A Northeast Ohio construction company bids government work as a prime contractor. CMMC Level 2 certification became a condition of eligibility. Nobody in the office knew what the standard asked for, quotes from assessors ranged widely, and the risk was not a fine but losing the ability to bid. Tech Dynamix ran a gap assessment against all 110 controls, produced a prioritized remediation plan, and turned an unbounded compliance question into a project with a scope and a sequence.
The situation
The company holds its government contracts directly. There is no prime above it to absorb the requirement or interpret it on its behalf, and there is nobody to inherit an answer from. The obligation sits in the contract terms, and everything below it flows down from this company rather than to it.
What the company had was a working business and an IT setup that had grown around it. What the standard asked for was evidence, control by control, that specific things were true.
- Nobody internally could say which controls the business already met and which it did not
- Controlled unclassified information was on the network, but nobody could say exactly where it was, who could reach it, or where it had been copied to. On a construction project that means drawings, specifications, site plans, and facility details, the working documents that get emailed and shared as a matter of routine
- Work happens away from the office. Job site trailers, field tablets, and laptops in trucks are not on the same network, and not on the same patching or backup schedule, and no plan accounted for that
- Controlled information does not stay inside the company by design. It goes out to subcontractors, architects, and engineers, and nobody had a record of what had been sent where. As the prime, the company is answerable for what happens to it after it leaves
- Advice from outside ranged from "you are basically fine" to quotes for a program costing more than the contracts were worth
- The exposure was not a penalty. It was ineligibility. Failing to certify meant being unable to hold the contracts the business bids on, and prime contractors do not get a grace period from anyone above them
The hardest part was not any single control. It was that nobody could see the shape of the whole job, so it felt unbounded, and an unbounded problem is one that gets postponed.
What we did
We started by scoping, because scope is what decides the cost of the entire program.
Tech Dynamix mapped where controlled unclassified information actually lived: which systems held it, which people touched it, which parts of the network it crossed, and where it went when it left the company. Narrowing that boundary is the single most effective thing a contractor can do to reduce what certification costs. Every system inside the boundary carries the full weight of the control set. Every system outside it does not.
What the exercise found was three problems rather than one.
- Systems too weak to hold controlled information. Parts of the environment could not meet the standard as configured, and in some cases could not meet it at all in their current form
- No written procedures. The business did things a particular way, but that way lived in people's heads. The standard does not accept that. It asks for documented process, and there was none to hand an assessor
- Limited logging and audit trails. Where records existed they were thin, and where they did not exist there was no way to reconstruct who did what. A large share of the control set depends on being able to answer that question after the fact
With the boundary drawn, we assessed against all 110 controls and wrote down, in plain language, three things for every one of them: whether it was met, what evidence would prove it, and what it would take to close it.
The remediation plan that came out of that was ordered by risk and by effort rather than by control number.
- Already met. Controls the business satisfied, with the evidence identified so it exists before an assessor asks
- Close quickly. Configuration and policy work with real security value and little cost. Multi-factor authentication across every account that touches controlled information. An access review to establish who actually needs what, which almost always removes more access than it grants. Session lockout and screen timeouts. Turning on logging where the capability was already licensed and simply switched off. Removing local administrator rights from standard users
- Plan and budget. The items with a real price and a lead time: the systems that cannot meet the standard as they stand, segmenting job site connectivity from the office network, and bringing field devices under management
- Document. The written procedures, the system security plan, and the plan of action. This is the part contractors most often leave until last, it takes the longest, and in this case it was starting from nothing
Not all of it was built in house, and it did not need to be. A large part of the control set is satisfied by security tooling that already exists and does the job well, so the work is choosing it, deploying it correctly, and running it rather than inventing it. Multi-factor authentication, endpoint detection and response, centralized logging and a SIEM to make those logs mean something, email security, vulnerability scanning, and device management for equipment that never comes back to the office are all products. What they are not is self-managing. The control is not satisfied by owning the tool. It is satisfied by the tool being configured to the standard, monitored by somebody, and evidenced when asked, which is the part a business without a security team cannot carry alone.
Documentation is not a formality here. Certification tests documentation as much as configuration, and a business that has done the work but cannot evidence it fails anyway.
Where it landed
The company now has a compliance program with a scope and a sequence rather than an open question.
- A defined boundary, so the work and the cost apply to part of the business rather than all of it
- A position on all 110 controls, in writing, that the business can put in front of a contracting officer or an assessor
- A remediation plan ordered by risk and effort, with the cheap high-value items separated from the ones that need budget and lead time
- Evidence collected as the work is done, rather than reconstructed under time pressure later
- Written procedure where there was none, and logging and audit trails built as the program proceeds rather than bolted on before an assessment
The work is ongoing. That is the honest state of most CMMC programs at this stage, and it is a better position than it sounds, because the expensive uncertainty is gone. The business knows what it has to do, roughly what each piece costs, and what order to do it in.
The security improvements are real and would have been worth doing without a contract requiring them. Multi-factor authentication, knowing who has access to what, logging that someone actually reads, control over what leaves the company and who it goes to, and field devices that are managed rather than assumed are not compliance theater. They are the controls that stop the ordinary attacks, and construction is a target for the ordinary attacks precisely because so much of the work happens over email between parties who have never met.
Compliance work is expensive when it is undefined. Once the boundary is drawn and the gaps are written down against every control, it becomes what it should have been from the start, which is a project.
The numbers
| Metric | Before | After |
|---|---|---|
| Controls assessed against the standard | 0 | All 110 |
| Known position on each control | Unknown | Documented, control by control |
| Systems holding controlled information | Unknown | Identified and bounded |
| Controlled information shared outside the company | Untracked | Known and governed |
| Written procedures | None | Being produced as part of the program |
| Logging and audit trails | Limited | Centralized, retained, and monitored |
| Security tooling | Assorted and unmanaged | Selected against the control set and managed |
| System security plan | None | In progress |
| Plan of action and milestones | None | In progress, with owners |
| Remediation cost | Unknown | Scoped and prioritized by effort |
What it changed
- Scope defined before spend was committed
- Every one of the 110 controls assessed and written down
- Remediation sequenced by risk and cost rather than by control number
- Documentation produced alongside the technical work rather than after it