How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.
Applied solution
Kieri Compliance Documentation
Kieri Reference Architecture
Crux Solutions faced a situation familiar to many small and mid-sized defense contractors. They had DoD work worth protecting, no internal IT team, and a compliance requirement that would reshape how they operated.
Crux is a technology consulting and design firm serving the built environment industry out of Fort Worth, Texas. They work with architects, engineers, and construction firms, helping clients integrate technology into the spaces they create. Their client base splits between commercial and federal work, with DoD contracts making up a meaningful portion of the business.
When CMMC requirements became unavoidable, leadership faced a straightforward decision.
“We made a strategic decision for our company that we want to be in that space,” explains Gale Moericke, Vice President and Chief Security Officer at Crux. “If this is a requirement, this is what we’re going to go do.”
Gale brought serious credentials to the effort. He’s a CISM-certified cybersecurity professional with years of experience in ISO-audited environments. He understood exactly what needed to happen.
Understanding the destination and knowing how to get there, though, are two different things.
“I cannot be the first guy to ever want to do this.Somebody out there has probably put together a package that I could buy into.”
“I just had to have some faith that if I do it the way you said do it, it’s all going to kind of work out in the end. And it did.”
Crux started their earnest push in March 2025. They could have been ready by December, but couldn’t get assessors scheduled until February 2026.
Perfect 110 score. First attempt.
The assessment went faster than expected. Gale’s ISO background had trained him to treat document control seriously — every revision got a proper version number, every release was tracked. When the C3PAO team arrived, the documentation told a clean story from policy to procedure to evidence.
“Our assessment went fast. They were done quicker than they thought they would be. It’s because our documentation was so straightforward to follow.”
The MSP strategy worked exactly as Gale designed it. SentinelEdge stayed in a supporting role, outside the audit crosshairs, while Crux kept full ownership of the enclave and the CUI. No shared hosting, no MSP access to the enclave, no scope creep that would have pulled them into their own CMMC assessment.
“They don’t host anything for me. They don’t have access to my enclave. They can’t put their fingers on my CUI.”
The KCD’s cross-mapping structure between SSP, policies, and procedures was a major accelerator during the assessment itself. Assessors could follow a thread from an assessment objective to exactly where Crux addressed it across their documentation.
“That technique of saying these words in this SSP right here are addressed in that policy over there in that section was very effective. That tying it together made it really quick.”
Today, Crux treats CMMC as a lifestyle rather than a one-time project. The monthly subscriber calls keep them current on requirements. Their policies, procedures, and evidence collection run as standard operating practice, not as a scramble before the next assessment.
“It just has to be the way you run the business. If you’ll do that, then a lot of this gets less scary.”
For Crux, passing CMMC wasn’t the finish line. It was the start of how the company now operates. The compliance program runs as standard practice, not as a scramble before the next assessment.
Gale’s advice to other defense contractors comes from experience, not theory.
“Make sure you want to do this. Anything where you have to demonstrate ongoing compliance to a standard is a lifestyle thing. It’s not a one and done thing.”
The monthly KCD subscriber calls stay useful long after certification. Gale submits questions during the live sessions and gets answers from certified assessors in real time.
“Those monthly calls were pretty handy. I put a couple of questions to them that I thought might have been general interest questions, and sure enough, they talked about them in the call.”
For contractors still shopping for a path forward, Gale’s message is direct.
“Looking at the DoD timelines for when they’re going to start enforcing contract terms, if you’re just starting, I don’t know what to tell you, but get on it.”
He also knows that the right IT partnership can make or break the effort. For Crux, that meant bringing SentinelEdge into the journey as a committed partner rather than a reluctant vendor.
“If your IT partners don’t become your best friends and your arm-in-arm partners, you will not get there from here.”
Crux Solutions proved that a technology consulting firm without internal IT can achieve CMMC Level 2 certification with a perfect 110 score. Using the Kieri Compliance Documentation and a strategic MSP partnership, they built a custom enclave tailored to their AEC workflows, passed assessment on the first attempt, and now run compliance as standard business practice.
Your company can do the same.
Schedule a consultation with Kieri Solutions to discuss your compliance journey.
How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves
How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months
How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.
How a historic preservation firm built a compliant enclave on their own terms, adapting the KRA to fit unique design workflows
How a 250-person construction company built their own compliant enclave, saved over $200,000, and passed assessment on the first try
A 39-year-old defense subcontractor with government expertise finds the documentation and consulting guidance needed to finally feel confident about assessment.
How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.
How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves
How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months
How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.
How a historic preservation firm built a compliant enclave on their own terms, adapting the KRA to fit unique design workflows
How a 250-person construction company built their own compliant enclave, saved over $200,000, and passed assessment on the first try
A 39-year-old defense subcontractor with government expertise finds the documentation and consulting guidance needed to finally feel confident about assessment.
How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.
We deliver modern CMMC solutions designed to simplify compliance, eliminate uncertainty, and protect your contract pipeline — without forcing one rigid path.
Talk with a certified CMMC assessor who can help you figure out your next step.
CMSS consulting
Know where you stand
NIST SP 800-171
Official CMMC certification
CMMC 2.0
Official CMMC certification
Our Ethical Standards
Know where you stand
Free Gap Assessment
Your compliance status