Challenge
9 months out from a CMMC Level 2 third-party assessment with a partial SSP (47/110 controls drafted), a 400-line POA&M spreadsheet last touched 6 months earlier, and a self-reported SPRS score of 62 that nobody could trace back to evidence. CUI scope spanned three business systems — an ERP, an engineering PLM, and a legacy on-prem file share — plus a hybrid M365 commercial tenant the team assumed (incorrectly) was inheritable.
Approach
Week 1-2: scoped the CUI enclave and migrated PLM access into a GCC High tenant. Week 3-6: ingested existing policies, SOC 2 evidence, and configuration baselines into Athena; auto-generated 110 SSP narratives from real evidence with Athena flagging 23 controls as 'insufficient evidence.' Week 7-9: closed the 23 gaps, regenerated the SSP, moved the POA&M into milestone-tracked items with named owners. Week 10-11: ran a DIBCAC-mock walkthrough, exported the C3PAO submission pack.
Outcome
Mock assessment surfaced 4 minor findings instead of the 30+ the team had projected. SPRS score moved from 62 (self-reported, undefended) to 94 (evidence-backed, every point traceable). SSP regeneration cycle: 8 weeks → under 10 days. Total spend on the program (tooling + remediation + assessment fee): ~37% under the original consultant budget.
Before → After
Time to defensible binder
9 months projected → 11 weeks actual
SPRS score (evidence-backed)
62 (undefended) → 94
SSP regeneration cycle
8 weeks → <10 days
Mock-assessment findings
30+ projected → 4 minor
Illustrative composite