The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Cuick Trac CMMC Profile: What It Covers, What It Costs, and What You Still Own

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

Cuick Trac is Beryllium InfoSec's managed virtual desktop for work on Controlled Unclassified Information (CUI). For readers searching for a Cuick Trac CMMC review, the direct answer is this: set up and enforced correctly, it may let company laptops qualify as Out-of-Scope Assets for Cybersecurity Maturity Model Certification (CMMC). Beryllium says it inherits 264 of 320 Level 2 assessment objectives. You still own or share the other 56, and CMMC assesses your company's information system, not the product.

Know this first: we found no independent hands-on test in the sources and results checked, and we did not test it either. What we did was check Beryllium's public claims against the rules behind them, read its published contract terms and service-level language, and map the three places buyers can get surprised — the endpoints, the 56 shared or customer-managed objectives, and published terms that do not allow termination for convenience unless your Order Form changes them.

CMMC status, checked September 23, 2026. The Department of War — the name current official sites use alongside Department of Defense (DoD) — suspended CMMC Phase II on July 13, 2026. Phase II had been scheduled for November 10, 2026 and would have introduced Level 2 (C3PAO) requirements as a condition of award for applicable contracts. Phase I self-assessment requirements remain, and current suspension procedures limit new solicitations to Level 1 (Self) or Level 2 (Self). We found no official replacement Phase II date. The acquisition rule's broader clause-insertion schedule still contains a November 10, 2028 milestone; official sources checked did not identify that as a Phase II restart. See what changed and what still binds you.

For an enclave buyer, the suspension changes the immediate assessment timing, not the underlying cybersecurity work. Where DFARS 252.204-7012 applies, an external cloud service provider that stores, processes, or transmits covered defense information must meet the FedRAMP Moderate baseline or equivalent and support the clause's cyber-incident duties. Any self-assessment, CMMC status, SPRS record, or annual affirmation you submit must match the system you actually operate.

This page is for you if you handle CUI, you are considering Cuick Trac, and you want to know what it really covers before you sign.

It is not the right page if you only handle Federal Contract Information (FCI) — start with our Level 1 self-assessment checklist — or if you are choosing an assessor for a formal assessment. For that, see how to verify CMMC provider roles.

Before any demo, answer three quick questions:

  1. Does your contract or your prime's flow-down include DFARS 252.204-7012, or has an authorized source identified information you receive or create as CUI? If you cannot answer that, read FCI vs. CUI first.
  2. Do only a handful of your people touch CUI — not most of the company?
  3. Can that CUI work happen in Windows programs on a remote desktop, instead of requiring local processing on shop-floor or engineering systems?

Three yeses mean Cuick Trac is worth a demo. A "no" anywhere means read the fit section below before you book one.

Cuick Trac at a glance

Cuick Trac is a managed CUI enclave: a locked-down Windows virtual desktop, run by Beryllium InfoSec, that CUI users log into for email, files, and approved programs. It is a cloud service offering, not a C3PAO assessment, and it does not give a customer CMMC status. Here is what we could confirm and how sure we are.

Question — Short answer — How sure we are
QuestionShort answerHow sure we are
What is it?The Cuick Trac Managed Enclave (CTME): a virtual desktop with encrypted storage, secure email and file sharing, multifactor authentication (MFA), logging, patching, backups, and other managed security functions. Beryllium says it is based in Microsoft's GCC High environment.Company-stated (cuicktrac.com, checked Sept. 23, 2026)
Who runs it?Beryllium InfoSec, Inc., Dallas, Texas.Company-stated; the same legal name and city appear in a Department of War contract record
Is the product "CMMC certified"?No. CMMC status belongs to an assessed information system. Beryllium says its own system received Level 2 status after a third-party assessment in 2025 using Cuick Trac.Rule: verified. Outcome: company-stated
Is it FedRAMP authorized?Beryllium claims FedRAMP Moderate equivalency, not FedRAMP authorization. It also announced FedRAMP Ready in 2025, but FedRAMP retired that label in July 2026. We could not independently confirm Cuick Trac's current Marketplace label.Mixed — see the next section
Cyber AB roleBeryllium says it is a Registered Provider Organization (RPO), a readiness role rather than a C3PAO role.Company-stated; verify the current Cyber AB Marketplace record
CoverageBeryllium's contact page says 264 inherited, 21 shared, and 35 customer-managed objectives. Other Beryllium pages describe the same coverage differently.Company-stated and internally inconsistent
PriceNo current per-seat price is published. Beryllium's own comparison page estimates $75,000-$100,000 in first-year cost for 50 users.Company estimate, not an independent market range or customer quote
ContractThe published Terms auto-renew, do not allow termination for convenience, hold the seat floor during a subscription period, and increase fees 5% annually unless the Order Form changes those terms.Verified from Beryllium's published Terms of Service
Staffed monitoring and supportMarketing pages describe 24/7 logging, alerting, and monitoring. The published SLA describes personnel monitoring Monday-Friday, 8:00 a.m.-6:00 p.m. CST and business-hours remediation unless the SOW says otherwise. It lists after-hours support at $200 per hour with a two-hour minimum, $500 per hour from 11:00 p.m.-6:00 a.m. CST, and onsite support at $2,000 per day plus expenses.Verified from company-published pages; the buyer's SOW may override the public SLA
Government programsBeryllium is one of eight companies selected in May 2026 to compete for orders under the Army's Next-Gen Commercial Operations in Defended Enclaves (NCODE) contract.Verified in the Department of War's May 5, 2026 contract announcement

Cuick Trac's claims, checked against the record

Most of Cuick Trac's big claims are plausible, but most are company-stated, one public label it used was retired, and its own pages describe its coverage and schedule several different ways. The claim that matters most — FedRAMP Moderate equivalency — is one you must verify with documents, because the contractor remains responsible for confirming that its cloud use satisfies the clause.

