GO
Overall Score
SignerProof
1. One-liner
Keeps the dated proof behind the CEO’s annual SPRS affirmation, and flags the controls that quietly broke since signing.
2. Trend signal — why now?
Three things moved in the last nine months, and they moved in opposite directions — which is exactly why this is fresh.
The deadline everybody was selling against disappeared. On 13 July 2026 the Department of War suspended the transition to CMMC Phase 2, which had been set for 10 November 2026. Every vendor in this category had built its pitch around “get certified before the deadline.” The deadline evaporated.
The recurring duty did not. DFARS 252.204-7019, 7020 and 7021 still bind. A contractor still needs a current NIST SP 800-171 self-assessment score posted in SPRS, and under 32 CFR § 170.22 a named senior executive — the affirming official — must submit an annual affirmation attesting the organisation “has implemented and will maintain implementation of all applicable CMMC security requirements.” No current affirmation, no award, no option exercise. The pause killed the assessment; it did not kill the signature.
Enforcement got personal and got current. DOJ’s Civil Cyber-Fraud Initiative recovered over $52M in cybersecurity False Claims Act cases in FY2025, with five of nine settlements originating from internal whistleblowers. The anchor case is MORSE: it posted an SPRS score of 104 in January 2021, a third-party gap analysis in July 2022 found the real score was −142, and MORSE did not correct SPRS until June 2023 — three months after being served a subpoena. $4.6M settlement; the whistleblower took $851,000. Honeywell Aerospace settled for $2,042,518 on 1 September 2026, four days before I wrote this.
The gap between what the signer believes and what they can prove is now measurable. A survey of 273 DIB contractors after the pause found 96% were confident their SPRS score would hold up under scrutiny — but only 60% maintained a current submission. Thirty-one percent scored as “Exposed.” That 36-point delta is the product.
Provenance:
- Signal 1 (demand): 273-contractor DIB survey — 96% confident their SPRS score would survive scrutiny vs 60% with a current submission; 31% “Exposed”; 98% took action after the pause — https://www.kiteworks.com/cmmc-compliance/cmmc-2-0-dib-compliance-report/ — 2026
- Signal 2 (economic): MORSE $4.6M FCA settlement for failing to update a wrong SPRS score until after a subpoena ($851K whistleblower share); Honeywell $2.04M settled 2026-09-01; $52M+ FY2025 cyber-FCA recoveries — https://www.justice.gov/opa/pr/alabama-defense-contractor-agrees-pay-507144-resolve-false-claims-act-liability-relating + https://davidkoran.com/sprs-score-accuracy/ — 2026-09-01
- Signal 3 (feasibility): independent 2026 vendor review of CMMC software concludes no vendor is focused on annual-affirmation evidence tracking or SPRS score drift; incumbents priced from ~$8,000/yr (Paramify) to $120K/yr sustainment — https://thedefensecompliancereport.com/best-cmmc-software/ — 2026-06
- Signal 4 (regulatory): CMMC Phase 2 suspended 2026-07-13, but DFARS 7019/7020/7021, SPRS scores and annual affirmations still bind — https://www.governmentcontractslaw.com/2026/07/dod-suspends-cmmc-phase-2-what-happened-what-it-means-and-what-nobody-is-telling-you/ — 2026-07-13 Category: Regulatory arbitrage (a duty survived the deadline that vendors were selling against) + Underserved niche (the enterprise GRC band starts above the 10–50 person contractor)
3. The opportunity
Every incumbent in this market sells getting the score. Nobody sells defending the signature.
That distinction is the whole business. A CMMC/GRC platform — Vanta, Drata, Secureframe, Hyperproof, PreVeil, Paramify — runs you through 110 controls and 320 assessment objectives, produces an SSP and a score, and hands you a number to post in SPRS. Job done, from their point of view. But the affirming official’s exposure doesn’t start at the assessment. It starts the day they sign, and it runs for the next twelve months while the environment drifts underneath them: an admin leaves and their access isn’t revoked, MFA gets disabled on a legacy box during a migration, a new subcontractor touches CUI, a POA&M item silently blows past its 180-day close-out window.
