Fifth Gait Technologies provides advanced survivability solutions to the U.S. Government, defense contractors, and commercial partners, with expertise spanning radiation effects testing, nuclear hardening, optoelectronics, modeling and simulation, and system survivability. As a defense subcontractor, the company receives and generates Controlled Unclassified Information, including program data and source code, under prime contractor relationships. CMMC Level 2 is becoming a condition of award under DFARS 252.204-7012 and the CMMC final rule, so certification protected existing contract eligibility and positioned the company for future work.
The commitment predated the requirement. Fifth Gait held a DIBCAC On-Site (High) assessment and carried a perfect SPRS score of 110 from its DCMA audit in 2023. CMMC Level 2 was the natural continuation of a program already in place, formalized once assessment requirements began flowing down through contracts.
Their technical foundation was already strong. Fifth Gait ran a cloud-native Zero Trust architecture on Microsoft 365 GCC High G5: Entra ID as the sole identity provider with Conditional Access, PIM just-in-time privilege, phishing-resistant MFA through Windows Hello for Business, Intune-managed Windows 11 and macOS endpoints, the full Defender G5 stack, and Sentinel in Azure Government.
The gap was elsewhere.
"Documentation and evidence maturity, not technology," the team said of the hardest part. "The hard part was translating a strong environment into assessment-ready artifacts: a complete SSP, CRM inheritance mapping across multiple FedRAMP providers, accurate data-flow and network diagrams, and an evidence trail an assessor could follow end to end."
The biggest unknown was modeling shared-responsibility inheritance correctly across those providers - the question of which controls Fifth Gait owned versus which it inherited from its cloud environments, and whether that mapping would hold up under examination.