What Cuick Trac says — What the rule or record shows — Our read — Ask for this
What Cuick Trac saysWhat the rule or record showsOur readAsk for this
"FedRAMP Moderate Equivalent," assessed by an independent third-party assessment organization (3PAO) in January 2025Where DFARS 252.204-7012 applies, a cloud service provider storing, processing, or transmitting covered defense information must meet the FedRAMP Moderate baseline or equivalent and follow paragraphs (c) through (g). DoD's December 2023 equivalency memo calls for assessment against the full applicable Moderate baseline by a FedRAMP-recognized 3PAO and a body of evidence supporting the result.Company-stated. The 3PAO is not named publicly, and we did not inspect the private attestation or body of evidence.The 3PAO's attestation letter, assessor name and status, assessment date and scope, open findings or exceptions, the body-of-evidence access process, and the Customer Responsibility Matrix (CRM).
"FedRAMP Ready" status in 2025FedRAMP retired Ready on July 28, 2026. Services that did not convert were renamed Legacy FedRAMP Ready. Ready and Legacy Ready do not satisfy the DFARS cloud requirement by themselves.The 2025 statement is dated; the current Cuick Trac Marketplace label was not independently confirmed.The current live product record on the FedRAMP Marketplace, including the product name, status, date, and package identifier.
Built on Microsoft GCC HighMicrosoft's government-cloud services cover Microsoft's layer. The virtual desktop, monitoring, support, configuration, applications, and operating procedures Beryllium adds remain Beryllium's and the customer's responsibility to document.Company-stated architecture, not a certification or CMMC status.A current boundary diagram and inheritance matrix showing what Microsoft, Beryllium, the customer, and any MSP each cover.
Supports approved third-party applicationsThe published SLA says software outside Cuick Trac's approved whitelist is reviewed case by case. Terms §7.6 says an unsupported or non-standard service receives no representation or warranty and that deployment and service-level guarantees do not apply.Application support is buyer- and version-specific; "approved" is not the same as covered by the standard SLA.The current whitelist, exact application/version status, proof-of-concept results, support classification, added price, and written SOW coverage.
Beryllium completed a Level 2 third-party assessment using Cuick Trac, with 110 of 110 requirementsCMMC status attaches to the assessed information system and organization seeking assessment, not to a standalone product.Company-stated. It describes one implementation; it does not validate a different customer's scope, people, applications, or evidence.The exact assessment type and date, the assessed boundary, and — if available and lawful to share — customer references with a comparable scope.
You inherit 264 of 320 objectives; 21 are shared; 35 are customer-managedA requirement is MET only when all applicable objectives are MET. DoD Assessment Methodology point values attach to the parent requirements, not to individual objectives.Company-stated and described differently across Beryllium pages.The current CRM mapped to all 110 requirements and 320 objectives, with evidence owners, SSP references, and the parent requirement's DoD score value for every shared or customer-managed objective.
"CUI never touches the OSC's network or device"A virtual-desktop endpoint can be an Out-of-Scope Asset only when the endpoint does not process, store, or transmit CUI beyond keyboard, video, and mouse. The configuration must be verified.True only when the actual client, settings, peripherals, people, and workflow enforce that condition.The exact endpoint settings, enforcement method, evidence, exception list, and data-flow tests.
Users onboard in "as few as 10 business days" — and "as few as 15 days" on the same siteOnboarding is not workflow migration, operational readiness, assessment readiness, or CMMC status. Beryllium separately says "12+ weeks" on one page and "3-6 months" on another for broader readiness.Company-stated and inconsistent unless each milestone is defined.Written prerequisites, milestone definitions, customer workload, acceptance criteria, and the remedy if a milestone is missed.
"Predictable and transparent pricing"Published Terms raise fees 5% at each anniversary unless the parties agree otherwise in writing. The public SLA also allows added charges for work outside stated hours.Partly supported, but only the Order Form and SOW reveal the buyer's actual total.A three-year itemized price, renewal assumptions, after-hours rates, required add-ons, storage/compute/app costs, and exit charges in writing.
"24/7 logging, alerting, and monitoring"The product page may describe continuous technical capability. The published SLA describes company-personnel monitoring five days a week, 8:00 a.m.-6:00 p.m. CST, and business-hours remediation unless the SOW says otherwise. Public after-hours rates are $200 per hour with a two-hour minimum and $500 per hour from 11:00 p.m.-6:00 a.m. CST.The public documents do not establish 24/7 staffed monitoring or remediation.The SOW's staffed coverage, after-hours escalation, incident-notification clock, response targets, rates, service credits, and any override of the public SLA.
U.S. soil, U.S. persons only; supports ITAR dataThose are relevant representations for export-controlled technical data, but they do not determine the customer's export authorization, data classification, or complete compliance.Company-stated.Contract language covering locations, administrative access, subprocessors, citizenship/person status, and changes during the term.
Cyber AB RPO with CCPs and CCAs on staffThe Cyber AB Marketplace is the current source for ecosystem roles and individual credentials. An RPO is not a C3PAO.Company-stated; current listing did not render independently in this audit.The current Marketplace record, grant/expiration dates, and names and roles of the people assigned to your work.
Selected for the Army's NCODE contractThe May 5, 2026 DoW announcement names Beryllium as one of eight firms that compete for each order under a $49 million IDIQ. It does not promise an order, subsidy, or cost share to a particular contractor.Verified.If you are an eligible Army small-business supplier, use the Army NCODE page to ask whether the program and a task order apply to you.
Its comparison page says third-party assessments are required for awards "starting November 2026"The Department suspended the scheduled Phase II transition on July 13, 2026. Official pages checked September 23 did not announce a replacement Phase II date.Outdated.Ignore sales urgency built on the suspended November 2026 date; read the actual solicitation, contract, modification, and flow-down.

