MICKAI®ArticlesITAR and CMMC Bite in 2026: How U…
Article · 30 July 2026

ITAR and CMMC Bite in 2026: How UK Defence Suppliers Keep Controlled Data Sovereign and Stay Contract Eligible

Keep controlled technical data on hardware you own, produce the CMMC and DEFCON 658 evidence, and drop the cloud SIEM and GRC subscriptions.

Author
Micky Irons
Published
30 July 2026
Follow Micky Irons
LinkedInX
itar-compliancecmmcdefence-suppliersdata-sovereigntysovereign-ai
ITAR and CMMC Bite in 2026: How UK Defence Suppliers Keep Controlled Data Sovereign and Stay Contract Eligible

For a defence supplier, ITAR and CMMC compliance is no longer a policy exercise, it is a test of whether you can still bid. The lowest-cost way to pass it in 2026 is to run your security operations and your controls on a sovereign system you own: a fully offline, air-gapped deployment keeps ITAR technical data and controlled unclassified information on authorised infrastructure, produces the DEFCON 658 and CMMC Level 2 evidence an assessor asks for, and removes the cloud SIEM and GRC subscriptions that could never lawfully hold that data in the first place.

Why ITAR and CMMC compliance is a contract eligibility test in 2026

The rules moved from paper to procurement this year. In the United States, the CMMC final rule took effect on 10 November 2025, and industry guidance now points defence contractors that handle controlled unclassified information toward a third-party CMMC Level 2 assessment by 10 November 2026. In the United Kingdom, the Ministry of Defence brought its Cyber Security Model version 4 into force on 3 November 2025, underpinned by Defence Standard 05-138 Issue 4 and enforced through the DEFCON 658 contract condition, so a single supplier standard now runs across MoD contracts and subcontracts. A multi-billion-pound defence technology framework also opened to SME suppliers this year, which pulls more small firms into the same controlled-data obligations at once.

The point of all this is eligibility. Miss the standard and the exposure is not a line on a spreadsheet, it is penalties, debarment and lost contracts. For a supplier whose revenue depends on the framework, that is the whole business, so the question stops being whether to comply and becomes how to comply without renting a cost base you cannot sustain.

What the cloud route costs you, and why it does not fit

The default answer a supplier reaches for is a stack of cloud tools: a hosted SIEM to watch the network, an endpoint agent that reports to a vendor cloud, a GRC subscription to track the controls, and a managed detection retainer on top. Two problems follow. The first is money. A hosted SIEM bills by the volume of data you ingest, endpoint tools bill per device, GRC platforms bill per seat, and the retainer renews every year, so the meter never stops and grows with you. The second problem is lawful fit. ITAR technical data and controlled unclassified information cannot simply sit in a shared, cross-border cloud, and if a control asks you to evidence where that data went, egress to a third party is exactly the answer you do not want to give. You end up paying for tooling you then cannot lawfully point at the data it is meant to protect.

How Phylax and Nomos run the whole thing on hardware you own

Mickai is sovereign, on-device AI: it runs offline on your own hardware, and every AI action is sealed under post-quantum cryptography into a signed audit record we call the Open Audit Record. The work is done by studios, and a studio is a ready-made application for one business function that runs inside a single system. Two of them carry most of this brief.

Phylax is our security operations studio, a sovereign SOC in a box that correlates host, network and identity telemetry into explained detections, triages and enriches each alert, and seals a regulator-ready incident timeline, fully offline and air-gapped, with any containment action left as an operator-gated step. Nomos is our compliance studio, which runs a live statute crosswalk across frameworks including ITAR, with control-gap assessments and a sealed audit trail, again fully offline. Together they replace the hosted SIEM and the GRC subscription with one system, sitting on infrastructure you control, where the controlled data never crosses a network boundary.

Codex, the studio for drafting and managing structured technical and invention disclosures on device, keeps the other sensitive asset in scope where it belongs: export-controlled technical data and proprietary IP are drafted and held on your own hardware, sealed to the audit record, rather than pushed into a cloud editor. The Assistant that drives all of this runs on your own brain, built on your own data, so nothing is sent out to be answered.

The evidence CMMC and DEFCON 658 want, generated not commissioned

Both regimes are, in the end, evidence regimes. CMMC Level 2 turns on a documented system security plan and proof that the controls are implemented and monitored. DEFCON 658 and CSMv4 turn on a cyber risk profile and the assurance behind it. The expensive way to produce that evidence is to commission it: consultants to write it up, a platform to store it, and a scramble every time an assessor asks. The sovereign way is to generate it as a by-product of the work. Every detection Phylax raises and every control Nomos assesses is sealed to the Open Audit Record as it happens, so the file the assessor wants is already prepared.

To be precise about the boundary: the system produces the evidence that supports a CMMC Level 2 assessment and DEFCON 658 assurance, it does not issue the certificate. That remains the assessor's to award, on evidence you now hold rather than evidence you have to reconstruct under time pressure.

