{
  "version": "https://jsonfeed.org/version/1",
  "title": "soloprenuer on J. Gregory McVerry",
  "icon": "https://cdn.micro.blog/DoctorMac/avatar.jpg",
  "home_page_url": "https://www.drmacscybersecuritybrief.com/",
  "feed_url": "https://www.drmacscybersecuritybrief.com/feed.json",
  "items": [
      {
        "id": "http://doctormac.micro.blog/2026/08/29/the-onelaptop-security-department.html",
        "title": "The One-Laptop Security Department",
        "content_html": "<p>Hats. We all have many, but for a small business owner you wear them all at the same time. This includes running your Security Program (unless, and you should, farm work out to an External Service Provider).</p>\n<p>CMMC isn&rsquo;t a framework or a standard. You need a program. A one person company does not need an enterprise security department. Instead as a founder you need a routine. All programs need routines to run.</p>\n<h2 id=\"products-do-not-implement-controls\">Products Do Not Implement Controls</h2>\n<p>Microsoft Defender can find vulnerabilities. Huntress can monitor security events. Intune can enforce device settings. A FedRAMP provider can protect its cloud infrastructure. An MSP can review alerts.</p>\n<p>None of those tools decides how your company operates.</p>\n<p>Someone has to decide who gets access, which software the company allows, when vulnerabilities require action, what happens after an alert, and when a business change affects the CUI boundary. Wearing your security officer hat you need to turn technology into procedures.</p>\n<p>You do not need to create 20 Standard Operating Procedures. We want to identify the small number of things our founder must actually do and later write those actions directly into the SSP. Creating wave after wave of documentation will lead to problems for a small company. Document drift will cause you to fail assessments.</p>\n<p>Instead treat your system security plan as a top level document that describes your plan for system security. Almost like it is in the name, or something. You will need some procedures and artifacts documented, especially inventory. Basically write down things you need to do your business. Put all your security related stuff in your SSP.</p>\n<h2 id=\"think-in-rhythms-not-departments\">Think in Rhythms, Not Departments</h2>\n<p>A one-person security program works better when you divide the work into four buckets:</p>\n<ul>\n<li>things the technology does continuously,</li>\n<li>things to review on a schedule,</li>\n<li>things to do when something changes, and</li>\n<li>things to do when something goes wrong.</li>\n</ul>\n<p>That gives us a security department without creating a security department.</p>\n<h2 id=\"what-happens-automatically\">What Happens Automatically</h2>\n<p>Start with the work you already paid someone else to do.</p>\n<p>Defender continuously evaluates the managed Windows endpoint for vulnerabilities and malware. Intune checks whether the laptop still meets the required configuration. Huntress monitors for suspicious activity. The cloud providers generate authentication, access, and file activity logs.</p>\n<p>Do not recreate these technical processes manually. In your SSP explain that these requirements get inherited. You just need to make sure the services remain active.</p>\n<blockquote>\n<p><strong>Automation performs the check. The company remains responsible for the decision.</strong></p>\n</blockquote>\n<p>If Defender finds a vulnerability, Defender has done its job. The control still requires someone, you (or your MSP that you really should hire), to decide what to do about the finding.</p>\n<h2 id=\"the-weekly-security-routine\">The Weekly Security Routine</h2>\n<p>For a one-laptop company, start with one scheduled security review each week.</p>\n<p>Pick a day. Put it on the calendar. Treat it like bookkeeping.</p>\n<p>You or your MSP reviews (in our example architecture):</p>\n<ul>\n<li>Defender vulnerability findings,</li>\n<li>security alerts,</li>\n<li>Windows and application update status,</li>\n<li>Intune device compliance,</li>\n<li>failed or unusual sign-ins,</li>\n<li>Huntress alerts or reports, and</li>\n<li>outstanding remediation items.</li>\n</ul>\n<p>The review does not need to become a three-hour meeting with yourself. Most weeks, nothing interesting should happen. Feature, not bug.</p>\n<p>You check the dashboards, handle anything that requires action, and record that the review occurred. If an MSP performs the review, you review the MSP report and follows up on anything that requires a business decision.</p>\n<p>Now we have turned a large collection of NIST requirements into a simple habit:</p>\n<p><strong>Once a week, check the health of the one system that can touch CUI.</strong></p>\n<h2 id=\"vulnerability-management-means-running-more-than-a-scanner\">Vulnerability Management Means Running More Than a Scanner</h2>\n<p>Defender, using the E3+P2 license in our model, can continuously identify vulnerabilities on the laptop and supported applications. That solves the technical scanning problem.</p>\n<p>You still need to spell out a process in your SSP on how to handle a vulnerability when spotted.</p>\n<p>When Defender identifies a vulnerability, the founder or MSP reviews the finding, determines whether it affects the system, applies the update or mitigation, and verifies that the vulnerability no longer appears.</p>\n<p>The company also needs to react when a new vulnerability appears between scheduled reviews. A Microsoft advisory, CISA notice, Huntress alert, or software vendor warning may trigger another review.</p>\n<p>The procedure remains simple:</p>\n<p><strong>Find it. Decide what it means. Fix it. Verify the fix. Keep the record.</strong></p>\n<p>That sentence will eventually become much more valuable in our SSP than a paragraph that says, &ldquo;See Vulnerability Management Policy.&rdquo;</p>\n<p>You can write directly in the SSP how you Find it. Decide what it means. Fix it. Verify the fix. Keep the record. Keep your documentation lean.</p>\n<h2 id=\"access-control-with-one-user\">Access Control With One User</h2>\n<p>When a small business owner opens up NIST-SP-800-171 for the first time they get overwhelmed reading 3.1.1.</p>\n<p>Many access-control requirements sound complicated because large companies need to manage hundreds or thousands of accounts. You only have one authorized CUI user.</p>\n<p>The 1099 contractors do not receive CUI access. Their BYOD devices cannot access the CUI repository. Their Government-Furnished Equipment does not connect to company systems.</p>\n<p>What you need are multiple identities with your multiple hats.</p>\n<p>Access Control specifically calls for separation of duties and least privilege. Feels like an oxymoron for a one person company.