Whether Cuick Trac is the right buy depends on facts no company profile can see: your required CMMC level and assessment type, whether you handle FCI or CUI, where CUI actually goes, your applications and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer cannot resolve those facts for you, use The Defense Compliance Report's Find My CMMC Path tool to see whether a managed enclave, GCC High, an encrypted email-and-file tool, readiness help from an RPO, or a Managed Security Service Provider (MSSP) fits your situation before you request quotes — and do not submit CUI, drawings, or sensitive contract details.

FedRAMP "Ready," "Equivalent," and "Certified": which one counts?

For a cloud service handling covered defense information under DFARS 252.204-7012, the relevant paths are FedRAMP Certification at Moderate or higher, or an equivalency package that satisfies DoD policy. Beryllium claims equivalency. Ready and Legacy FedRAMP Ready are not either path.

Label — Who establishes it — Does it meet the DFARS cloud requirement on its own?
LabelWho establishes itDoes it meet the DFARS cloud requirement on its own?
FedRAMP Certified at Moderate or higherFedRAMP, reflected on the MarketplaceIt establishes the security-baseline path. The provider still must satisfy the applicable contract's incident-reporting, preservation, forensic-access, and cooperation duties.
FedRAMP Moderate equivalencyThe CSP/contractor supports the claim with the DoD-required 3PAO assessment and body of evidence; it is not a FedRAMP statusIt can satisfy the security-baseline path if the package actually meets DoD's memo and the clause. The contractor must perform due diligence.
FedRAMP Ready / Legacy FedRAMP ReadyA legacy Marketplace readiness designation; Ready was retired July 28, 2026No.
"Built on GCC High"A statement about underlying architectureNo. It describes Microsoft's layer, not the complete managed service or the customer's implementation.

Think of it like buying a used truck. "Ready" was a pre-inspection label. "Equivalent" is an evidence package showing a full inspection against the required baseline, but it is not a FedRAMP certification and you still have to inspect the report. Our guide to FedRAMP equivalency for cloud providers walks through the evidence.

Will Cuick Trac keep your laptops out of CMMC scope?

It can, but only if the virtual desktop is configured and used so the endpoint does not process, store, or transmit CUI beyond keyboard, video, and mouse. The CMMC rule allows that endpoint to be treated as an Out-of-Scope Asset, and DoD says the configuration must be verified. A download, local cache, redirected drive, uncontrolled clipboard path, local application, or other CUI path changes the answer.

Here is why. An enclave works like a locked room inside your building where the CUI work happens. Watching the work through a window does not put the laptop in the room. Carrying a drawing out does.

If this happens — What it means for scope — Rule or evidence
If this happensWhat it means for scopeRule or evidence
Users only see the remote screen and send keyboard and mouse inputThe endpoint may qualify as an Out-of-Scope Asset if the condition is verified and documented.32 CFR 170.19(c)(1), Table 3 and the DoD CMMC FAQ
A file downloads, syncs, or caches on the laptopThe endpoint processes or stores CUI and becomes a CUI Asset.Same
Copy-and-paste, drive mapping, screenshots, or another function transfers CUI locallyThe endpoint is no longer KVM-only; classify and assess it based on what it does.Same
Someone prints CUIThe paper is CUI media and enters the handling program. The printer, print server, and local spool path must be classified from the actual architecture; they are not automatically all the same asset type.32 CFR 170.19; NIST SP 800-171 Rev. 2 media-protection requirements
A CAD/CAM workstation opens CUI files locallyThat workstation processes CUI and is a CUI Asset.32 CFR 170.19
A CNC machine, coordinate-measuring machine, or test device receives CUIIt may qualify as a Specialized Asset if it meets the rule's definition. It must be inventoried, documented in the SSP and network diagram, and shown to be managed under the contractor's risk-based security policies, procedures, and practices; at Level 2, the SSP is reviewed and the asset is not assessed against the other CMMC security requirements.32 CFR 170.19(c)(1), Table 3
A tool protects an in-scope system — for example, an identity or security tool supporting the enclaveIt may be a Security Protection Asset and is assessed against the requirements relevant to the capability it provides.32 CFR 170.19(c)(1), Table 3
CUI goes to regular company emailThe email environment processes CUI and enters scope. If an external cloud provider handles covered defense information where DFARS 252.204-7012 applies, the cloud requirement also applies.32 CFR 170.19(c)(2); DFARS 252.204-7012

A hypothetical to make it concrete. Say you run a 40-person machine shop, and six people handle drawings from a prime. The drawings arrive in the enclave's secure email, and your engineers review them there. Their laptops may stay out of scope if the verified client remains KVM-only. But the moment a drawing lands on the CAM station that writes the machine program, that station is a CUI Asset. CNC machines or test equipment that receive the data may qualify as Specialized Assets depending on their characteristics and use; at Level 2, they still must be inventoried and documented, but are not assessed against the other CMMC security requirements. The enclave shrinks the job. It does not erase the shop floor. Our guide for machine shops and Level 2 scoping guide go deeper.

What you still own with Cuick Trac

By Beryllium's own contact-page count, you own 35 of the 320 Level 2 assessment objectives and share 21 more. Because a requirement is MET only when every applicable objective is MET, those 56 objectives can affect more of the 110 requirements than a single percentage suggests. The document that settles the split is the Customer Responsibility Matrix — the line-by-line record of who implements each objective and who produces the evidence.

First, the numbers. Beryllium's pages do not describe the split the same way.

