CMMC Level 2 Readiness for a Defense Contractor
A defense contractor | Six-month engagement
A small defense contractor holding DFARS 252.204-7012 obligations needed to demonstrate NIST SP 800-171 compliance to protect its contract position. The company had capable people and no formal compliance program — no documented policies, no system security plan, and no environment purpose-built for handling Controlled Unclassified Information.
What we did
Runtime Cyber Defense scoped the CUI boundary first, then built to it. We stood up a Microsoft 365 GCC High enclave with conditional access, phishing-resistant multifactor authentication, endpoint detection and response, data loss prevention, and audit logging across the environment. In parallel we authored the full governance package — policies and procedures spanning every control family, mapped to the 110 requirements of NIST SP 800-171 — and built the system security plan and POA&M in a compliance platform the client's team could maintain themselves.
Documentation alone doesn't survive an assessment. Each control was implemented in the tenant, verified against the actual configuration, and evidenced. Where a requirement couldn't be fully met, it was scored honestly and carried on the POA&M rather than papered over.
Result
In six months, the client went from no formal program to a completed CMMC Level 2 self-assessment with a documented, evidenced control environment and a remediation plan for the remainder. The company retains an independent path to a future C3PAO certification assessment — Runtime Cyber Defense is not a C3PAO, so nothing we built creates a conflict when they go for certification.
Client identity withheld at the client's discretion.
