SERVICES
We integrate AI into your business. Here is what it costs to start.
In short
The engagement is AI integrated into your operation, built inside your compliance boundary on infrastructure your data never leaves. It starts with one fixed-price step: the AI Integration Assessment — $12,500, fixed scope, 4–6 weeks. You leave with a sequenced build plan carrying rough-order-of-magnitude costs — and with the four answers that decide whether that plan survives contact with your organisation: who can get access and how long it takes, who is allowed to approve what, whether your records can carry an automated process, and where the system is allowed to run. Credits in full against an implementation engagement.
The first step
AI Integration Assessment
Around two weeks of our effort inside a four-to-six week calendar. The extra weeks are not padding. The answers come from your people, your paperwork, and often a provider you outsource to — and none of them are sitting idle waiting for us.
Credits in full against an implementation engagement.
Exclusions are written into the scope, not discovered later.
A sequenced, costed plan for putting AI into your operation: what to build, in what order, what each module costs, and what has to be true before any of it can start — who can get access and how long that takes, who is allowed to approve what, whether your records are in a state an automated process can act on, and where the system is allowed to run. Delivered as a document your CFO can budget from and your compliance team can put in a file.
What you receive
The first one is the spine — it is what you buy. The other four exist because a sequence is only a plan if somebody can get you access, somebody is empowered to approve, and the data can carry it. Without them it is a wish with dates on it.
- 1
A sequenced build plan, with ROM costs and the route to a fixed price
Documents and interviewsWhat to build, in what order, and a rough-order-of-magnitude cost against each module — then a named discovery step that converts the ROM into a fixed price before you commit to it. The modules are scoped so one can be added, deferred or dropped without reopening the agreement, because scope moves on work like this and the structure should absorb that instead of renegotiating it. The first ninety days are planned around what actually consumes them: environment, identity, access, and the paperwork that gates all three.
- 2
The access and identity plan
Documents and interviewsEvery account, network path, credential and device that has to exist before anything can be built — who has to act to create each one, which ones gate the others, and what happens when one breaks after it was declared done. It names the parties outside your company: the managed IT provider who holds your firewall, the administrator of an ERP you do not run yourself, the tenant you inherited. They have their own queue and no obligation to your schedule, which is precisely why access is treated as a workstream with an owner rather than a precondition assumed to be met.
- 3
The approval map — who is allowed to approve what
Documents and interviewsA role-by-permission matrix, the dollar thresholds at which an approval escalates, and the non-dollar triggers you may want treated the same way. Where your answer does not exist yet you get a first draft to react to rather than a blank form — including what to do about approver seats that are vacant, and where separation of duties would block the person currently doing two jobs. Automation cannot route an approval your organisation has not decided on, and deciding takes longer than configuring.
- 4
The data-readiness verdict
Needs a look insideWhether your records can carry an automated process at all: which fields are missing on the records that matter, which records are not real and are inflating your own reporting, which conventions were never agreed, and what has to be corrected by hand before anything can be switched on — with an estimate of that work and who has to do it. We can start from exports you send us; confirming it against the live system is the part that waits on access.
- 5
The boundary and attestation pack
Documents and interviewsTwo-sided, because the pressure comes from both. Outward: where your data may and may not go, drawn against DFARS 252.204-7012(b)(2)(ii)(D), and where the system itself would run — your own hardware, a government-community cloud, or a commercial region — with the impact level named and the recurring cost of each option written down rather than discovered on an invoice. Inward: what your prime, your assessor and your own compliance team will ask about any system or vendor you let inside your boundary, what evidence answers each question, and which of that evidence exists today.
Documents and interviews means we can produce it from what you can send us and the conversations we have. Needs a look insidemeans it starts the same way and is confirmed against your live system once access exists — which is why access has its own line below rather than being assumed.
What it does not include
Travel and time onsite
The assessment runs remotely. If you want us in the building, that is quoted separately and gladly — it is simply not inside this price.