</p>\n<p>Under NIST-SP-800-171 different identities can be defined by roles. Give yourself a normal account for daily work and a separate privileged account when administrative access becomes necessary.</p>\n<p>Microsoft already made you buy enough roles to do this. Just enforce this on your laptop. Have one user to change and update stuff, and your everyday user to do stuff.</p>\n<p>Then once a month review your accounts and access to confirm a bunch of new users weren&rsquo;t added or changes weren&rsquo;t made without approval.</p>\n<p>The review should take less than a half hour.</p>\n<p>You need to examine the user list, privileged accounts, and file-sharing permissions. You have a small scope, make sure to create small repeatable procedures.</p>\n<h2 id=\"change-control-and-the-single-computer\">Change Control and the Single Computer</h2>\n<p>When you read the configuration management requirements for approving changes a single person company can get frustrated. It seems like overkill.</p>\n<p>You do not need to form a Configuration Control Board every time you want to install something new.</p>\n<p>What you need in your procedures is something that ensures you:</p>\n<p><strong>Do not install or change software without considering the security impact first.</strong></p>\n<p>Before adding software, you need to document what the company needs, why the company needs it, whether the vendor supports it, whether it creates a new cloud connection, and whether it changes how CUI flows.</p>\n<p>You can make a form, send yourself an email, use a spreadsheet. Even paying for a ticketing system has value for a single person company. Having everything organized in one place with little effort can be worth the money.</p>\n<p>After installation, you verify stuff works, close the ticket.</p>\n<p>You must document:</p>\n<ul>\n<li>what changed,</li>\n<li>why it changed,</li>\n<li>when it changed,</li>\n<li>who approved it, and</li>\n<li>whether the change affected the system boundary.</li>\n</ul>\n<p>You need traceability.</p>\n<p>A ticketing system is something I encourage every company to have. If you want to use Microsoft Forms here are instructions.</p>\n<h2 id=\"some-events-require-immediate-up-to-72-hours-action\">Some Events Require Immediate (up to 72 hours) Action</h2>\n<p>Scheduled reviews handle ordinary operations. Certain events should trigger immediate action.</p>\n<p>Examples include:</p>\n<ul>\n<li>Defender or Huntress reports a serious security event,</li>\n<li>you lose the laptop,</li>\n<li>someone sends CUI to the wrong system,</li>\n<li>a new vulnerability creates an immediate risk,</li>\n<li>the laptop falls out of compliance,</li>\n<li>you detect malware,</li>\n<li>someone attempts unauthorized access, or</li>\n<li>you suspect that CUI may have left the approved boundary.</li>\n</ul>\n<p>Having an MSP can help the single person shop handle these events.</p>\n<p>Later in the SSP, we can spell out the exact steps.</p>\n<p>For now, the founder only needs to understand the principle:</p>\n<blockquote>\n<p><strong>Routine problems follow the routine. Security events interrupt the routine.</strong></p>\n</blockquote>\n<h2 id=\"business-changes-can-become-security-changes\">Business Changes Can Become Security Changes</h2>\n<p>Some of the most important security events do not look like cybersecurity events at all.</p>\n<p>You might hire another employee. A contractor suddenly needs access to CUI, or you buy another laptop. Maybe your Prime wants to change the file-transfer process.</p>\n<p>Those requests may sound operational, but they can change the CMMC boundary.</p>\n<p>Our founder therefore needs one more procedure:</p>\n<p><strong>Before changing who can access CUI, where CUI can go, or what technology can touch it, stop and review the scope.</strong></p>\n<p>We introduced this as a scope-change trigger in Post One.</p>\n<p>Now it becomes part of normal security operations.</p>\n<h2 id=\"what-must-i-do-for-cmmc-compliance\">What Must I Do for CMMC Compliance?</h2>\n<p>When we strip away the product names and compliance language, the one-laptop security department has a pretty short job description.</p>\n<table>\n<thead>\n<tr>\n<th>When</th>\n<th>Founder or MSP Action</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Continuous</td>\n<td>Security tools monitor the endpoint, identity, and authorized services.</td>\n</tr>\n<tr>\n<td>Weekly</td>\n<td>Review vulnerabilities, alerts, compliance, updates, and outstanding remediation.</td>\n</tr>\n<tr>\n<td>Monthly</td>\n<td>Review accounts, access, authorized software, and major configuration changes.</td>\n</tr>\n<tr>\n<td>When software changes</td>\n<td>Review the security impact, approve the change, verify the system, and record the change.</td>\n</tr>\n<tr>\n<td>When a vulnerability appears</td>\n<td>Review it, remediate it, verify the correction, and keep evidence.</td>\n</tr>\n<tr>\n<td>When a security event occurs</td>\n<td>Contain the problem, investigate it, escalate when necessary, and document the response.</td>\n</tr>\n<tr>\n<td>When the business changes</td>\n<td>Check whether the change affects the CUI boundary before implementing it.</td>\n</tr>\n</tbody>\n</table>\n<p>That starts to look much more manageable than &ldquo;implement 110 security requirements.&rdquo;</p>\n<h2 id=\"the-msp-can-do-work-but-the-founder-still-owns-decisions\">The MSP Can Do Work, but the Founder Still Owns Decisions</h2>\n<p>A founder who wants to spend very little time on IT can pay an MSP to perform most of the weekly review. A managed VDI provider can take even more technical work off the company&rsquo;s plate.</p>\n<p>That does not remove the founder from the security program.</p>\n<p>A good small-business security program separates technical work from business authority. You can buy as much technical work as makes financial sense, but you always own the business decisions.</p>\n<h2 id=\"keep-evidence-while-you-work\">Keep Evidence While You Work</h2>\n<p>Do not wait until the CMMC assessment and try to recreate the last year of activity from memory.</p>\n<p><strong>Make evidence a side effect of doing the work.</strong></p>\n<p>This will save a small company an enormous amount of time and money.</p>\n<p>A weekly vulnerability review creates a review record. An Intune check creates device-compliance evidence. A Defender finding and later clean scan create remediation evidence.</p>\n<p>If you are going at it alone how can you ensure you follow the evidence collection needs?</p>\n<h2 id=\"what-we-just-built-for-the-ssp\">What We Just Built for the SSP</h2>\n<p>We now have enough information to start writing actual operating procedures into our SSP.</p>\n<p>We know:</p>\n<ul>\n<li>who reviews the security environment,</li>\n<li>what tools operate continuously,</li>\n<li>what the founder reviews each week,</li>\n<li>how the company handles vulnerabilities,</li>\n<li>how the company reviews accounts and access,</li>\n<li>how the founder controls software changes,</li>\n<li>what events trigger immediate action,</li>\n<li>what business changes trigger a scope review, and</li>\n<li>what records those activities create.</li>\n</ul>\n<p>Notice what we did not create.</p>\n<p>We did not write a separate Vulnerability Management Plan, Access Control Plan, Configuration Management Plan, Security Operations Procedure, and five other documents just to explain how one person manages one laptop.</p>\n<p>We described what actually happens.</p>\n<p>As a small business focus on doing the do and let the residuals of work prove the procedures in your System Security Plan.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2026/1415449418-dd82c4af17-k.jpg\">\n",