What you replace, and what you save

Here is the swap in concrete terms, using the tools defence suppliers most often run today and the meter that disappears in each case.

What you run todayWhat it costs youWith Mickai
Cloud SIEM and endpoint tooling (Splunk, Microsoft Sentinel, CrowdStrike, IBM QRadar)Per-ingest and per-device fees, on data that cannot lawfully sit in a shared cloudPhylax correlates the same telemetry offline and air-gapped, with no data-volume meter
GRC and compliance SaaS (OneTrust, Vanta, Drata, LogicGate)Per-seat annual subscriptions renewed every yearNomos runs the ITAR and CUI crosswalk on device, with no per-seat fee
Outsourced managed detection and cyber consultantsAn ongoing retainer for monitoring and readiness adviceThe SOC and the control assessment sit in house on hardware you own
Cloud editors and stores for technical data packagesPer-user fees, and export-controlled data leaving the buildingCodex drafts and holds technical and invention disclosures on device
Cross-border cloud processing of controlled dataEgress charges and an ITAR or CUI exposure you cannot evidence awayNothing leaves authorised infrastructure, so there is no egress and no transfer to explain

How to move controlled data onto a sovereign system

The migration is a short, ordered sequence rather than a rip and replace.

  • Inventory where ITAR technical data and controlled unclassified information sit today, including any cloud SIEM, GRC seats and shared drives that touch them.
  • Stand the system up on your own hardware, air-gapped where the contract demands it, so no controlled data crosses a network boundary.
  • Point Phylax at host, network and identity telemetry and let it correlate detections offline, with any containment action left as an operator-gated step.
  • Run the Nomos crosswalk against ITAR, CUI, DEFCON 658 and CMMC Level 2 controls, and capture the gaps as a worklist you can close and re-check.
  • Seal every assessment, detection and disclosure to the Open Audit Record, so the file an assessor asks for is already prepared and time-stamped.

Frequently asked questions

Does Mickai make my firm CMMC or DEFCON 658 certified?

No. It runs offline on your own hardware and produces the evidence that supports a CMMC Level 2 assessment and DEFCON 658 assurance, sealed to the Open Audit Record. The certificate itself is awarded by the assessor, not by the software, which is why we are careful to say the system supports the examination rather than passing it for you.

Can it run fully air-gapped for ITAR and CUI?

Yes. Phylax and Nomos are built to run fully offline and air-gapped, so ITAR technical data and controlled unclassified information stay on authorised infrastructure and never cross a network boundary. Any containment or remediation step is operator-gated, so the system advises and detects while a human stays in control of the action.

What subscriptions does this actually replace?

The cloud SIEM and endpoint tooling (Splunk, Microsoft Sentinel, CrowdStrike, IBM QRadar) and the GRC subscriptions (OneTrust, Vanta, Drata, LogicGate), plus outsourced managed detection retainers. The per-ingest, per-seat and per-device meters stop, because the same detections and control assessments now run on hardware you own rather than in a vendor cloud.

We are an SME being pulled into the supply chain. Is this only for primes?

No. The same system runs on hardware a smaller supplier can own, which is the point of it: an SME can meet the same controlled-data obligations as a prime without standing up a cloud security budget it cannot sustain across a contract. The cost moves from a recurring subscription into a capability you keep.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/defence-suppliers-itar-cmmc-data-sovereignty. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
14 Aug 2026
How to Meet NIS2 Without Splunk Scale SIEM Bills: A Sovereign Security Operations Studio
You can meet NIS2 on hardware you own and stop paying a per gigabyte SIEM bill at the same time. Phylax runs the security operations centre on premise with no data volume charge, moving the NIS2 compliance cost from a rising subscription into one owned system.
14 Aug 2026
Only 15 Percent of Companies Can Run Agentic AI: Close the Readiness Gap Without a Consultancy Bill
Only about 15 percent of companies can run agentic AI in production. You can close the AI readiness gap 2026 on your own hardware, with Forge and Vault running the readiness pass and Omni standing the Assistant up on your own data, so the budget buys a system you keep rather than a consultancy slide deck.
13 Aug 2026
The Average Company Runs 275 SaaS Apps and Wastes Half the Licences: Consolidate to One Owned System
SaaS sprawl consolidation in 2026 means moving the business functions you rent as separate subscriptions onto one system you own, running offline on your own hardware with no per seat meter, so recurring licence spend becomes a single owned cost.
13 Aug 2026
CSRD After the 2026 Omnibus: Fewer Datapoints Still Need an Assured Evidence Trail
The CSRD Omnibus 2026 cut mandatory datapoints by roughly 61 percent, yet the figures that remain still need a limited assurance evidence trail. Gaia computes Scope 1, 2 and 3 and seals that trail on your own hardware, so the work moves in house instead of into annual ESG platform fees.