assumptions.
A managed VDI enclave such as CuickTrac lands between them. It costs a little more over five years than the file-share model but can dramatically reduce the amount of technical work the founder needs to perform.
Migration changes the GCC High story. Once a company already has a commercial Microsoft tenant, the 150-hour migration makes GCC High and the file-share model almost identical over five years. The founder then needs to decide whether consolidation justifies the larger first-year bill.
At five users, the dedicated file share becomes the least expensive architecture because the $12,000 subscription already includes all five users. GCC High costs more but offers broader capabilities, while managed VDI costs the most because every additional seat increases the subscription.
The goal is not to buy the most cybersecurity products or chase the cheapest advertised license.
Buy the architecture that leaves you with the fewest security problems you personally have to solve at a price your business can a afford.
What We Just Built for the SSP
We now know where CUI lives, how users reach it, which services manage identity and endpoints, how the company handles vulnerability management and monitoring, which providers operate technical controls, and which responsibilities remain with the founder.
Next: The One-Laptop Security Department
In the next post, we stop shopping and start doing. We will look at what you need to do every day, every week, every month, and every time something changes.
That is where security controls stop looking like product features and start becoming procedures.