Client Challenge
A specialty contractor working on defense-related projects was told by a prime contractor that CMMC compliance would be required to remain eligible for future work. Leadership had limited visibility into where Controlled Uncilateral Information (CUI) was stored, who had access, and which NIST 800-171 controls were already in place versus missing.
Environment
A mixed environment of on-premise file servers, Microsoft 365 for email and collaboration, and remote access for field and project teams. Access controls were broad, mobile devices were not consistently managed, and there was no documented system security plan or evidence of control implementation.
Risk
Without demonstrable CMMC readiness, the contractor risked losing current and future defense work, a significant portion of revenue. Poorly controlled access to CUI also created security exposure and potential contractual liability.
Titan's Approach
- Conducted a NIST 800-171 gap assessment to identify which controls were met, partially met, or missing.
- Worked with leadership to identify where CUI was created, stored, and transmitted across the environment.
- Implemented access controls and segmentation to limit CUI exposure to authorized users and systems.
- Enforced MFA and conditional access policies for Microsoft 365 and remote access.
- Deployed managed endpoint protection and centralized device management for company and remote devices.
- Configured logging, monitoring, and backup controls aligned to the required security objectives.
- Helped prepare the documentation and evidence needed to demonstrate control implementation.
Technology Improvements
- Centralized device management for company-owned and remote workforce devices.
- Structured CUI storage with defined access boundaries rather than broad shared drives.
- Documented network and system architecture to support ongoing compliance evidence.
Security Improvements
- MFA and conditional access enforced across Microsoft 365 and remote access.
- Endpoint protection with managed detection and response deployed across all devices.
- Access controls aligned to least-privilege principles for CUI handling.
- Monitoring, logging, and immutable backup configured to support security and compliance objectives.
Business Outcome
The contractor moved from unclear compliance status to a documented, evidence-backed posture aligned with NIST 800-171 and CMMC readiness expectations. Leadership gained visibility into where CUI lived and who could access it, and the business preserved its eligibility for defense work. Titan provides ongoing alignment as compliance requirements evolve.
Lessons Learned
- Compliance readiness starts with knowing where sensitive information actually resides.
- CMMC is an ongoing process of control implementation and evidence, not a one-time checkbox.
- Access control and identity protection are foundational to nearly every NIST 800-171 requirement.
- Documentation created during implementation becomes the evidence needed later.
This case study is anonymized to protect client confidentiality. Details have been generalized while accurately reflecting the nature of the engagement, the risks involved, and the outcomes achieved.
