How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves
Applied solution
Kieri Compliance Documentation
Consulting Support
Roger Curtis had been watching CMMC since 2019.
As Director of Technology and Compliance at Masser Technologies, he had a front-row seat to the regulation’s evolution. The El Paso, Texas-based company occupies a unique position in the defense industrial base. They’re both an MSSP providing managed security services and an OSC holding contracts with the Department of the Army.
That dual role meant Curtis needed to solve two problems at once. Get his own company certified. Then help his clients do the same.
“We started our CMMC journey by first becoming a federal contractor in 2019, seeing the 7012 clause in our contracts, and then hearing about CMMC coming down the pike,” Curtis explains. “The contract requirement is what kept us focused on this area.”
CMMC kept changing along the way. Requirements shifted. Assumptions got challenged. What seemed certain one month became uncertain the next. Through it all, Curtis kept watching, learning, and preparing.
When the time came to move from preparation to implementation, he knew exactly what he needed.
Masser Technologies had already started their compliance journey through a peer group focused on NIST 800-171 documentation. It was a good place to get their feet wet.
But documentation was only part of the puzzle.
“We learned about proper scoping and the enclave option,” Curtis recalls. “But, we were not sure how to properly implement a CMMC-compliant enclave and fully document it.”
Configuration and documentation needed to work together. Most solutions handled one or the other. Few handled both.
Eventually, one name kept coming up.
“I learned about Kieri from attending CMMC-focused webinars and following CMMC thought leaders on LinkedIn.”
The timing aligned perfectly. Kieri had just released documentation for GCC environments. That was exactly the route Masser Technologies was taking.
Curtis had watched Amira’s videos and seen her speak at conferences.
“Amira’s YouTube videos talking about CMMC topics came from the angle of the challenges DIB contractors face implementing a compliance program and creating the necessary documentation needed to show how the program has been set up and the processes that are being followed.”
What sealed the decision was the holistic approach.
“It wasn’t just here’s some templates and run with it,” Curtis explains. “It was templates, but it also pointed to configurations and configuration settings were provided as well. So it was the whole package.”
Templates alone weren’t enough. Configuration guidance alone wasn’t enough. Masser Technologies needed both working together.
The KCD and KRA delivered exactly that.
Need documentation and configuration guidance that work together? Explore the KCD and KRA
Masser Technologies purchased the KCD and KRA in July 2024. Their challenge was adapting the documentation to their unique MSSP situation. In fact, the KCD is designed for an OSC doing everything themselves.
The challenge wasn’t understanding what needed to be done. The KCD made that clear. The challenge was adapting it to their unique situation.
The KCD is designed for an OSC doing everything themselves. SharePoint for ticketing. SharePoint for asset inventory. SharePoint for tracking maintenance tasks.
Masser Technologies already had their own tools. A ticketing system. Asset management platforms. MSSP infrastructure serving multiple clients.
“As an MSSP we already have tools we use for several of the aspects that the KCD provides a solution for, such as incident ticketing, asset database. These were areas where we modified the KCD documentation to reflect how we do business and provide support to our customers,” Curtis explains.
The substance stayed the same. The locations changed. Every requirement still got addressed. The evidence still got generated. It just lived in different places.
Curtis made a strategic choice early. Rather than build a pure Microsoft-only environment, he brought their existing MSSP tools into the enclave.
“My thought was maintaining scalability that MSSP rely on, tools that can be deployed with similar settings and policies, rather than recreating the wheel for DIB contractor environments,” he explains.
That meant service desk staff could work the same way across commercial clients, GCC clients, and federal customers. One set of processes. One set of tools. Consistency across the board.
The tradeoff was additional complexity. Pure Microsoft would have been simpler. But Curtis was thinking long-term.
“We gained clarity with the CMMC final rule regarding what MSP tools required FedRAMP Moderate authorization. With the clarity came changes to our plan, our assumptions. We no longer needed a separate FedRAMP version of a tool or platform and documentation references also changed.”
“You got to go back and tweak documentation multiple times from start to finish.”
The KCD’s structure made those tweaks manageable. Everything connected. Change one reference, and the system stayed coherent.
Working through the documentation, Curtis had a realization.
“We didn’t know all of the things we didn’t know until we saw a complete set of documentation from start to finish. Everything was there—we only needed to make minor changes to line up with how we do things.”
The KCD showed the complete picture. Not just what policies to write. Not just what configurations to implement. The whole system. How policies connected to procedures. How procedures connected to evidence. How evidence proved compliance.
Without that complete picture, gaps would have been invisible until assessment day.
Masser Technologies reached out to C3PAOs at the start of 2025. They had a specific requirement. They needed an assessor who understood MSSPs.
“There are now over 100 C3PAOs in the ecosystem, but many of them are just big assessment organizations that don’t know the specifics of how MSSPs operate and provide services to their customers,” Curtis explains. “They will just go down the list of assessment objectives not understanding that an MSSP is meeting a particular objective.”
They needed someone who understood how an MSSP providing services to an OSC works differently than a company doing everything internally.
After evaluating options, they chose KLC Consulting. Kyle and his team understood the MSSP model.
The assessment came in May 2025. In the end, they finished with time to spare.
Curtis had spent months training his team. Service desk. Networking. Audit log reviewers. Everyone needed to know where to find answers and how to demonstrate compliance.
“During our assessment there was a day that was mostly me answering the assessor’s questions. That is when it became clear that I had not prepared myself to the same level as I was asking my team to be at. I had to answer the assessor with, ‘I’ll get back to you on that.'”
Thankfully, everything was fixable.
“At the end of the assessment day the C3PAO assessors will hold a ‘hot wash’ where they cover anything that was missing for the day. This was where we had the list of any objectives or specific evidence that was still missing. That was our homework that we had to address to keep our assessment on track.”
