How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.
Applied solution
Kieri Compliance Documentation
Exigo Corporation serves the U.S. Space Force as their primary customer. As a cloud-first organization, they’ve built their entire infrastructure around modern technology. No on-premises servers. No traditional VPNs. Everything runs through Microsoft Entra and cloud services.
John Hilb serves as both Chief Technology Officer and Chief Compliance Officer. His background includes 15 years working for a managed service provider, giving him deep expertise in configuring Office 365 and managing cloud environments.
The technical implementation side of CMMC was familiar territory.
The documentation and body of evidence required to actually pass an assessment was a different story.
“It was a great skeleton. It gives you, hey, here’s all the stuff that you need to be talking about. When you don’t know what you don’t know, it really gives you, here’s what you don’t know and here’s what you need to answer.”
“Having somebody who’s on the C3PAO say, ‘Hey, this is sort of what this actually means’ is very helpful, at least as a sanity check. To be like, okay, so this is what they’re asking us to do, and we are doing that.”
Because Exigo used the KCD, they couldn’t use Kieri Solutions as their C3PAO due to conflict of interest requirements. Kieri maintains strict separation between consulting and assessment services. They chose Sentinel Blue, specifically because of alignment on cloud architecture.
“We wanted to find a company that got it, that understood what the technology stack we were using is, so that we wouldn’t have to explain to our assessor, ‘Well, here’s what conditional access is.'”
The assessment itself validated everything Exigo had built.
“We handed over all of our policies and procedures and everything for the pre-assessment. When it came time to do the actual assessment, there was very little to actually do because everything had been answered in the paperwork we had already given.”
Exigo Corporation achieved CMMC Level 2 certification.
When assessors had questions about specific implementations, John could make his case. When he explained why an alternative approach met the control’s intent, the assessors agreed.
“That’s how it’s supposed to work. It’s not supposed to say the assessor wants X, and if you don’t have X, you fail. You should be able to make the case: here’s why Y is a good substitute for X.”
John’s guidance comes from experience with multiple government audits, not just CMMC.
“If you can hand all of your documentation and artifacts to the assessor and they can go through and say, ‘This control is this, this control is this,’ and not ask you any questions, everybody’s going to be happy.”
John admits he went into the assessment uncertain. “Going into it, I thought, I don’t know if we’re ready for this. Every control, I was like, well, I could read this in a way that…”
But the preparation paid off. The documentation held. The certification came through.
“The community is very helpful for all this stuff. You don’t go it alone. Don’t just try to figure this out by yourself.”
Exigo Corporation started with a yes/no SSP template that wouldn’t have passed assessment. With the Kieri Compliance Documentation, they built a comprehensive body of evidence that let assessors work through controls without asking questions.
Whether you’re cloud-first like Exigo or running traditional infrastructure, the KCD provides the skeleton you need to document your specific environment.
Your company can do the same.
Schedule a consultation with Kieri Solutions to discuss your compliance journey.
How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves
How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months
How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.
How a historic preservation firm built a compliant enclave on their own terms, adapting the KRA to fit unique design workflows
How a 250-person construction company built their own compliant enclave, saved over $200,000, and passed assessment on the first try
A 39-year-old defense subcontractor with government expertise finds the documentation and consulting guidance needed to finally feel confident about assessment.
How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.
How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves
How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months
How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.
How a historic preservation firm built a compliant enclave on their own terms, adapting the KRA to fit unique design workflows
How a 250-person construction company built their own compliant enclave, saved over $200,000, and passed assessment on the first try
A 39-year-old defense subcontractor with government expertise finds the documentation and consulting guidance needed to finally feel confident about assessment.
How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.
We deliver modern CMMC solutions designed to simplify compliance, eliminate uncertainty, and protect your contract pipeline — without forcing one rigid path.
Talk with a certified CMMC assessor who can help you figure out your next step.
CMSS consulting
Know where you stand
NIST SP 800-171
Official CMMC certification
CMMC 2.0
Official CMMC certification
Our Ethical Standards
Know where you stand
Free Gap Assessment
Your compliance status