🧬 Interested in pharma, biotech and medical device news? Visit PharmaDeviceNews.com →

Beryllium joins DIU Certificate Shepherd initiative as Pentagon pauses CMMC Phase II

Beryllium will provide a Microsoft-based managed enclave to DIU portfolio companies, although federal CMMC reforms could reshape certification demand and programme economics.

Private cybersecurity company Beryllium InfoSec, Inc. has been selected to support the Defense Innovation Unit’s Certificate Shepherd initiative, which is intended to accelerate Cybersecurity Maturity Model Certification Level 2 readiness among commercial technology companies seeking to enter the U.S. defence market. Beryllium was one of two companies chosen and will provide the programme’s sole Microsoft-based solution through its Cuick Trac managed enclave platform. The initiative could reduce the cybersecurity infrastructure and documentation burden that prevents smaller technology companies from handling Controlled Unclassified Information and progressing into the Defense Industrial Base. However, no programme value, participant volume, delivery schedule or guaranteed certification outcome was disclosed. The selection also arrives three days after the Pentagon suspended the planned expansion of CMMC Phase II, creating a tension between continuing demand for secure environments and uncertainty over the future certification model.

What has Beryllium been selected to deliver through the DIU Certificate Shepherd initiative?

The Certificate Shepherd initiative will provide participating Defense Innovation Unit portfolio companies with access to secure infrastructure and advisory support intended to improve their readiness for CMMC Level 2 requirements.

Beryllium will deliver onboarding assistance, compliance advisory services and access to the Cuick Trac Managed Enclave. The platform is designed to isolate Controlled Unclassified Information within a defined security boundary, reducing the number of systems, applications, devices and users that must be included in a contractor’s compliance environment.

The initiative is being facilitated through the One Nation Innovation Other Transaction Agreement framework. Other Transaction Agreements provide the U.S. government with a more flexible route for prototype and innovation work than conventional Federal Acquisition Regulation contracts. The structure is frequently used when agencies want to engage non-traditional companies that may be discouraged by lengthy procurement and compliance processes.

Only two providers were selected for Certificate Shepherd. Beryllium said Cuick Trac is the programme’s sole Microsoft-based option, giving it a differentiated position among DIU portfolio companies already operating within Microsoft environments.

Selection does not mean that Beryllium has received an unrestricted government-wide contract or that all DIU portfolio companies will adopt Cuick Trac. The announcement does not identify the second provider, the number of participating companies, individual task values, the initiative’s total budget or whether DIU will subsidise the full cost of each deployment.

The immediate opportunity will therefore depend on how many portfolio companies are referred to Beryllium, how quickly they can be onboarded and whether participation creates continuing commercial relationships after the initial readiness work.

Why does a managed enclave reduce the CMMC burden without transferring all contractor responsibility?

CMMC Level 2 is based on the 110 security requirements contained in National Institute of Standards and Technology Special Publication 800-171 Revision 2. Those requirements cover areas including access control, configuration management, incident response, audit logging, authentication, physical protection and system integrity.

For a small software, engineering or manufacturing company, applying those controls across an entire corporate network can be costly and disruptive. A managed enclave provides an alternative by restricting Controlled Unclassified Information to a smaller, purpose-built environment.

Cuick Trac operates within Microsoft Azure Government and Microsoft GCC High. It incorporates preconfigured security tooling, monitoring, audit logging, managed endpoints and compliance documentation. Beryllium says the platform is designed to cover more than 80% of CMMC Level 2 assessment objectives, allowing customers to inherit controls that are managed centrally rather than building every technical capability themselves.

The platform also uses a display-only virtual desktop architecture intended to prevent Controlled Unclassified Information from being downloaded to unmanaged devices. This approach can narrow the assessment boundary and reduce the risk that sensitive information spreads across ordinary corporate email, laptops, mobile devices or file storage.

See also  How the U.S. multicloud shift is accelerating Oracle’s rise as a hyperscaler alternative

Inherited controls do not transfer complete responsibility to Beryllium. Customers must still understand where controlled information enters their organisation, who can access it, how users are trained and which policies remain their responsibility. Personnel security, physical access, incident reporting, supplier management and business processes can remain outside the enclave provider’s control.

A managed enclave is consequently a shared-responsibility model rather than a certification shortcut. Its commercial value depends on making the division of responsibilities sufficiently clear that a contractor can produce evidence during an assessment without discovering late-stage control gaps between its own operations and the managed platform.

