SMPL-C's AI Platform Lands a Former DHS CISO for the Defense Contractor's Compliance Burden

The South Carolina startup, backed by MACH37 and SCRA, is betting its generative AI can automate the manual documentation required for CMMC certification.

About SMPL-C

Published

For a small defense contractor, the path to a government contract is paved with acronyms and anxiety. The Cybersecurity Maturity Model Certification (CMMC) is a non-negotiable requirement, a sprawling framework of over 100 security controls that must be documented, attested, and evidenced. The process is notoriously manual, a paperwork labyrinth that can stall business for months. SMPL-C, a startup from Mount Pleasant, South Carolina, is betting that generative AI can turn that slog into a systematic workflow.

Founded in 2023, the company has built a SaaS platform designed to automate the creation, collection, and management of compliance documentation for CMMC and the related NIST 800-171 standard. The goal is not just to check boxes, but to provide a continuous, auditable system for the defense-industrial base, a market of over 300,000 companies that must now prove their cyber hygiene to the Pentagon. The company claims its AI-enabled workflows can accelerate the compliance process by 40%, a figure that speaks to the profound inefficiency of the status quo but remains, for now, a company-provided metric without independent peer review [Perplexity Sonar Pro Brief, June 2026].

The wedge into a regulated market

The company's product wedge is specificity. While general-purpose compliance platforms like Vanta or Drata serve a broad commercial market, SMPL-C is built from the ground up for the exact language, control families, and evidence requirements of CMMC. The platform aims to streamline gap assessments, auto-generate required system security plans and policies, and maintain a continuous evidence trail. Its target users are not just internal IT teams at aerospace giants, but the ecosystem of CMMC consultants and managed service providers (MSPs) who act as guides for smaller contractors.

This focus has attracted a notable class of early advisors, a signal in a domain where regulatory credibility is currency. The most prominent is Kenneth Bible, the recently retired Chief Information Security Officer for the U.S. Department of Homeland Security, who has joined the company's board of advisors [citybiz, retrieved 2026]. His public endorsement, alongside advisors like former entrepreneur Paul Anuszkiewicz and Falcon 5 Capital's Manish Mehta, lends operational and strategic weight to a young team.

Building the team and the traction

The founding trio brings complementary backgrounds to the problem. CEO Srikant Rachakonda identified the compliance burden firsthand while working in cybersecurity, later founding SMPL-C after seeing experts and contractors struggle with documentation in 2021 [Megan McConville Sisson - Marketer | Story-Seeker, retrieved 2026]. Co-founder and CTO Yash Kumar, a former Amazon employee and the founder/CEO of developer tools startup Runnable, is responsible for the platform's technical and AI foundation [TechCrunch, May 2012] [TechCrunch, September 2016]. Jody Stoehr rounds out the team as Chief Revenue Officer.

Traction, while early, points to market validation. The company was a Venture Atlanta 2024 Showcase Company and has formed a strategic partnership with Rackspace Technology to offer combined compliance services [Markets Insider, Unknown]. Public directories list several organizations as customer references, including C3EL, Mandex, and Gray Analytics, though specific contract values or implementation details are not disclosed [Perplexity Sonar Pro Brief, Unknown].

Role Name Key Background
Founder & CEO Srikant Rachakonda Cybersecurity product strategy; identified CMMC documentation problem.
Co-Founder & CTO Yash Kumar Former Amazon; Founder/CEO of Runnable.
Co-Founder & CRO Jody Stoehr Not specified in public record.
Advisor Kenneth Bible Recently retired CISO, U.S. Department of Homeland Security.
Advisor Paul Anuszkiewicz Exited entrepreneur, venture partner.

