The Pentagon's zero-trust architecture push is real, the contracts are flowing, and the technology is largely ready. What's quietly strangling the pipeline is something far more mundane: the compliance infrastructure a company needs before it can even bid.
That's the story buried inside Arkenstone Defense's $35 million launch this week — and it reframes the entire conversation about venture-backed cyber startups winning DoD modernization work.
The Compliance Wall Is Getting More Expensive, Not Less
Here's the number that should stop you cold: the Defense Department estimates it costs a small contractor close to $490,000 over three years just to earn Cybersecurity Maturity Model Certification Level 2 — and that's one line on a longer checklist. Fewer than 90 assessors are authorized to do that work nationwide, and enforcement turns mandatory in November.
Meanwhile, the supplier base is shrinking. The Pentagon worked with roughly 76,700 businesses in 2017. By 2021, that number had dropped to around 60,000, per National Defense Industrial Association data cited in Arkenstone's launch. Prime contractors have thinned from 51 in the 1990s to five today.
This is the structural problem that cyber resilience startups run into before they ever get to demonstrate their actual technology. A company can have genuinely differentiated zero-trust tooling — network segmentation, identity verification, continuous monitoring — and still spend years building the government back office required to sell it. Many give up. The ones that don't often burn so much runway on compliance that they arrive at the contract table undercapitalized.
Arkenstone's pitch is that this is a solvable infrastructure problem, not an immutable feature of the defense market. Its managed platform handles payroll, personnel security, Defense Contract Audit Agency compliance, facility accreditation, and the full CMMC lifecycle as a single service — built around a professional employer organization that legally employs the cleared workforce. More than two dozen defense tech companies are already running on it. Co-founder Peter Dixon previously co-founded Second Front Systems and served as a Marine Corps major; co-founder William Treseder spent over 15 years bridging Silicon Valley and the Pentagon through BMNT and Hacking for Defense. The seed round was led by J2 Ventures, with Susa Ventures, Granite Hill Capital Partners, and Artis Ventures participating.
The investor thesis here is essentially: if you can commoditize the compliance layer, you unlock a much larger pool of capable vendors who can actually compete for zero-trust and cyber resilience contracts.
What This Means for the Cyber Startup Thesis
The assigned topic — venture-backed cyber resilience startups winning DoD zero-trust contracts — is real as a directional trend, but the source pool this week doesn't surface specific contract awards to name. What it does surface is something arguably more important: the structural reason that trend is moving slower than the technology would suggest it should.
Think about it from an investor's perspective. You back a cyber startup with genuinely novel zero-trust architecture. The technology works. The Pentagon has a documented need. But your portfolio company spends 18 months and nearly half a million dollars getting CMMC-certified, hiring cleared staff through a patchwork of arrangements, and navigating DCAA compliance before it can even respond to a solicitation. That's not a technology problem. That's a market access problem — and market access problems are exactly what infrastructure plays like Arkenstone are designed to solve.
The parallel to what's happening in European defense tech is instructive. Helsing just raised $1.8 billion in Europe's largest-ever defense startup round, valuing the Munich-based AI company at $18 billion. Founded in 2021, Helsing has moved fast precisely because it focused on software-defined capabilities — AI platforms, battlefield operations software, autonomous systems — and built the institutional relationships to deploy them at scale. The lesson isn't that European defense tech is ahead; it's that the companies moving fastest are the ones that solved the infrastructure problem early and then competed on technology.
The same dynamic is visible in how the DIU structures its competitions. The agency's recently launched Spectacular MIST Challenge — a joint effort with the Navy to accelerate containerized payloads on manned and unmanned surface vessels — explicitly calls for "open-system architectures and software-defined capabilities." That framing is deliberate: it's designed to let non-traditional vendors compete without having to rebuild their entire technical stack to meet legacy integration requirements. But open architecture doesn't dissolve the compliance burden. A startup responding to that solicitation still needs cleared personnel, DCAA-compliant accounting, and a facility security infrastructure in place before it can deliver.
The Procurement Bottleneck Is the Investment Thesis
I've written before about how the Pentagon's zero-trust push produced a more complicated contract story than the hype suggested. The Air Force's zero-trust initiative revealed that institutional inertia and integration complexity were slowing deployment even when the technology was available. The CMMC enforcement deadline adds a new dimension: it's about to force a reckoning on the supply side.
Companies that haven't completed CMMC Level 2 certification by November face real consequences for competing on sensitive defense work. That deadline is a forcing function — and it's going to separate the startups that built their compliance infrastructure early from those that treated it as an afterthought. It's worth noting that this pressure isn't unique to cyber: the Army's newly selected vendors for its autonomous breaching program — Caterpillar, Forterra, IDV USA, and Overland AI — are all companies that had already cleared the institutional bar required to participate in a formal Army program. The compliance infrastructure came first; the contract followed.
Watch for two things in the next 90 days: whether the CMMC enforcement deadline actually holds (there's historical precedent for slippage), and whether Arkenstone's model attracts imitators. If the compliance-as-a-service category develops real competition, the cost of market entry for cyber startups drops materially — which means the zero-trust contract pipeline opens up faster than the current bottleneck would suggest.
The technology was never the hard part. It rarely is.
