⚠ Educational Use Only — Fictional Scenario

All company names, personnel, contract numbers, CAGE codes, and data in this case study are entirely fictional and created for educational purposes. This material is part of the SANDS/MVCC CMMC Program curriculum. Do not use any information herein as actual legal, compliance, or cybersecurity guidance.

Case Study Metadata

Version1.0 — June 2025
ScopeCMMC Level 2 — 110 NIST SP 800-171 practices across 14 domains
Learner LevelIntermediate — assumes basic familiarity with CMMC/DFARS
Deliverables11 practitioner documents (SSP, POA&M, SAR, IRP, and more)
Educational UseSANDS/MVCC CMMC Program — not for commercial distribution

About This Case Study

ThreadBridge Solutions, LLC is a fictional small business that manufactures both combat utility uniforms for the Department of Defense and sells commercial office supplies to federal agencies via GSA Schedule. This dual-revenue model places ThreadBridge at the intersection of two distinct compliance regimes: CMMC Level 2 (for CUI-laden defense contracts) and CMMC Level 1 (for commercial GSA supply). Learners will analyze the company's technical environment, identify security gaps, evaluate two real security incidents, and produce the eleven practitioner documents required for a CMMC Level 2 assessment. The scenario deliberately embeds multiple realistic compliance failures common in small-to-midsize defense contractors.

Case Study Documents — Click to Open

Each card opens the corresponding document workspace in the Documents tab.

Doc 01
System Security Plan (SSP)
Doc 02
Plan of Action & Milestones (POA&M)
Doc 03
Asset Inventory
Doc 04
Security Assessment Report (SAR)
Doc 05
Incident Response Plan (IRP)
Doc 06
Access Control Matrix
Doc 07
Audit Log & Monitoring Report
Doc 08
Configuration Management Plan
Doc 09
Vulnerability Scan Report
Doc 10
SPRS Score Worksheet
Doc 11
Maintenance Report
Industry Context
Defense Textile & Apparel — DoD Uniform Manufacturing Sector

The defense uniform manufacturing sector is a specialized niche of the broader defense industrial base (DIB). Companies operating in this space typically hold Defense Logistics Agency (DLA) contracts for combat utility uniforms, physical fitness uniforms, and service dress components. The sector is characterized by high volume, tight delivery schedules, strict technical specifications, and substantial CUI obligations—particularly around material composition and camouflage pattern data that DLA provides to contractors. Below are five representative companies operating in adjacent or overlapping market segments to ThreadBridge Solutions.

CompanyLocationPrimary ProductsContract VehicleCUI/Compliance Notes
American Apparel Inc.Selma, ALCombat utility uniforms for all branchesDLA Troop Support IDIQ ($48M)CUI Uniform specs
Bluewater DefenseCorozal, PRMajor military uniforms, ~$1B DoD revenueDLA multiple-award IDIQCUI Specs + delivery data
Crye PrecisionBrooklyn, NYPremium military uniform/equipment, ~150 employeesDirect DoD + DLAITAR-adjacent; CUI threshold applies
Propper InternationalSt. Charles, MOFull-line military uniformsDLA + GSA accessoriesFCI CUI Both apply
Staples Inc.Framingham, MAOffice supplies to DoD via GSA MASGSA MAS Contract 47QSEA19D008TFCI Only — Level 1
ThreadBridge's Unique Position: Unlike pure-play defense apparel manufacturers or pure commercial suppliers, ThreadBridge occupies the intersection of both product lines—manufacturing combat utility uniforms under a DLA IDIQ (triggering CMMC Level 2 obligations) while simultaneously supplying office materials via GSA Schedule (Level 1 only). This dual exposure creates compliance complexity: different data classification requirements, different flow-down clauses, and different assessment timelines must be managed simultaneously within a single 82-person organization.
Company Background
ThreadBridge Solutions, LLC — Organizational Profile

Key Personnel — Click a card to view system access

Margaret Holloway
Chief Executive Officer
FCICUI

System Access

  • Email (M365)
  • SharePoint
  • QuickBooks (view-only)
Access Level: FCI + CUI All Categories
Dennis Park
IT Manager / de facto CISO
FCICUI⚠ Risk

System Access

  • Domain Admin — ALL systems
  • ERP (admin)
  • All servers (local + remote)
  • VPN management
  • Firewall admin
Least Privilege Violation: Domain Admin used for day-to-day operations. Links to G-02.
Sandra Ybarra
Contracts Manager
FCICUI

System Access

  • ERP (Epicor)
  • Email (M365)
  • SharePoint (contracts)
Access Level: FCI + CUI (Contracts)
Robert Chen
Production Manager
FCICUI

System Access

  • ERP (Epicor)
  • Email (M365)
  • Manufacturing tablets (Android)
Access Level: FCI + CUI (Specs)
Lisa Nguyen
HR Manager
FCICUI

System Access

  • Email (M365)
  • SharePoint (HR)
  • QuickBooks (HR view)
Access Level: FCI + CUI (Personnel)
Marcus Webb
Warehouse Supervisor
FCI

System Access

  • ERP (Epicor — inventory module)
  • Email (M365)
Access Level: FCI Inventory Only

Organization Profile

Legal NameThreadBridge Solutions, LLC
CAGE Code7T4X2 (fictional)
DUNS/UEI08-347-2198 / TBS22CUMBERLAND
Founded2004
OwnershipPrivately held; WOSB
HQ1148 Industrial Parkway, Cumberland, MD 21502
Satellite88 Commerce Drive, Frostburg, MD 21532
Warehouse — 12 miles from HQ
Employees82 total
Annual DoD Revenue~$14.2M