The MORSE facts are the shape of the risk exactly. The failure wasn’t the original bad score — it was the 11 months between learning the score was wrong and fixing SPRS. That’s not an assessment problem. That’s a monitoring-and-record problem, and it is the specific thing FCA “reckless disregard” attaches to.
Why the incumbents structurally won’t build it: a GRC platform that continuously tells you “the score you posted is now wrong” is selling insurance against its own output. It undermines the assessment it just charged you for, and it manufactures the written record a plaintiff’s lawyer or a qui tam relator would subpoena. That’s the vendor-conflict-of-interest gap — the incumbent is the party whose work product would be impeached.
And the pause made it worse for them, not better. Their entire funnel was deadline-driven. With Phase 2 suspended, their urgency pitch is dead — while the annual signature keeps coming due regardless.
4. Target market
- Primary customer: The affirming official at a 10–75 person DoD subcontractor handling CUI — typically the CEO/owner at a machine shop, or the FSO/ops lead at an engineering or specialty-manufacturing firm. Roughly $2M–$40M revenue. The person whose name, not just the company’s, is on the SPRS record.
- Why they buy: Because the signature is personal. As the trade press puts it, the affirming official “is staking their name and career on the accuracy of a statement that their organization continuously meets every applicable security requirement,” and is “personally exposed, independent of any corporate liability.” A 42-person machine shop, as one analysis noted, “is not going to out-recruit Lockheed Martin for a CMMC-cleared security engineer.” So the owner signs a document they cannot personally verify, once a year, under penalty of treble damages.
- Rough TAM reasoning: The DIB is ~200,000+ registered suppliers; projections put 33,000–44,000 (15–20%) exiting between 2025 and 2027 over exactly this cost burden. The survivors are the market. Even a narrow read — the small-to-mid CUI-handling subcontractors who must affirm annually — is comfortably in the tens of thousands of firms. I need ~400 of them.
- Why now for them: 40% of Level-2-focused small contractors have already spent >$100,000. They’ve paid for the assessment; they cannot pay $120K/yr sustainment on top. The pause gave them breathing room on certification and simultaneously left them holding an annual personal liability with no tooling and a shrinking consultant budget.
5. Product sketch (MVP)
- Signature packet. One dated, immutable bundle per affirmation: the score as posted, the assessment date and scope, per-control evidence with timestamps, and who attested what. This is the artifact you hand a DOJ investigator or an acquirer’s diligence team.
- Drift watch. Read-only connectors to M365/Entra, Google Workspace, and the endpoint/MDM tool the shop already runs. Flags the handful of changes that actually move the SPRS number — MFA disabled, privileged account added, offboarded user still active, unmanaged device touching the CUI enclave.
- Score delta. “Your posted score is 88. Based on 4 changes since 12 March, your defensible score today is 78.” Weighted per the real 5/3/1 deduction scheme, not a generic control checklist.
- POA&M clock. Tracks each open item against its 180-day conditional window, with escalation before the window closes — not after.
- Duty-to-correct alert. The MORSE trigger. When the delta crosses a threshold, it tells the affirming official plainly: you now have knowledge, and the clock on correcting SPRS has started.
- Affirmation brief. Two pages the signer reads before signing: what’s proven, what’s assumed, what’s unresolved. Converts a blind signature into a documented one.
- Evidence requests. Chases the named human for the missing screenshot or policy attestation, so the record closes without the CEO doing the chasing.
6. AI angle — what’s load-bearing
Two jobs that are genuinely hard without a model, and one that isn’t.
Mapping messy config state to control objectives. 110 controls decompose into 320 assessment objectives written in NIST prose. Turning “conditional access policy 7 was modified to exclude the service-accounts group” into “this affects AC.L2-3.1.1 and AC.L2-3.1.2, weighted −5 each, and here is why” is judgment work across heterogeneous tenant configs. Hand-coded rules cover the top 20 and then rot with every vendor UI change.
