All case studies Aerospace & Defense

A CMMC Level 2 Enclave for an Aerospace Supplier

A precision-manufacturing DoD supplier reached CMMC Level 2 readiness by building a CUI-only enclave that cut assessment scope by roughly 85%.

Compliance & CMMCManaged Security (SOC)
7 mo
To CMMC Level 2 readiness
~85%
Audit scope reduced
$11M
DoD contract eligibility preserved

Challenge

A precision-manufacturing DoD supplier needed CMMC Level 2 but couldn’t afford to re-architect their full environment to the CUI scope. Applying all 110 controls across the entire estate would have been prohibitively expensive and slow.

What we did

  • Designed and operated a CUI-only enclave with a segmented network, a dedicated identity tenant, hardened endpoints, and a separated cloud tenant
  • Reduced audit scope by ~85% by keeping CUI inside a tightly defined boundary
  • Segmented and monitored the production OT network
  • Authored the SSP and calculated the SPRS score

Outcome

  • CMMC Level 2 readiness achieved in 7 months
  • CUI scope reduced to under 15% of the estate
  • Production OT network segmented and monitored
  • Preserved eligibility on $11M in DoD contracts

Pursuing CMMC Level 2? Request a gap assessment.

Get started

Ready to write yours?

Start with a security review and a clear, no-pressure plan.