Provisioning our access to your environment
Standing up an account, a network path, MFA, and sometimes a managed device for an outside firm inside a regulated boundary is its own workstream involving people who are not party to this engagement. We plan it as part of the assessment. Executing it — and the waiting — is scoped and priced on its own.
Work with, or waiting on, your other providers
Your managed IT provider, your ERP administrator and anyone else holding a key are not parties to this engagement and do not answer to its schedule. Coordinating them is billable work, not a rounding error.
Producing attestation artifacts for your primes and assessors
The assessment tells you what will be asked and what evidence answers it. Writing your disaster-recovery plan, completing a prime’s security questionnaire, or assembling POA&M evidence is separate work with its own scope.
Building anything, and fixing your data
This step decides what to build and what it costs. Implementation, and the record-by-record backfill the data-readiness verdict calls for, are the engagement this fee credits against.
None of that is a trapdoor. It is the opposite: every item is work with parties and a clock we do not control, so it is quoted where it can be sized instead of hidden inside a number that then has to move.
Tell us what you do and what you are trying to automate. If it is not a fit, we will say so on the call. If the scope is close but not quite your situation, tell us what is missing — that shapes what we build next.
Why this is the first step and not a quote
Nobody can buy “integrate AI into my company” cold, because the scope is unknowable until somebody establishes it. And what makes it unknowable is almost never the modelling. It is: who can issue an account to an outside firm, and who has to approve that. Who is allowed to sign off on a decision the system will make. Whether the records the automation would act on are complete enough to act on. Whose paper the work runs under while the master agreement is still with the lawyers. A proposal written before those answers exist is a guess with a number attached to it.
So the plan is the product, and the plan is honest about its own preconditions. It is priced as its own deliverable because it is worth having on its own: if you walk away, you keep a document that tells you what to build, in what order, what it costs, and what has to be true first — usable by your own team or by whoever you hire instead. Credits in full against an implementation engagement.
Access is a workstream. We price it as one.
Plans like this are usually written as though access were a precondition somebody has already satisfied: an account exists, a network path exists, someone can approve a firewall change this week. Inside a regulated boundary it is none of those things. It runs through whoever administers your identity — frequently an outsourced provider with their own ticket queue and no contract with us — and it can reach as far as a managed device that has to be built and shipped before anyone can look at anything.
It also does not stay done. An address changes, a person joins, a grant expires, and it re-opens. So the assessment treats it as a deliverable: what has to exist, who has to act, what it gates, and what to do when it breaks. Executing it — and waiting on it — is scoped and quoted separately, once we know whether there are two parties involved or four. We do not publish a number for that, because a number written before we know who is in the room would be fiction.
This is the same reason one deliverable above is badged needs a look inside. Everything we can honestly do from documents, interviews and exports is inside the fixed price. What genuinely requires a working account in your environment is scheduled against reality instead of promised against a deadline.
The boundary question arrives from outside your company
Most AI advice stops at “use the enterprise tier,” as though the boundary were an internal preference. It is not. The question that decides whether an AI system can run is put to you by somebody else — a prime asking what you have let inside your network, an assessor asking what evidence supports the answer, a compliance team asking what you are going to attest to about a vendor. And it is written down in a contract clause: the moment an external cloud service provider stores, processes or transmits covered defense information, you carry a specific obligation about that provider.
Which is why the boundary work in the assessment runs both ways. Outward, it places each of your flows on the correct side of the test below, and names where the system itself would run and what that costs to keep running. Inward, it assembles what you will be asked about the system by people who are not your customer — and about us, since we are one of the vendors you would be attesting to.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
Read that clause precisely
- It requires security equivalent to the FedRAMP Moderate baseline. It does not require a FedRAMP authorization, and a product without one is not automatically a violation.
- It does not require FedRAMP High, and it does not require DoD Impact Level 4. Those are higher bars that some contracts impose separately — not what this paragraph says.