Where Beryllium says it, checked Sept. 23, 2026 — Wording — Does it reconcile to 320?
Where Beryllium says it, checked Sept. 23, 2026WordingDoes it reconcile to 320?
Contact page FAQ264 inherited, 21 shared, 35 customer-managedYes: 264 + 21 + 35 = 320
Compliance page264 inherited "including 21 shared"; 35 customer-managedNo: that wording describes 299 non-overlapping objectives
Homepage FAQ"82%" handled; advisers guide the customer through "the remaining 22%"No: 104%
CTME page FAQ"82%" handled; "the remaining 18%"Yes as percentages, but it does not identify the shared subset
Comparison page264 of 320, "covering 80% of technical requirements"A different denominator or measure
Homepage FAQ and demo pageMeets "ALL technical controls"; takes on "every technical practice"Not reconciled with 21 shared and 35 customer-managed objectives

The only public split that reconciles numerically is 264 inherited + 21 shared + 35 customer-managed = 320. That does not mean Beryllium alone "handles 285" or that 82.5% of the work disappears: shared objectives still require customer action and evidence, and effort is not distributed evenly across objectives. Get the current CRM itself.

Why does that matter? Each of the 110 requirements has one or more assessment objectives. If one applicable objective is NOT MET, the parent requirement is NOT MET. Some parent requirements carry 5 points in the DoD Assessment Methodology, but the points belong to the requirement, not to each objective. Ask for the matrix mapped to all 110 requirements and 320 objectives, with the parent requirement's score value beside every shared or customer-managed objective. Our guide to responsibility matrices shows what a defensible one contains.

Here is how the work splits, based on Beryllium's public description and the rule:

Area — Cuick Trac's part, company-stated — Your part
AreaCuick Trac's part, company-statedYour part
Enclave technology: encryption, firewall, logging, patching, backups, MFAOperates the contracted platform functions. The public SLA describes staffed personnel monitoring during stated weekday hours unless the SOW says otherwise.Approve users and roles, remove access promptly, review evidence, and confirm the SOW supplies the coverage your contract and risk require.
Security-awareness trainingTemplates and optional advisory help may be available.Deliver the training, cover your actual procedures, track completion, and retain evidence.
Incident responseMonitors the enclave under the contracted SLA and must notify you no later than 72 hours after becoming aware under published Terms §13.3.Detect and handle incidents outside the enclave, make reporting decisions, submit any required DoD report on your clock, preserve evidence, and coordinate the complete response. Negotiate notice sooner than the outer 72-hour limit.
Personnel securityLimited platform role.Screening, onboarding, role changes, offboarding, sanctions, and records.
Physical securitySupplies evidence for provider-controlled facilities and infrastructure where applicable.Offices, work areas, printouts, paper CUI, local devices, visitors, and physical handling.
Policies and your SSPPublished Terms describe policy and procedure "shell documents."Complete and approve them so they truthfully describe your organization, scope, people, and actual implementation.
SPRS and annual affirmationMay advise.Your organization posts the applicable result or status, and a senior official completes the required affirmation on the applicable cadence.
Laptops used to log inSupplies client guidance and service-side controls.With your managed service provider (MSP), configure, test, document, and maintain the endpoint so it remains KVM-only if you intend to claim it is out of scope.
Applications and peripheralsMay host approved applications and supported workflows.Prove your exact applications, license servers, printers, scanners, portals, offline work, and supplier exchanges stay within the designed boundary.

Who Cuick Trac fits — and who should look elsewhere

Cuick Trac is a plausible fit for a small CUI team whose work is mainly documents, email, files, and supported Windows programs at a company that wants a managed technical boundary. It is a weaker fit when CUI must be processed locally on shop-floor or engineering systems, when most staff work in CUI all day, when after-hours staffed support is essential and not contracted, or when the company needs the freedom to cancel. The deciding factor is where CUI actually goes.

Your situation — Preliminary fit — What decides it
Your situationPreliminary fitWhat decides it
FCI only, no CUINot required for CMMC Level 1Level 1 uses 15 FAR 52.204-21 safeguards, an annual self-assessment, and annual affirmation. A Level 2 CUI enclave is not a CMMC Level 1 requirement.
A handful of CUI users working in documents, email, and filesPlausible fitThe work can stay inside the virtual desktop without local CUI paths.
No in-house IT or security staffPlausible fitThe managed platform reduces technical operation, but your organization still owns the customer and shared objectives, governance, and evidence.
Heavy CAD/CAM, GPU rendering, or plottersTest before shortlistingYour exact versions, licenses, plugins, files, graphics needs, printers, latency, and support terms must pass a real test. The standard public build lists 200 GB of storage and 8 GB vRAM, company-stated.
CUI must reach CNC machines or test equipmentVerify the architecture firstThose devices stay in your program and must be classified and documented correctly; some may qualify as Specialized Assets, which are documented and risk-managed but not assessed against the other Level 2 security requirements.
Most of the company touches CUI daily in Microsoft 365Compare with a broader GCC High architectureA second desktop for nearly everyone can create friction and workarounds. Beryllium's own comparison page also presents broader GCC High deployment as an alternative.
Export-controlled ITAR or EAR technical dataVerify in writingContracted U.S.-person, location, subprocessors, administrative access, and export obligations. Confirm applicability with qualified export counsel.
You require 24/7 staffed monitoring or after-hours remediationVerify the SOW firstPublic marketing and the published SLA do not establish the same staffing promise.
You need to cancel on short noticeCautionPublished Terms have no termination for convenience, require advance fees, and hold the seat floor during a subscription period unless the Order Form changes them.
Small business supporting Army workCheck NCODE eligibilityBeryllium can compete for NCODE orders; the Army determines eligibility, acquisition route, task-order availability, and payment structure.