Drafting the defensible narrative. The value in the signature packet isn’t the raw log — it’s the plain-English account of why a control was considered met on the affirmation date, written so it survives being read back in a deposition. That’s summarisation against a legal standard, and it’s the part small contractors currently pay a consultant $200/hr to write.
What isn’t AI: the connectors, the deduction arithmetic, and the clock. Those are plumbing. If you removed the model you’d still have a product — a worse, more brittle one that needs a human analyst per customer, which is precisely the economics that make incumbents charge $120K/yr. The AI is what lets one operator serve 400 shops. That’s load-bearing enough for me, but I’m not going to pretend the model is the moat.
7. Localization angle
N/A — this is a US-only play by construction. The duty exists solely under DFARS and 32 CFR § 170.22, the record lives in SPRS at sprs.csd.disa.mil, and the liability is US False Claims Act. There is no localisation wedge; the regulatory specificity is the wedge. The nearest analogue elsewhere — UK Cyber Essentials Plus, EU NIS2 — has no personal-signature-plus-treble-damages mechanic, so the product doesn’t port.
8. Business model — path to $1M–$5M ARR
- Pricing: $400/mo base for the affirming official’s record on a single CUI enclave, $700/mo with drift connectors and the POA&M clock. Annual prepay discount, because the duty is annual and that’s how these firms budget.
- ACV: ~$6,000. Deliberately set below the $8,000/yr entry point of the cheapest published CMMC tool (Paramify) and an order of magnitude under the $120K/yr sustainment figure. This is a line item an owner approves without a board conversation.
- Rough math to $1M ARR: 167 customers × $500/mo × 12 = $1.0M.
- Rough math to $5M ARR: ~700 customers at a $7,200 blended ACV. Requires the multi-entity tier (holding companies with several CAGE codes) and an MSP/consultant reseller motion — the ~90 APEX Accelerators and the regional MSPs already serving these shops become the channel rather than the competition.
- Expansion path: second and third enclaves; per-affirmation packet fees at renewal; an acquirer-diligence export (the Holland & Knight piece flags affirmation history as an M&A exposure for acquirers, which is a second buyer with a bigger wallet); and a prime-contractor view for flow-down verification of subs under DFARS 7020.
9. Go-to-market wedge — first 100 customers
- Mine SPRS staleness against SAM.gov. SAM.gov registration data is public and filterable by NAICS and size. Cross-reference defense-relevant NAICS codes against firms whose posted assessment date is aging toward the three-year limit. That produces a named list with a dated, verifiable hook: “your assessment date is 14 months old and your affirmation is due.” Not a cold pitch — a fact about their record.
- The 90+ APEX Accelerators. DoD-funded, present in 49 states, free to contractors, and already counselling on CMMC. They cannot recommend a $120K platform to a 30-person shop in good conscience, which is why a $500/mo tool is a gift to their counsellors. Run a webinar with three of them; each has a standing mailing list of exactly my customer.
- Whistleblower-case-driven outreach. Every FCA settlement is a public DOJ press release naming a contractor and its failure mode. When one lands — they’re landing roughly monthly — a short, factual breakdown of what the affirming official should have had on file, mailed to a segment list, converts on genuine fear. The MORSE and Honeywell facts sell this product without embellishment.
- The FSO and GovCon communities. NDIA chapters, the r/NISTControls and r/govcon communities, and the CMMC-focused LinkedIn groups are where these people already argue about affirmation liability. Show up with the score-delta tool as a free single-tenant check, not a pitch.
- MSP channel. Regional MSPs serving defense shops are asked to “handle CMMC” and are terrified of owning the liability. White-label the drift watch so they can sell monitoring without signing anything themselves.
