Controlled Unclassified Information, export-controlled technical data, and material subject to contractual handling requirements need a defined boundary, documented controls, and evidence you can produce on request. Sentry builds and operates that environment, and tells you plainly where our responsibility ends and yours begins.
A prime has flowed down DFARS 252.204-7012, a contract references CMMC, or a customer has sent a security questionnaire you cannot answer. You need an environment that holds up to assessment, and documentation that exists before someone asks for it.
Law firms, consultancies, and investigative practices that receive controlled technical data or CUI from clients rather than from a contract. The regulatory analysis is yours. The environment that keeps the material where it belongs is ours.
As of August 2026: on July 13, 2026, the Department of War suspended CMMC Phase II third-party certification requirements pending a comprehensive program review. Phase I self-assessment requirements remain in effect and DFARS 252.204-7012 obligations are unchanged. This is an active review and the position may change, so confirm the current state before relying on it.
The practical effect is that more of the burden sits with you. Scoping the environment correctly, implementing the controls, maintaining current evidence, and standing behind every representation entered into SPRS. A self-assessment that does not match the actual environment is a real liability. If you subcontract to a prime, note that it may still require certification under its own flow-down terms independent of this pause. Our federal contractor page covers this in more detail.
The expensive mistake is treating the whole organization as in scope. Most of what your people do every day does not touch controlled information, and hardening every mailbox and laptop to a standard only a fraction of the work requires costs more and delivers less. We scope the boundary first, put a purpose-built environment around that, and leave the rest of the business on a normal, well-run managed IT foundation.
Where controlled material actually arrives, where it needs to live, and who genuinely needs to touch it. This determines everything downstream, and it is where most of the cost is decided.
A defined environment for the controlled work, separate from day-to-day operations. Depending on scope that can be an encrypted overlay for email and files, or a managed virtual desktop configured so the material never lands on an endpoint.
A system security plan, control ownership documented line by line, and the records an assessor or a client questionnaire will ask for. Built as the environment is built, not reconstructed afterward.
No platform does. An authorized assessor makes that determination. Any vendor selling a "CMMC-compliant" product does not understand the regime, and you should treat that claim as a warning sign.
Whether a flow-down reaches you, what a protective order requires, which regulations govern a given matter: those are yours and your counsel's to determine. Given a classification you supply, we design where the data lives, who can reach it, and how it is monitored.
Endpoint monitoring, administrative access, where our vendors' personnel sit and what they can retrieve during an investigation. In writing, before you ask, and configured to your requirements where the platform allows it.
Some requirements in the standard cannot be performed by any platform or any provider. Personnel screening, physical security at your own facility, and awareness training are yours no matter what you buy. We keep that list, and we will walk you through it on the first call rather than after you have signed something.
When a provider manages your security tooling, that provider becomes part of your assessment. That is how the rule works. Most will not mention it. We will, and we are prepared to be assessed alongside you with our own documentation ready.
If you need an assessor, a specialized architect, or counsel, we will say so and coordinate the handoff rather than improvising past the edge of what we do.
Managing a personal laptop to a controlled-data standard is difficult, invasive, and often unnecessary. A machine that also holds someone's personal life, or another client's confidential work, is a poor place to draw a compliance boundary.
Built correctly, an enclave keeps the physical device outside the boundary entirely. Federal guidance is specific about what correctly means: the session carries only video, keyboard and mouse, copy-paste and file transfer are blocked at the server, authentication uses a token separate from the device itself, and the configuration is verified rather than assumed. We hold environments to that standard and can produce the configuration evidence behind it.
The result is that people work from the machines they have, and the sensitive material stays somewhere with real controls around it. Where an environment does not meet that standard, we will tell you, because the devices come back into scope and the cost changes.
Where devices do need management, we are explicit about what that means: what is visible to us, what is not, and what happens to your data if the relationship ends.
The work is driven by the size and complexity of the boundary, not by headcount. A ten-person supplier and a four-person firm handling the same category of material need substantially the same environment, documentation, and control set. So this is quoted as a monthly figure for the organization plus the platform subscription, scoped after the first conversation. Managed IT for the rest of the business is priced separately and normally.
If Sentry manages your IT, the enclave fits alongside the environment we already run. If another provider manages it, we can build and operate the controlled-data environment on its own and coordinate with them, on one condition: they have to document their control ownership and produce evidence on the cadence the standard requires. Compliance is a claim about systems, and nobody can evidence controls on systems they do not administer.
Where a provider will not work that way, we will say so early rather than sell you an environment we cannot stand behind. Either way, the boundary is documented and the split of responsibility is written down before the work starts.
The first conversation is about what you actually receive, how it arrives, and who needs to touch it. That determines the environment and the cost, and it usually takes about thirty minutes. It will keep you from buying more than you need.
Schedule a Scoping ConversationNo pressure, no obligation. We work with organizations across the East Coast, with onsite support available when required.