- The duty to require and ensure equivalency sits on you, the contractor. A vendor’s marketing page is not the evidence; the authorization record and the vendor’s own written scope are.
Getting this backwards in either direction is expensive: over-reading it rules out tools you could lawfully use, and under-reading it puts CUI somewhere it must not be. The boundary and attestation pack is where each of your flows gets placed on the correct side of that test, with the evidence attached — and where the same evidence gets organised for whoever asks you to justify it.
See the same test applied to Copilot, ChatGPT, Gemini and Claude, free →What $12,500 sits next to
You do not have to take our word for what compliance work in this market costs. DoD had to price CMMC in order to publish the rule, so the final rule carries a Regulatory Impact Analysis with per-entity estimates broken out by labor category, hour count and hourly rate. These are the government’s own numbers for a small entity.
What DoD budgeted, per entity
Level 2 certification assessment, small entity
$101,752
publishedOne triennial certification assessment. Assessment effort only — DoD excluded the cost of implementing the NIST SP 800-171 requirements themselves.
of which: external service provider time
$45,809
derivedAbout 176 hours at the $260.28/hr external rate DoD published — a rate set by the government, not by us. Separated from DoD's labor-category itemization: our arithmetic on DoD's line items, not a DoD-published figure.
of which: the C3PAO assessor fee
$31,234
publishedDoD modeled a 3-person, 120-hour assessment team for a small entity. Inside the total above, not on top of it.
Source: DoD CMMC Final Rule RIA, 89 FR 83185–86 — Cybersecurity Maturity Model Certification (CMMC) Program, final rule, 89 FR 83092 (Oct. 15, 2024). Cost narrative at 89 FR 83178–83189. DoD’s estimates assume the organization passes on the first attempt, and DoD says plainly that they are “representative of average assessment efforts” rather than market prices. Every line here is reported from, or computed on, the same model behind our CMMC cost estimator.
A contractor in this market is already budgeting six figures to be assessed. The $12,500assessment answers a different question — what to build, in what order, what it costs, and what has to be true before it can start — and it costs less than the outside-help line item DoD models inside a single certification assessment.
To be explicit about what these figures are not: DoD’s numbers price a CMMC assessment, which is not what we sell and not something we could sell. They are here because they are the budget reality this buyer already lives in, and because they come from the rulemaking rather than from a vendor’s price list.
How the build gets bought after the assessment
This is the sequence the assessment is written to feed, and it is the part of the offer we are most confident about. It exists to solve one problem: scope on work like this always moves — something gets deferred because you are not ready to define it, something gets added because a phase went well — and the commercial structure should absorb that instead of turning every change into a renegotiation.
1. Rough order of magnitude, in the assessment
Each module in the sequence carries a cost range and a statement of what would make it land at the top or the bottom of that range. A range you can interrogate is worth more than a precise number nobody can defend.
2. Discovery burns down the integration risk
Before the first module is priced firm, a short discovery step looks at the integrations it depends on — the systems it has to read from, the identities it has to honour, the fields that have to exist. That is where a ROM either narrows or turns out to have been optimistic, and it is far cheaper to find out here.
3. Fixed price, module by module
One statement of work per module, under one master agreement. A module can be added, deferred or dropped on its own — including by you, because you would rather define the requirement properly first — without reopening everything else or renegotiating the relationship.
4. Build in-boundary, prove it, then move on
Each module is implemented where your data already lives — your VPC, your on-premise hardware, or an air-gapped enclave — and proven in production before the next one starts, so there is never a single point where everything can break at once. Inference runs inside that boundary, so what a third-party model provider retains does not arise for the data that matters. Each module operates with a record of what it did and why: that record is what your compliance team reviews, and it is what makes the next module easier to approve than the last.
