Real engagements with California's defense supply chain.
CMMC Level 2 is now law. Phase 1 enforcement has been active since November 10, 2025. The five engagements in this series show how Consilien helps NADCAP-accredited aerospace suppliers, full-scope metal finishing shops, and tier-2 defense manufacturers in Southern California meet CMMC requirements without disrupting the shop floor, the AS9100 quality system, or the contracts that keep the lights on.
DIB contractors expected to need CMMC Level 2 certificationDoD estimate - 32 CFR Part 170
Authorized C3PAOs in The Cyber AB MarketplaceCyber AB / Secureframe - March 2026
Of the DIB has reached Level 2 certification to dateCyber AB Town Hall - March 2026
Of contractors report CMMC preparation has taken over a yearRedspin 2025 (n=180)
The DIB CMMC readiness gap, May 2026
The gap: demand for CMMC Level 2 certification vastly exceeds current certification throughput. Approximately one percent of the expected DIB has achieved Level 2 to date. Sources: 32 CFR Part 170, Cyber AB Marketplace data analyzed by Secureframe (March 2026), Redspin 2025 "Momentum but Slow Movement" survey of 180 DoD contractors.
CMMC compliance is hardest where the cyber world meets the shop floor.
Most CMMC content on the internet was written for office-only environments - software firms, consulting practices, IT services companies. That guidance breaks down inside a real manufacturer. Paper travelers move across the shop. Controlled drawings live on machinist toolboxes. Temporary contract workers handle parts marked with CUI. NADCAP cages and AS9100 quality records intersect with information security controls the framework was never designed to map onto.
These five case studies are drawn from real Consilien engagements with manufacturers in those exact conditions. They are anonymized to industry vertical only. The methods, decisions, and trade-offs are presented as they happened.
Aligning Shop-Floor and IT Processes to CMMC Level 2
How a NADCAP-accredited aerospace metal finishing supplier bridged its AS9100 quality culture with the cyber controls CMMC Level 2 demands - without disrupting production.
Read case study Case Study 02Designing a Hybrid Physical and Digital CUI Workflow
Most CMMC guidance assumes a digital-first environment. For a full-scope metal finishing workshop, paper travelers, contract workers, and the NADCAP cage all flow CUI. Here is how we built a defensible boundary anyway.
Read case study Case Study 03Building a Complete CMMC Policy and Procedure Architecture from Scratch
Templates do not survive a C3PAO assessment. We built an Information Security Policies and Standards document, a five-playbook Incident Response chain, an Operations Security Procedures Manual, and Shared Responsibility Matrices - all in one engagement.
Read case study Case Study 04PreVeil Enclave Design Instead of a Full GCC High Rollout
Industry data shows GCC High deployments can run to six figures and require an organization-wide rip-and-replace. For a mid-sized aerospace supplier with a narrow CUI footprint, an enclave architecture was the smarter path.
Read case study Case Study 05Building Audit-Ready Evidence Architecture for a C3PAO Assessment
The number one reason CMMC assessments fail is documentation and evidence gaps. We engineered a controlled evidence chain that maps every NIST 800-171A assessment objective to dated, hash-verified artifacts.
Read case studyThe CMMC clock is no longer hypothetical.
The Final Rule integrating CMMC into the Defense Federal Acquisition Regulation Supplement was published in the Federal Register on September 10, 2025, and took effect November 10, 2025. Phase 1 enforcement is active in new DoD solicitations now. Contractors that do not hold or are not actively pursuing the appropriate level of CMMC certification face the loss of contract eligibility as option periods and renewals come up.
of DoD contractors surveyed had already received CMMC flow-down demands from prime contractors.
Source: Redspin 2025 readiness surveyof contractors surveyed have spent more than $250,000 preparing for CMMC; another 26% have spent $100K-$250K.
Source: Redspin 2025 readiness surveyof organizations report cybersecurity skills gaps; 59% describe those gaps as critical or significant.