Active Contracts

Contract #AgencyTypeValueDataRenewal
FA4890-25-D-0014 DLA Troop Support IDIQ FFP $11.2M / 5yr CUI 18 months URGENT
GS-02F-8847X GSA MAS Sch 75 MAS $3.2M annual FCI only Annual renewal
Technical Environment
Asset Inventory, MFA Status, and Third-Party Providers

Asset Inventory

Asset IDDescriptionOS/PlatformLocationFunctionFCICUI
SRV-001ERP Server (Epicor 10.2)Windows Server 2019Cumberland server roomProduction scheduling, inventory, contractsYESYES
SRV-002File Server TBS-FS01Windows Server 2022Cumberland server roomCentralized file storageYESYES
SRV-003Domain Controller TBS-DC01Windows Server 2019Cumberland server roomAD, DNS, DHCP, Group PolicyYESIndirect
SRV-004Backup NAS (Synology DS1821+)Synology DSM 7.2Cumberland server roomVeeam backup target; NO offsite backupYESYES Often Overlooked!
WRK-001–040Windows Workstations (40)Win 10/11 ProCumberland (30) / Frostburg (10)Office use, ERP, emailYESPARTIAL (8 of 40)
MOB-001–008Android Tablets (8)Android 12 SamsungManufacturing floorProduction tracking via ERP web clientYESNO Same LAN as CUI servers
NET-001Sophos XG 310 FirewallSophos SFOS 19.5Cumberland server roomPerimeter, VPN gateway, IDS/IPSN/AN/A
NET-002Cisco SG350 Switches (3)Cisco IOSCumberland (2) / Frostburg (1)LAN NO VLANsN/AN/A
CLO-001Microsoft 365 Business PremiumCloud (Azure)Microsoft-hostedEmail, Teams, SharePoint, OneDriveYESYES — SharePoint folders
CLO-002QuickBooks EnterpriseWin 10 (ACCT-WRK-01)Accounting officeAP/AR, payroll supportYESNO Orphaned admin account
PRN-001–003Ricoh IM C4500 MFPs (3)Ricoh OSCumberland (2) / Frostburg (1)Print, scan-to-email, copyYESPOTENTIAL — can scan to any email
VPN-001Sophos SSL VPN (12 users)Embedded in NET-001Remote accessRemote workersYESYES — tunnels CUI traffic NO MFA

MFA Status by System

SystemMFA Enforced?MethodGap Reference
M365 (Email/SharePoint/Teams)YESConditional Access — Azure AD
ERP (Epicor 10.2)NOLocal password only⚠ Gap G-01
File Server (TBS-FS01)NOAD credentials⚠ Gap G-01
Domain Controller (RDP)NOAD credentials⚠ Gap G-01
Sophos VPNNOAD credentials⚠ Gap G-01
QuickBooks EnterpriseNOLocal QB database⚠ G-01 + orphaned account
Backup NAS (Synology)NOShared local account⚠ Gap G-01

Third-Party Service Providers

ProviderLocationServicesCUI Access?Contract Status
TechServ LLCFrederick, MDERP maintenance; monthly on-site + remote VPNYES — ERP (CUI)Basic MSA only NO CUI clause
Cascade NetworksLocalISP + managed firewallFirewall access onlyISP agreement — no security addendum
ADPCloudPayroll processingEmployee PII = CUI-PrivacyStandard ADP agreement — no flow-down clause
Ricoh USANationalPrinter maintenance (quarterly)Physical MFP accessStandard maintenance contract
MicrosoftCloudM365 cloud servicesAll email + SharePoint dataFedRAMP Moderate ✓
Data Classification
Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) at ThreadBridge
FCI Federal Contract Information
Contract Pricing Data
Bid data, cost proposals to DLA/GSA
Location: File Server + SharePoint
Access: Holloway, Ybarra
Production/Delivery Schedules
Manufacturing timelines, lot quantities
Location: ERP + File Server
Access: Ybarra, Chen, Webb
Contract Performance Reports
Monthly metrics to DLA COR
Location: SharePoint + Email
Access: Ybarra, Holloway
Purchase Order Data (GSA)
Office supply orders, billing codes
Location: ERP + Email
Access: Sales team, Ybarra
Subcontractor Pricing
Vendor bids, raw material pricing
Location: File Server + Email
Access: Ybarra, Chen
CUI Controlled Unclassified Information
Critical Technology — Uniform Technical Specs
Material composition, camo patterns, Army/AF OCP tolerances
Location: /CUI/Contracts/DLA/Specs + SharePoint
Access: Chen, Park, Ybarra
CTI — Delivery Destination Data
Military unit locations, installation addresses for shipments
Location: ERP delivery module + File Server
Access: Ybarra, Chen, Webb
Privacy—Personnel — Employee Clearance Submissions
SF-86 data, personnel security questionnaire responses
Location: /HR/Clearances + SharePoint
Access: Nguyen, Holloway
Export Controlled (EAR) — Synthetic Fabric Data
EAR-controlled synthetic material specs (not ITAR)
Location: /CUI/Materials/EAR + encrypted email
Access: Chen, Park
NOT ALL SENSITIVE DATA IS CUI: Production labor hours, employee payroll, and commercial vendor invoices are sensitive business data but do NOT meet the CUI definition under 32 CFR Part 2002 or the CUI Registry. Misclassifying non-CUI data as CUI creates unnecessary compliance burden without legal basis.

Interactive Quiz: FCI or CUI?

Classify each data item. You'll receive immediate feedback after each answer.

Question 1 of 6
Unit pricing submitted to DLA contracting officer