How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months
Applied solution
Kieri Reference Architecture
Kieri Compliance Documentation
Consulting Support
IntelliGenesis is a small defense contractor headquartered in Columbia, Maryland, with additional offices in Georgia and Texas. They operate as a tight-knit team where everyone wears multiple hats. Jose Faura serves as Chief Information Security Officer, handling the technical side. Jeremiah Jensen is Chief Operating Officer, overseeing operations and bringing his proposal-writing team into the compliance effort.
The company already knew its way around audits. They maintain ISO 9001 and CMMI certifications, so the concept of third-party assessment wasn’t foreign. But CMMC presented a different challenge entirely.
Jose started the NIST 800-171 journey back in November 2017. That initial assessment revealed a long list of changes needed. Hardware that would never be FIPS 140 compliant. Network switches that had to go. Access controls and physical security that needed upgrading.
Rather than panic, they started chipping away.
By late 2024, IntelliGenesis had spent years making incremental changes. New headquarters with proper physical security. Updated network infrastructure. GCC High licensing secured back in 2021 when getting those licenses took over a month.
But the documentation side remained daunting.
Jose knew the technical requirements cold. He understood what needed to happen. The problem was translating that knowledge into auditable policies, procedures, and a System Security Plan that would satisfy assessors.
“As a technical person, we read too deep into some of these controls,” Jose explains. “A lot of times you’re going down a rabbit hole that you don’t need to be there.”
Meanwhile, every vendor conversation became its own project. Finding the FedRAMP-compliant version of Adobe took five weeks just to reach the right person. Getting Microsoft’s shared responsibility matrix was another ordeal.
“Almost every single SaaS company we talked to that we have to have some information from, it’s hard to find who you need to talk to.”
Jose started looking for assessment scheduling and discovered something on Kieri’s website.
“I saw the documentation. Great, this is going to save so much time. So I went ahead and purchased it without telling anybody.”
Need a starting point for your CMMC documentation? Learn about the Kieri Compliance Documentation
Jose had been researching Maryland-based C3PAOs, partly to take advantage of the Maryland Cybersecurity Tax Credit. A pattern emerged quickly.
“Talking to several companies, Kieri kept coming up on top because you guys were teaching the assessors.”
That credibility mattered. When you’re trying to pass an assessment, working with the people who train the assessors makes sense.
Jose brought the KCD to Jeremiah. Initially, Jeremiah was apprehensive.
“That’s a lot of work to do,” he thought.
Then Jose showed him what he’d purchased.
“I said, no, I have this. I’m going to show you.”
IntelliGenesis split the work in a way that played to each team’s strengths.
Jose and the IT manager handled the technical implementation. Network changes. Configuration. Making sure everything was actually compliant.
Jeremiah brought in his proposal-writing team to handle documentation.
“Technical guys hate documentation. We work on the proposal side, we’re doing documentation all the time. So kind of working together, they filled in those gaps.”
The KCD’s roadmap became the project plan.
“I could lay it onto a schedule. I could say, all right, you got your policies, you got your procedures, you have all your documentation. It helped basically set a schedule for Jose, what he needs to be doing weekly, monthly, yearly.”
One wrinkle: IntelliGenesis runs on Macs, not Windows. The KCD templates needed significant modification.
“The documents were set up in a Windows environment, so we had to modify them significantly because we’re a Mac environment.”
But starting from existing templates still beat starting from scratch.
“It’s a lot easier to tweak than it is to try to start something from scratch.”
They incorporated the KCD content into their existing ISO 9001 documentation structure, keeping version control and formatting consistent across all their compliance programs.
When Jose and Jeremiah disagreed about how to interpret a requirement, they had a tiebreaker.
“Every time we have an issue with interpretation between me and the other people, well, let’s go watch the video. What did Amira have to say?”
The training videos became the authoritative source. No more guessing.
Questions about implementing the KCD? Schedule a consultation
The IT manager, Jason, made a decision that changed everything: put the answers in the SSP itself.
