
Achieving CMMC Success in a Code-Driven Environment
Most CMMC assessments rely on traditional screen-sharing and administrative portal checks. But what happens when an organization’s entire security architecture is managed through code? For one global aerospace leader, the challenge wasn’t a lack of technical maturity—it was translating a highly sophisticated, automated infrastructure into an assessment-ready evidence package. Here is how they partnered with KLC Consulting to turn complex infrastructure as code into a perfect CMMC Level 2 score of 110.
Executive Summary & Client Profile
A large, global, publicly traded aerospace organization supporting defense-related work and satellite operations engaged KLC Consulting (KLC) for a bundled CMMC Level 2 Mock Assessment and Certification Assessment. The company manufactures and launches satellites. A CMMC assessment scope focuses on the technical CUI environment used to manage the project, in this case, through a highly controlled technical environment involving CUI, classified-adjacent concerns, and infrastructure managed through code.
The client operated in a highly technical, software-defined environment where key system configurations were managed through infrastructure as code rather than traditional administrative interfaces. That made the assessment unusually complex. KLC’s assessment team needed to evaluate not only policies and procedures, but also how the organization’s controls were implemented through code.
The client chose KLC’s CMMC Mock + Level 2 Assessment Bundle to reduce the risk of discovering deficiencies during the official assessment. The Mock Assessment identified several gaps, primarily related to documentation and evidence presentation, not a lack of technical maturity. After remediation, the same KLC team conducted the official certification assessment, and the organization achieved a perfect score of 110.
The Challenge: A Sophisticated Environment Built Around Infrastructure as Code
Most CMMC assessments involve some amount of “click ops.” An assessor may ask to see user lists, configuration settings, access controls, or other evidence by having the OSC open administrative portals and navigate through system screens.
That was not how this environment worked.
The client used infrastructure as code, meaning key operational and security settings were managed through scripts and configuration code. John Sciandra, KLC Consulting’s Lead CCA on the project, explained that the team had to move beyond standard screen-based validation and understand the underlying software implementation:
“That wasn’t the case here. We had to understand software… when I was confronted with all of the control settings… I got to feel comfortable because I was back to my old hat of doing a code walk.”
— John Sciandra, Principal CMMC Assessor-Advisor
This required a CMMC assessment team possessing regulatory expertise and technical depth with software. The assessors needed to understand how the client’s code-driven environment mapped to CMMC practices, how configurations were represented, and how evidence could be evaluated without forcing the client into an artificial assessment model.
That point is the real feature of this case study. The client would not have failed their assessment because they lacked sophistication. Their challenge was translating a sophisticated implementation into an assessment-ready evidence package.
Why the Client Chose the CMMC Mock + Level 2 Assessment Bundle
The client selected KLC’s CMMC Level 2 Mock + Certification Assessment Bundle because they wanted a realistic first look before the official certification assessment.
This was not a casual readiness check. The Mock Assessment followed the same structure and rigor of an official assessment to identify deficiencies before they affected the official outcome. The client understood that even a mature technical environment could still have gaps in documentation, evidence presentation, or assessment readiness.
For a large organization, the bundle also reduced operational risk. Larger companies often prefer the Mock Assessment first because it’s their first attempt with certification in CMMC and “they don’t want to do it twice.” Repeating a full official assessment can cost significantly more in time, effort, money, and lost contract opportunity.
Mock Assessment Findings
- The Mock Assessment showed that the client’s technical environment was mature. The organization had many controls in place through its technology, infrastructure as code, and implementation configurations.
- The primary gaps were documentation-related. This is a common problem for technically strong organizations. A control may be implemented, but if it is not documented, evidenced, and presented clearly enough for assessment, it can still create deficiencies.
“They have a lot of the controls in place, through their technology, from the infrastructure as code, from the implementation configurations… There were some areas that [were] lacking and their deficiencies were in the documentation.”
— Kyle Lai, President and CISO, KLC Consulting
The Value of a Mock Assessment as a First Look
The Mock Assessment created space for the client to work through documentation and evidence issues before the official assessment. That mattered because the client’s environment did not fit neatly into a conventional evidence model.
In a traditional environment, assessors expect screenshots, administrative views, exported reports, or other familiar artifacts. In this case, much of the evidence lived in code. The client needed to demonstrate how controls were defined and implemented in a way that would be understandable, reviewable, and defensible under the CMMC Assessment Process.
