← Back to CMMC Portal Home
🛡 CMMC 2.0 Training Portal

CMMC Training Case Studies

Sector-specific fictional DoD contractors with realistic IT environments, CUI data flows, network diagrams, and CMMC gaps — designed for hands-on Level 2 assessment practice.

8
Available Now
8
DIB Sectors
14
Domains Covered
9
Audit Doc Types
🎓

How to Use These Case Studies

Each case study presents a fully developed fictional DoD contractor in a specific Defense Industrial Base sector. Students receive a complete organizational profile, IT asset inventory, network architecture, CUI data flow diagram, security control gaps, vendor relationships, and a CMMC domain assessment. Exercises ask students to validate compliance posture, map findings to specific NIST SP 800-171 practice IDs, produce one of nine standard audit documents, and work through scenario injects that simulate realistic audit findings. Each case study can be used independently or combined for cross-sector comparison exercises.

🏗 Types of DoD Contractors — Defense Industrial Base (DIB)

The Defense Industrial Base spans over 80,000 companies across virtually every economic sector. CMMC applies to any organization that processes, stores, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on behalf of the Department of Defense — regardless of size or industry. Click any category below to explore what these contractors do and how CUI and CMMC obligations arise in their work.

Why Case Studies? — CMMC compliance is not a checkbox exercise — it requires applying abstract cybersecurity principles to concrete, operational environments. Case studies bridge that gap by immersing students in a real-world organizational context: a specific business, a network, a set of contracts, and a collection of people making imperfect security decisions. Rather than simply reciting NIST SP 800-171 control requirements, students must identify which controls apply, assess whether they are implemented, document findings using professional audit tools, and recommend remediation — exactly as a C3PAO assessor would. Sector diversity across these case studies ensures that students encounter the full breadth of CUI environments: manufacturing floors, cloud-native IT providers, university labs, logistics warehouses, embedded firmware shops, and biodefense facilities. Each sector presents distinct risk patterns, regulatory overlaps (ITAR, EAR, HIPAA), and technical configurations that demand situational judgment — not rote memorization.
🏭

Facilities & Construction

DoD Contractor Category

Category Overview

Products & Services

Representative Examples

CMMC & CUI Considerations

Available Now — All 8 Sectors
🏭 Defense Manufacturing
🏢

Meridian Precision Defense Systems, Inc.

Mid-size DoD subcontractor manufacturing actuator housing assemblies and providing UAV systems integration support. Holds three active DoD contracts across Army, Air Force, and NAVAIR. Operates two sites in Dayton OH and Huntsville AL.

Employees: 147
Revenue: ~$31M
Contracts: 3 Active
CMMC Gap: 8 Findings
Sites: Dayton OH + Huntsville AL
CAGE Code: 7RK42
ITAR / EAR No VPN MFA No SCRM Stale Accounts 9 Audit Documents Edit & Print
Open Full Interactive Case Study →
💻 IT Services & Cyber
🖥

Atlas Systems Group, LLC

DoD IT services contractor providing managed help desk, SOC-as-a-service, and enterprise IT support to multiple federal agencies. All CUI processed in Azure Government. 85 employees, Arlington VA.

Employees: 85
Revenue: ~$19M
Contracts: 2 Active
CMMC Gap: 7 Findings
Location: Arlington, VA
Cloud: Azure Gov
Shared Admin Accounts Cloud Misconfiguration No IR Testing SOC / MDR Software Supply Chain
Open Case Study →
✈ Aerospace & Aviation

Keystone Aerospace LLC

Precision aerospace component manufacturer producing structural airframe parts and avionics housings for DoD prime contractors. Heavy ITAR exposure. 320 employees across two Kansas facilities.

Employees: 320
Revenue: ~$64M
Contracts: 3 Active
CMMC Gap: 7 Findings
Location: Wichita, KS
CAGE Code: 4MX71
Legacy ERP w/ CUI No MFA (Engineering) Unencrypted Supplier Email ITAR / 22 CFR 121 Media Sanitization Gap
Open Case Study →
🔬 Research Institution
🔬

Summit Research Institute

University-affiliated DoD research laboratory performing DARPA and ONR-funded research on autonomous systems and advanced materials. Handles CUI and export-controlled technical data. 45 researchers plus graduate students.

Researchers: 45 + students
Funding: ~$8.2M/yr
Grants: 3 Active
CMMC Gap: 8 Findings
Location: State College, PA
Oversight: DARPA / ONR
Student CUI Access Foreign National Gap BYOD on CUI Network ITAR / EAR No Formal SSP
Open Case Study →
📦 Defense Logistics
📦

Fortis Defense Logistics, Inc.

Defense supply chain and warehouse management contractor operating logistics support contracts for Army and Marine Corps. Manages controlled inventory tracking and shipment documentation containing CUI. Jacksonville FL headquarters.

Employees: 210
Revenue: ~$38M
Contracts: 2 Active
CMMC Gap: 6 Findings
Location: Jacksonville, FL
CAGE Code: 8FP33
WMS on Flat Network No Audit Logs (WMS) Contractor Access Unmanaged CUI in Shipment Docs Paper CUI Unprotected
Open Case Study →
🖥 Embedded Systems
💾

Vector Embedded Systems, Inc.

Embedded software and firmware developer producing safety-critical control code for naval weapons system components. Small but highly technical contractor with CI/CD pipeline, open-source dependencies, and serious CMMC obligations. San Diego CA.

Employees: 60
Revenue: ~$12M
Contracts: 2 Active
CMMC Gap: 7 Findings
Location: San Diego, CA
CAGE Code: 9VE14
Unsecured Code Repo No SBOM / SCRM Dev Laptops w/ CUI, No MDM Firmware / Safety-Critical CI/CD Pipeline Unsecured
Open Case Study →
📋 Management Consulting
💼

Coastal Defense Consulting Group

DoD management consulting firm providing acquisition support, program management, and policy advisory services to OSD and military departments. Primarily a knowledge-work business — CUI lives in documents, email, and SharePoint. McLean VA.

Employees: 38
Revenue: ~$9M
Contracts: 3 Active
CMMC Gap: 7 Findings
Location: McLean, VA
CAGE Code: 5CG82
CUI in Unencrypted Email No VPN Enforcement (Home) DMS Not in SSP Scope High Turnover Staff Slow Offboarding
Open Case Study →
🧬 BioDefense Research
🧬

Apex BioDefense Laboratories, Inc.

Biodefense research contractor performing BARDA and DoD-funded medical countermeasure development. Operates BSL-2 and BSL-3 laboratory facilities with separate IT and OT environments. Handles CUI, export-controlled biological research, and personnel data. Frederick MD.

Employees: 95
Revenue: ~$22M
Contracts: 2 Active
CMMC Gap: 8 Findings
Location: Frederick, MD
CAGE Code: 6AB95
CUI on Open Network Intl. Collaborators w/ CUI BYOD Researchers BSL-3 / EAR No CUI Marking Process
Open Case Study →