        "date_published": "2026-08-29T17:46:31-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2026/08/29/the-onelaptop-security-department.html",
        "tags": ["soloprenuer"]
      },
      {
        "id": "http://doctormac.micro.blog/2026/08/27/scoping-out-costs-of-solution.html",
        "title": "Scoping out Costs of Solution Architecture",
        "content_html": "<p>For many small entrepreneurs the cost of CMMC drives your scope. You may engineer a solution that allows you to buy inherited solutions so you do not have to build every security control yourself. Microsoft GCCH will always have lower lifetime costs, but not every contractor can live by five year plans.</p>\n<blockquote>\n<p>This is the third post in the series on the soloprenuer and CMMC. You can find the <a href=\"https://www.drmacscybersecuritybrief.com/2026/08/25/cmmc-for-a-company-of.html\">first post here</a> and the second post <a href=\"https://www.drmacscybersecuritybrief.com/2026/08/26/one-laptop-does-not-need.html\">here</a>.</p>\n</blockquote>\n<p>You may live TO by TO even after winning a spot on an IDIQ. Maybe you make it from RFP response to response and need to survive lean times between awards. Paying for the costly migration of a Microsoft tenant may not be in the cards until after award. So you utilize a FedRAMP Fileshare until then.</p>\n<p>No matter what the interwebz say, no one way exists to engineer a NIST-SP-800-171 environment for a single employee company. You have to right fit your solution to your business needs.</p>\n<p><strong>What do I actually need to buy?</strong></p>\n<p>A tiny contractor does not need one product for every NIST SP 800-171 requirement. Really the first question you need to ask, the most important thing to interview is Time and not money. How much time do you want to spend on IT, and does this have an impact on time available for Direct work?</p>\n<p>Really try to see if your Prime will bring you in scope and provide you a device, but when they say no,  four practical strategies emerge:</p>\n<ol>\n<li>\n<p><strong>Keep Microsoft 365 Commercial and add a dedicated CUI repository.</strong></p>\n</li>\n<li>\n<p><strong>Build a Microsoft 365 GCC High environment.</strong></p>\n</li>\n<li>\n<p><strong>Rent a fully managed VDI enclave.</strong></p>\n</li>\n<li>\n<p><strong>Use an MSP to take recurring security work off your plate.</strong></p>\n</li>\n</ol>\n<p>The products may change, but the business question will not.</p>\n<p><strong>Cheap does not simply mean the smallest monthly bill.</strong></p>\n<p>A founder needs to look at the first-year check, five-year cost, implementation labor, inherited controls, and the amount of time the company must spend running the environment.</p>\n<h2 id=\"first-set-a-common-budgeting-baseline\">First, Set a Common Budgeting Baseline</h2>\n<p>We need an apples-to-apples starting point before comparing CUI solutions.</p>\n<p>For this article, every architecture <strong>except GCC High</strong> starts with the same commercial Microsoft baseline:</p>\n<p><strong>$32 per user per month for Microsoft 365 Business Premium/E3 plus the P2 add-on.</strong></p>\n<p>That gives us:</p>\n<ul>\n<li><strong>$384 per user per year</strong></li>\n<li><strong>$1,920 per year for five users</strong></li>\n</ul>\n<p>This baseline gives the company the Microsoft identity, endpoint-management, and Defender capabilities that support the managed endpoint. Defender handles vulnerability management, and Huntress remains the monitoring/SIEM platform.</p>\n<p>You might be a Google Workspace customer, and of so just skip ahead to the Managed VDI section. Explaining the difference in what a Google versus Microsoft stack brings goes way beyond the scope of this post. Google shops will need a managed VDI.</p>\n<p>The important budgeting rule looks like this:</p>\n<blockquote>\n<p><strong>File sharing and VDI add to the commercial Microsoft baseline. GCC High replaces the commercial Microsoft baseline.</strong></p>\n</blockquote>\n<p>We do not buy Business Premium/E3 + P2 and then stack equivalent GCC High licensing on top of it for the same CUI users.\nA one person company would rarely need a CUI enclave. You would not maintain two tenants unless you made significant commercial money overseas.</p>\n<h2 id=\"strategy-one-keep-commercial-microsoft-365-and-add-a-cui-repository\">Strategy One: Keep Commercial Microsoft 365 and Add a CUI Repository</h2>\n<p>You have all seen the commercials. Heard the channel sales pitch. Building a CUI enclave, meaning logical boundaries, around a FedRAMP High File share is quite common. Many business owners will pay more to keep Microsoft 365 Commercial for ordinary business and FCI while placing CUI in a separate FedRAMP High file-sharing service. This introduces less change to how business already gets done</p>\n<p>For this example, we budget <strong>$12,000 per year</strong> for a product-agnostic FedRAMP High file-sharing service. We also assume that price includes <strong>five CUI users</strong>.</p>\n<p>You always need more than one user, even as a single user company.</p>\n<p>The business still controls the laptop, approves access, reviews vulnerabilities, handles remediation, manages CUI, and keeps evidence. The cloud provider handles the infrastructure inside the CUI repository.</p>\n<p>For one user let us assume:</p>\n<p><strong>$12,000 file share + $384 Microsoft baseline = $12,384 per year</strong></p>\n<table>\n<thead>\n<tr>\n<th>One-User File-Share Model</th>\n<th>Cost</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Commercial M365 + P2 baseline</td>\n<td>$384.00/year</td>\n</tr>\n<tr>\n<td>FedRAMP High file share</td>\n<td>$12,000.00/year</td>\n</tr>\n<tr>\n<td>Annual recurring cost</td>\n<td><strong>$12,384.00</strong></td>\n</tr>\n<tr>\n<td>Five-year cost</td>\n<td><strong>$61,920.00</strong></td>\n</tr>\n</tbody>\n</table>\n<p>This architecture has one easy rule:</p>\n<blockquote>\n<p><strong>CUI goes in the CUI repository. Commercial business information stays in commercial Microsoft 365.