Masser Technologies Case Study

Masser Technologies Passes CMMC Assessment with Flying Colors as Both MSSP and OSC

How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves

 

CMMC Level 2

Applied solution

Kieri Compliance Documentation

Consulting Support

0

Perfect CMMC Score

0 mo

KCD Purchase to Certification

0

ROLES CERTIFIED (MSSP + OSC)

0

MAJOR FINDINGS

About Masser Technologies

Roger Curtis had been watching CMMC since 2019.

As Director of Technology and Compliance at Masser Technologies, he had a front-row seat to the regulation’s evolution. The El Paso, Texas-based company occupies a unique position in the defense industrial base. They’re both an MSSP providing managed security services and an OSC holding contracts with the Department of the Army.

That dual role meant Curtis needed to solve two problems at once. Get his own company certified. Then help his clients do the same.

“We started our CMMC journey by first becoming a federal contractor in 2019, seeing the 7012 clause in our contracts, and then hearing about CMMC coming down the pike,” Curtis explains. “The contract requirement is what kept us focused on this area.”

CMMC kept changing along the way. Requirements shifted. Assumptions got challenged. What seemed certain one month became uncertain the next. Through it all, Curtis kept watching, learning, and preparing.

When the time came to move from preparation to implementation, he knew exactly what he needed.

The Challenge

Masser Technologies had already started their compliance journey through a peer group focused on NIST 800-171 documentation. It was a good place to get their feet wet.

But documentation was only part of the puzzle.

“We learned about proper scoping and the enclave option,” Curtis recalls. “But, we were not sure how to properly implement a CMMC-compliant enclave and fully document it.”

Configuration and documentation needed to work together. Most solutions handled one or the other. Few handled both.

Eventually, one name kept coming up.

“I learned about Kieri from attending CMMC-focused webinars and following CMMC thought leaders on LinkedIn.”

Roger Curtis,

Director of Technology and Compliance, Masser Technologies

The timing aligned perfectly. Kieri had just released documentation for GCC environments. That was exactly the route Masser Technologies was taking.

Finding Kieri

Curtis had watched Amira’s videos and seen her speak at conferences.

“Amira’s YouTube videos talking about CMMC topics came from the angle of the challenges DIB contractors face implementing a compliance program and creating the necessary documentation needed to show how the program has been set up and the processes that are being followed.”

Roger Curtis,

Masser Technologies

What sealed the decision was the holistic approach.

“It wasn’t just here’s some templates and run with it,” Curtis explains. “It was templates, but it also pointed to configurations and configuration settings were provided as well. So it was the whole package.”

Templates alone weren’t enough. Configuration guidance alone wasn’t enough. Masser Technologies needed both working together.

The KCD and KRA delivered exactly that.

Need documentation and configuration guidance that work together? Explore the KCD and KRA

The Solution

Masser Technologies purchased the KCD and KRA in July 2024. Their challenge was adapting the documentation to their unique MSSP situation. In fact, the KCD is designed for an OSC doing everything themselves.

The challenge wasn’t understanding what needed to be done. The KCD made that clear. The challenge was adapting it to their unique situation.

The MSSP Adaptation

The KCD is designed for an OSC doing everything themselves. SharePoint for ticketing. SharePoint for asset inventory. SharePoint for tracking maintenance tasks.

Masser Technologies already had their own tools. A ticketing system. Asset management platforms. MSSP infrastructure serving multiple clients.

“As an MSSP we already have tools we use for several of the aspects that the KCD provides a solution for, such as incident ticketing, asset database. These were areas where we modified the KCD documentation to reflect how we do business and provide support to our customers,” Curtis explains.

The substance stayed the same. The locations changed. Every requirement still got addressed. The evidence still got generated. It just lived in different places.

The Scalability Decision

Curtis made a strategic choice early. Rather than build a pure Microsoft-only environment, he brought their existing MSSP tools into the enclave.

“My thought was maintaining scalability that MSSP rely on, tools that can be deployed with similar settings and policies, rather than recreating the wheel for DIB contractor environments,” he explains.

That meant service desk staff could work the same way across commercial clients, GCC clients, and federal customers. One set of processes. One set of tools. Consistency across the board.

The tradeoff was additional complexity. Pure Microsoft would have been simpler. But Curtis was thinking long-term.

“We gained clarity with the CMMC final rule regarding what MSP tools required FedRAMP Moderate authorization. With the clarity came changes to our plan, our assumptions. We no longer needed a separate FedRAMP version of a tool or platform and documentation references also changed.”

“You got to go back and tweak documentation multiple times from start to finish.”

The KCD’s structure made those tweaks manageable. Everything connected. Change one reference, and the system stayed coherent.

The Revelation

Working through the documentation, Curtis had a realization.

“We didn’t know all of the things we didn’t know until we saw a complete set of documentation from start to finish. Everything was there—we only needed to make minor changes to line up with how we do things.”

Roger Curtis,

Masser Technologies

The KCD showed the complete picture. Not just what policies to write. Not just what configurations to implement. The whole system. How policies connected to procedures. How procedures connected to evidence. How evidence proved compliance.