10. Build complexity — justification
Medium. The connectors (Entra/M365 Graph, Google Workspace, common MDM) are off-the-shelf read-only OAuth integrations, and the SPRS deduction arithmetic is published and deterministic. The genuine work is the control-mapping layer — encoding 320 assessment objectives well enough that a drift signal maps to a defensible delta — plus an append-only evidence store that a lawyer would accept as tamper-evident. Call it 14–18 weeks for a strong pair, with the first 6 producing a manual-import version that already sells. Handling CUI itself is explicitly out of scope for v1: the product reads configuration metadata, not controlled content, which keeps FedRAMP off the critical path. That scoping decision is what makes this Medium rather than High, and it’s non-negotiable — the moment you store CUI you inherit an authorisation problem that kills the timeline.
11. Gating checklist
| Gate | Pass? | Note |
|---|---|---|
| Legal in target market | ✅ | Read-only monitoring and record-keeping. No regulated advice; ship with clear “not legal advice” framing and let the customer’s counsel own the affirmation decision. |
| Ethical — no harm / dark patterns | ✅ | The product’s bias is toward telling the signer an uncomfortable truth before they sign. Selling on FCA risk is fair only if the facts are cited, not inflated — the DOJ releases are public and quoted as-is. |
| Market exists (evidence above) | ✅ | 273-contractor survey, $52M FY2025 recoveries, published incumbent pricing, 90+ APEX Accelerators counselling the segment. |
| 1–5 person team can build this | ✅ | Two people, 14–18 weeks. Domain advisor needed. |
| Launchable with <$50K / ₹40L | ✅ | Well under. Main cost is a domain-expert advisor and inference. |
All five pass.
12. Feasibility score
| Axis | Weight | Score | Notes |
|---|---|---|---|
| Problem intensity | 20 | 17/20 | Personal FCA liability with treble damages, signed annually by a named human who cannot verify what they’re signing. Not quite 18+ because the pause removed the acute deadline — the pain is real but its timing is now diffuse, spread across each firm’s own affirmation anniversary. |
| Demand evidence | 15 | 13/15 | Strong and multi-sourced: the 96%-vs-60% confidence gap, 40% having spent >$100K, live monthly settlements, published incumbent pricing. Docked because the confidence gap proves exposure, not willingness to pay for this specific artifact — 96% confident people don’t always buy proof. |
| Build feasibility | 15 | 11/15 | Connectors and arithmetic are standard; the 320-objective mapping layer is real work and needs domain expertise to be trustworthy. 14–18 weeks, not 6. |
| Distribution clarity | 15 | 12/15 | SAM.gov gives a named, filterable list with a dated hook, and APEX Accelerators are a warm DoD-funded channel. Held below 13 because government-adjacent channel partners move slowly and the buyer is a busy owner-operator. |
| Revenue mechanics | 15 | 12/15 | $6K ACV against an $8K–$120K incumbent range is a comfortable, defensible position, and 167 customers for $1M is achievable. Docked because ACV in this segment is pressured by exactly the budget scarcity that creates the opportunity. |
| Time to first revenue | 10 | 7/10 | A manual-import v1 can pre-sell in ~8 weeks, but govcon owners buy on their affirmation anniversary, which staggers the funnel and slows the first cohort. |
| Defensibility | 10 | 5/10 | Honest score. The control-mapping corpus and the accumulating evidence history compound into workflow lock-in — you don’t move your affirmation record mid-cycle. But an incumbent could bolt this on if they decided to impeach their own assessments, and the regulatory knowledge is learnable. Execution moat, not a structural one. |
| Total | 100 | 77/100 |
13. Qualitative modifiers
Founder-fit tags
technical-heavy · domain-expertise-required
You need someone who can build OAuth connectors and an append-only store, paired with someone who genuinely knows NIST 800-171 scoring — an ex-FSO, a C3PAO assessor, or a govcon compliance consultant. Do not attempt this without the second person; the mapping layer is where the product’s credibility lives, and getting it wrong in this market is fatal.