</strong></p>\n</blockquote>\n<p>For a tiny contractor, that clarity has real value. Many contractors also want to pay less up front and might start with a file-share and then move to GCCH once they win award. You gamble with less, and hope you win the award.</p>\n<h2 id=\"strategy-two-replace-the-commercial-stack-with-gcc-high\">Strategy Two: Replace the Commercial Stack With GCC High</h2>\n<p>The second strategy moves the CUI users into Microsoft 365 GCC High. GCC High can provide CUI email, SharePoint, OneDrive, Teams, identity, device management, and related security capabilities inside one Microsoft government environment. Defender still handles endpoint vulnerability management, and Huntress still supports monitoring.</p>\n<p>The key budget difference matters:</p>\n<p><strong>GCC High replaces the $32-per-user commercial Microsoft baseline for those CUI users.</strong></p>\n<p>We do not add $384 per user to the GCC High number.</p>\n<p>We also need to remember that one employee does not mean one GCC High identity. Our one-person company needs a licensed daily-use account, a separate licensed privileged-administrator account, and two cloud-only emergency-access identities. The architecture comparison uses this same separation because the founder should not use the account that reads email and browses the web to administer the entire tenant.</p>\n<table>\n<thead>\n<tr>\n<th>Identity</th>\n<th>Purpose</th>\n<th>Daily Use?</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Daily user</td>\n<td>Email, Teams, SharePoint, OneDrive, and CUI work</td>\n<td>Yes</td>\n</tr>\n<tr>\n<td>Privileged administrator</td>\n<td>Tenant and security administration</td>\n<td>No</td>\n</tr>\n<tr>\n<td>Emergency access 1</td>\n<td>Tenant recovery</td>\n<td>No</td>\n</tr>\n<tr>\n<td>Emergency access 2</td>\n<td>Tenant recovery</td>\n<td>No</td>\n</tr>\n</tbody>\n</table>\n<p>Our current planning model puts that GCC High stack at approximately <strong>$7,871.88 per year</strong> for the one-person environment.</p>\n<p>Then we have to build it.</p>\n<h2 id=\"gcc-high-has-a-first-year-problem\">GCC High Has a First-Year Problem</h2>\n<p>Let us assume a qualified Microsoft provider charges an average of <strong>$150 per hour</strong>.</p>\n<p>A greenfield GCC High deployment requires about <strong>100 hours</strong> of engineering. The provider needs to configure the tenant, identities, administrative accounts, device management, Defender, Conditional Access, logging, SharePoint, OneDrive, security settings, testing, and documentation.</p>\n<p>That creates a <strong>$15,000 setup project</strong>.</p>\n<table>\n<thead>\n<tr>\n<th>One-User Greenfield GCC High</th>\n<th>Cost</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Annual GCC High stack</td>\n<td>$7,871.88</td>\n</tr>\n<tr>\n<td>100-hour implementation at $150/hour</td>\n<td>$15,000.00</td>\n</tr>\n<tr>\n<td>Year-one cost</td>\n<td><strong>$22,871.88</strong></td>\n</tr>\n<tr>\n<td>Five-year cost</td>\n<td><strong>$54,359.40</strong></td>\n</tr>\n</tbody>\n</table>\n<p>GCC High costs less over five years than the dedicated file-share model, but the founder has to absorb a much larger first-year bill.</p>\n<p>That creates the cash-flow problem.</p>\n<h2 id=\"migrating-an-existing-tenant-costs-even-more-up-front\">Migrating an Existing Tenant Costs Even More Up Front</h2>\n<p>A founder who already runs a commercial Microsoft tenant faces a larger project. The provider now needs to build GCC High and move identities, mail, files, permissions, devices, DNS, and configurations.</p>\n<p>We will budget <strong>150 hours</strong> for that work.</p>\n<p>At $150 per hour, the migration costs <strong>$22,500</strong>.</p>\n<p>If you know how to all the Microsoft stuff you can knock down these costs, but it will still take time. If you are in between awards time may not be scarce, if you have Direct hours to bill your time gets expensive.</p>\n<table>\n<thead>\n<tr>\n<th>One-User GCC High Migration</th>\n<th>Cost</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Annual GCC High stack</td>\n<td>$7,871.88</td>\n</tr>\n<tr>\n<td>150-hour migration at $150/hour</td>\n<td>$22,500.00</td>\n</tr>\n<tr>\n<td>Year-one cost</td>\n<td><strong>$30,371.88</strong></td>\n</tr>\n<tr>\n<td>Five-year cost</td>\n<td><strong>$61,859.40</strong></td>\n</tr>\n</tbody>\n</table>\n<p>Notice what happened.</p>\n<p>The five-year cost of migrating into GCC High gets close to  commercial Microsoft and adding the $12,000 file share. Two to Five users, if you can get an affordable file-share package is the sweet spot.</p>\n<p>The business decision now depends much more on cash flow, workflow, and how much infrastructure the founder wants to manage.</p>\n<h2 id=\"strategy-three-rent-a-managed-cui-workspace\">Strategy Three: Rent a Managed CUI Workspace</h2>\n<p>A fully managed VDI enclave takes another path.</p>\n<p>A service such as <strong>CuickTrac, ATX, or Midwatch</strong> moves much of the technical operation into the managed enclave. You get access to a VDI solution that keeps your endpoint out of scope. Suddenly more of your security requirements get inherited. This is as close as turn key getd</p>\n<p>For this comparison we will assume three users. Just like the Fileshare and M365 a single person company needs multiple identities to fill roles of least privilege.</p>\n<p>For this compliance story we will use <strong>$325 per user per month, with a three-user minimum, plus a $5,000 one-time setup fee.</strong></p>\n<p>The commercial Microsoft baseline still applies because this model does not replace the company&rsquo;s Business Premium/E3 + P2 environment.You still need to pay for your commercial side of the business.</p>\n<p><strong>3 × $325 = $975 per month for Managed Enclave</strong></p>\n<p>Then we add our one-user Microsoft baseline:</p>\n<p><strong>$975 + $32 = $1,007 per month</strong></p>\n<table>\n<thead>\n<tr>\n<th>One-User Model</th>\n<th>Cost</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Commercial M365 + P2 baseline</td>\n<td>$384.00/year</td>\n</tr>\n<tr>\n<td>Three-seat minimum</td>\n<td>$11,700.00/year</td>\n</tr>\n<tr>\n<td>Annual recurring cost</td>\n<td><strong>$12,084.00</strong></td>\n</tr>\n<tr>\n<td>One-time setup</td>\n<td>$5,000.00</td>\n</tr>\n<tr>\n<td>Year-one cost</td>\n<td><strong>$17,084.00</strong></td>\n</tr>\n<tr>\n<td>Five-year cost</td>\n<td><strong>$65,420.00</strong></td>\n</tr>\n</tbody>\n</table>\n<p>Now the fully managed VDI model sits in an interesting position.