Customer Story

CMMC Level 2 Documentation: How Fifth Gait Scored 110 out of 110

COMPANY

Fifth Gait Technologies

EMPLOYEES

1-50 Employees

SOLUTION

CMMC Level 2 Certification Assessment

INDUSTRY

Defense & Space

The Problem

Fifth Gait Technologies provides advanced survivability solutions to the U.S. Government, defense contractors, and commercial partners, with expertise spanning radiation effects testing, nuclear hardening, optoelectronics, modeling and simulation, and system survivability. As a defense subcontractor, the company receives and generates Controlled Unclassified Information, including program data and source code, under prime contractor relationships. CMMC Level 2 is becoming a condition of award under DFARS 252.204-7012 and the CMMC final rule, so certification protected existing contract eligibility and positioned the company for future work.

The commitment predated the requirement. Fifth Gait held a DIBCAC On-Site (High) assessment and carried a perfect SPRS score of 110 from its DCMA audit in 2023. CMMC Level 2 was the natural continuation of a program already in place, formalized once assessment requirements began flowing down through contracts.

Their technical foundation was already strong. Fifth Gait ran a cloud-native Zero Trust architecture on Microsoft 365 GCC High G5: Entra ID as the sole identity provider with Conditional Access, PIM just-in-time privilege, phishing-resistant MFA through Windows Hello for Business, Intune-managed Windows 11 and macOS endpoints, the full Defender G5 stack, and Sentinel in Azure Government.

The gap was elsewhere.

"Documentation and evidence maturity, not technology," the team said of the hardest part. "The hard part was translating a strong environment into assessment-ready artifacts: a complete SSP, CRM inheritance mapping across multiple FedRAMP providers, accurate data-flow and network diagrams, and an evidence trail an assessor could follow end to end."

The biggest unknown was modeling shared-responsibility inheritance correctly across those providers - the question of which controls Fifth Gait owned versus which it inherited from its cloud environments, and whether that mapping would hold up under examination.

"Ignyte told us the truth when it would have been easier to rubber-stamp us, and that honesty is exactly why we walked into the formal assessment prepared and walked out with a perfect 110 out of 110."

Collin Barrow

VP of Information Security

The Solution

Fifth Gait selected Ignyte as an authorized C3PAO with defense-sector assessment depth. The structured, platform-based approach - eMASS-aligned pre-assessment, artifact request lists, discovery-first methodology - suited a small team that needed a clear framework.

"Their willingness to run a real discovery phase and tell us honestly where we stood, rather than march us straight into a formal audit, mattered."

The certification assessment was conducted by Ignyte Federal as an authorized C3PAO. Having previously been through a DIBCAC High audit with DCMA, Fifth Gait's expectations were calibrated. "Ignyte was every bit as professional and thorough as DCMA was, which gave us real confidence in their assessment."

The Customer Responsibility Matrix evaluation was where the assessment went deepest. Ignyte reviewed Fifth Gait's CRMs and verified the actual FedRAMP High and DoD IL4 cloud environments behind them, validating inheritance against the real authorized environments rather than accepting the mapping on paper.

Internally, the effort ran on clear ownership and a documented cadence. The software team provided real-world SDLC walkthroughs. Program managers supplied CUI boundary processes and review-cycle cadences. The ISSO produced the bulk of the configuration evidence. The ISSM delivered enterprise architecture design, scope, policies, procedures, SSPs, and CRMs. The CEO provided authorized ownership of the program, and the FSO supplied security procedures, where the cleared facility overlapped with facility security requirements. Jira carried change and access evidence; GCC High SharePoint gave the team a disciplined evidence-folder structure for the C3PAO handoff.

What surprised them was the proportion: "How much of the effort was documentation and inheritance modeling rather than net-new technical controls, and how precisely assessors expect the SSP, CRMs, and diagrams to match what the environment actually does. The bar for evidence consistency was higher than a controls-checklist mindset would suggest."

110 / 110

CMMC Level 2 assessment score

2

Consecutive perfect federal assessment scores, following a 110 SPRS score from DCMA in 2023

6

Internal functions contributing evidence: software, program management, ISSO, ISSM, CEO, and FSO

The Result

A Perfect 110 out of 110

Fifth Gait is a certified CUI custodian able to bid and perform on contracts requiring CMMC Level 2. The perfect score demonstrates maturity rather than a bare pass, and continues the perfect score earned under the company's 2023 DCMA assessment. "It protects the CUI we handle and signals to primes and customers that our security is operationalized, not aspirational."

Different Conversations with Primes

"Certification removes a qualification hurdle in prime and customer conversations and shifts the discussion from 'can you protect CUI' to 'what can we build together.' A perfect score is a real differentiator among small-business subcontractors."

Compliance Made Operational

Formalized documentation with consistent naming and versioning across SSPs, policies, and SOPs. Repeatable processes including an operational compliance calendar, a lessons-learned roadmap, and a quarterly PM and security CUI cadence. Named data owners with defined ISSM and ISSO roles. Role-based security awareness training delivered through the Ethena platform.

Get ahead of the Game
Build Trust, not Checklists

Multiple Cybersecurity Frameworks Management at once has never been easier.

We listen and learn about your business challenges  - Meet with a Ignyte experts

Get a custom tailored demo of Ignyte Platform

Discover the best practices and strategies to automate your security risk management challenges

Book your Demo today

Contact us to see the demonstration of Ignyte Assurance Platform, a purpose-built commercialized end-to-end authorization & attestation technology for organizations looking to go beyond checklists.