Customer Story

CMMC Level 2 Assessment in Three and a Half Days: Practical Energetics Research

COMPANY

Practical Energetics Research

EMPLOYEES

1 - 50

SOLUTION

CMMC Level 2 Certification Assessment

INDUSTRY

Defense & Space

The Problem

Practical Energetics Research supports the Department of Defense through engineering, analysis, design, and testing of advanced lethality systems, which means handling Controlled Unclassified Information is most of what the business does. Roughly two years before their CMMC Level 2 assessment, the CMMC program was, in their Facility Security Officer's word, rudimentary.. Some documentation framework was in place, but not the finer detailed work. Real practices were running but disjointed, not yet a holistic approach across every system touching secure data.

Three challenges defined the effort:

Separation of duties at 30 employees. Building a strict separation of duties and a role-based access control matrix in a company where the same person often owns provisioning, approval, and review because there is nobody else to hand it to.

Evidence volume, and evidence age. Aggregating and organizing technical artifacts across every system touching CUI, including artifacts that had aged beyond acceptance and had to be regathered during the assessment itself.

A compressed review window. A holiday week cut the standard five-day technical control review to four days, and in practice to about three and a half.

"It required us to do a self-inspection on our own systems," said David Odle, PER's Information System Security Manager. "There were things we thought we were doing correctly that actually needed improvement, and we found those while prepping for the audit."

The role-based access problem was the one that surprised them. Separation of duties assumes there are enough people to separate. At just over thirty employees, meeting the requirement meant engineering around headcount the company did not have.

The biggest distinction was how clear it was from the beginning how the different phases of the assessment would operate. Discovery, then controls evaluation, then the risk exposure table and reporting, then the final reporting. It was all clear from the start.

David Odle

Information System Security Manager, Practical Energetics Research

The Solution

PER's preparation and PER's assessment were separate engagements run by separate teams. The pre-audit work ran roughly four months ahead of the assessment window, surfacing gaps and missing artifacts early enough for PER to gather what was missing before the assessment began. The certification assessment was conducted by Ignyte Federal as an authorized C3PAO, with a different team handling the technical control review, risk exposure reporting, and final reporting.

The assessment ran in four defined phases: discovery, controls evaluation, risk exposure table and reporting, then final reporting. Odle had been through SOC 2 and ISO 27001 assessments previously, and cited the phase clarity as the main difference. "Other audits I've been through, discovery just feels like you're uploading artifacts into a black hole and then waiting for a finding."

The assessment was conducted virtually, which reduced cost, a factor PER weighed heavily when selecting an assessor. Cost was their first filter. "We've all heard about small businesses in the industry struggling to afford these third-party audits, so price was important."

After the technical control review, the assessment team delivered a risk exposure table identifying the requirements PER had not yet met. Christina Sweitzer, PER's Facility Security Officer, credited that document directly with the outcome: "I don't think we would have gotten as good a score, or been as successful, without that explicit indication of where we still had risk."

107 / 110

CMMC Level 2 assessment score

3.5 days

Technical control review completed in a holiday-shortened window, against a five-day standard

4 months

Lead time between discovery and the certification assessment

The Result

Verified Status in SPRS

PER's score posted to SPRS, giving the company documented proof to provide federal customers. "As soon as that official score was updated in SPRS, we had proof to give all of our federal customers that we're doing what we can to safeguard their data and these critical things that contribute to our nation's defense."

From Firefighting to Cadence

The role-based access control work that had been the hardest part of preparation became the structure the company runs on. "The standardization of processes and the role-based access controls certainly helped transition us to a more proactive, routine approach as opposed to a reactive, firefighting one. It's definitely helped create more of a cadence, a highly visible, compliant cadence, around these controls."

Positioned Ahead of the Requirement

PER pursued Level 2 in anticipation of contract requirements rather than in response to them, completing the assessment before DoD announced a delay to the Level 2 rollout. David Odle's advice to similar organizations: "There's no reason to wait. The work you're doing to safeguard data hasn't been paused. Those requirements are still in contracts right now. And that's the part that takes the most effort."

Get ahead of the Game
Build Trust, not Checklists

Multiple Cybersecurity Frameworks Management at once has never been easier.

We listen and learn about your business challenges  - Meet with a Ignyte experts

Get a custom tailored demo of Ignyte Platform

Discover the best practices and strategies to automate your security risk management challenges

Book your Demo today

Contact us to see the demonstration of Ignyte Assurance Platform, a purpose-built commercialized end-to-end authorization & attestation technology for organizations looking to go beyond checklists.