5. Hand over an operable system
Deployment modes, data boundaries, the audit trail and the governance model are documented rather than tribal — the same material we publish about our own architecture, written for your environment. Who owns and operates the hardware afterwards, and what does or does not recur, is settled in the assessment rather than discovered in month seven.
Where this is already running
We deliver proposal automation and AI products for a defense contractor operating under CMMC 2.0, built entirely inside their boundary — infrastructure their data never leaves. We also run our own company on the same substrate. Both are the evidence behind everything on this page.
Who this is for
Defense contractors under CMMC and 800-171
You hold CUI, DFARS 252.204-7012 is in your contracts, and every AI tool your team wants to use is a boundary decision somebody has to sign. Third-party CMMC certification was suspended on July 13, 2026 pending a program review — but 7012, your NIST SP 800-171 implementation, your SPRS submission and your annual affirmations were not. With no assessor checking the claim, your own attestation is the record, which makes an accurate boundary map worth more than it was before, not less.
The CMMC path →Regulated businesses with the same constraint
Healthcare, finance, legal, and multi-unit operators whose contracts or regulators dictate where data may live. The clause is different; the problem is identical. You need AI in workflows that touch data which cannot be handed to a commercial multi-tenant service, and you need to be able to show exactly what an automated process did and why.
Operations AI →If your data can go anywhere and nobody audits your workflows, you do not need us — buy the commercial tool and get on with it. This is for the case where that is not an option.
Where we stand ourselves
You are about to let a vendor map your boundary, so you are entitled to ask what our own posture is. Stated the same way we state it on our security page, including the parts that are not finished.
- FedRAMPNot authorized
- Cabrillo holds no FedRAMP authorization and has no assessment in progress. The platform runs in AWS GovCloud (US), which is itself FedRAMP High authorized, so deployments inherit its physical and environmental controls — that is inheritance, not authorization of our software.
- SOC 2 Type 1Preparation — no engagement signed
- An internal readiness assessment against all five trust service criteria was completed 2026-05-26 and scored our posture AMBER, with documented gaps. No auditor is engaged and no report exists.
- CMMC Level 2Self-assessment in progress — never assessed by a C3PAO
- Our System Security Plan is documented and the NIST SP 800-171 Rev 2 controls are enumerated in our own compliance system and tracked continuously. Most applicable controls are not yet assessed and some are known non-compliant, with open POA&Ms. We are not CMMC-certified and have never been assessed by a third party.
We are also not a CMMC Third-Party Assessment Organization and are not seeking authorization as one, so nothing we build for you creates a conflict with whoever eventually assesses you. The full compliance roadmap, including the unfinished parts.
Not ready to buy anything? Start here.
These are free, need no signup, and answer the questions that usually come first. They are built on the same sources the assessment uses.
“Can I use Copilot with CUI?”
The AI tool CUI checker: where each assistant sends your prompts, what authorization actually covers it, every verdict cited to a primary source.
Check a tool →“What is our SPRS score?”
The real DoD Assessment Methodology weights, not the one-point-per-control simplification. Answers never leave your browser.
Score yourself →“What will CMMC cost us?”
DoD’s own per-entity estimates by size and assessment path, with the Federal Register cite on every line — the same model behind the figures above.
Price it →Looking for product subscriptions rather than an engagement? Signals, ProposalOS and FinanceOS are licensed separately and priced on the pricing page. The assessment on this page is about integrating AI into your workflows, whether or not any of our products end up in the answer.
Questions buyers ask first
What exactly do I get for $12,500?
A sequenced, costed plan for putting AI into your operation: what to build, in what order, what each module costs, and what has to be true before any of it can start — who can get access and how long that takes, who is allowed to approve what, whether your records are in a state an automated process can act on, and where the system is allowed to run. Delivered as a document your CFO can budget from and your compliance team can put in a file. The deliverables are: A sequenced build plan, with ROM costs and the route to a fixed price; The access and identity plan; The approval map — who is allowed to approve what; The data-readiness verdict; The boundary and attestation pack. Fixed scope. Fixed price. 4–6 weeks elapsed.
