Practical Energetics Research supports the Department of Defense through engineering, analysis, design, and testing of advanced lethality systems, which means handling Controlled Unclassified Information is most of what the business does. Roughly two years before their CMMC Level 2 assessment, the CMMC program was, in their Facility Security Officer's word, rudimentary.. Some documentation framework was in place, but not the finer detailed work. Real practices were running but disjointed, not yet a holistic approach across every system touching secure data.
Three challenges defined the effort:
Separation of duties at 30 employees. Building a strict separation of duties and a role-based access control matrix in a company where the same person often owns provisioning, approval, and review because there is nobody else to hand it to.
Evidence volume, and evidence age. Aggregating and organizing technical artifacts across every system touching CUI, including artifacts that had aged beyond acceptance and had to be regathered during the assessment itself.
A compressed review window. A holiday week cut the standard five-day technical control review to four days, and in practice to about three and a half.
"It required us to do a self-inspection on our own systems," said David Odle, PER's Information System Security Manager. "There were things we thought we were doing correctly that actually needed improvement, and we found those while prepping for the audit."
The role-based access problem was the one that surprised them. Separation of duties assumes there are enough people to separate. At just over thirty employees, meeting the requirement meant engineering around headcount the company did not have.