If Cuick Trac does not fit, the answer is usually a different category, not a different logo:

Category — Best considered when — Our guide
CategoryBest considered whenOur guide
Microsoft 365 GCC High, company-wide or as an enclaveMost staff work in CUI; collaboration is broad; ITAR-sensitive Microsoft workloads dominateGCC High for CMMC · Enclave vs. GCC High
Encrypted email-and-file toolCUI is mostly email and files for a few people, and local applications matterPreVeil profile · PreVeil alternatives
Other managed enclavesYou like the boundary model and want to compare responsibilities, workflow, evidence, and contract termsManaged enclaves · CUI enclave providers
Government-cloud buildCUI lives in applications, databases, engineering systems, or integrations that do not fit a standard VDIAWS GovCloud · Azure Government
Readiness help firstYou do not yet know your CUI flow, scope, evidence, or provider splitWho to hire first · RPO vs. C3PAO

No web page — including this one — can tell you whether Cuick Trac fits your company. That turns on where your CUI goes, and only you can map and validate it. The good news is that one well-run demo using a realistic but non-sensitive workflow will answer most of the operational questions. The checklist further down shows exactly how.

If a row above came out "it depends," sort out the category before you book a demo. The tool asks about your contract, FCI or CUI, environment, timeline, and budget, and shows which kind of path and help fit.

See whether a managed enclave fits your situation

What Cuick Trac costs

Beryllium does not publish a current per-seat price; it quotes after a consultation. Its own comparison page, updated in August 2026, estimates $75,000-$100,000 in first-year cost for 50 users — about $125 to $166.67 per user per month if the total is spread evenly across 50 users and 12 months. That is our arithmetic on Beryllium's estimate, not a quote or independent market range, and the public page does not establish that every buyer receives the same scope.

One older data point: a 2021 marketplace listing attributed to Beryllium put the starting price at $295 per enclave user per month. It is a dated signal, not a current price.

The public Terms add a 5% annual increase unless the parties agree otherwise in writing. The published SLA lists support outside 8:00 a.m.-6:00 p.m. CST at $200 per hour with a two-hour minimum, support from 11:00 p.m.-6:00 a.m. CST at $500 per hour, and onsite support at $2,000 per day plus expenses. Neither public number captures onboarding, application hosting, storage or compute upgrades, advisory work, your staff time, MSP work on endpoints and interfaces, extra assessment support, formal assessment costs when applicable, or exit and migration. The calculator below keeps those buckets separate so nothing gets counted twice or silently becomes zero. For category-wide numbers, see our CMMC enclave cost guide.

Cuick Trac 3-Year Quote Normalizer

This calculator runs in your browser and stores nothing. Do not enter CUI, drawings, contract numbers, or sensitive contract or system details.

Optional cost inputs

Worked example. Every price here is made up for illustration — it is not a Cuick Trac quote or a market estimate. Say you get a quote for six seats at $200 per user per month, on a 12-month initial term, and you plan across three years. Your staff will spend 100 hours getting started and about four hours a month after that, at a loaded cost of $75 an hour. The quote does not say whether there is an onboarding fee. For this fictional horizon, formal assessment is marked not applicable.

Line — How it is figured — Amount
LineHow it is figuredAmount
Year 1 subscription6 x $200 x 12$14,400.00
Year 2 subscriptionYear 1 x 1.05 under Terms §9.5$15,120.00
Year 3 subscriptionYear 2 x 1.05$15,876.00
Your staff time(100 x $75) + (4 x 36 x $75)$18,300.00
Onboarding feeNot stated in the quoteUnknown
Known costs so farSubscription plus staff time$63,696.00
Per seat per month, known costs only$63,696 / 216 seat-months$294.89
Published-term minimum entered hereYear 1 subscription; no termination for convenience in published Terms$14,400.00

Notice two things. The 5% increase adds $2,196 over three years compared with a flat per-seat price. And the total stays marked incomplete until you get the onboarding number — because an unknown is not zero.

The contract terms to read before you sign

Beryllium's published Terms of Service, Version 2.0 and last updated June 11, 2026, are strict in several places. They do not allow termination for convenience, do not permit seat reductions during a Subscription Period, increase fees 5% annually unless the parties agree otherwise, and require the customer to retrieve its data before service ends. Your Order Form, statement of work, and responsibility matrix rank above the general Terms, so that is where to change what matters.

We read the full Terms of Service and the published Service Level Agreement on September 23, 2026. These are the provisions that affect money, support, risk, and exit:

