Skip to content

Industries

The companies that actually make up the defense supply chain

Primes set the requirements. Everyone below them has to satisfy them, usually with a fraction of the staff and none of the budget. Those are the companies we built this firm for.

Who we serve

Same requirements, very different constraints

The 110 requirements do not change between a machine shop and a research lab. What changes is how you satisfy them without stopping the business, and that is where sector experience earns its keep.

Aerospace & Defense Manufacturing

Aerospace & Defense Manufacturing

Machine shops, precision manufacturers, and Tier 2/3 suppliers handling drawings, specs, and technical data packages that are almost always CUI.

What makes it hard

  • · Drawings, specifications, and technical data packages that are almost always CUI
  • · Shop-floor workstations shared between operators, often on legacy operating systems
  • · CNC controllers and test equipment that cannot be patched or joined to a domain
  • · Third-party maintenance technicians with physical access to production systems

How we approach it

We treat specialised assets as their own category rather than pretending they can meet the same baseline as a laptop, segment them properly, and keep the engineering workstations that genuinely touch CUI inside a tightly-drawn enclave.

Engineering & Professional Services

Engineering & Professional Services

Firms delivering SETA support, systems engineering, and research services where CUI arrives by email every single day.

What makes it hard

  • · CUI arriving by email daily from multiple primes with inconsistent markings
  • · Highly mobile staff working from customer sites, home, and hotels
  • · Heavy collaboration requirements that conflict with strict external sharing controls
  • · Subject-matter experts who resist anything that slows their tooling down

How we approach it

A defined intake process so inbound CUI lands inside the boundary rather than in a general mailbox, plus conditional access and virtual desktops so people can work from anywhere without dragging their devices into scope.

Prime Contractors & Their Subs

Prime Contractors & Their Subs

Primes pushing flow-down requirements onto their supply chain, and the subcontractors who now have to answer for them.

What makes it hard

  • · Flow-down requirements arriving with short deadlines and little explanation
  • · Security questionnaires that decide teaming agreements before price is discussed
  • · Uncertainty about whether what you receive is genuinely CUI or over-marked
  • · Obligation to flow the same requirements down to your own suppliers

How we approach it

We handle the questionnaires, build the evidence library that makes the fifth one take an hour, and help you flow requirements down to your suppliers without creating obligations you cannot verify.

Research, Labs & Universities

Research, Labs & Universities

Federally funded research organizations balancing open collaboration against controlled unclassified information.

What makes it hard

  • · Academic openness colliding with controlled information handling
  • · Transient staff, students, and visiting researchers with legitimate access needs
  • · Federal funding conditions layered on top of contractual security requirements
  • · Fundamental research exclusions that are frequently misapplied

How we approach it

A clear boundary between open research and controlled work, with identity lifecycle management that copes with high turnover and short-term access without leaving orphaned accounts behind.

IT & Software Suppliers to Government

IT & Software Suppliers to Government

Software vendors, integrators, and cloud providers that need FedRAMP-aligned posture and a defensible security program.

What makes it hard

  • · Customers demanding FedRAMP-aligned posture and detailed architecture evidence
  • · Development environments that touch production and customer data
  • · Rapid release cycles that outpace configuration management discipline
  • · Cloud infrastructure spanning commercial and government regions

How we approach it

Security built into the pipeline rather than bolted on afterwards, clear separation between development and controlled environments, and documentation that answers customer due-diligence without a fire drill each time.

Logistics, Maintenance & Field Services

Logistics, Maintenance & Field Services

MRO, depot, and logistics providers with distributed teams, shared workstations, and complex physical-security requirements.

What makes it hard

  • · Distributed sites, field technicians, and shared kiosk-style workstations
  • · Physical protection requirements across warehouses and depots
  • · Handheld and ruggedised devices that resist standard management tooling
  • · High staff turnover creating constant onboarding and offboarding load

How we approach it

Practical physical controls, device management that copes with ruggedised hardware, and automated joiner-mover-leaver workflows that produce the access evidence an assessor asks for.

Common ground

What every one of them needs

Whatever the sector, the same five things determine whether a programme is affordable and whether it survives an assessment.

See all services
  • A boundary drawn around CUI rather than around the whole company
  • Identity and access controls that are enforced, not merely written down
  • Logging that is collected, retained, and demonstrably reviewed by a person
  • Documentation that describes the environment as it actually runs
  • Someone accountable for keeping it true between assessments

If you are not sure which of those you have, the free gap check will tell you in about an hour.

Straight answers

Sector questions

Ask us something else

We are a small subcontractor. Do CMMC requirements really apply to us?

If a prime passes you CUI, yes. Requirements flow down through the supply chain, and the size of your company does not change the obligation. What it does change is how the programme should be built. A fifteen-person supplier should not be running an enterprise compliance programme, and does not need to.

Our shop floor runs equipment that cannot be patched. Is that a dealbreaker?

No. CMMC recognises specialised assets such as test equipment, machine controllers, and operational technology, and there is a defined way to handle them. What matters is that they are inventoried, categorised, segmented, and documented rather than quietly ignored.

Do you only work with manufacturers?

No. Manufacturers are a large part of what we do because technical data packages are so often CUI, but we work across engineering services, research organisations, software suppliers, and logistics providers. The compliance obligation is the same; the operational constraints differ, which is what changes the design.

We are not sure whether what we receive is actually CUI.

That is extremely common, and it is the right question to resolve before spending anything. Over-marking by primes is real, and so is CUI arriving unmarked. We work through what you actually receive and from whom, which frequently changes the scope, and therefore the cost, significantly.

Next step

Find out what your CMMC gap really looks like

A short, no-obligation conversation and a written summary of where you stand, what it will take, and roughly what it will cost. No sales theatre.