EN
Back to the archive

The archive · Developer & Business Tools · Strategic decision · 2015–2026

PreVeil bets CMMC's mandate makes encrypted email a defense must-buy

Boston zero-knowledge email startup rides DoD's CMMC rule to 2,500+ contractor customers, then the Pentagon suspends Phase 2 in July 2026.

PreVeil

The betThat CMMC would force tens of thousands of contractors to protect CUI, and a cheap zero-knowledge overlay — not GCC High — would be how small shops pass audits.Scaling

What the business is

PreVeil is an end-to-end encrypted email and file-sharing platform for organizations that handle sensitive data, installed as an overlay on Microsoft 365 or Google Workspace and marketed mainly to defense contractors that must meet CMMC, NIST 800-171 and ITAR rules.

Starting capitalAbout $27M total raised, including a $20M Series C led by PSG (October 2022).

How it started

PreVeil was founded in Boston in 2015 by former Apple and Airvana executives Randy Battat and Sanjeev Verma, building on MIT encryption research by CTO Raluca Ada Popa. The original pitch was end-to-end encryption that ordinary users can operate: data is encrypted on the device, no server, admin or even PreVeil can read it, and there is no single point of attack.

What happened

The defense pivot came when NIST 800-171 and ITAR made CUI protection a contractual condition: PreVeil became the compliance path for small contractors that could not afford Microsoft's GCC High government cloud. PSG led a $20M Series C in October 2022 to expand beyond defense. DoD's CMMC 2.0 final rule (October 2024) and Phase 1 enforcement (November 2025) turned compliance into a purchase trigger, and by February 2026 PreVeil counted 2,500+ defense-contractor customers with 60+ perfect-110 CMMC certifications.

How it ended up

Still running. On July 13, 2026 the Pentagon suspended CMMC Phase 2 — the third-party Level 2 certification due November 10, 2026 — citing prohibitive compliance costs, a severe assessor shortage, and harm to small suppliers, and opened a 60-day CMMC Reform Task Force review, leaving the regulatory tailwind the company bet on under reform.

Background

PreVeil, founded in Boston in 2015 by former Apple and Airvana executives Randy Battat and Sanjeev Verma, sells end-to-end encrypted email and file sharing for organizations that handle sensitive data. The product installs as an overlay on Microsoft 365 or Google Workspace: messages and files are encrypted on the device, and even PreVeil cannot read them — a 'zero knowledge' architecture aimed at defense contractors, universities and law firms.

The company's real bet was regulatory: the Pentagon's Cybersecurity Maturity Model Certification (CMMC) program, finalized as a rule in October 2024, requires contractors handling controlled unclassified information (CUI) to implement NIST 800-171 controls and prove it. Instead of forcing small shops to migrate to Microsoft's GCC High cloud — quoted above $200,000 by one contractor — PreVeil wrapped the controls in software and shipped assessment-ready documentation. PSG led a $20 million Series C in October 2022, when PreVeil said 600+ organizations and 30,000+ users relied on it.

Enforcement began in November 2025 with self-assessments, and by February 2026 PreVeil counted more than 2,500 defense-contractor customers and 60+ CMMC Level 2 certifications, all scoring a perfect 110 of 110. Then, on July 13, 2026, the Pentagon suspended CMMC Phase 2 — third-party certification due November 10, 2026 — citing prohibitive costs and a shortage of assessors (roughly 100 assessors for more than 100,000 companies), and opened a 60-day program review.

As of September 2026 PreVeil is still operating and expanding beyond defense; the core NIST 800-171 obligations remain in force, but the specific certification mandate it grew on is under reform.

What has to be true

  • The bet was timed to regulation, not fashion: CMMC turned an optional security product into a condition of winning government contracts.
  • The architecture attacked the cost objection: a quoted ~$200,000 GCC High migration versus ~$20,000 for PreVeil made the pitch obvious for small contractors.
  • Concrete audit results — 60+ customers with perfect 110/110 scores — gave the company proof that its compliance bundle worked.
  • The July 2026 suspension shows the risk of building on a mandate: one memorandum paused the exact deadline the company marketed against.

What can be applied

A startup can ride a regulatory mandate to a customer base, but the same regulator can pause it: sell to the underlying obligation, not to the specific certification deadline.

Aftermath

As of September 2, 2026, PreVeil is still running with roughly 2,500+ defense-contractor customers. The CMMC Reform Task Force's 60-day review was expected to report around mid-September 2026; DoD kept NIST SP 800-171 self-assessment obligations in place but removed C3PAO Level 2 and Level 3 certification requirements from solicitations during the pause. PreVeil's guidance to customers is that DFARS 252.204-7012 obligations endure while the certification program is reassessed, and the company continues marketing to professional services, financial services and healthcare alongside defense.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases