$90K to $420K MRR across 22 months.
An Albuquerque federal-adjacent SaaS · $90K → $420K MRR.
Industry archetype drawn from federal-adjacent B2B SaaS work in the Sandia and Kirtland corridor of Albuquerque, New Mexico. Across 22 months, the shape holds steady. 4.7x MRR, a shipped NIST 800-171 attestation, FedRAMP-Low-aware engineering, NRR at 128 percent, and a 6x Sandia-area defence-prime partner pipeline.
Industry archetype. Based on patterns across multiple defense-adjacent SaaS clients in the New Mexico / Albuquerque corridor. Brand name and identifying details are illustrative; metrics are representative ranges across the engagement type. No fictional brand identity is being claimed as a real client.
A federal-adjacent B2B SaaS in the Sandia and Kirtland corridor of Albuquerque scaled from $90K MRR to $420K MRR in 22 months. It began with 9 commercial customers and zero federal readiness. Three moves changed the trajectory: a NIST SP 800-171 Rev. 3 self-attestation, a migration to AWS GovCloud (US), and a partner channel built through defence primes near Sandia National Laboratories.
The result took a five-pillar shape. 4.7x MRR, a 22-month horizon, NRR at 128 percent, and a 6x partner pipeline. One operational change gated all of it. The NIST 800-171 attestation is what unblocked the CUI-handling contracts.
- MRR delta: $90K to $420K in 22 months · 4.7x trajectory.
- Growth multiple: 4.7x with the partner-channel cohort contributing 41 percent of the lift.
- Time horizon: 22 months from kickoff to milestone, including a 14-week build window.
- NRR uplift: 102 percent to 128 percent on the back of multi-year defence-prime expansions.
- Operational change: NIST SP 800-171 self-attestation + AWS GovCloud migration unblocked CUI-handling contracts.
Defence-prime partner channel pipeline post NIST 800-171.
Net Revenue Retention from multi-year defence-prime expansion.
A commercial SaaS sitting next to a federal-procurement gravity well.
Here is a pattern we ship into again and again. Picture a commercial-first B2B SaaS built by ex-Sandia or ex-Kirtland engineers, working somewhere between Uptown ABQ and the Sandia Science and Technology Park. It runs $90K MRR across 9 commercial customers. Business on the commercial side is good.
Then the inbound shifts. Defence-prime subcontractors keep asking the same three questions. Are you NIST 800-171 attested? Do you run in GovCloud? Can you handle CUI? The founder knows the answer is no. The founder also knows the next 18 months of revenue sits locked behind those three questions.
The pre-engagement state was purely commercial. $90K MRR on a commercial AWS region, single-tenant. No Controlled Unclassified Information handling boundary. No NIST 800-171 self-attestation on file in the SAM.gov Supplier Performance Risk System (SPRS) score record. No audit trail, no separation-of-duty controls, no SAML SSO.
The stack was a typical commercial-SaaS combination: Next.js front end, a Python service tier, Postgres, Stripe, Auth0, and vanilla AWS networking inside a single VPC. Nothing wrong with any of those choices on the commercial side. But every one of them became a question mark the moment a defence prime's security team asked, "show us your boundary diagram and your CUI flow-down".
Three structural problems were compounding the revenue ceiling. One, defence-prime subcontractor contracts that touch CUI (Controlled Unclassified Information) require a current NIST SP 800-171 self-assessment posted to SPRS. Without it, the SaaS could not even appear on the prime's approved-vendor short-list, no matter how strong the product was.
Two, several of the prime's downstream customers required FedRAMP-Low-aware controls for any tool crossing into their environment. That group included the Air Force Research Laboratory at Kirtland and a couple of Sandia program offices. The requirement held even though the SaaS itself never needed a full Authorization to Operate.
Three, the partner motion the defence corridor runs on was new to the founding team. Vendor onboarding. Security questionnaires. Trade Agreements Act flow-down. ITAR-aware data residency assertions. Past-performance documentation. Capability statements. All of it was fresh ground.
Under all three sat a deeper problem: the clock. The prime's procurement runs on fiscal-year cycles tied to the federal calendar. Miss one round of vendor-onboarding paperwork, and you wait six to nine months for the next prime-led teaming opportunity.
Two of the founder's strongest inbound inquiries had already slipped that way. So the cost of doing nothing was not just slow growth. It was a measurable opportunity-cost line on the founder's own deal log.
The Federal-Ready Stack. 14 weeks. Five workstreams.
We call the method the Federal-Ready Stack. It is a 14-week, five-workstream build. It takes a commercial-first SaaS from a plain AWS deployment to something NIST 800-171 attested, FedRAMP-Low-aware, partner-channel-ready, and SPRS-scored.
All five workstreams ran in parallel. Weekly Tuesday MT standups, Friday demos, every milestone Loom-recorded for the founder's federal advisor. We anchored the timeline to the prime's fiscal-year teaming windows. So the SPRS score posted at week 9, right as the next round of vendor-onboarding calls opened, not mid-cycle when procurement was already locked out for the quarter.
Workstream 1 · NIST SP 800-171 Rev. 3 self-attestation. We ran a full gap assessment against the 110 security requirements in NIST SP 800-171 Rev. 3. Then we drafted the System Security Plan, tracked the Plan of Action and Milestones weekly, and posted the resulting score to SPRS via SAM.gov.
The coverage spans the full control set. Access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
Workstream 2 · AWS GovCloud (US) migration with FedRAMP-Low controls. We moved workloads from commercial AWS regions to AWS GovCloud (US). Then we aligned the build to the FedRAMP-Low baseline, a subset of NIST 800-53 Rev. 5 controls.
In practice that means FIPS 140-3 validated cryptography, US-citizen-only operations staffing for the GovCloud tenancy, and full audit logging into CloudWatch plus an immutable S3 GovCloud archive. The architecture is ATO-ready. A full ATO stays a 12 to 18-month follow-on project.
Workstream 3 · Continuous-compliance tooling. We stood up continuous compliance evidence collection through Vanta with the NIST 800-171 framework template. Then we layered Drata on top for the SOC 2 Type II evidence trail the founder's commercial customers still required. Daily automated control checks. Monthly evidence packages exported to a defence-prime portal. Quarterly internal audit.
Workstream 4 · SSO, RBAC, and CUI-handling boundary. We implemented SAML 2.0 SSO via a federal-friendly identity provider, plus role-based access control with separation-of-duty enforcement. A clearly-bounded CUI-handling module segregates Controlled Unclassified Information from commercial-tier data. Every administrative action lands in the audit trail. The trail exports on demand for prime-subcontractor security questionnaires.
Workstream 5 · Sandia-corridor partner channel. We built the partner motion from scratch. That meant a capability statement aligned to the prime's Statement of Work language, past-performance write-ups stripped to the redactable subset, sub-tier vendor onboarding kits, a security questionnaire library with the common 280-question review pre-answered, and a partner enablement portal.
The channel pipeline 6x'd over 12 months, once the NIST 800-171 attestation landed in SPRS.
Two cross-cutting choices made the timing work. First, the SPRS score posted in week 9, right after the Workstream 1 gap-close. That posting became the unlock signal for every other outbound conversation.
Second, the GovCloud migration ran exactly six weeks ahead of the partner-channel work. So when the first prime asked for an architecture diagram, the GovCloud tenancy was already live, with three weeks of operational telemetry behind it. Sequence matters. We have rebuilt this 14-week plan four times, and the sequencing is the one part that never moves.
Federal-aware core. GovCloud-deployable. Boring choices.
The stack is intentionally boring. Every component sits in a documented, audited deployment pattern that an outside 3PAO (third-party assessment organisation) or a prime's security team can recognise in 10 minutes. No bespoke crypto. No untested infra. No proprietary policy-as-code language. Every choice maps to a recognised federal control baseline.
AWS GovCloud (US)
AWS GovCloud (US) with FedRAMP-Low alignment, FIPS 140-3 cryptography, US-citizen-only operations.
NIST SP 800-171 Rev. 3
110-requirement framework from the NIST Computer Security Resource Center, scored to SPRS.
Vanta + Drata
Vanta for the NIST 800-171 evidence trail; Drata for SOC 2 Type II.
WorkOS SAML + PIV-ready
SAML 2.0 SSO via WorkOS; PIV-card-ready login path for future federal-direct deployments.
SAM.gov SPRS posted
SAM.gov entity registration; NIST 800-171 score posted to the Supplier Performance Risk System.
CloudWatch + S3 GovCloud archive
Immutable audit logs with object-lock retention aligned to the prime's record-retention flow-down.
The numbers behind the headline.
The archetype rests on five metric pillars. MRR grew 4.7x, from $90K to $420K. The time horizon was 22 months. NRR moved from 102 percent to 128 percent on multi-year defence-prime expansions.
The partner-channel pipeline 6x'd through Sandia-corridor primes. And one operational change gated the rest: the NIST SP 800-171 self-attestation posted to SPRS. Specific brands inside the pattern land within plus or minus 25 percent on each line.
| metric | pre-engagement | month 8 | month 22 |
|---|---|---|---|
| MRR | $90K | $185K | $420K |
| Defence-prime sub-tier wins | 0 | 3 | 11 |
| NIST 800-171 score (SPRS) | not posted | 68 / 110 | 102 / 110 |
| GovCloud + FedRAMP-Low-aware | none | migrated | aligned |
| Partner pipeline (count) | 2 | 6 | 12 |
| NRR | 102% | 115% | 128% |
Metrics representative of the archetype; specific brands within the pattern range plus or minus 25 percent on each line.
What transfers to a comparable Albuquerque build. Five capabilities move straight from the archetype to a paired engagement. First, a NIST SP 800-171 Rev. 3 gap assessment, with the System Security Plan and Plan of Action and Milestones drafted to defence-prime audit standards.
Second, an AWS GovCloud (US) migration sized to the federal-tier workloads only, with the commercial cohort left on cheaper commercial regions. Third, a continuous-compliance evidence trail in Vanta plus Drata. That turns the monthly export to a prime's security portal into a five-minute task instead of a five-day fire drill.
The last two are just as portable. SAML 2.0 SSO with PIV-card-ready paths and a clean separation-of-duty role model. And a Sandia-corridor partner-channel kit, with the pre-answered 280-question security questionnaire library, a redacted past-performance section, and a capability statement aligned to common Statement of Work language from the primes near Kirtland.
Treat the five-pillar shape as a benchmark, not a promise. The pillars again: 4.7x MRR over 22 months, NRR at 128 percent, a 6x partner pipeline, and one operational change, the NIST 800-171 attestation posted to SPRS.
Every engagement we have shipped on this pattern landed within plus or minus 25 percent of those numbers. The variance comes down to one thing: how fast the founder's prime relationships move from interested to request for proposal. Two engagements hit $420K MRR in 18 months. One took 28 months, because the founder's largest prime relationship froze for a fiscal-year transition.
"We spent two years explaining to primes why we were almost ready. The NIST 800-171 score posted to SPRS, then the GovCloud tenancy went live, and inside six weeks the conversation flipped from 'maybe next cycle' to 'can you onboard by the end of the quarter'. The work was tedious. The unlock was immediate."
Five questions Albuquerque founders always ask first.
Is a NIST SP 800-171 self-attestation the same as a CMMC certification? +
Does AWS GovCloud cost more than commercial AWS? +
Do I need a full FedRAMP Authorization to Operate to sell to defence primes near Sandia? +
You are based in New York and Delhi. Can you handle ITAR-aware work for an Albuquerque client? +
How long does the 14-week Federal-Ready Stack take in calendar time, including review cycles? +
Sandia corridor. 4.7x trajectories don't ship themselves.
30-minute call on Mountain Time. Written scope and fixed-price quote in 48 hours. US-citizen-led staffing on any ITAR-aware workstream.
Published · Last updated .