A GovCon Software Provider Maps Its Path from CMMC to FedRAMP Moderate

Get a Quote
The Project

Overview

A software provider serving government contractors engaged BD Emerson for a six-week security, compliance, and technology assessment. It already held a SOC 2 Type II report and CMMC Level 2 certification, and the assessment showed why FedRAMP Moderate comes next.
Partnership

BD Emerson x 

FedRAMP Moderate Readiness Assessment for a GovCon Software Provider

The client and the problem

A software provider that runs accounting and timekeeping for government contractors had already done serious compliance work. It held a clean SOC 2 Type II report and a CMMC Level 2 certification, and it served hundreds of contractor customers and thousands of timekeeping users. Leadership wanted an outside view of what came next: how mature the controls behind those results were, whether the technology and operations under the product could scale, and whether customers would soon ask for something the company did not have.

What we did

We ran two workstreams over six weeks. The security and compliance workstream reviewed CMMC Level 2 maturity against all 110 practices, reviewed the SOC 2 controls, and tested whether compliance automation could take manual evidence work off a small team. The technology and organizational workstream reviewed the SQL Server architecture, disaster recovery, and gaps in database administration and IT operations coverage.

What we found

The headline finding was regulatory. The provider's customers are defense contractors, and the controlled unclassified information in their timekeeping and accounting records passes through the platform. Under DFARS 252.204-7012, a defense contractor that uses a cloud service provider to store, process, or transmit covered defense information must ensure the provider meets security requirements equivalent to the FedRAMP Moderate baseline. The provider's own CMMC certification does not satisfy that requirement for the cloud service its customers rely on. The assessment also found that only a small fraction of customers had single sign-on enabled, and because single sign-on was how the platform delivered multifactor authentication, that gap carried straight into MFA coverage.

The result

The final report and leadership workshop gave the provider a clear recommendation: pursue FedRAMP Moderate, and begin with a strategic assessment that sets the authorization boundary and the path to authorization. The technology findings gave the operations team a prioritized list for the database and recovery gaps. After the readout, the provider's team began working through FedRAMP 20x, the path that certifies directly through FedRAMP without an agency sponsor. BD Emerson prepares companies for FedRAMP and does not perform the assessment. An independent 3PAO does, which keeps the firm preparing you separate from the firm evaluating you.

Why the client is not named

Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. The work ran through our FedRAMP compliance consulting and CMMC gap assessment practices. Our guide to FedRAMP requirements explains what authorization involves, and our FedRAMP 20x readiness service covers the newer path. We are glad to walk through comparable work under NDA.

Industry
Government Contracting Software
Location
United States
Company size
Small business
Founded
Undisclosed
CONTACT

Selling software to defense contractors?

Get a Quote

We map what your customers' contracts require of your platform and build the path to FedRAMP Moderate. An independent 3PAO performs the assessment. Book a working session.

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.