For a defence supplier, ITAR and CMMC compliance is no longer a policy exercise, it is a test of whether you can still bid. The lowest-cost way to pass it in 2026 is to run your security operations and your controls on a sovereign system you own: a fully offline, air-gapped deployment keeps ITAR technical data and controlled unclassified information on authorised infrastructure, produces the DEFCON 658 and CMMC Level 2 evidence an assessor asks for, and removes the cloud SIEM and GRC subscriptions that could never lawfully hold that data in the first place.
Why ITAR and CMMC compliance is a contract eligibility test in 2026
The rules moved from paper to procurement this year. In the United States, the CMMC final rule took effect on 10 November 2025, and industry guidance now points defence contractors that handle controlled unclassified information toward a third-party CMMC Level 2 assessment by 10 November 2026. In the United Kingdom, the Ministry of Defence brought its Cyber Security Model version 4 into force on 3 November 2025, underpinned by Defence Standard 05-138 Issue 4 and enforced through the DEFCON 658 contract condition, so a single supplier standard now runs across MoD contracts and subcontracts. A multi-billion-pound defence technology framework also opened to SME suppliers this year, which pulls more small firms into the same controlled-data obligations at once.
The point of all this is eligibility. Miss the standard and the exposure is not a line on a spreadsheet, it is penalties, debarment and lost contracts. For a supplier whose revenue depends on the framework, that is the whole business, so the question stops being whether to comply and becomes how to comply without renting a cost base you cannot sustain.
What the cloud route costs you, and why it does not fit
The default answer a supplier reaches for is a stack of cloud tools: a hosted SIEM to watch the network, an endpoint agent that reports to a vendor cloud, a GRC subscription to track the controls, and a managed detection retainer on top. Two problems follow. The first is money. A hosted SIEM bills by the volume of data you ingest, endpoint tools bill per device, GRC platforms bill per seat, and the retainer renews every year, so the meter never stops and grows with you. The second problem is lawful fit. ITAR technical data and controlled unclassified information cannot simply sit in a shared, cross-border cloud, and if a control asks you to evidence where that data went, egress to a third party is exactly the answer you do not want to give. You end up paying for tooling you then cannot lawfully point at the data it is meant to protect.
How Phylax and Nomos run the whole thing on hardware you own
Mickai is sovereign, on-device AI: it runs offline on your own hardware, and every AI action is sealed under post-quantum cryptography into a signed audit record we call the Open Audit Record. The work is done by studios, and a studio is a ready-made application for one business function that runs inside a single system. Two of them carry most of this brief.
Phylax is our security operations studio, a sovereign SOC in a box that correlates host, network and identity telemetry into explained detections, triages and enriches each alert, and seals a regulator-ready incident timeline, fully offline and air-gapped, with any containment action left as an operator-gated step. Nomos is our compliance studio, which runs a live statute crosswalk across frameworks including ITAR, with control-gap assessments and a sealed audit trail, again fully offline. Together they replace the hosted SIEM and the GRC subscription with one system, sitting on infrastructure you control, where the controlled data never crosses a network boundary.
Codex, the studio for drafting and managing structured technical and invention disclosures on device, keeps the other sensitive asset in scope where it belongs: export-controlled technical data and proprietary IP are drafted and held on your own hardware, sealed to the audit record, rather than pushed into a cloud editor. The Assistant that drives all of this runs on your own brain, built on your own data, so nothing is sent out to be answered.
The evidence CMMC and DEFCON 658 want, generated not commissioned
Both regimes are, in the end, evidence regimes. CMMC Level 2 turns on a documented system security plan and proof that the controls are implemented and monitored. DEFCON 658 and CSMv4 turn on a cyber risk profile and the assurance behind it. The expensive way to produce that evidence is to commission it: consultants to write it up, a platform to store it, and a scramble every time an assessor asks. The sovereign way is to generate it as a by-product of the work. Every detection Phylax raises and every control Nomos assesses is sealed to the Open Audit Record as it happens, so the file the assessor wants is already prepared.
To be precise about the boundary: the system produces the evidence that supports a CMMC Level 2 assessment and DEFCON 658 assurance, it does not issue the certificate. That remains the assessor's to award, on evidence you now hold rather than evidence you have to reconstruct under time pressure.
What you replace, and what you save
Here is the swap in concrete terms, using the tools defence suppliers most often run today and the meter that disappears in each case.
| What you run today | What it costs you | With Mickai |
| --- | --- | --- |
| Cloud SIEM and endpoint tooling (Splunk, Microsoft Sentinel, CrowdStrike, IBM QRadar) | Per-ingest and per-device fees, on data that cannot lawfully sit in a shared cloud | Phylax correlates the same telemetry offline and air-gapped, with no data-volume meter |
| GRC and compliance SaaS (OneTrust, Vanta, Drata, LogicGate) | Per-seat annual subscriptions renewed every year | Nomos runs the ITAR and CUI crosswalk on device, with no per-seat fee |
| Outsourced managed detection and cyber consultants | An ongoing retainer for monitoring and readiness advice | The SOC and the control assessment sit in house on hardware you own |
| Cloud editors and stores for technical data packages | Per-user fees, and export-controlled data leaving the building | Codex drafts and holds technical and invention disclosures on device |
| Cross-border cloud processing of controlled data | Egress charges and an ITAR or CUI exposure you cannot evidence away | Nothing leaves authorised infrastructure, so there is no egress and no transfer to explain |
How to move controlled data onto a sovereign system
The migration is a short, ordered sequence rather than a rip and replace.
- Inventory where ITAR technical data and controlled unclassified information sit today, including any cloud SIEM, GRC seats and shared drives that touch them.
- Stand the system up on your own hardware, air-gapped where the contract demands it, so no controlled data crosses a network boundary.
- Point Phylax at host, network and identity telemetry and let it correlate detections offline, with any containment action left as an operator-gated step.
- Run the Nomos crosswalk against ITAR, CUI, DEFCON 658 and CMMC Level 2 controls, and capture the gaps as a worklist you can close and re-check.
- Seal every assessment, detection and disclosure to the Open Audit Record, so the file an assessor asks for is already prepared and time-stamped.
Frequently asked questions
Does Mickai make my firm CMMC or DEFCON 658 certified?
No. It runs offline on your own hardware and produces the evidence that supports a CMMC Level 2 assessment and DEFCON 658 assurance, sealed to the Open Audit Record. The certificate itself is awarded by the assessor, not by the software, which is why we are careful to say the system supports the examination rather than passing it for you.
Can it run fully air-gapped for ITAR and CUI?
Yes. Phylax and Nomos are built to run fully offline and air-gapped, so ITAR technical data and controlled unclassified information stay on authorised infrastructure and never cross a network boundary. Any containment or remediation step is operator-gated, so the system advises and detects while a human stays in control of the action.
What subscriptions does this actually replace?
The cloud SIEM and endpoint tooling (Splunk, Microsoft Sentinel, CrowdStrike, IBM QRadar) and the GRC subscriptions (OneTrust, Vanta, Drata, LogicGate), plus outsourced managed detection retainers. The per-ingest, per-seat and per-device meters stop, because the same detections and control assessments now run on hardware you own rather than in a vendor cloud.
We are an SME being pulled into the supply chain. Is this only for primes?
No. The same system runs on hardware a smaller supplier can own, which is the point of it: an SME can meet the same controlled-data obligations as a prime without standing up a cloud security budget it cannot sustain across a contract. The cost moves from a recurring subscription into a capability you keep.
Top comments (0)