Stealth Technology Group

Metal fabrication shop passes its CMMC Level 2 assessment

From overwhelmed to certified: how a 38-person defense supplier passed CMMC Level 2 and won new business

Industry: Manufacturing

Employees: 38

Location: Northeastern US

Solution: Partnered with a Managed IT provider to implement security controls, document processes, and prepare for assessment
Results: Passed the CMMC Level 2 assessment in July 2026, reduced internal stress, and secured a new multi-year defense contract

Results

CMMC Level 2 assessment passed — July 2026

Written policies, MFA, backup, antivirus, and patching in place — with evidence

A new multi-year defense contract, and confidence with every prime

The Challenge

The leadership team at a growing metal fabrication shop was facing increasing pressure from their defense customers to become CMMC Level 2 compliant. While they excelled at delivering tight-tolerance components on time, their internal IT systems told a different story:

  • Passwords were shared informally
  • Laptops weren’t encrypted
  • There was no formal backup plan, no MFA, and no training
  • And most of the team didn’t even know what “CMMC” stood for

 

The owner had recently lost a valuable DoD subcontract opportunity because the client’s prime contractor required documentation they couldn’t provide. He admitted, “We didn’t know what we didn’t know — and it was starting to hurt the business.”
What started as a compliance concern quickly became a source of stress, anxiety, and lost revenue.

The Solution

After connecting with our team, the first step was taking ownership of the problem — together.

We began with a readiness assessment mapped to CMMC Level 2 controls, then delivered a structured plan to:

  • Implement MFA across all email and remote access
  • Ensure antivirus and patching on all workstations
  • Standardize user access, logins, and device policies
  • Move sensitive files to Microsoft 365 with access control and cloud backup
  • Create simple written policies (passwords, backups, physical security, etc.)
  • Deliver staff training so everyone knew the “why” behind new policies

 

Throughout the process, we met weekly with leadership to explain steps, simplify technical language, and give them peace of mind.
“We didn’t want another vendor. We needed a partner. And that’s exactly what we got.”

“This wasn’t just about compliance. It was about protecting the business and unlocking growth. You helped us do both.”
Manufacturing Firm
Operation Manager
Scroll to Top