</p>\n<p>It costs less in year one than either GCC High approach, and its five-year cost stays reasonably close to both the dedicated file share and a GCC High migration.</p>\n<p>The founder pays a premium over greenfield GCC High but buys much more operational help.</p>\n<h2 id=\"compare-the-one-person-company\">Compare the One-Person Company</h2>\n<table>\n<thead>\n<tr>\n<th>One-Person Architecture</th>\n<th>Year One</th>\n<th>Five Years</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Commercial M365 + P2 + FedRAMP High file share</td>\n<td>$12,384.00</td>\n<td>$61,920.00</td>\n</tr>\n<tr>\n<td>Cuick Trac + Commercial M365 + P2</td>\n<td>$17,084.00</td>\n<td>$65,420.00</td>\n</tr>\n<tr>\n<td>GCC High — greenfield</td>\n<td>$22,871.88</td>\n<td>$54,359.40</td>\n</tr>\n<tr>\n<td>GCC High — migrate existing tenant</td>\n<td>$30,371.88</td>\n<td>$61,859.40</td>\n</tr>\n</tbody>\n</table>\n<p><strong>The dedicated file share creates the lowest first-year cost.</strong></p>\n<p><strong>Greenfield GCC High creates the lowest five-year cost.</strong></p>\n<p><strong>Managed Enclaves have the highest lifetime cost but the lowest level of effort.</strong></p>\n<p><strong>Migrating into GCC High costs almost exactly the same over five years as the dedicated file-share model, but the founder has to fund much more of that cost during year one.</strong></p>\n<p>None of those choices are right or wrong. They solve different problems.</p>\n<h2 id=\"scale-changes-the-answer\">Scale Changes the Answer</h2>\n<p>Now let the company grow from one CUI user to five.</p>\n<p>Our commercial Microsoft baseline follows the number of users:</p>\n<p><strong>5 × $32 × 12 = $1,920 per year</strong></p>\n<p>The file-share service still costs $12,000 because our planning assumption includes five licenses.</p>\n<p>That gives the five-user file-share model a major scaling advantage.</p>\n<table>\n<thead>\n<tr>\n<th>Five-User File-Share Model</th>\n<th>Cost</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Five Commercial M365 + P2 users</td>\n<td>$1,920.00/year</td>\n</tr>\n<tr>\n<td>FedRAMP High file share with five included users</td>\n<td>$12,000.00/year</td>\n</tr>\n<tr>\n<td>Annual recurring cost</td>\n<td><strong>$13,920.00</strong></td>\n</tr>\n<tr>\n<td>Five-year cost</td>\n<td><strong>$69,600.00</strong></td>\n</tr>\n</tbody>\n</table>\n<p>At one user, the company pays for file-sharing capacity it does not use. At five users, the company finally uses all five included licenses while the $12,000 repository cost stays flat.</p>\n<h2 id=\"five-users-in-gcc-high\">Five Users in GCC High</h2>\n<p>A five-person GCC High company also needs more than five identities.</p>\n<p>Our design uses five licensed daily-use accounts, one separate licensed privileged-administrator account, and two cloud-only emergency-access identities.</p>\n<p>That gives the company <strong>eight identities</strong>, with six licensed identities in our planning model.</p>\n<p>The current planning figure puts the five-user GCC High stack at approximately <strong>$12,335.88 per year</strong>.</p>\n<p>GCC High still replaces the commercial Microsoft baseline. We do <strong>not</strong> add another $1,920 for Business Premium/E3 + P2.</p>\n<table>\n<thead>\n<tr>\n<th>Five-User GCC High</th>\n<th>Year One</th>\n<th>Five Years</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Greenfield — 100-hour setup</td>\n<td>$27,335.88</td>\n<td>$76,679.40</td>\n</tr>\n<tr>\n<td>Migration — 150 hours</td>\n<td>$34,835.88</td>\n<td>$84,179.40</td>\n</tr>\n</tbody>\n</table>\n<p>GCC High now loses the five-year price advantage it had at one user because our file-share service includes five seats for the same $12,000 annual price. File-share pricing model scales unusually well from one to five users.</p>\n<h2 id=\"five-users-in-managed-enclave\">Five Users in Managed Enclave</h2>\n<p>Managed Enclaves scale differently because they charge per user.</p>\n<p>Using our earlier estimage Five users cost:</p>\n<p><strong>5 × $325 × 12 = $19,500 per year</strong></p>\n<p>We then add the five-user commercial Microsoft baseline:</p>\n<p><strong>$19,500 + $1,920 = $21,420 per year</strong></p>\n<table>\n<thead>\n<tr>\n<th>Five-User Cuick Trac Model</th>\n<th>Cost</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Five Commercial M365 + P2 users</td>\n<td>$1,920.00/year</td>\n</tr>\n<tr>\n<td>Five users</td>\n<td>$19,500.00/year</td>\n</tr>\n<tr>\n<td>Annual recurring cost</td>\n<td><strong>$21,420.00</strong></td>\n</tr>\n<tr>\n<td>One-time setup</td>\n<td>$5,000.00</td>\n</tr>\n<tr>\n<td>Year-one cost</td>\n<td><strong>$26,420.00</strong></td>\n</tr>\n<tr>\n<td>Five-year cost</td>\n<td><strong>$112,100.00</strong></td>\n</tr>\n</tbody>\n</table>\n<p>The managed VDI looks much more attractive at one user than at five because the three-seat minimum already forces the tiny company to buy unused capacity.</p>\n<p>Once the company reaches five people, every new VDI user increases recurring cost.</p>\n<h2 id=\"the-five-user-comparison\">The Five-User Comparison</h2>\n<table>\n<thead>\n<tr>\n<th>Five-User Architecture</th>\n<th>Year One</th>\n<th>Five Years</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Commercial M365 + P2 + FedRAMP High file share</td>\n<td>$13,920.00</td>\n<td>$69,600.00</td>\n</tr>\n<tr>\n<td>Cuick Trac + Commercial M365 + P2</td>\n<td>$26,420.00</td>\n<td>$112,100.00</td>\n</tr>\n<tr>\n<td>GCC High — greenfield</td>\n<td>$27,335.88</td>\n<td>$76,679.40</td>\n</tr>\n<tr>\n<td>GCC High — migrate existing tenant</td>\n<td>$34,835.88</td>\n<td>$84,179.40</td>\n</tr>\n</tbody>\n</table>\n<p>The file-share model wins the five-user price comparison because the $12,000 subscription already includes five CUI users.GCC High costs more over five years at this size, but it provides a much broader collaboration environment. The company gains CUI email, Teams, SharePoint, OneDrive, identity, device management, and other services under one ecosystem.</p>\n<p>Managed Enclaves cost substantially more at five users, but price does not tell the whole story. The company pays the provider to operate much more of the environment. A founder who does not want to build or maintain the technical stack may still value that trade.</p>\n<h2 id=\"what-are-you-really-buying\">What Are You Really Buying?</h2>\n<p>The three architectures sell different kinds of inheritance.</p>\n<p>With the <strong>FedRAMP High file-share model</strong>, you buy  a controlled place for CUI while keeping the commercial Microsoft security stack.</p>\n<p>With <strong>GCC High</strong>, the founder replaces the commercial Microsoft stack with a government cloud environment and pays a substantial engineering cost to build it correctly.</p>\n<p>With *<em>Managed Enclave</em>, the founder keeps the commercial Microsoft baseline and pays a managed-enclave provider to take much more responsibility for the CUI workspace.