By the end of the assessment, nothing major remained. A few t’s to cross. A few i’s to dot. Within one or two days of the 10-day window, everything was done.
“Even after my own preparation shortcomings the end result was passing with 110—flying colors! Documentation was the shining part that made it all possible.”
Masser Technologies achieved CMMC Level 2 certification in May 2025.
The assessment covered both their OSC side and parts of their MSSP operations. The enclave they built using the KRA passed scrutiny. The documentation they adapted from the KCD held up under examination.
By the Numbers
| Metric | Result |
|---|---|
| CMMC Level | Level 2 Certified |
| Timeline | ~10 months (July 2024 to May 2025) |
| Implementation Model | DIY with check-in calls |
| Environment | Microsoft 365 GCC with MSSP tools |
| C3PAO | KLC Consulting |
| Assessment Duration | Completed with time to spare |
Certification was the first hurdle. Maintaining compliance is the marathon.
“Once the assessment has been completed, the real work begins, the continuous maintenance tasks that prove a mature cybersecurity program exists.”
The tickets are there. The recurring tasks are scheduled. The cadence is established. But people have day jobs. Priorities compete.
“Nobody wants to consider 3 years down the road at reassessment time the assessor asks for evidence of 36 routine monthly task tickets and we can only show 32.”
Personnel changes add another layer. Someone who handled audit log reviews during the assessment has already moved to a different role. Now Curtis is training their replacement.
“Compliance upkeep is the challenge—personnel turnover and training the replacement to complete the same routine tasks. Nothing can stop those compliance tasks.”
Curtis has a clear message for companies just starting their compliance journey.
“If you are coming into compliance or CMMC with all of the nuanced requirements, having documentation that’s already geared toward the compliance framework is a game changer. It gets the organization started more quickly.”
Without a complete documentation set, the blank page is paralyzing.
“Receiving blank, disjointed generic documents leaves you struggling to find what those documents need to say, how much detail to include.”
Everything connects. Policies reference procedures. Procedures reference evidence. Evidence proves you did what you said. Getting those connections right from the start matters.
“Having a complete package, which the KCD and the KRA together are, really fills in the gaps and keeps you on the right path.”
— Roger Curtis, Masser Technologies
Curtis completed his assessment right before the CMMC Phase 2 pause was announced.
“We have cleared the hurdle, the time crunch, the scheduling backlog,” Curtis says. “Now we can look forward to competing for new contracts and supporting current and future federal contracts without the distraction.”
When requirements clarify and assessments resume, scheduling will tighten. Companies that waited will compete for limited C3PAO availability. Masser Technologies will already be certified and focused on maintenance.
“MSSPs that have already achieved this milestone are head and shoulders above their competition. No need to get back in the C3PAO ‘line’.”
When Curtis talks to potential clients, the question usually comes down to price. But he frames it differently now.
“Your time is already short, you are way behind the power curve. Kieri documentation will help jumpstart your organization’s CMMC journey.”
The KCD provides documentation. The KRA provides configuration guidance. Together, they provide a complete starting point.
“If you haven’t started, this is going to definitely get you going much more quickly than if you’re just jumping in yourself and trying to figure it out, especially this late in the game.”
— Roger Curtis, Masser Technologies
And the value extends beyond just OSCs.
“The KCD and the KRA, the combination works well for both somebody who is an MSP providing compliance services or consulting, or if you’re an OSC walking in and you’re going, well, how do I do this myself? It fits across the board.”
As for the investment?
“I don’t feel like the price was a showstopper. It was a good price for what you’re getting, and it definitely gets you ready to go out and find your C3PAO of choice much more quickly.”
— Roger Curtis, Masser Technologies
Masser Technologies spent years watching CMMC evolve. When implementation time came, the KCD and KRA gave them the complete picture they needed. Documentation that connected. Configurations that worked. A path from start to certification.
Whether you’re an MSSP, an OSC, or both, the KCD and KRA provide the foundation for a successful compliance program.
Get started with the Kieri Compliance Documentation or schedule a consultation to discuss your compliance journey.
Kieri Solutions is one of few authorized C3PAOs in the United States. Our team trains CMMC assessors and maintains strict separation between consulting and assessment services.
How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves
How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months
How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.
How a historic preservation firm built a compliant enclave on their own terms, adapting the KRA to fit unique design workflows
How a 250-person construction company built their own compliant enclave, saved over $200,000, and passed assessment on the first try
A 39-year-old defense subcontractor with government expertise finds the documentation and consulting guidance needed to finally feel confident about assessment.
How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.
How a dual-role company adapted the KCD and KRA to fit their unique position serving defense contractors while being one themselves
How a small defense contractor split the work between technical and documentation teams, then finished their final push in three months
How a Fort Worth technology consulting firm built a custom enclave, partnered with their MSP, and passed assessment on the first try.
How a historic preservation firm built a compliant enclave on their own terms, adapting the KRA to fit unique design workflows
How a 250-person construction company built their own compliant enclave, saved over $200,000, and passed assessment on the first try
A 39-year-old defense subcontractor with government expertise finds the documentation and consulting guidance needed to finally feel confident about assessment.
How a Space Force contractor used the KCD to transform “yes/no” documentation into assessment-ready evidence.
We deliver modern CMMC solutions designed to simplify compliance, eliminate uncertainty, and protect your contract pipeline — without forcing one rigid path.
Talk with a certified CMMC assessor who can help you figure out your next step.
CMSS consulting
Know where you stand
NIST SP 800-171
Official CMMC certification
CMMC 2.0
Official CMMC certification
Our Ethical Standards
Know where you stand
Free Gap Assessment
Your compliance status