Source — What it says, in plain English — Why it matters — What to ask for
SourceWhat it says, in plain EnglishWhy it mattersWhat to ask for
Terms §19.1No termination for convenience.You cannot walk away mid-term merely because a contract or business need changes.A shorter first term or a negotiated exit tied to losing the covered work, a material service failure, or a security/compliance change.
Terms §9.4Auto-renews in one-year Renewal Terms. Written notice is due at least 60 days before term end. After two Renewal Terms, the parties execute a new Order Form/SOW at updated pricing.Miss the window and another annual term may begin.Put every notice deadline on the calendar the day you sign and define an address/method that satisfies the notice clause.
Terms §9.5Fees rise 5% on each anniversary unless otherwise agreed in writing.A three-year comparison must include escalation.Fixed pricing or a capped increase in the Order Form.
Terms §§5.4.5, 9.2Seats cannot be reduced during a Subscription Period, and billing follows the Order Form quantity.Extra seats bought "just in case" can remain billable for the term.Start with the supported minimum and state when reductions are allowed at renewal.
Terms §9.1Fees are due in advance unless the Order Form says otherwise.Cash-flow and leverage.Monthly or quarterly billing and a holdback tied to acceptance where appropriate.
Terms §13.6One audit or certification process is supported in a 12-month period without an added fee; additional processes are time-and-materials.Readiness review, C3PAO assessment, POA&M closeout, DIBCAC activity, or reassessment can create ambiguity over what counts as one process.Define included events, hours, artifacts, interviews, closeout support, and rates.
Terms §13.3Beryllium says it will notify the customer no later than 72 hours after becoming aware of a security incident.The contractor's DFARS reporting window is also 72 hours from discovery. An outer-limit provider notice could consume the customer's reporting time.Faster initial notice, reporting RACI, DoD portal responsibility, escalation contacts, and evidence-preservation steps.
Terms §14.3Forensic preservation is described as reasonable efforts, without a guarantee.DFARS 252.204-7012 requires preservation of images and monitoring data for at least 90 days after reporting and cooperation with forensic access and damage assessment.Contract language mapping paragraphs (e) through (g) to the provider, customer, and any other party.
Terms §§11.4, 15.1The customer must retrieve data. §11.4 says the company may delete data 90 days after the agreement ends and backups may remain up to 12 months; §15.1 says dedicated storage is wiped during deprovisioning after the last service day and cannot be recovered.The provisions describe different stores and timelines. A buyer should not assume a 90-day recovery period.A written exit runbook identifying production storage, backups, logs, evidence, formats, assistance, deletion timing, retention, and destruction confirmation.
Terms §25.1Beryllium may identify the customer and use its logo unless the customer opts out in writing.Some defense suppliers keep customer relationships nonpublic.A written publicity opt-out in the Order Form.
Terms §5.2.3Access is limited to authorized users and applicable DoD or third-party assessors; an outside consultant who is not an Authorized User may not access the service.A readiness adviser may need approved access and a licensed seat.How an adviser becomes an Authorized User, what access can be limited, and what it costs.
Terms §8.3The service includes policy and procedure "shell documents" that the customer completes.A template is not a finished or accurate SSP, policy set, or implementation.Exact advisory deliverables, review cycles, owners, and completion criteria.
Terms §26.1Beryllium may assign the agreement in a merger, reorganization, or sale.Provider ownership or control can change during the term.Notice, security-review, subcontractor, data-location, and exit rights after an assignment.
Terms §3.1General Terms can change on 30 days' notice unless the customer objects in writing.Material language can move during the relationship.Freeze negotiated terms in the Order Form and define the consequence of an objection.
Terms §28.1The Order Form, SOW, and CRM control over conflicting general Terms.The buyer can negotiate the operating reality.Attach the current CRM, SLA/SOW commitments, price schedule, and exit runbook to the Order Form.
Published SLA, last updated July 21, 2026Personnel monitoring is described as Monday-Friday, 8:00 a.m.-6:00 p.m. CST; remediation occurs during business hours unless the SOW says otherwise. The listed rates are $200 per hour outside service hours with a two-hour minimum, $500 per hour from 11:00 p.m.-6:00 a.m. CST, and $2,000 per onsite day plus expenses. P1 target response is one business hour. Credits are conditional, begin accruing only after three months, and require a written claim within 30 days."24/7 logging" is not the same as 24/7 staffed monitoring, response, or remediation, and the credit exclusions include onboarding and advisory services.Exact staffed hours, P1 response around the clock, after-hours rates, on-call escalation, maintenance windows, availability calculation, credit process, and every SOW override.

Two other terms worth knowing: the published Terms cap liability at 12 months of fees and exclude fines and penalties under §24, and they send disputes to binding arbitration in the Dallas area under §29.4. Those provisions can matter more than a product feature if an incident, missed deadline, or failed transition causes a contract loss.

The enclave handles a large part of the technical environment. Training, policies, your SSP, customer and shared objectives, workflow enforcement, and assessment preparation remain yours — and who should help with them depends on your level, team, and timeline.

See which kind of help covers the rest

How to verify Cuick Trac before you sign

Ask for documents before you rely on labels, and run your actual workflow in the demo with made-up files. A capable provider should have most of this ready. Some evidence — especially the body of evidence behind an equivalency claim — may require a nondisclosure agreement or controlled review. That is reasonable only if there is a real path for you, your adviser, and your eventual assessor to inspect what they need.

Copy this request and send it before your demo:

We are evaluating Cuick Trac for our CUI work and need to check it against our contract, data flows, applications, and assessment scope. Please send, or arrange secure review of, the items below. We will not send CUI, drawings, contract numbers, or sensitive system details by regular email.