Beryllium itself achieved CMMC Level 2 certification using Cuick Trac in 2025. That provides an internal proof point for the environment, but it does not guarantee that every customer will pass because assessment outcomes also depend on how each organisation configures and operates its remaining controls.

How does the Pentagon’s CMMC Phase II suspension change the value of Beryllium’s selection?

The timing of the announcement is unusually significant. On July 13, 2026, the U.S. Department of War immediately suspended the transition to CMMC Phase II, which had been scheduled to take effect on November 10.

Phase II would have expanded mandatory third-party assessments for applicable contractors handling Controlled Unclassified Information. The department said it was pausing the expansion because compliance costs and administrative burdens risked pushing small, medium-sized and non-traditional businesses out of the defence supply chain.

A CMMC Reform Task Force is conducting a 60-day review intended to align the programme with the Pentagon’s wider acquisition transformation agenda. That review is expected to consider how cybersecurity assurance can be maintained while reducing the cost and complexity faced by commercial suppliers.

The suspension does not remove existing cybersecurity obligations. Phase I self-assessments remain in place, and contractors handling Controlled Unclassified Information continue to face requirements under DFARS 252.204-7012 and NIST SP 800-171 Revision 2. The department also plans to use selected government-led assessments during the review period.

This distinction preserves much of the operational need addressed by Certificate Shepherd. DIU portfolio companies still require protected environments if they are to receive or generate Controlled Unclassified Information, regardless of whether a third-party CMMC certificate is immediately required.

The pause could nevertheless affect the pace of commercial demand. Some contractors may defer external certification spending while waiting for the reform task force’s recommendations. Assessment volumes could be lower than previously expected, and providers whose revenue models depend heavily on mandatory third-party certification could face delayed demand.

Beryllium may be comparatively well positioned if the review favours scalable managed environments that reduce barriers for smaller suppliers. Cuick Trac’s value proposition centres on inherited controls, a restricted compliance boundary and operational support, all of which align with the Pentagon’s stated objective of lowering compliance burdens without abandoning cybersecurity.

The risk is that the reformed programme changes assessment requirements, allows wider use of self-attestation or introduces different technical standards. Beryllium would then need to adapt its platform and advisory services to the revised framework.

Why is Cuick Trac’s Microsoft architecture strategically important for DIU portfolio companies?

Many commercial technology companies already use Microsoft identity, productivity and cloud tools, but ordinary commercial Microsoft environments may not provide the configuration and controls needed for sensitive defence information.

Cuick Trac places the controlled environment within Azure Government and Microsoft GCC High, which are designed for U.S. government and regulated-sector workloads. This can reduce the amount of unfamiliar infrastructure a Microsoft-oriented company must introduce when preparing to work with defence customers.

See also  Can Greenlane Holdings Inc. turn Berachain’s HONEY collateral expansion into a credible digital asset treasury signal?

The platform has been assessed as FedRAMP Moderate Equivalent. That designation is commercially relevant but should not be confused with a direct FedRAMP authorisation issued to a cloud service through the federal authorisation process. Equivalency indicates that the environment has been assessed against the relevant Moderate control baseline through an approved independent assessment process.

Being the programme’s sole Microsoft-based option may give Beryllium access to DIU companies whose existing systems, employees and development processes are already closely aligned with Microsoft technology. Integration familiarity could shorten deployment and reduce user training requirements.

The architecture also creates concentration considerations. Customers may become dependent on Beryllium’s configuration, Azure Government services and GCC High licensing. Data migration, interoperability with non-Microsoft development tools and the recurring cost of specialised cloud services will influence whether the enclave remains economical after the initial readiness programme.

For early-stage defence technology companies, the more important test will be whether the enclave can protect controlled information without slowing software development, collaboration or customer delivery. A secure environment that becomes operationally restrictive could replace a compliance barrier with a productivity barrier.

How does the DIU initiative build on Beryllium’s earlier U.S. Army NCODE selection?

The Certificate Shepherd selection follows Beryllium’s May 2026 inclusion in the U.S. Army’s Next-Gen Commercial Operations in Defended Enclaves pilot programme, known as NCODE.

NCODE is a $49 million initiative intended to provide eligible defence contractors with access to managed enclave environments and cybersecurity resources. Beryllium was selected as one of a limited number of Verified External Service Providers permitted to compete for task orders under the programme.

The two selections address related parts of the same defence supply-chain problem. NCODE focuses on helping eligible contractors implement NIST SP 800-171 requirements through secure external environments, while Certificate Shepherd targets DIU portfolio companies attempting to progress towards CMMC Level 2 readiness.

