Skip to main content Skip to main content
(443) 741-0823 Free Quote
Case Study · Government Contracting

CMMC 2.0 Level 2 Certification for a Herndon, VA Federal IT Subcontractor

From a NIST score of 42 to full CMMC Level 2 certification in 14 months — protecting $2.8M in DoD contract revenue.

Herndon, VA Government Contracting

42→109

NIST SP 800-171 score improvement

14 months

Assessment to certification timeline

$2.8M

Contract revenue protected

68

Security gaps identified and remediated

The Situation Before Metro Point IT

A 35-person federal IT subcontractor in Herndon, Virginia supporting a DoD prime contractor received a contract modification requiring CMMC 2.0 Level 2 certification within 18 months. The company had no System Security Plan, had never conducted a formal NIST SP 800-171 gap assessment, and their CUI was stored across personal Dropbox accounts, unencrypted USB drives, and a shared network drive with no access controls. Their initial self-assessment score against NIST SP 800-171 was 42 out of 110 — well below the passing threshold.

What Was at Stake

The subcontract represented $2.8 million in annual revenue — 40% of the company's total. Failure to achieve CMMC Level 2 certification would result in contract loss. The 18-month timeline was tight given the scope of remediation required.

What Metro Point IT Implemented

Metro Point IT provided a structured CMMC 2.0 remediation engagement over 14 months:

Month 1-2 — Assessment and Documentation: Complete NIST SP 800-171 gap assessment across all 110 controls. System boundary definition — scope limited to systems that process, store, or transmit CUI. System Security Plan (SSP) drafted with current state and planned controls. Plan of Action and Milestones (POA&M) created for all 68 identified gaps.

Month 3-6 — Technical Remediation: Microsoft 365 GCC environment deployed — FedRAMP Moderate authorized, appropriate for CUI. All CUI migrated from Dropbox and USB drives to GCC-compliant SharePoint. MFA enforced on all accounts. Privileged access workstations implemented for admin functions. Endpoint protection (Microsoft Defender for Business) deployed and configured. Network segmentation implemented — CUI systems isolated from general office network.

Month 7-10 — Process and Policy: Written security policies for all 110 control families. Employee security awareness training program launched. Incident response plan written and tabletop exercise conducted. Vulnerability management program established — monthly scans, documented remediation.

Month 11-14 — Assessment Preparation: Pre-assessment review with CMMC Registered Practitioner. All gaps remediated or documented with accepted risk. SSP updated to reflect final state. C3PAO assessment scheduled and supported.

Measurable Outcomes

Final outcomes:

Outcomes

CMMC 2.0 Level 2 certification achieved. NIST SP 800-171 score: 42 at engagement start, 109 at certification. $2.8M subcontract retained. Complete SSP and compliance documentation maintained. Ongoing compliance monitoring included in managed IT plan — annual risk assessment and SSP updates.

Similar Results for Your Government Contracting Business

Get a free technology assessment and see how Metro Point IT can solve your specific IT challenges.

Explore More

Our IT Services

Industries We Serve

Service Areas