  1. Your current Customer Responsibility Matrix, dated and versioned, mapped to all 110 NIST SP 800-171 Revision 2 requirements and all 320 assessment objectives. Show the implementation owner, evidence owner, SSP reference, and parent requirement's DoD Assessment Methodology point value for every shared or customer-managed objective.
  2. Which published coverage statement governs — 264 inherited / 21 shared / 35 customer-managed, 82% / 18%, 82% / 22%, or 80% of technical requirements — and a written reconciliation of the differences.
  3. Your current 3PAO attestation for FedRAMP Moderate equivalency: assessor legal name and current recognition, assessment date, assessed service and boundary, exceptions or open findings, and the secure process by which we and our assessor can inspect the body of evidence.
  4. Your current FedRAMP Marketplace product record, if any, showing the live product name, status, date, and package identifier.
  5. A current boundary and data-flow diagram showing what Microsoft, Beryllium, our company, our MSP, and any other external service provider each cover.
  6. The exact virtual-desktop settings and evidence for downloads, clipboard, screenshots, drive mapping, printing, scanning, USB, browser upload/download, offline access, mobile access, and local cache — plus every supported exception.
  7. Whether our exact applications, versions, license servers, plug-ins, file sizes, GPU needs, printers, scanners, plotters, machine interfaces, and supplier portals run inside the enclave; what each costs; and what support is contracted.
  8. Your incident-response RACI: monitoring and escalation, the initial-notice deadline, who submits any DoD report, DoD medium-assurance certificate responsibility, malicious-software submission, 90-day preservation, forensic access, and damage-assessment support under DFARS 252.204-7012 paragraphs (c) through (g).
  9. Monitoring, patching, vulnerability management, backup, restore, change-management, log-retention, and evidence-export details mapped to the CRM.
  10. The controlling SLA and SOW: staffed monitoring and support hours, 24/7 on-call coverage if any, P1 response and resolution targets, after-hours rates, maintenance windows, availability calculation, service credits, and every difference from the public SLA.
  11. A three-year price in writing, including the 5% annual increase or negotiated cap, minimum seats, base fee, storage, compute/GPU, applications, integrations, onboarding, migration, advisory work, MSP work, after-hours support, extra audit support, travel, overages, and exit assistance.
  12. The minimum seat count, when seats may be added, when they may be reduced, and the price and notice rule at each renewal.
  13. A written exit plan: production data, backups, logs, CRM, SSP-ready statements, and assessment evidence; export formats; timing; transition help; overlap period; fees; deletion; residual retention; and destruction confirmation.
  14. Your current Cyber AB Marketplace organization record and the current names, roles, and credential status of the RP, CCP, or CCA personnel assigned to us.
  15. If available and lawful to share, references from organizations with a comparable scope that completed the applicable Level 2 assessment using the enclave. State the assessment type and date without exposing their sensitive information.
  16. Your U.S.-person, administrative-access, subprocessor, and U.S.-location commitments in contract language, plus notification and approval rules for changes.
  17. Please opt us out in writing from customer-name, logo, case-study, and publicity use under Terms §25.1.

Then, in the demo, test the work your people actually do. Use made-up files only.

Test in the demo — It passes when — Warning sign
Test in the demoIt passes whenWarning sign
Sign in from a normal laptopThe session works, the local restrictions are documented, and the test confirms the endpoint remains KVM-only.Any CUI-like test content caches, downloads, or becomes locally accessible.
Open, edit, and save a test fileThe file stays in enclave storage and the evidence shows where it went.A temporary file, sync folder, browser download, or redirected drive appears locally.
Copy and paste out of the desktopBlocked, or allowed only through a documented approved process that does not create an uncontrolled local CUI path.Unrestricted clipboard, drag-and-drop, or screen-capture workflow.
PrintThe approved print path, spool behavior, printer boundary, marking, custody, and paper-handling rules are documented.Printing to an unmanaged local printer or no answer about the spooler.
ScanThe scan enters the approved enclave location with identity, logging, and handling controls.It lands in regular email, a consumer app, or a local folder.
Send to an outside recipientEncryption, recipient authentication, expiration, logging, and the recipient's responsibility are defined.Plain email, open link, uncontrolled download, or no downstream process.
Run CAD/CAM or another engineering applicationThe exact version, license server, plug-ins, file size, GPU demand, peripherals, and performance meet the buyer's written threshold."Should work" without a live synthetic-data test.
Use a supplier or government web portalUploads, downloads, browser cache, and identity remain inside the documented flow.The browser becomes a back door to the local endpoint.
Work offline or in the fieldThere is an approved documented method — or an explicit and operationally acceptable "not supported."Users would need to invent workarounds.
Let the MSP support usersAdministrative access, tools, logs, remote-support paths, and evidence are in the SSP and CRM.MSP tooling or access the documentation does not mention.
Run a mock incidentAlert, human escalation, provider notice, evidence preservation, and customer reporting actions meet the written RACI and timeline.No after-hours owner, no usable timeline, or missing evidence.
Export assessment evidenceCurrent artifacts can be exported by requirement/objective in usable formats, with version/date and source.A dashboard score with no assessor-usable evidence or export rights.

Finally, define the milestones in writing, because Beryllium's public timelines range from 10 business days to 3-6 months depending on what is being measured:

Milestone — What it should mean
MilestoneWhat it should mean
Users onboardedAuthorized users can authenticate and perform the agreed basic tasks.
Workflows movedThe approved CUI workflow works end to end inside the designed boundary, including applications, peripherals, external recipients, and support.
Documents completedThe SSP, policies, CRM, diagrams, inventories, and evidence references match what the organization actually does.
Ready for the applicable assessmentAn independent readiness review finds no unexplained scope, implementation, evidence, or provider-responsibility gap.
CMMC statusThe required assessment and affirmation are complete and recorded through the applicable official process.

Cuick Trac Buyer Request + Demo Test Sheet

Use made-up files in demos. Do not send CUI, drawings, contract numbers, or sensitive system details by regular email or web form.

What a Cuick Trac CMMC review can — and cannot — verify

We found no independent hands-on review of Cuick Trac in the sources and results checked. What turns up is vendor pages, role-only testimonials, software-directory listings that repeat sales copy, reseller pages, and press releases — plus one checkable government record, the Army NCODE contract announcement.

What you may read — What the evidence supports
What you may readWhat the evidence supports
A reseller page calling Cuick Trac itself "CMMC Level 2 certified"A product is not assigned CMMC status. An assessed organization's information system receives the applicable CMMC status. Beryllium says its own system completed a Level 2 third-party assessment.
Directory pages promising compliance in 14 daysBeryllium's current pages distinguish onboarding claims of 10 business days or 15 days from broader readiness claims of 12+ weeks or 3-6 months. None is your CMMC status date.
Directory alternatives filled with governance, risk, and compliance softwareThose tools may organize controls and evidence; a managed enclave is an operating environment where CUI can be processed. They solve different jobs.
"FedRAMP Ready"A label FedRAMP retired July 28, 2026. Ready and Legacy Ready do not satisfy the DFARS cloud requirement on their own.
Cuick Trac's comparison page naming Cuick Trac the best choice for a segmentIt is a company sales page. Its competitor descriptions and cost figures are Beryllium's comparisons, not independent rankings or market measurements.

