
A software provider that runs accounting and timekeeping for government contractors had already done serious compliance work. It held a clean SOC 2 Type II report and a CMMC Level 2 certification, and it served hundreds of contractor customers and thousands of timekeeping users. Leadership wanted an outside view of what came next: how mature the controls behind those results were, whether the technology and operations under the product could scale, and whether customers would soon ask for something the company did not have.
We ran two workstreams over six weeks. The security and compliance workstream reviewed CMMC Level 2 maturity against all 110 practices, reviewed the SOC 2 controls, and tested whether compliance automation could take manual evidence work off a small team. The technology and organizational workstream reviewed the SQL Server architecture, disaster recovery, and gaps in database administration and IT operations coverage.
The headline finding was regulatory. The provider's customers are defense contractors, and the controlled unclassified information in their timekeeping and accounting records passes through the platform. Under DFARS 252.204-7012, a defense contractor that uses a cloud service provider to store, process, or transmit covered defense information must ensure the provider meets security requirements equivalent to the FedRAMP Moderate baseline. The provider's own CMMC certification does not satisfy that requirement for the cloud service its customers rely on. The assessment also found that only a small fraction of customers had single sign-on enabled, and because single sign-on was how the platform delivered multifactor authentication, that gap carried straight into MFA coverage.
The final report and leadership workshop gave the provider a clear recommendation: pursue FedRAMP Moderate, and begin with a strategic assessment that sets the authorization boundary and the path to authorization. The technology findings gave the operations team a prioritized list for the database and recovery gaps. After the readout, the provider's team began working through FedRAMP 20x, the path that certifies directly through FedRAMP without an agency sponsor. BD Emerson prepares companies for FedRAMP and does not perform the assessment. An independent 3PAO does, which keeps the firm preparing you separate from the firm evaluating you.
Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. The work ran through our FedRAMP compliance consulting and CMMC gap assessment practices. Our guide to FedRAMP requirements explains what authorization involves, and our FedRAMP 20x readiness service covers the newer path. We are glad to walk through comparable work under NDA.