</p>\n<p>The cheapest choice depends on the size of the company and the kind of inheritance the founder values.</p>\n<h2 id=\"strategy-four-buy-back-the-founders-time\">Strategy Four: Buy Back the Founder&rsquo;s Time</h2>\n<p>An MSP can support the commercial Microsoft and GCC High models by reviewing Defender findings, monitoring Huntress, coordinating remediation, managing endpoint configuration, reviewing accounts, gathering evidence, and preparing reports.</p>\n<p>The founder still owns the CMMC program, but the founder does not need to spend every Friday staring at security dashboards.</p>\n<p>That time has value.</p>\n<p>If a founder spends five hours each month managing cybersecurity, the company loses 60 hours per year. At a $200 billable rate, that represents <strong>$12,000 of potential revenue</strong>.</p>\n<p>A spreadsheet that ignores the founder&rsquo;s time does not show the true cost of the architecture.</p>\n<h2 id=\"inheritance-does-not-make-responsibility-disappear\">Inheritance Does Not Make Responsibility Disappear</h2>\n<p>Microsoft can operate the cloud. A FedRAMP provider can secure the repository. Defender can identify vulnerabilities. Huntress can monitor security events. CuickTrac can operate a managed enclave. An MSP can review alerts.</p>\n<p>The founder still approves users, decides who may access CUI, maintains the system boundary, manages company procedures, reviews provider responsibilities, makes risk decisions, and keeps the SSP accurate.</p>\n<p>That gives us the real lesson behind inheritance:</p>\n<blockquote>\n<p><strong>You do not need to build every security control yourself. You need to understand which controls you own and which controls you bought from somebody else.</strong></p>\n</blockquote>\n<h2 id=\"so-what-should-our-founder-choose\">So What Should Our Founder Choose?</h2>\n<p>For a one-person company, the <strong>dedicated file-share architecture provides the lowest first-year cost</strong>, while <strong>greenfield GCC High produces the lowest five-year cost</strong> under these assumptions.</p>\n<p>A <strong>managed VDI enclave such as CuickTrac</strong> lands between them. It costs a little more over five years than the file-share model but can dramatically reduce the amount of technical work the founder needs to perform.</p>\n<p>Migration changes the GCC High story. Once a company already has a commercial Microsoft tenant, the 150-hour migration makes GCC High and the file-share model almost identical over five years. The founder then needs to decide whether consolidation justifies the larger first-year bill.</p>\n<p>At five users, the dedicated file share becomes the least expensive architecture because the $12,000 subscription already includes all five users. GCC High costs more but offers broader capabilities, while managed VDI costs the most because every additional seat increases the subscription.</p>\n<p>The goal is not to buy the most cybersecurity products or chase the cheapest advertised license.</p>\n<blockquote>\n<p><strong>Buy the architecture that leaves you with the fewest security problems you personally have to solve at a price your business can a afford.</strong></p>\n</blockquote>\n<h2 id=\"what-we-just-built-for-the-ssp\">What We Just Built for the SSP</h2>\n<p>We now know where CUI lives, how users reach it, which services manage identity and endpoints, how the company handles vulnerability management and monitoring, which providers operate technical controls, and which responsibilities remain with the founder.</p>\n<h2 id=\"next-the-one-laptop-security-department\">Next: The One-Laptop Security Department</h2>\n<p>In the next post, we stop shopping and start doing. We will look at what you need to do every day, every week, every month, and every time something changes. You need to think about security controls stop as product features and start building procedures to get better at business.</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2026/6107919083-ab1177c1ce-h.jpg\">\n",
        "date_published": "2026-08-27T17:30:36-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2026/08/27/scoping-out-costs-of-solution.html",
        "tags": ["soloprenuer"]
      },
      {
        "id": "http://doctormac.micro.blog/2026/08/26/one-laptop-does-not-need.html",
        "title": "One Laptop Does Not Need an Enterprise Security Program",
        "content_html": "<p>A one-person company struggles to prepare for CMMC. Often, folks begin in the wrong place.</p>\n<blockquote>\n<p>All month long I am focusing on how a single-user company can create controls that meet NIST SP 800-171 security requirements and pass a CMMC assessment using the NIST SP 800-171A assessment objectives. You can find the first post <a href=\"https://www.drmacscybersecuritybrief.com/2026/08/25/cmmc-for-a-company-of.html\">here</a>.</p>\n</blockquote>\n<p>You download NIST SP 800-171. You see 110 requirements. You throw up in your mouth when you realize you must meet 320 assessment objectives. You have no employees. How can you meet requirements meant for a large enterprise?</p>\n<p>You start hearing about policies, SIEMs, VLANs, vulnerability scanners, privileged access workstations, firewalls, incident response plans, configuration management boards, and a dozen other things that sound like they belong in a Fortune 500 company.</p>\n<p>Before long, a founder with one laptop tries to design an enterprise security program.</p>\n<p>Stop this backward approach.</p>\n<p>Before we decide how to protect the system, we need to answer a much simpler question:</p>\n<p><strong>What exactly do we need to protect?</strong></p>\n<p>For a small contractor who runs staffing agencies and hires 1099 employees to work on GFE, the simplicity of the environment matters.</p>\n<h2 id=\"start-with-the-business-not-nist-sp-800-171\">Start With the Business, Not NIST SP 800-171</h2>\n<p>We work with many companies that operate on similar principles.</p>\n<p>One founder serves as the principal contractor. She has one company-controlled Windows laptop. Only this company device can process, store, or transmit Controlled Unclassified Information.</p>\n<p>The company also uses 1099 contractors, but those contractors perform their government work onsite using Government-Furnished Equipment.\nTheir GFE does not connect to the company&rsquo;s systems.\nThe company does not grant those contractors access to CUI.</p>\n<p>For ordinary company communications and Federal Contract Information, the contractors may use their own devices to access Microsoft 365 Commercial.\nBut that Microsoft 365 environment only touches FCI. Contractors cannot access the CUI repository.