Representative scenario — a composite of common engagements, not a specific client.
A roughly 40-person aerospace machining supplier learned, mid-year, that a new prime contract carried a CMMC Level 2 flow-down requirement. They had strong shop-floor operations and almost no formal cybersecurity program — and a deadline measured in months, not years.
The challenge
Two problems at once: a long list of CUI-handling requirements they had never formally implemented, and a small team with no capacity to run a compliance project on top of production. The instinct — buy a big GRC tool and hope — would have burned budget without closing the gap.
What we did
We started with scope, not tools. Mapping where CUI actually lived let us pull most of the shop floor out of the assessment boundary and concentrate protections on a small, defined enclave. From there we built the SSP against the 110 requirements, stood up the operational controls that were missing (MFA coverage, logging, access reviews), and assembled the evidence as we went — so the proof existed by the time it was needed.
The readiness arc
Roughly four months from kickoff, the supplier was assessment-ready: an accurate SSP, a short and closing POA&M, and controls their own people could speak to. They went into the engagement with their C3PAO prepared rather than scrambling — and kept producing parts the whole time.
Whether the certification is ultimately granted is the C3PAO’s call; our job was to make them genuinely ready for it. See how we help suppliers get ready for Level 2.