Without that complete picture, gaps would have been invisible until assessment day.

The Assessment

Masser Technologies reached out to C3PAOs at the start of 2025. They had a specific requirement. They needed an assessor who understood MSSPs.

“There are now over 100 C3PAOs in the ecosystem, but many of them are just big assessment organizations that don’t know the specifics of how MSSPs operate and provide services to their customers,” Curtis explains. “They will just go down the list of assessment objectives not understanding that an MSSP is meeting a particular objective.”

They needed someone who understood how an MSSP providing services to an OSC works differently than a company doing everything internally.

After evaluating options, they chose KLC Consulting. Kyle and his team understood the MSSP model.

The assessment came in May 2025. In the end, they finished with time to spare.

The Day of Reckoning

Curtis had spent months training his team. Service desk. Networking. Audit log reviewers. Everyone needed to know where to find answers and how to demonstrate compliance.

“During our assessment there was a day that was mostly me answering the assessor’s questions. That is when it became clear that I had not prepared myself to the same level as I was asking my team to be at. I had to answer the assessor with, ‘I’ll get back to you on that.'”

Thankfully, everything was fixable.

“At the end of the assessment day the C3PAO assessors will hold a ‘hot wash’ where they cover anything that was missing for the day. This was where we had the list of any objectives or specific evidence that was still missing. That was our homework that we had to address to keep our assessment on track.”

By the end of the assessment, nothing major remained. A few t’s to cross. A few i’s to dot. Within one or two days of the 10-day window, everything was done.

“Even after my own preparation shortcomings the end result was passing with 110—flying colors! Documentation was the shining part that made it all possible.”

Roger Curtis,

Masser Technologies

The Results

Masser Technologies achieved CMMC Level 2 certification in May 2025.

The assessment covered both their OSC side and parts of their MSSP operations. The enclave they built using the KRA passed scrutiny. The documentation they adapted from the KCD held up under examination.

By the Numbers

MetricResult
CMMC LevelLevel 2 Certified
Timeline~10 months (July 2024 to May 2025)
Implementation ModelDIY with check-in calls
EnvironmentMicrosoft 365 GCC with MSSP tools
C3PAOKLC Consulting
Assessment DurationCompleted with time to spare

The Ongoing Challenge

Certification was the first hurdle. Maintaining compliance is the marathon.

“Once the assessment has been completed, the real work begins, the continuous maintenance tasks that prove a mature cybersecurity program exists.”

The tickets are there. The recurring tasks are scheduled. The cadence is established. But people have day jobs. Priorities compete.

“Nobody wants to consider 3 years down the road at reassessment time the assessor asks for evidence of 36 routine monthly task tickets and we can only show 32.”

Personnel changes add another layer. Someone who handled audit log reviews during the assessment has already moved to a different role. Now Curtis is training their replacement.

“Compliance upkeep is the challenge—personnel turnover and training the replacement to complete the same routine tasks. Nothing can stop those compliance tasks.”

Advice for Defense Contractors

Curtis has a clear message for companies just starting their compliance journey.

“If you are coming into compliance or CMMC with all of the nuanced requirements, having documentation that’s already geared toward the compliance framework is a game changer. It gets the organization started more quickly.”

Roger Curtis,

Masser Technologies

Without a complete documentation set, the blank page is paralyzing.

“Receiving blank, disjointed generic documents leaves you struggling to find what those documents need to say, how much detail to include.”

Everything connects. Policies reference procedures. Procedures reference evidence. Evidence proves you did what you said. Getting those connections right from the start matters.

“Having a complete package, which the KCD and the KRA together are, really fills in the gaps and keeps you on the right path.”

— Roger Curtis, Masser Technologies

The Competitive Advantage

Curtis completed his assessment right before the CMMC Phase 2 pause was announced.

“We have cleared the hurdle, the time crunch, the scheduling backlog,” Curtis says. “Now we can look forward to competing for new contracts and supporting current and future federal contracts without the distraction.”

When requirements clarify and assessments resume, scheduling will tighten. Companies that waited will compete for limited C3PAO availability. Masser Technologies will already be certified and focused on maintenance.

“MSSPs that have already achieved this milestone are head and shoulders above their competition. No need to get back in the C3PAO ‘line’.”

Why Kieri

When Curtis talks to potential clients, the question usually comes down to price. But he frames it differently now.

“Your time is already short, you are way behind the power curve. Kieri documentation will help jumpstart your organization’s CMMC journey.”

The KCD provides documentation. The KRA provides configuration guidance. Together, they provide a complete starting point.

“If you haven’t started, this is going to definitely get you going much more quickly than if you’re just jumping in yourself and trying to figure it out, especially this late in the game.”

— Roger Curtis, Masser Technologies

And the value extends beyond just OSCs.

“The KCD and the KRA, the combination works well for both somebody who is an MSP providing compliance services or consulting, or if you’re an OSC walking in and you’re going, well, how do I do this myself? It fits across the board.”

