CMMC Level 2 Required. The Infrastructure Wasn’t Ready.
A Tier 2 defense contractor needed CMMC Level 2 certification to maintain DoD contracts but had significant gaps in security controls, no formal security program, and legacy infrastructure that couldn’t meet compliance requirements.
The clock was already compressed: a C3PAO assessment date was on the calendar, tied to a contract renewal, leaving no room for the phased 12-to-18-month security program build-out that CMMC readiness typically takes. The gap wasn’t a handful of missing technical controls — it was the absence of the governance artifacts a Level 2 assessor requires alongside the technical controls themselves: a System Security Plan that didn’t exist yet, no formal Plan of Action & Milestones process, and production and engineering systems that had never been segmented from the systems handling Controlled Unclassified Information (CUI).
A Coordinated Sprint Across Three Portfolios
vCISO services led the CMMC Level 2 readiness sprint end to end: a control-by-control gap assessment against all 110 NIST SP 800-171 Rev. 2 requirements, System Security Plan (SSP) development, and — for anything that couldn’t be fully closed inside the 90-day window — a Plan of Action & Milestones (POA&M) with a committed remediation date. CMMC Level 2 certification sits directly on top of that underlying NIST 800-171 assessment and SSP; a C3PAO assessor doesn’t score controls in isolation, they score whether the SSP accurately describes how each control is actually implemented in that specific environment.
AI-assisted documentation accelerated first-draft SSP language and control-to-evidence mapping — drafting the “how this control is implemented here” narrative for each of the 110 requirements from configuration data, log samples, and existing IT documentation, and producing a first-pass mapping between implemented controls and CMMC assessment objectives. None of that draft language shipped unreviewed: every AI-drafted narrative went through a two-stage human check, first for technical accuracy against the actual environment, then cross-checked against the specific NIST 800-171A assessment procedure a C3PAO assessor would apply. An SSP describing a control that isn’t really implemented, or implemented differently than described, is a direct path to a failed assessment — so the AI compressed drafting time, not evidentiary accuracy, and every finalized narrative carried an explicit reviewer sign-off.
Deployed a Zero Trust architecture scoped to CMMC’s access-control and system-and-communications-protection domains — network segmentation isolating CUI-handling systems from the general corporate network, identity threat detection and response (ITDR) tuned to the credential-based attack patterns the IA and AC control families exist to prevent, and privileged access management (PAM) to close the AC.L2 controls governing administrative and elevated accounts. A SIEM platform was stood up specifically to satisfy the audit (AU) control family: CMMC assessors expect documented evidence that log review, retention, and alerting are actually operating, not just that logging exists, and 24/7 SOC monitoring gave the deployment a live response function rather than an archive nobody watches.
Infrastructure modernization addressed the environment underneath the policy work: network segmentation to define a discrete CUI enclave, migration of CUI-handling workloads to Azure GovCloud, and a backup architecture with air-gapped, offline copies. That backup design maps directly to the contingency-planning (CP) and system-and-information-integrity (SI) control families — a requirement that on-prem backup running on the same network it protects cannot satisfy, since a ransomware event that reaches production also reaches a backup target that’s still network-reachable.
What Changed
Achieved CMMC Level 2 certification in 90 days while maintaining $24M in annual DoD contract revenue.
Security program maturity increased from ad-hoc to managed and measurable, with all 110 NIST 800-171 controls fully implemented.
Ongoing compliance monitoring was established post-certification, with the initial assessment closing at zero audit findings.
The 90-day certification timeline, $24M in protected contract revenue, 110/110 controls implemented, and zero-findings result above are aggregated from anonymized outcome data across multiple real Armorstack CMMC Level 2 engagements with Tier 2 DoD defense contractors. They are not drawn from, or attributed to, any single client, and no spokesperson quote is attached to them. Figures are recalculated from engagement data at each publication refresh; ask us for the underlying methodology.
Ready for Results Like These?
If your organization is staring down a CMMC Level 2 assessment date with an SSP that doesn’t exist yet, no POA&M process, and DoD contract revenue riding on getting there — that compressed timeline is exactly what this engagement model is built for. Let’s talk about your assessment date.Talk to Armorstack →
877-890-5508 · [email protected]