Our client – a Richmond-area aviation contractor – is well on the road to CMMC compliance – without killing their business with overwhelming IT costs. Here’s how they did it with our CMMC managed IT services (which includes CMMC consulting).
This particular government contractor (who also serves commercial clients) came to us about six years ago. At first, they were looking for a full-time IT person but then saw the value of our staff augmentation services. Not long after, they hired us as a managed IT services provider.
Six years may seem like an incredibly long time to be on the road to CMMC compliance, but we weren’t just working on CMMC over those years. A lot of what we’ve been doing is day-to-day user support that includes everything from onboarding to setting up conference room phone systems to refreshing their VPN, computers and server.
Planning for compliance costs
Planning ahead for CMMC allowed our client to move toward compliance and still keep their business running. A small business only has capacity to do so much in a year. And you need to plan for and spread out your costs. For example, we did a server refresh one year and migrated the company to Microsoft GCC High the next year.
We took a huge step last year when we moved this client into a Department of Defense approved cloud product. Moving to a FedRAMP-approved tenant like Microsoft GCC High reworks everything – your email and all your settings have to be redone, all of your devices need to be managed, and you have to build out more policies than before – and document them.
Every time you change out a system, you’re going to have to revisit policies and procedures, so we are helping our client write those, which takes substantial time and effort.
Read the full case study