</p>\n<p>The company realizes it has:</p>\n<ul>\n<li>no CUI printers,</li>\n<li>no company servers,</li>\n<li>no corporate LAN,</li>\n<li>no removable-media workflow for CUI, and</li>\n<li>no reason to drag every device the company touches into the CMMC boundary.</li>\n</ul>\n<h2 id=\"your-company-does-not-automatically-equal-your-cmmc-boundary\">Your Company Does Not Automatically Equal Your CMMC Boundary</h2>\n<p>A small business may own or interact with all kinds of technology.\nThat does not mean all of it has to become part of the system that handles CUI.\nOur founder may use a personal phone.\nThe 1099 contractors may own laptops and tablets.\nThe Government may provide computers.\nThe company may have a commercial Microsoft 365 tenant.\nT he founder may have a home router.\nNone of those facts automatically place all of those devices inside the CUI environment.</p>\n<p>As you start to scope a single-person company, begin with critical questions:</p>\n<ul>\n<li>Can the device process CUI?</li>\n<li>Can it store CUI?</li>\n<li>Can it transmit CUI?</li>\n<li>Does it provide security protection to the CUI environment?</li>\n</ul>\n<h2 id=\"keep-the-cui-workflow-small\">Keep the CUI Workflow Small</h2>\n<p>Our boundary may look like this:</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2026/single-contractor.png\" width=\"600\" height=\"654\" alt=\"Auto-generated description: A network flowchart illustrates the Prime CUI Portal Architecture involving government systems, contractor environments, Microsoft 365 services, a hardened in-scope endpoint, cloud SIEM, FedRAMP fileshare, and authorized U.S. person recipients with various access and security controls.\">\n<p>Or like this:</p>\n<img src=\"https://cdn.uploads.micro.blog/29546/2026/singlelaptopscope.png\" width=\"600\" height=\"450\" alt=\"\">\n<p>We keep the center of the diagram intentionally boring.</p>\n<p>When you realize the scope involves a single company-managed Windows laptop, you can get a handle on CMMC.\nThat laptop connects to the authorized services used to protect and handle CUI. Everything else gets separated by function.\nThe Government-Furnished Equipment stays in the Government environment.\nThe contractors' personally owned devices stay in the FCI workflow.</p>\n<p>Microsoft 365 Commercial stays an FCI environment and provides SPA support as an External Connection.</p>\n<p>The contractors never receive access to the CUI repository.\nCUI does not move onto their personal devices.\nCUI does not move onto the Government equipment through the company&rsquo;s systems.\nCUI does not get printed.</p>\n<p>The result:</p>\n<p><strong>CUI scope, Government systems, and ordinary FCI collaboration do not have to become one giant blob.</strong></p>\n<p>That makes both cybersecurity and CMMC easier.</p>\n<h2 id=\"every-asset-has-a-cost\">Every Asset Has a Cost</h2>\n<p>A hidden cost appears every time you allow CUI onto another device.\nSuppose the founder decides to let a contractor download one CUI drawing onto a personal laptop.\nThat sounds like one small workflow change.</p>\n<p>No.\nWe just added another device to our boring middle, and we increased scope.</p>\n<p>Now we have another device that we may need to inventory, configure, harden, monitor, patch, protect, assess, and describe in the SSP. We need to know who administers it. We need to control access. We need to know where the file gets stored.We need to know whether it gets backed up.</p>\n<p>We need to think about browser caches, temporary files, local accounts, malware protection, encryption, vulnerabilities, and incident response.All because we wanted to make one file easier to access. The same thing happens with printers.</p>\n<p>If we do not print CUI, then we do not need to design procedures for protecting CUI sitting in an output tray, storing paper records, transporting hardcopy, sanitizing printer storage, or destroying printed CUI.</p>\n<p>The simplest printer control for a tiny company:</p>\n<p><strong>Do not print CUI.</strong></p>\n<p>That gives us one of the most important lessons in this entire series:</p>\n<blockquote>\n<p><strong>Every asset you keep out of the CUI workflow is an asset you do not have to protect as part of the CUI system.</strong></p>\n</blockquote>\n<p>That does not mean ignoring security on the rest of the business.</p>\n<p>FCI still has safeguarding requirements.\nCommercial systems still need security.\nEmployees and contractors still need safe computing practices.\nIt simply means that we should not unnecessarily turn every business system into a CUI system.</p>\n<h2 id=\"draw-the-boundary-before-you-buy-anything\">Draw the Boundary Before You Buy Anything</h2>\n<p>This is why I would not start a small company&rsquo;s CMMC project by shopping for cybersecurity tools.</p>\n<p>I would start with a diagram.</p>\n<ul>\n<li>Where does CUI come from?</li>\n<li>Where can it go?</li>\n<li>Who can see it?</li>\n<li>Which device can open it?</li>\n<li>Where can it be stored?</li>\n<li>How does it leave the company?</li>\n<li>What systems are expressly prohibited from receiving it?</li>\n</ul>\n<p>If a founder cannot explain the boundary in plain English, you will struggle to write an accurate SSP around it.</p>\n<p>If the assessor cannot understand the boundary, the assessment will get much more complicated.</p>\n<h2 id=\"the-boundary-builds-a-business-rule\">The Boundary Builds a Business Rule</h2>\n<p>Technology alone will not keep this design small.\nThe company also needs rules.</p>\n<ul>\n<li>The 1099 contractors do not get added to the CUI access group.</li>\n<li>The founder does not forward CUI to commercial email.</li>\n<li>Government-Furnished Equipment does not log into company systems.</li>\n<li>Personal devices do not download CUI.</li>\n</ul>\n<p>Those operating decisions preserve the boundary.</p>\n<h2 id=\"what-we-just-built-for-the-ssp\">What We Just Built for the SSP</h2>\n<p>We still have not written any of the 110 NIST SP 800-171 requirements.</p>\n<p>But we have already created some of the most important content that will eventually go into the System Security Plan.</p>\n<p>We now know:</p>\n<ul>\n<li>the system environment,</li>\n<li>the CUI system boundary,</li>\n<li>the physical and logical separation of the environment,</li>\n<li>the roles involved,</li>\n<li>who has authorization to access CUI,</li>\n<li>how CUI flows through the company,</li>\n<li>which assets and workflows remain outside the boundary,</li>\n<li>what systems cannot receive CUI, and</li>\n<li>which changes require us to reconsider scope.</li>\n</ul>\n<p>That is why I wanted to start the series here.</p>\n<p>If we get the boundary wrong, everything we build afterward gets harder.