Funding a niche bet

Public funding records show a mosaic of early-stage support, typical for a capital-efficient startup targeting a specialized government-adjacent sector. SMPL-C has progressed through accelerators like MACH37 and the Harbor Entrepreneur Center. Its financing includes a reported $145,000 seed round, a $50,000 grant from South Carolina's SCRA, and a $1 million angel round led by MACH37 closed at the end of 2024 [Tracxn, April 2024] [Caplight, October 2024] [PitchBook, December 2024]. The cumulative total is difficult to pin down due to database discrepancies, but the backing from a cybersecurity-focused accelerator like MACH37 and a state economic development engine like SCRA suggests investors see a tangible need.

The competitive and execution landscape

The path forward is not without its obstacles. The competitive set is layered and well-resourced.

  • The giants. Microsoft offers extensive compliance tooling within its Azure Government cloud, embedding security controls directly into the infrastructure. This represents a platform-level competitor where compliance is a feature, not a product.
  • The commercial GRC players. Companies like Secureframe, Sprinto, Vanta, and Drata have built robust businesses automating standards like SOC 2 and ISO 27001. Their expansion into government frameworks like FedRAMP,and potentially CMMC,is a logical next step, leveraging existing sales channels and brand recognition.
  • The encryption specialists. PreVeil and Virtru focus on data-in-transit and at-rest security for defense and regulated industries, solving a different but adjacent piece of the cybersecurity puzzle.

SMPL-C's answer is its focused expertise. The company is betting that a dedicated, AI-native tool built exclusively for the nuances of CMMC will outperform generalized platforms. Its partnership with Rackspace and advisor roster are early moves to build the channel credibility and domain authority required to navigate this complex sale. The primary execution risk is scaling a go-to-market motion within the fragmented, often relationship-driven defense contractor ecosystem with a team that public records suggest numbers between one and ten employees [Perplexity Sonar Pro Brief, Unknown].

The patient population and the standard of care

The ultimate test for SMPL-C will be its impact on the ground for the businesses it serves. The patient population here is the vast network of small-to-midsize defense contractors and subcontractors,machine shops, software firms, component manufacturers,for whom CMMC is a costly, confusing barrier to revenue. For them, the current standard of care is a painful blend of expensive consultants, spreadsheets, and shared drives, a manual process prone to error and drift. It is a compliance burden that directly impacts national security by slowing the onboarding of innovative suppliers.

If SMPL-C's AI can reliably turn that chaos into a coherent, maintainable system, it will have done more than build a software business. It will have addressed a critical friction point in the defense supply chain, a humane outcome measured not in uptime, but in the number of companies that can securely compete for the work of keeping the nation safe. The next twelve months will be about proving that its platform can move beyond early references to become a trusted, scalable system for this highly specialized, and critically important, market.

Sources

  1. [citybiz, retrieved 2026] Kenneth Bible joins SMPL-C's board of advisors | https://citybiz.co/
  2. [Megan McConville Sisson - Marketer | Story-Seeker, retrieved 2026] Srikant Rachakonda founding story | https://www.linkedin.com/
  3. [TechCrunch, May 2012] Article referencing Yash Kumar's background | https://techcrunch.com/2012/05/04/new-start-up-codenow-com-lets-you-build-and-test-code-in-real-time-in-your-browser/
  4. [TechCrunch, September 2016] Runnable general availability announcement | https://techcrunch.com/2016/09/20/runnable-general-availability/
  5. [Markets Insider, Unknown] Rackspace Technology and SMPL-C partnership announcement | https://markets.businessinsider.com/news/stocks/rackspace-technology-and-smpl-c-announce-strategic-better-together-partnership-to-accelerate-cmmc-compliance-for-government-contractors-1035077155
  6. [Tracxn, April 2024] SMPL-C seed round reporting | https://tracxn.com/d/companies/smplc/__X-zIDqnX6vGtKk8TNQcvVkmeplO8mci-4mkNz6T4gow
  7. [Caplight, October 2024] SCRA grant reporting | https://caplight.com/
  8. [PitchBook, December 2024] $1 million angel round reporting | https://pitchbook.com/profiles/company/592339-78

Read on Startuply.vc