档案库 · 开发与企业工具 · 战略决策 · 2015–2026
PreVeil押注CMMC强制令,让加密电子邮件成为国防采购必选品
波士顿零知识电子邮件初创公司借助DoD的CMMC规则赢得2500多家承包商客户,随后五角大楼于2026年7月暂停第二阶段。
PreVeil
做的是什么生意
PreVeil is an end-to-end encrypted email and file-sharing platform for organizations that handle sensitive data, installed as an overlay on Microsoft 365 or Google Workspace and marketed mainly to defense contractors that must meet CMMC, NIST 800-171 and ITAR rules.
启动资金:About $27M total raised, including a $20M Series C led by PSG (October 2022).
起因
PreVeil was founded in Boston in 2015 by former Apple and Airvana executives Randy Battat and Sanjeev Verma, building on MIT encryption research by CTO Raluca Ada Popa. The original pitch was end-to-end encryption that ordinary users can operate: data is encrypted on the device, no server, admin or even PreVeil can read it, and there is no single point of attack.
经过
The defense pivot came when NIST 800-171 and ITAR made CUI protection a contractual condition: PreVeil became the compliance path for small contractors that could not afford Microsoft's GCC High government cloud. PSG led a $20M Series C in October 2022 to expand beyond defense. DoD's CMMC 2.0 final rule (October 2024) and Phase 1 enforcement (November 2025) turned compliance into a purchase trigger, and by February 2026 PreVeil counted 2,500+ defense-contractor customers with 60+ perfect-110 CMMC certifications.
结果
Still running. On July 13, 2026 the Pentagon suspended CMMC Phase 2 — the third-party Level 2 certification due November 10, 2026 — citing prohibitive compliance costs, a severe assessor shortage, and harm to small suppliers, and opened a 60-day CMMC Reform Task Force review, leaving the regulatory tailwind the company bet on under reform.
背景
PreVeil由前苹果和Airvana高管Randy Battat和Sanjeev Verma于2015年在波士顿创立,销售端到端加密电子邮件和文件共享服务,面向处理敏感数据的组织。该产品作为Microsoft 365或Google Workspace的覆盖层安装:消息和文件在设备上加密,连PreVeil也无法读取——这是一种“零知识”架构,面向国防承包商、大学和律师事务所。
该公司的真正赌注是监管:五角大楼的网络安全成熟度模型认证(CMMC)计划于2024年10月最终确定为规则,要求处理受控非机密信息(CUI)的承包商实施NIST 800-171控制措施并证明合规。PreVeil没有迫使小企业迁移到微软的GCC High云——一位承包商报价超过20万美元——而是将控制措施包装在软件中,并提供可评估的文档。PSG于2022年10月领投2000万美元C轮,当时PreVeil声称有600多个组织和3万多名用户依赖其服务。
执法于2025年11月开始,首先是自我评估,到2026年2月,PreVeil拥有2500多家国防承包商客户,并取得60多项CMMC 2级认证,全部获得满分110分。然后,2026年7月13日,五角大楼暂停了CMMC第二阶段——原定于2026年11月10日进行的第三方认证——理由是成本过高和评估员短缺(约100名评估员对应10万多家公司),并启动了60天的项目审查。
截至2026年9月,PreVeil仍在运营并扩展到国防以外;核心NIST 800-171义务仍然有效,但其赖以发展的特定认证任务正在改革中。
这件事要成立,得有什么
- 赌注盯准了监管而非时尚:CMMC将可选的安全产品变成了赢得政府合同的条件。
- 架构解决了成本异议:约20万美元的GCC High迁移与约2万美元的PreVeil形成鲜明对比,使得小承包商的购买理由显而易见。
- 具体的审计结果——60多家客户获得满分110分——为公司提供了合规捆绑有效的证据。
- 2026年7月的暂停显示了建立在任务之上的风险:一份备忘录就暂停了公司营销时针对的截止日期。
可借鉴之处
初创公司可以借助监管规定获得客户基础,但同一监管机构也可能暂停它:向基础义务销售,而不是向特定的认证截止日期销售。
后续进展
截至2026年9月2日,PreVeil仍在运营,拥有约2500多家国防承包商客户。预计CMMC改革工作组的60天审查报告将在2026年9月中旬左右发布;DoD保留了NIST SP 800-171自我评估义务,但在暂停期间从招标中移除了C3PAO 2级和3级认证要求。PreVeil对客户的指导是,DFARS 252.204-7012义务在认证计划重新评估期间仍然有效,公司继续在国防之外向专业服务、金融服务和医疗保健领域营销。
资料来源
- PreVeil Announces Series C Funding Round Led by PSG
- DOD halts cybersecurity requirements for CMMC Phase 2: 'The math just simply doesn't math'
- Reassessing CMMC: DOD Suspends CMMC Phase II, But Core DFARS Obligations Endure
- PreVeil for Japanese Defense Suppliers: Achieving CMMC, DFARS, and ITAR Compliance Without Disrupting Your Business
- Company — PreVeil
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