</p>\n<p>If we get the boundary right, a one-person company can remain a one-person security problem instead of accidentally becoming an enterprise security problem.</p>\n<p>When it comes time to write the System Security Plan, your boundary diagram will support many controls:</p>\n<ul>\n<li><strong>3.1.3</strong> — The company limits CUI flow to the managed laptop and authorized CUI services.</li>\n<li><strong>3.1.20</strong> — The diagram shows GFE, BYOD, and Microsoft 365 Commercial as external or out-of-boundary systems and documents restricted or prohibited CUI connectivity.</li>\n<li><strong>3.12.4</strong> — The diagram documents the CUI system boundary and external connections.</li>\n<li><strong>3.13.1</strong> — The diagram identifies the logical boundary between the CUI enclave, Government environment, BYOD environment, and commercial FCI environment.</li>\n<li><strong>3.13.6</strong> — The diagram can mark prohibited paths and support the allow-by-exception architecture.</li>\n<li><strong>3.13.8 / 3.13.11</strong> — The diagram can identify approved encrypted and FIPS-protected CUI connections.\nThe  boundary diagram exists to mainly meet 3.12.4, 3.13.1, and 3.1.3. It defines everything about CMMC</li>\n</ul>\n<h2 id=\"next-now-we-can-buy-something\">Next: Now We Can Buy Something</h2>\n<img src=\"https://cdn.uploads.micro.blog/29546/2026/cfcf929ad0.png\">\n",
        "date_published": "2026-08-26T08:05:37-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2026/08/26/one-laptop-does-not-need.html",
        "tags": ["soloprenuer"]
      },
      {
        "id": "http://doctormac.micro.blog/2026/08/25/cmmc-for-a-company-of.html",
        "title": "CMMC for a Company of One: Building a Business Not a Burden",
        "content_html": " <p>If you are a founder, independent consultant, or owner of a very small defense contractor, NIST SP 800-171  feels overwhelming. You stare at the CMMC scoping guide and know someone wrote it for a company much larger than yours.</p>\n<p>You may have one employee, one laptop, no server room, no IT department, and no corporate network. Yet if your company handles Controlled Unclassified Information (CUI), you still need to protect that information and explain how you meet the requirements of NIST SP 800-171. You have to meet the same 110 requirements as Boeing, RTX, or General Dynamcs</p>\n<p><ip>I get it. That  doesn’t seem fair.</ip></p>\n<p>In this series, we will  build a complete System Security Plan (SSP) for a fictional one-person company. But we will not start with the SSP.</p>\n<p>We will begin with how the business actually operates, define the CUI boundary, select the technology, write the procedures, identify the evidence, and only then assemble the SSP.</p>\n<p>The goal: Create an SSP that tells the founder exactly what to do instead of constantly pointing to separate policies, plans, and procedures. You do not need to swim in pages of procedures. We will also include a cost analysis of different solutions, and consider the implications to how you do business better. We will focus on implementing controls not on how they fall in in NIST-SP-800-171 but on the ROI for security for a micro-business</p>\n<h2>Meet Our Fictional Company</h2>\n<p>Our company has one principal contractor who may receive and work with CUI. The principal uses one company-managed Windows laptop as the only company-controlled endpoint authorized for CUI.</p>\n<p>The company also uses 1099 contractors. When performing government work, they use Government-Furnished Equipment (GFE) onsite. The company does not grant those contractors access to its CUI environment.</p>\n<p>For normal business communications and Federal Contract Information (FCI), the contractors may use personally owned devices to access Microsoft 365 Commercial. That environment is not authorized for CUI.</p>\n<p>There are no company servers, no CUI printers, and no removable media used for CUI.</p>\n<h2>The Boundary We Will Use</h2>\n<p>The same system boundary will be used throughout the series. The important part is the separation: the managed laptop and authorized CUI services are inside the CUI environment, while contractor GFE, BYOD devices, and the Microsoft 365 Commercial FCI environment remain outside it.</p>\n<img src=\"https://cdn.uploads.micro.blog/4002/2026/examplenetworkdiagram.png\" width=\"600\" height=\"450\" alt=\"\">\n<p>This deliberately narrow architecture gives us a manageable example for showing how a micro-business can implement NIST-SP 800-171 without designing an enterprise network it does not need. Our solution also relies on using strategic partners when it makes more economic sense than trying to do it on your own.</p>\n<h2>What the Series Will Cover</h2>\n<ul> <li>\n<strong>Define the Scope:</strong> Identify where CUI exists, who can access it, what is in the assessment boundary, what stays out, and what changes would require the company to reassess scope. We will compare the cost of a variety of solutions. Scoping defines budgets as much as boundaries </li>\n<li>\n<strong>Build the Architecture:</strong> Select the endpoint, identity, monitoring, vulnerability-management, and CUI storage services, while separating what the company must do from controls inherited from cloud providers.</li>\n<li>\n<strong>Write the Procedures:</strong> Turn NIST SP 800-171 requirements into plain-language instructions describing what the founder actually does, when it happens, and which technology supports the process.</li>\n<li>\n<strong>Prove the Do:</strong> Determine what evidence demonstrates that the procedures are actually being followed, including vulnerability reviews, access records, device compliance, logs, alerts, configuration records, and remediation evidence.</li>\n<li>\n<strong> Build the SSP:</strong> Bring everything together at the NIST SP 800-171A assessment-objective level and place the procedures directly into the SSP instead of sending the assessor through a maze of separate documents.</li> </ul>\n<h2>Why Build It This Way?</h2>\n<p>A common mistake small is to start with 110 requirements and immediately begin writing policies.</p>\n<p>That reverses the process.</p>\n<p>First understand the business. Then follow the CUI. Draw the boundary. Select the technology. Assign responsibilities. Write the procedures. Identify the evidence. You want to use CMMC to do business better.</p>\n<p><strong>Then write the SSP.</strong></p>\n<p>By the end of this series, the SSP should be more than an assessment document. It should function as the operating manual for protecting CUI in this small environment.</p>\n<p>We will build this outcome together.</p>\n",
        "date_published": "2026-08-25T13:04:40-04:00",
        "url": "https://www.drmacscybersecuritybrief.com/2026/08/25/cmmc-for-a-company-of.html",
        "tags": ["soloprenuer"]
      }
  ]
}
