Defense consulting firm passes its C3PAO CMMC Level 2 assessment — 110 of 110 controls
How a defense-industry consulting firm went from kickoff to a perfect Level 2 assessment in about 90 days
Industry: Professional services — defense contractor
Location: Northeastern US
Solution: CMMC Level 2 preparation and managed IT from Stealth Technology Group, a Cyber AB Registered Practitioner Organization — gap assessment, remediation, evidence, SSP and POA&M, and assessment-day support
Results: Passed the C3PAO CMMC Level 2 assessment with a perfect 110 of 110 controls, roughly 90 days from kickoff to assessment-ready
Results
C3PAO CMMC Level 2 assessment passed — 110 of 110 controls
About 90 days from kickoff to assessment-ready
One partner for managed IT and CMMC — no hand-offs, no finger-pointing
The Challenge
The firm needed a CMMC Level 2 certification to keep doing the defense work it was built for — and wanted one partner to run its IT and carry it through the assessment, rather than an MSP and a compliance consultant pointing at each other.
The bar was the full one: all 110 NIST SP 800-171 controls, implemented and proven with evidence a third-party assessor would accept, on a timeline the business could live with.
The Solution
Stealth ran the engagement as a single accountable team — the same people operating the environment were the people preparing the evidence.
- Scoped the CUI environment and mapped every control to an owner
- Closed the gaps: identity and MFA, endpoint and email protection, logging, backup, and access control
- Wrote the System Security Plan and POA&M, and built the evidence package control by control
- Rehearsed the assessment before the assessor arrived
Roughly 90 days after kickoff, the firm was assessment-ready. The assessor found all 110 controls met.