Most SSPs reference other documents. Control 3.1.1? See the Access Control Policy, Section 4.2. That sends assessors hunting through multiple files, following trails from document to document.
IntelliGenesis took a different approach.
“The first 20 pages of the SSP summarized how the whole thing worked. How the network should work. How the data flow works. How the policies work within the procedures.”
The result? Assessors didn’t have to chase references.
“The assessors said it’s the best implementation they have ever seen.”
The assessment finished in four days instead of five. No documentation questions. No rabbit holes.
IntelliGenesis achieved CMMC Level 2 certification in March 2026.
The final push took about three months of intense work. But that sprint sat on top of seven years of incremental progress.
Assessment completed early. Perfect execution. Assessor praise.
| Metric | Detail |
|---|---|
| Journey Start | November 2017 (initial NIST assessment) |
| Final Push Duration | ~3 months |
| Assessment Duration | 4 days (scheduled for 5) |
| Documentation Questions | None |
| Assessor Feedback | “Best implementation they have ever seen” |
Jose expected a grueling technical examination. What he got was more straightforward.
“What surprised me was that it was a lot easier than I expected. I thought it was going to be a lot more technical rabbit hole where you go through every single control and the sub-items.”
Instead, assessors verified that controls were in place, did some testing, and moved on. The thorough documentation made their job easy.
“As long as you cover the controls, that’s good enough.”
Jose and Jeremiah’s guidance centers on one theme: start early.
“Start early. Just chip away at what you can do. Don’t wait until you’re going to get assessed next year. Some of this stuff takes a long time.”
The examples pile up. GCC High licensing took over a month to provision. Finding the right Adobe product took five weeks. Microsoft’s shared responsibility matrix required endless calls.
“Start that now. Don’t wait until later.”
Technical people tend to build technical solutions. Sometimes that’s overkill.
“A simple paper banner on the copier with the CUI marking will be enough, rather than having to do all this crazy technical thing with the copy machine.”
Jose wishes he’d known that earlier. The KCD and training videos helped calibrate the appropriate level of response for each control.
Perhaps the most important mindset shift:
“People need to realize being certified is not the end goal here. This is the beginning. You have to be cyber secure now every day for the next three years and show that you’re doing what you said you were going to do.”
— Jose Faura, IntelliGenesis
IntelliGenesis integrated the KCD’s maintenance tasks into their bi-weekly Change Advisory Board meetings. They track changes formally, update policies when needed, and build the historical record they’ll need for reassessment.
“The first assessment is usually easier than the second. The second assessment, you have to show that historical.”
When asked what he’d tell someone on the fence, Jose didn’t hesitate.
“It’s silly not to pick the people that are actually teaching all the assessors how to do their jobs.”
— Jose Faura, IntelliGenesis
Jeremiah focused on the practical value.
“Having the policies, the procedures, the documentation, the roadmap for a PM basically saves tons of work on the back end. You can get things done a lot quicker rather than recreating the wheel.”
The bottom line:
“As long as we work, we probably would not have been able to make it on time if we didn’t have the documentation package.”
IntelliGenesis spent seven years preparing for CMMC, making incremental changes while running their business. When it came time for the final push, the KCD provided the roadmap and templates that let their proposal team handle documentation while the technical team handled implementation.
The result: an assessment that finished early, with assessors calling it the best implementation they’d ever seen.
Whether you’re years into your journey or just getting started, the KCD can help you organize what you know and fill in what you don’t.
Get started with the Kieri Compliance Documentation or schedule a consultation to discuss your compliance journey.
Kieri Solutions is one of few authorized C3PAOs in the United States. Our team trains CMMC assessors and maintains strict separation between consulting and assessment services.
CMSS consulting
Know where you stand
NIST SP 800-171
Official CMMC certification
CMMC 2.0
Official CMMC certification
Our Ethical Standards
Know where you stand
Free Gap Assessment
Your compliance status