Key assumptions to validate (3–5)
- Assumption: Affirming officials perceive personal liability sharply enough to buy a tool the company hasn’t budgeted for. How to test: 30 calls with CEOs/FSOs at 10–75 person CUI-handling subs. Ask directly: “when you signed last time, what did you personally read first?” Listen for whether they hesitated. If they shrug, the emotional premise is wrong and the score drops hard.
- Assumption: The drift signal is real — meaningful SPRS-relevant changes actually occur between annual affirmations. How to test: instrument 5 friendly shops read-only for 60 days and count scoring-relevant changes. Fewer than ~3 per shop per quarter and the “watch” half of the product is theatre; sell the packet alone.
- Assumption: $500/mo clears the bar where $8K/yr doesn’t. How to test: price-test both against the same list segment. Watch whether the objection is price or “we already pay someone for CMMC.”
- Assumption: APEX Accelerators will co-market a commercial tool. How to test: approach 5 directly. They’re DoD-funded and may be constrained from endorsing vendors — find out in week one, because two of my three channels lean on institutional goodwill.
Risk flags
- Regulatory reversal risk. The Phase 2 pause is under review by a Reform Task Force. If the affirmation requirement itself is softened or the annual cadence relaxed, the recurring duty — the entire retention thesis — weakens. This is the risk that would hurt most, and it’s live right now, not hypothetical.
- Incumbent absorption. PreVeil, Summit7 or a GRC platform could ship a “continuous affirmation” module. The conflict-of-interest argument says they won’t want to, but a well-funded player under funnel pressure from the dead deadline might do it anyway.
- Liability-adjacent positioning. Selling “here’s proof your posted score is wrong” creates discoverable records. That’s the product’s value and its danger — some customers will refuse precisely because they’d rather not know. Expect a real segment to self-select out.
- Segment shrinkage. 33,000–44,000 firms are projected to exit the DIB by 2027. The market is contracting while I sell into it; the survivors are better customers, but there are fewer of them each quarter.
14. Structured verdict
Score: 77/100
Verdict: GO
Confidence: Medium
Best-fit builder: Technical founder paired with an ex-FSO or C3PAO assessor
Time to revenue: 8–12 weeks (manual-import v1, pre-sold)
Capital to launch: $15–25K
Top 3 assumptions to validate first:
1. Personal-liability fear converts to purchase — 30 affirming-official calls, listen for hesitation at signing
2. Drift is measurable — instrument 5 shops read-only for 60 days, count scoring-relevant changes
3. $500/mo clears where $8K/yr doesn't — split price test on one list segment
Kill criteria:
- Abandon if <5 of 30 affirming officials can describe what they reviewed before last signing (means the liability is abstract to them, and the wedge is emotional fiction)
- Abandon if instrumented shops show <3 scoring-relevant changes per quarter (no drift = no recurring product, only a one-time packet)
- Abandon if the Reform Task Force removes or materially relaxes the annual affirmation requirement
15. Next step — 1-week validation sprint
- Day 1–2: Build the list. Pull SAM.gov registrations for defense-relevant NAICS codes at 10–75 employees, and identify firms with aging assessment dates. Target 200 named affirming officials with a verifiable, dated hook about their own record.
- Day 3–4: Thirty calls. One question carries the week: “When you signed the affirmation last time, what did you personally read before signing?” Count how many hesitate, admit they signed on IT’s word, or reference MORSE unprompted. Simultaneously ask 5 shops for 60-day read-only instrumentation access — the ask itself tests trust.
- Day 5: Decide. Go if ≥12 of 30 describe signing without independent verification AND ≥5 accept a paid pilot at $500/mo. No-go if the dominant response is “our MSP handles that” without follow-up interest — that means the liability hasn’t landed personally, and this product only works if it has.
The falsifiable result is the pilot count, not the sentiment. Twelve people admitting discomfort is interesting; five people paying before the software exists is the only evidence that matters.
Interested in a detailed proposal?
Get a deep-dive with market research, competitive analysis, and implementation roadmap.
Contact usinfo@startupbasket.ai