Together, the programmes give Beryllium two government-linked channels through which Cuick Trac can reach smaller defence contractors and commercial technology companies. They also provide external validation that federal organisations consider managed enclaves a potentially useful response to the cost and complexity of protecting Controlled Unclassified Information.

Neither selection guarantees material revenue. Under NCODE, Beryllium must compete for task orders, while the Certificate Shepherd announcement provides no financial terms. The strategic value currently lies in access, credibility and the opportunity to demonstrate measurable results.

If successful, the programmes could establish Cuick Trac as infrastructure used before a commercial company becomes a large defence contractor. That creates the possibility of retaining customers as their government work expands and their controlled-data requirements become more complex.

What commercial and execution risks remain undisclosed in the Certificate Shepherd announcement?

Beryllium is privately held and does not publish detailed financial statements, segment revenue or customer concentration data. The announcement therefore provides limited visibility into the economic importance of Certificate Shepherd.

There is no disclosed contract value, minimum purchase commitment or guaranteed number of customers. It is also unclear whether Beryllium will be paid directly through the initiative, through participating companies or through individual orders issued under the One Nation Innovation framework.

Onboarding capacity could become an execution constraint if multiple companies require simultaneous data-flow mapping, policy development, endpoint configuration and audit preparation. Compliance advisory work can be labour-intensive even when the underlying infrastructure is standardised.

See also  Regnology upgrades Ascend platform with agentic AI layer, targeting autonomous regulatory reporting for banks and supervisors

Beryllium will also need to maintain the platform as security requirements evolve. Continuous monitoring, vulnerability remediation, cloud configuration, audit evidence and incident response must remain effective after the initial deployment. A managed enclave that is assessment-ready at installation still requires continuing operational discipline.

Competition extends beyond the second Certificate Shepherd provider. Managed security companies, cloud consultants, specialised enclave providers and large defence technology integrators are all pursuing demand created by CMMC and NIST SP 800-171 requirements.

Beryllium’s differentiation will depend on deployment speed, customer outcomes and total cost rather than selection language. The company’s existing certification and government programme access are useful credentials, but they do not establish market leadership without evidence of recurring adoption.

Which milestones will show whether Beryllium can turn federal selection into scalable adoption?

The first measurable indicator will be the number of DIU portfolio companies onboarded through Certificate Shepherd. Beryllium will also need to demonstrate that participating companies reduce their time and cost to readiness compared with building independent compliance environments.

Assessment results will matter, although the Pentagon’s reform review may change which assessment route becomes relevant. Successful Level 2 self-assessments, government reviews or eventual third-party certifications would provide stronger evidence than platform deployment alone.

Commercial proof would include disclosed task orders, recurring enclave subscriptions, customer renewals and expansion from initial DIU work into longer-term defence contracts. Progress under the U.S. Army NCODE programme would provide a second indication of whether federal selection is translating into revenue.

The 60-day Pentagon review is the largest external variable. A reformed framework that retains NIST SP 800-171 while encouraging managed, scalable security boundaries could strengthen Beryllium’s positioning. A substantial reduction in certification requirements could delay some demand, although underlying obligations to protect Controlled Unclassified Information would remain.

Beryllium has gained access to a strategically relevant customer group at a moment when the government is actively reconsidering how commercial innovators enter the defence supply chain. The selection becomes commercially significant only if Cuick Trac can demonstrate that lower compliance friction does not come at the expense of security, accountability or operational performance.

What are the key takeaways from Beryllium’s DIU Certificate Shepherd selection?

  • Beryllium InfoSec was one of two providers selected for the Defense Innovation Unit’s Certificate Shepherd initiative.
  • Cuick Trac will be the programme’s sole Microsoft-based managed enclave solution.
  • Participating DIU companies will receive enclave access, onboarding assistance and CMMC Level 2 readiness support.
  • The platform operates within Azure Government and Microsoft GCC High and has FedRAMP Moderate Equivalent status.
  • Managed enclaves can narrow the compliance boundary, but customers retain responsibility for organisational and operational controls.
  • The Pentagon’s suspension of CMMC Phase II could delay mandatory third-party assessments while leaving Phase I and NIST SP 800-171 obligations in force.
  • The government’s focus on reducing compliance barriers may favour Beryllium’s inherited-control and managed-infrastructure model.
  • No programme value, customer volume, delivery schedule or guaranteed revenue was disclosed.
  • DIU onboarding volumes, NCODE task orders, assessment outcomes and the Pentagon’s 60-day reform review are the next measurable catalysts.

Discover more from Business-News-Today.com

Subscribe to get the latest posts sent to your email.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts