Enabling CMMC Readiness for an Asphalt & Concrete Manufacturer
Industry
Asphalt & Concrete Manufacturer
Company Size
~80-90 users
Services Provided
CMMC Submission Preparation, Managed Network Security, Policy Creation, and Access Controls
Overview
An asphalt and concrete manufacturer supporting infrastructure and government-related projects, partnered with InfoPathways to prepare for Cybersecurity Maturity Model Certification (CMMC). As compliance requirements from the Department of Defense continue to impact contractors and suppliers, achieving CMMC readiness became essential for maintaining eligibility and competitiveness.
The Challenge
While many DoD contractors are accustomed to CMMC compliance, the cybersecurity framework has recently been finding its way into federal contracts outside of the defense industry. Sometimes this is due to flow-down compliance requirements cascading from primes down to subcontractors, or (as in this case) it can be due to the presence of Controlled Unclassified information (CUI) appearing in non-DoD contracts.
This organization needed to gain CMMC compliance to continue and expand work on federal contracts that involved CUI such as maps and architectural drawings of military facilities. Their familiarity with CMMC compliance requirements is limited, and their existing IT practices were never built with these controls in mind. Legacy equipment and processes served day-to-day needs but fell short of modern security standards. Outside IT, policies for onboarding/offboarding, acceptable device use, and client and employee conduct existed only informally.
What makes this case particularly challenging is the variety of unconventional endpoints the organization’s work depends on. Engineering workstations, network enabled equipment for asphalt manufacturing, field devices used on job sites, and other specialized equipment must all be secured to a standard designed with conventional office IT in mind. These devices are essential to operations, yet they don't fit neatly into the CMMC control model.
Key challenges included:
- Limited alignment between existing IT practices and CMMC requirements, with no prior framework or institutional knowledge to build on
- Gaps in documentation, policies, and formal security processes that defense contractors typically already have in place
- Unconventional endpoints (engineering systems, field devices, and specialized equipment) that nonetheless must meet CMMC security controls
- Operational technology (OT) and business systems requiring secure integration without disrupting production
- Pressure to achieve compliance on a tight timeline without disrupting active project work and deliverables
The Solution
Strategic Compliance Leadership
InfoPathways assigned senior cybersecurity engineers to lead the engagement from the outset, ensuring the work was grounded in both technical depth and practical business awareness. The planning stage began with a thorough review of existing systems against CMMC requirements, from which the team built a prioritized roadmap aligned to the manufacturer's operational schedule. Throughout the process, compliance milestones were sequenced to protect uptime and minimize disruption to production workflows.
Gap Analysis and Framework Alignment
InfoPathways conducted a comprehensive gap assessment structured around NIST SP 800-171, the technical foundation of CMMC. Engineers evaluated the maturity of existing policies and documentation, identified missing or incomplete controls, and mapped risks across both IT systems and operational environments. The resulting analysis gave leadership a clear picture of where the organization stood and what work remained before certification.
Remediation and Implementation
With the gap assessment complete, senior engineers executed a targeted remediation effort spanning access controls, multi-factor authentication, endpoint protection, and network security hardening. The team also established logging, monitoring, and incident response processes, and developed the formal policies and procedures required under the framework. All implementation work was coordinated carefully to avoid interference with active manufacturing operations.
CMMC Submission Preparation
As remediation neared completion, InfoPathways shifted focus to preparing the manufacturer for formal CMMC submission. This included organizing required documentation and evidence packages, validating that controls were implemented correctly and completely, and confirming audit readiness across both technical and administrative domains. Submission preparation has been finalized, and InfoPathways continues to provide support as the organization moves through the certification process.
The Results
- The manufacturer achieved full CMMC readiness and has completed preparation for formal submission to the certifying body.
- InfoPathways translated complex NIST SP 800-171 requirements into practical, operational processes the internal team can sustain and audit over time.
- The engagement meaningfully strengthened the company's cybersecurity posture across both its IT infrastructure and production environment.
- With certification now within reach, the manufacturer is positioned to pursue and retain government-related contracts that require CMMC compliance.
What's Next?InfoPathways continues to partner with the manufacturer to:
- Maintain compliance as standards evolve
- Address any findings from certification review
- Continuously improve cybersecurity maturity
.png?width=200&height=200&name=golf%20ball%20logo%20(1).png)