Why 4–6 weeks and not two?
Around two weeks of our effort inside a four-to-six week calendar. The extra weeks are not padding. The answers come from your people, your paperwork, and often a provider you outsource to — and none of them are sitting idle waiting for us. There is a harder limit underneath it. Anything that requires us to look inside your live environment needs an account, multi-factor enrolment, a network path and sometimes a managed device — provisioned by people who have their own queue and no contract with us. A two-week engagement can be a document-and-interview exercise honestly, and an inspection only by pretending. So the deliverables say which they are: four are produced from documents, interviews and exports you send us; the data-readiness verdict starts the same way and is confirmed against your live system once access exists.
What is not included?
Five things, named up front because at this price the risk is a scope that quietly absorbs them: travel and time onsite; provisioning our access to your environment; work with, or waiting on, your other providers; producing attestation artifacts for your primes and assessors; building anything, and fixing your data. Each is real work with its own parties and its own clock, so each is scoped and quoted on its own rather than swallowed by a fixed fee.
Why not just quote the implementation?
Because nobody can honestly quote "integrate AI into my company" cold. The scope is not unknowable because the technology is hard — it is unknowable because it depends on who can get access, who is allowed to approve what, whether the records can carry an automated process, and whose paper the whole thing runs on. A quote written before those answers exist is a guess with a number on it. The assessment produces the answers and the price, it is priced as its own deliverable, and it is worth having even if you never hire us for the build.
What happens to the fee if we go ahead?
Credits in full against an implementation engagement. The plan it produces carries rough-order-of-magnitude costs, and a discovery step converts those into a fixed price before you commit to building anything. If you do not go ahead, you keep the document, and it is written to be usable by whoever does the work — including your own team.
Who has to be available on our side?
Fewer people than you fear, but specific ones. Somebody who can describe how work actually moves through the company; somebody who can say who is allowed to approve what, or who can get that decided; whoever administers your identity and network, including an outsourced provider if that is how it works; and somebody who can export a sample of your records. The engagement is scoped so that no single unavailable person stops it — but the calendar is set by them, not by us.
Is this a CMMC assessment?
No. This is an AI integration assessment: what to build, in what order, what it costs, and what has to be true before it can start. Cabrillo Club is not a CMMC Third-Party Assessment Organization, is not seeking authorization as one, and cannot certify anybody. DoD's cost figures appear on this page as budget context, not as a description of what we sell. The rule bars CMMC ecosystem members from assessing an organization they consulted for within the previous 3 years, so certification assessment and readiness work must be bought from different firms. Source: CMMC Final Rule, 89 FR 83221 (32 CFR 170.8(b)(17)(ii)(G)).
CMMC certification is suspended. Does any of this still matter?
Yes. The Department of War suspended CMMC Phase 2 third-party certification requirements on July 13, 2026 pending a program review. DFARS 252.204-7012, your NIST SP 800-171 implementation, your SPRS submission and your annual affirmations were not suspended. With no assessor verifying the claim, your own attestation is the record — which raises, not lowers, the cost of getting an AI boundary decision wrong.
Do we have to be a defense contractor?
No. The same method applies to any business whose data cannot go wherever a vendor would like to put it — healthcare, finance, legal, and multi-unit operators with contractual data-residency constraints. Defense is where the constraint is written down in a clause, which is why the work started there.
Where does the work run?
Inside your boundary, on your infrastructure. That is the point of the sovereign approach: the implementation is built where your data already lives so it does not have to leave to be useful. Deployment modes, data boundaries and the audit architecture are documented on our security and deployment page.
Get the plan, the costs, and the list of what has to be true first.
AI Integration Assessment — $12,500, fixed scope, fixed price, 4–6 weeks. Credits in full against an implementation engagement. Exclusions are written into the scope, not discovered later.
Request the assessment