CMMC 2.0 Level 2 Certification for a Herndon, VA Federal IT Subcontractor
From a NIST score of 42 to full CMMC Level 2 certification in 14 months — protecting $2.8M in DoD contract revenue.
42→109
NIST SP 800-171 score improvement
14 months
Assessment to certification timeline
$2.8M
Contract revenue protected
68
Security gaps identified and remediated
The Situation Before Metro Point IT
A 35-person federal IT subcontractor in Herndon, Virginia supporting a DoD prime contractor received a contract modification requiring CMMC 2.0 Level 2 certification within 18 months. The company had no System Security Plan, had never conducted a formal NIST SP 800-171 gap assessment, and their CUI was stored across personal Dropbox accounts, unencrypted USB drives, and a shared network drive with no access controls. Their initial self-assessment score against NIST SP 800-171 was 42 out of 110 — well below the passing threshold.
What Was at Stake
The subcontract represented $2.8 million in annual revenue — 40% of the company's total. Failure to achieve CMMC Level 2 certification would result in contract loss. The 18-month timeline was tight given the scope of remediation required.
What Metro Point IT Implemented
Metro Point IT provided a structured CMMC 2.0 remediation engagement over 14 months:
Month 1-2 — Assessment and Documentation: Complete NIST SP 800-171 gap assessment across all 110 controls. System boundary definition — scope limited to systems that process, store, or transmit CUI. System Security Plan (SSP) drafted with current state and planned controls. Plan of Action and Milestones (POA&M) created for all 68 identified gaps.
Month 3-6 — Technical Remediation: Microsoft 365 GCC environment deployed — FedRAMP Moderate authorized, appropriate for CUI. All CUI migrated from Dropbox and USB drives to GCC-compliant SharePoint. MFA enforced on all accounts. Privileged access workstations implemented for admin functions. Endpoint protection (Microsoft Defender for Business) deployed and configured. Network segmentation implemented — CUI systems isolated from general office network.
Month 7-10 — Process and Policy: Written security policies for all 110 control families. Employee security awareness training program launched. Incident response plan written and tabletop exercise conducted. Vulnerability management program established — monthly scans, documented remediation.
Month 11-14 — Assessment Preparation: Pre-assessment review with CMMC Registered Practitioner. All gaps remediated or documented with accepted risk. SSP updated to reflect final state. C3PAO assessment scheduled and supported.
Measurable Outcomes
Final outcomes:
Outcomes
CMMC 2.0 Level 2 certification achieved. NIST SP 800-171 score: 42 at engagement start, 109 at certification. $2.8M subcontract retained. Complete SSP and compliance documentation maintained. Ongoing compliance monitoring included in managed IT plan — annual risk assessment and SSP updates.