As for the investment?

“I don’t feel like the price was a showstopper. It was a good price for what you’re getting, and it definitely gets you ready to go out and find your C3PAO of choice much more quickly.”

— Roger Curtis, Masser Technologies

Ready to Prepare for Your CMMC Assessment?

Masser Technologies spent years watching CMMC evolve. When implementation time came, the KCD and KRA gave them the complete picture they needed. Documentation that connected. Configurations that worked. A path from start to certification.

Whether you’re an MSSP, an OSC, or both, the KCD and KRA provide the foundation for a successful compliance program.

Get started with the Kieri Compliance Documentation or schedule a consultation to discuss your compliance journey.

Kieri Solutions is one of few authorized C3PAOs in the United States. Our team trains CMMC assessors and maintains strict separation between consulting and assessment services.

Explore Related Case Studies

Masser Technologies logo and tagline Tech Aligned for Peace of Mind on a teal background, CMMC case study
Masser Technologies Passes CMMC Assessment with Flying Colors as Both MSSP and OSC

How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves

MSSP + OSC

View Kieri Solutions CMMC client case study

Both roles certified

IntelliGenesis CMMC Level 2 case study logo
IntelliGenesis Achieves CMMC Level 2 Certification by Chipping Away Over Seven Years

How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months

4 DAYS

View Kieri Solutions CMMC client case study

TO COMPLETE ASSESSMENT

Crux Solutions logo, a Fort Worth technology consulting firm and Kieri CMMC Level 2 case study client
Crux Solutions Achieves Perfect 110 Score by Treating CMMC as a Lifestyle, Not a Project

How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.

12 months

View Kieri Solutions CMMC client case study

To Certification

Quinn Evans Achieves CMMC Level 2 Certification with a Cloud-First Approach

How a historic preservation firm built a compliant enclave on their own terms, adapting the KRA to fit unique design workflows

CMMC L2

View Kieri Solutions CMMC client case study

Certified

Reynolds Construction logo
Reynolds Construction Achieves Perfect CMMC Level 2 Score Without an IT Background

How a 250-person construction company built their own compliant enclave, saved over $200,000, and passed assessment on the first try

$200,000

View Kieri Solutions CMMC client case study

Saved

Advanced Design Fabrication Corp logo
How a 10-Person Manufacturing Company Prepared for CMMC Level 2 After Nearly a Decade of Compliance Work

A 39-year-old defense subcontractor with government expertise finds the documentation and consulting guidance needed to finally feel confident about assessment.

93%

View Kieri Solutions CMMC client case study

SIEM Cost Reduction

Exigo Corporation logo
Exigo Corporation Achieves CMMC Level 2 Certification with a Cloud-First Approach

How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.

4x

View Kieri Solutions CMMC client case study

Faster Compliance Assessments

Masser Technologies logo and tagline Tech Aligned for Peace of Mind on a teal background, CMMC case study
Masser Technologies Passes CMMC Assessment with Flying Colors as Both MSSP and OSC

How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves

MSSP + OSC

View Kieri Solutions CMMC client case study

Both roles certified

IntelliGenesis CMMC Level 2 case study logo
IntelliGenesis Achieves CMMC Level 2 Certification by Chipping Away Over Seven Years

How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months

4 DAYS

View Kieri Solutions CMMC client case study

TO COMPLETE ASSESSMENT

Crux Solutions logo, a Fort Worth technology consulting firm and Kieri CMMC Level 2 case study client
Crux Solutions Achieves Perfect 110 Score by Treating CMMC as a Lifestyle, Not a Project

How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.

12 months

View Kieri Solutions CMMC client case study

To Certification

Quinn Evans Achieves CMMC Level 2 Certification with a Cloud-First Approach

How a historic preservation firm built a compliant enclave on their own terms, adapting the KRA to fit unique design workflows

CMMC L2

View Kieri Solutions CMMC client case study

Certified

Reynolds Construction logo
Reynolds Construction Achieves Perfect CMMC Level 2 Score Without an IT Background

How a 250-person construction company built their own compliant enclave, saved over $200,000, and passed assessment on the first try

$200,000

View Kieri Solutions CMMC client case study

Saved

Advanced Design Fabrication Corp logo
How a 10-Person Manufacturing Company Prepared for CMMC Level 2 After Nearly a Decade of Compliance Work

A 39-year-old defense subcontractor with government expertise finds the documentation and consulting guidance needed to finally feel confident about assessment.

93%

View Kieri Solutions CMMC client case study

SIEM Cost Reduction

Exigo Corporation logo
Exigo Corporation Achieves CMMC Level 2 Certification with a Cloud-First Approach

How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.

4x

View Kieri Solutions CMMC client case study

Faster Compliance Assessments

We deliver modern CMMC solutions designed to simplify compliance, eliminate uncertainty, and protect your contract pipeline — without forcing one rigid path.

See how defense contractors achieve CMMC certification with Kieri.

See how defense contractors achieve CMMC certification with Kieri.

Talk with a certified CMMC assessor who can help you figure out your next step.