How we built this profile

We read Cuick Trac's public product pages, its full published Terms and SLA, Beryllium's company announcements, and the primary rules and official records behind the consequential claims. We dated the checks. We did not use the product, inspect private evidence, review a customer Order Form or SOW, run an application test, or interview customers. Every claim that comes from Beryllium remains attributed to Beryllium.

What we verified — September 23, 2026

  • Read from primary authorities: DFARS 252.204-7012; 32 CFR Part 170, including § 170.19 scoping; NIST SP 800-171 Revision 2 and SP 800-171A; the DoD Assessment Methodology; FedRAMP notice NTC-0008; the Cyber AB Code of Professional Conduct v2.0 and CMMC Assessment Process v2.0.
  • Checked against current official records: the DoW CMMC status pages; the July 13, 2026 suspension release; the DARS class-deviation index showing 2026-O0025 Revision 3 dated September 3, 2026; the May 5, 2026 NCODE contract announcement; and the Army NCODE page.
  • Read as company documents: the Cuick Trac homepage, CTME, compliance, contact, demo, and comparison pages; Beryllium's Terms of Service v2.0; and its published SLA.
  • Company-stated, not independently proven: FedRAMP Moderate equivalency; Beryllium's own Level 2 result; the 264/21/35 split; GCC High basis; U.S.-person operation; application fit; timelines; price estimates; and Cyber AB RPO role.
  • Could not independently confirm: Cuick Trac's current FedRAMP Marketplace status or package identifier; Beryllium's current Cyber AB Marketplace role; the equivalency 3PAO's identity and private evidence package; any customer outcome; current buyer pricing; or the terms of any buyer-specific Order Form or SOW.
  • Source-access limitation: the official December 21, 2023 FedRAMP-equivalency memo remains linked as the authority, but its PDF did not render during this audit pass. The page therefore does not claim a fresh line-by-line re-read and tells the buyer to inspect the current attestation and body of evidence.

Frequently asked questions

Is Cuick Trac CMMC certified?

No product is assigned CMMC status. CMMC status belongs to the organization seeking assessment and its assessed information system. Beryllium says its own system, running on Cuick Trac, completed a third-party Level 2 assessment in 2025; that does not determine your scope, implementation, evidence, or outcome.

Is Cuick Trac FedRAMP authorized?

Beryllium claims FedRAMP Moderate equivalency, not FedRAMP authorization. It says an independent 3PAO assessed the offering in January 2025. Equivalency can satisfy the DFARS cloud security-baseline path only if the current package meets DoD policy; ask for the attestation, assessment scope, current exceptions, and body-of-evidence access rather than relying on the label.

Is Cuick Trac monitored 24/7?

Cuick Trac's product copy describes 24/7 logging, alerting, and monitoring. Beryllium's published SLA describes personnel monitoring Monday-Friday, 8:00 a.m.-6:00 p.m. CST, and business-hours remediation unless the SOW says otherwise. It lists $200 per hour with a two-hour minimum outside service hours and $500 per hour from 11:00 p.m.-6:00 a.m. CST. Treat 24/7 automated capability and 24/7 staffed response as different promises, and put the required staffing, escalation, and pricing in the SOW.

If I use Cuick Trac, do I still need a C3PAO assessment?

The enclave does not change the assessment type set by the applicable solicitation, contract, or modification. A C3PAO assessment is required when Level 2 (C3PAO) applies; under the current suspension procedures, new solicitations are limited to Level 1 (Self) or Level 2 (Self), while existing obligations and voluntary or government-led activity may still matter. Read the actual clause in your paperwork and the current official implementation direction.

Can Cuick Trac hold ITAR data?

Beryllium says the environment is operated on U.S. soil by U.S. persons and supports ITAR data. That is a company representation, not a determination of your export authorization or data jurisdiction. Put location, citizenship/person status, administrative access, subprocessors, and change-control commitments in the contract and confirm applicability with qualified export counsel.

Does Cuick Trac replace my MSP?

Beryllium says no; it is designed to work alongside an existing MSP or internal IT team. Your MSP still operates systems and interfaces outside the enclave. If you intend to keep login endpoints out of scope, the endpoint must not process, store, or transmit CUI beyond keyboard, video, and mouse, and the configuration must be verified. Our guide to CMMC requirements for MSPs covers their side.

Can the Army's NCODE program pay for Cuick Trac?

The official record shows that Beryllium is one of eight firms competing for NCODE task orders. The public Army page does not promise a grant, reimbursement, subsidy, or cost share to an individual contractor. Eligible Army small businesses can register interest with NCODE to learn whether the acquisition route and an available task order apply.

What happens to my data if I leave?

The published Terms require you to retrieve your data. §15.1 says dedicated storage is wiped during deprovisioning after the last service day and cannot be recovered; §11.4 says the company may delete data after 90 days and may retain backups up to 12 months. Do not assume you have a recovery window: obtain a written exit runbook covering each data store, logs, evidence, backups, export assistance, deletion, and residual retention.

Can the same company prepare me and assess me?

A C3PAO may not conduct a CMMC assessment of an organization it helped prepare for any CMMC assessment during the prior three years, and it may not provide consulting to an organization it assessed for three years after the assessment, under the Cyber AB Code of Professional Conduct v2.0. Beryllium presents Cuick Trac and its advisory work as readiness services; verify every provider's current Marketplace role and keep the formal assessor independent. See RPO vs. C3PAO.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Sources

All checked September 23, 2026, unless noted.

Rules and official records

Company sources — company-stated unless the page quotes published contract language

Our related guides


About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

We are not affiliated with the Cyber AB, DoD, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice — confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. Read our Editorial & Advertising Policy and methodology.

Map my CMMC path →