John Sciandra described the Mock Assessment as a way to get a “first look” without guaranteeing the final outcome:
“You get a first look. It doesn’t guarantee a perfect score in the official assessment, but typically, if the OSC can self-remediate all the issues, they’re more likely to attain a much better outcome.”
— John Sciandra, Principal CMMC Assessor-Advisor
That is a useful way to think about the bundle. It does not promise certification. It gives an organization a chance to identify and self-correct deficiencies before the official assessment begins.
Remediation Period Between the Mock and Certification Assessment
After the Mock Assessment, the client had time to remediate the deficiencies KLC identified. The client was given four weeks to address the documentation issues before the official certification assessment.
This remediation window was central to the success of the engagement. The client corrected gaps, organize artifacts, clarify documentation, and align its evidence package with what would be needed for the official assessment.
KLC also performs a remediation review prior to the official assessment, to verify clients effectively remediate deficiencies, thereby maximizing their probability of success.
Because KLC utilizes the same team to conduct both the Mock and Official Assessment, the certification phase benefits in consistency and context gained during the Mock Assessment. The team already understood the client’s environment, the infrastructure-as-code model, and the specific evidence challenges that had been addressed.
The Outcome: CMMC Level 2 Final Status With a Perfect Score
The client successfully self-remediated the deficiencies identified during the Mock Assessment. When KLC conducted the official CMMC Level 2 Certification Assessment, the organization achieved a perfect score of 110. The result was a clean certification outcome for a complex, highly technical environment.
“They chose to do the Mock Assessment first, and the results were actually pretty good if not perfect … they were able to remediate all the deficiencies before the certification assessment.”
— Kyle Lai, President and CISO, KLC Consulting
Why This Case Study Matters
This case study shows why technically mature organizations benefit from a Mock Assessment before the official CMMC Level 2 Certification Assessment.
Strong technical controls do not automatically produce assessment-ready evidence. In environments built around infrastructure-as-code, cloud architecture, software-defined operations, or highly customized security implementations, the assessment team must possess the technical ability to understand how the controls effectively work. They also need to evaluate those controls without forcing the OSC into a simplistic evidence model that does not align with the environment.
The Mock Assessment helped the client identify documentation and evidence gaps before they became official certification findings. The certification assessment then validated the remediated environment and confirmed that the organization had achieved the required CMMC Level 2 outcome.
Key Takeaway
KLC’s CMMC Level 2 Mock + Certification Assessment Bundle gave this aerospace organization a practical path from assessment uncertainty to CMMC Level 2 Final Status.
The Mock Assessment identified deficiencies early. The remediation period gave the client time to correct them. The certification assessment confirmed the results. For organizations with complex technical environments, that first look can be the difference between entering the official assessment with confidence and discovering preventable gaps too late.
Don’t risk your certification on preventable gaps. KLC’s CMMC Level 2 Mock + Certification Assessment Bundle gives you an exact blueprint of your readiness before the official audit begins. Identify documentation blind spots, bulletproof your evidence package, and enter your assessment with the confidence to achieve a perfect 110. For complex technical environments, that first look is the difference between discovering critical gaps too late and entering your official assessment with total peace of mind.
Why KLC Consulting is the Right C3PAO for You
We understand the natural apprehension people feel going into their high-stakes CMMC assessment. You worry you’ll get the invasive “gotcha!” type of auditor. At KLC Consulting, our warm, interactive assessment style alleviates that concern. As an objective C3PAO, we are dedicated to validating your demonstrated security practices. We deliver assessments with clear understanding and a human touch, focusing on complete and accurate compliance confirmation.

Assessing organizations that develop software for Department of Defense applications requires rare, specialized knowledge. KLC Consulting possesses deep expertise in evaluating SSDLCs and DevSecOps environments. We understand precisely how CUI should be handled and protected within codebases, design specifications, and continuous integration/delivery pipelines. Our depth of knowledge far exceeds foundational C3PAO requirements and the capabilities of most C3PAOs in the marketplace today, ensuring a precise assessment for even the most advanced operational contexts.
Let’s talk
Is your organization preparing for CMMC certification? So are 77,000 other OSCs! – Don’t delay – let’s talk today. Please use our meeting link to schedule a Zoom call at any convenient time. You can also reach us at [email protected] or call 617-314-9721 x158.
We look forward to talking with you.
Download our complete guide to your CMMC Level 2 certification assessment.



