The people who handle CUI work in a separate, hardened Google environment built for NIST SP 800-171. We build it, write the documentation from how it is actually configured, collect the evidence every month, and keep it current. The rest of your company stays where it is.
When a Google Workspace company asks how to handle CUI, the standard advice is to move everything to Microsoft GCC High: new licenses, new tools, retraining, and months of migration, all for the handful of people who touch CUI.
There is a narrower way. Keep the company on Google, and put CUI inside a defined enclave with its own users, devices, and controls. The boundary is smaller, the cost is lower, and the day-to-day work changes only for the people inside it.
A separate Google Workspace Enterprise Plus environment with Assured Controls, client-side encryption, context-aware access, data loss prevention, and labels. Built as code from a tested baseline, so every client starts from the same proven configuration.
Your System Security Plan is generated from the enclave's actual configuration, so it describes what the system does. Policies are written to match, ready for you to review and adopt.
Automated evidence collection mapped to the 110 requirements, so your SPRS score and annual affirmation rest on records rather than memory.
Configuration drift is detected and corrected, changes are applied and documented, and the documentation updates when the environment does.
Adopt policies, assign training, confirm a few procedures. Setup turns the organizational work into clear steps with a dashboard that shows your progress toward assessment-ready.
A named Stehrling practitioner, backed by a team that holds CCA and CCP credentials, plus a support assistant for everyday questions.
One call to confirm who handles CUI, where it comes from, and where it goes.
We deploy your enclave from our baseline and move CUI users and data into it.
You work through a guided checklist. Plan on about 15 hours of your team's time over 60 days.
A written readiness determination, with an independent mock assessment recommended before any C3PAO assessment.
Monitoring, monthly evidence, upkeep, and support for your annual affirmation.
No hourly billing. We stay with you until you are assessment-ready at the setup price.
From $27,500
About $2,700 / month for 5 CUI users
Early access pricing. Starting prices are for up to 10 people handling CUI at one location; larger groups and additional sites are quoted the same way. Your price is fixed before work begins.
Not by itself, and no platform does. About a third of the NIST SP 800-171 requirements are about people and process: policies you adopt, training your staff completes, physical security, and how incidents are handled. The enclave carries the technical controls, and guided setup turns your part into a checklist. Compliance depends on both.
No. The enclave is its own Google environment for the people who handle CUI. Everyone else keeps working as they do today.
We generate it from the enclave's configuration and complete it with you during setup. Because it is built from the system itself, it stays accurate as the system changes.
We recommend one before any C3PAO assessment. It is performed by assessors who did not build your environment, so the result is an outside view, not us grading our own work. It is quoted with your setup.
The enclave is built to the NIST SP 800-171 requirements that CMMC Level 2 assesses. Certification itself is performed by an authorized C3PAO, and we support you through it when your contract requires it.
We are onboarding a small number of first clients starting January 2027. Requesting early access holds your place and starts the scoping conversation.
First clients start in January 2027 and work directly with the people who designed the enclave. Stehrling is a CMMC Registered Practitioner Organization that works only with defense contractors.
What happens next: a response within one business day, then a 30-minute call to confirm fit and give you a fixed quote. No obligation.
A few short questions so the first call is useful. Please do not include CUI.
An independent firm building NIST 800-171 compliance programs and AI governance for defense contractors and the DIB.