Source: ISC2 2025 Cybersecurity Workforce StudyTwo structural realities make this harder for smaller manufacturers. First, the assessor ecosystem is thin: as of March 2026, only 103 organizations were authorized as C3PAOs, supported by approximately 759 Certified CMMC Assessors. Roughly 1,000 organizations have achieved Level 2 certification - about one percent of the contractors expected to need it. Booking windows at established C3PAOs already exceed one year.
Second, the cybersecurity talent gap that the ISC2 Workforce Study documents is felt most acutely in 25-to-200-person manufacturers. Hiring a dedicated chief information security officer at $200K-plus and a governance, risk, and compliance analyst at close to $100K is not a realistic option for a 60-person aerospace metal finishing shop. The work either gets done with the wrong people, or it gets outsourced to specialists. Consilien's CMMC compliance practice exists for the second path.
California's defense supply chain, with a Southern California specialty.
California is the largest aerospace and defense state in the country. The industry contributes an estimated $35 billion to state GDP, supports more than 511,000 high-paying jobs, and houses roughly one-third of all U.S. space-technology companies. The South Bay aerospace corridor - El Segundo, Hawthorne, Torrance, Long Beach - has been adding both jobs and industrial occupancy since 2022.
Southern California
South Bay aerospace corridor (El Segundo, Hawthorne, Torrance, Long Beach), Orange County (Anaheim, Santa Ana, Fullerton, Irvine), Inland Empire, San Diego, Antelope Valley (Palmdale, Lancaster), and the Santa Clarita Valley aerospace cluster.
San Francisco Bay Area
Defense suppliers and engineering firms in the South Bay, East Bay, and Sacramento corridor. Strong overlap with national-laboratory adjacencies and university-affiliated research that flow CUI through commercial subcontractors.
California-wide and beyond
Consilien serves clients across the rest of California and into adjacent western states. Engagements are typically remote-first with on-site visits for scoping, evidence walkthroughs, and assessor preparation.
Built for manufacturers, not for office-only environments.
Scoping and CUI footprint
We start by mapping where CUI actually lives in your environment - including paper, machinist toolboxes, paperless travelers, contract review files, ERP, and engineering data systems. Most manufacturers we encounter are over-marking CUI; reducing scope is usually the single largest cost lever available before any tooling decisions get made.
Gap assessment against NIST SP 800-171 Rev 2
Every one of the 110 controls in NIST 800-171 Rev 2 is benchmarked against your current environment, with a specific implementation status and supporting evidence pointer per control. Where evidence does not yet exist, we identify the artifact needed and queue it for creation.
Architecture and tooling decisions
This is where most consultancies default to a Microsoft GCC High recommendation. We will recommend GCC High when it is the right answer. We will also recommend a PreVeil enclave, a hybrid model, or no platform change at all when those are the right answers. The decision is driven by your CUI footprint and your business model, not by partner economics.
Policy, procedure, and evidence build
Information Security Policies and Standards, Incident Response playbooks, Operations Security Procedures, Shared Responsibility Matrices, and the evidence library that ties every NIST 800-171A assessment objective to dated artifacts. Built specifically for your environment - not generic templates.
C3PAO readiness and the assessment itself
Mock assessments aligned to the NIST 800-171A Examine, Interview, and Test methodology. Staff prepared for the interview questions that consistently trip up otherwise-prepared organizations. Documentation in place at the time of assessment, in the form defense counsel highlights as the threshold requirement.
Ongoing affirmation and program maintenance
CMMC is not a one-time event. Annual affirmations are required. Significant environment changes need to be reflected in your System Security Plan. Triennial re-assessments will come around faster than they sound. We stay engaged after certification because the regulation does.
The published controls and authorities behind this series.
Ready to talk through your CMMC path?
If you are a California manufacturer with DoD contracts or DFARS 7012 flow-down obligations, Consilien can scope your CMMC engagement against your actual environment in a 30-minute call. No sales pressure. No assumption that GCC High is the only answer.