At a Glance
| Client | ITI Engineering |
| Industry | Defense and aerospace engineering |
| Challenge | Prepare for CMMC Level 2 certification without outsourcing internal cybersecurity ownership |
| What was at stake | Multi-million-dollar DoD opportunities, prime contractor relationships, customer trust, and supply chain readiness |
| Alluvionic’s role | Gap assessments, remediation guidance, mock assessment, CUI scoping, documentation support, and assessment preparation |
| Results | CMMC Level 2 certification, perfect 110/110 score |
Snapshot
ITI Engineering has spent more than 20 years supporting the warfighter through engineering, software, and secure technology solutions for defense and aerospace programs. Early in CMMC’s rollout, ITI recognized that cybersecurity readiness would be critical to protecting its future DoD work, customer trust, and role in the defense supply chain.
Rather than treating CMMC as a last-minute compliance exercise, ITI took a deliberate, multi-year approach to readiness. With a lean internal IT and security team supporting their 100+ person organization, they sought expert, independent guidance to validate their interpretations, align with assessor expectations, and ensure defensible compliance across all 110 required controls.
Through five engagements with Alluvionic spanning gap assessment, remediation, and mock validation, ITI improved their SPRS score by nearly 40 points, ultimately achieving a perfect 110/110 score and CMMC Level 2 certification in March 2026.
“ITI Engineering’s CMMC Level 2 certification and perfect 110/110 score reflect years of intentional preparation, leadership commitment, and disciplined execution.” – Bobby Padilla, Director of Information Security at Alluvionic
The Stakes: Protecting Trust, Contracts, and Mission-Critical Work
With multi-million-dollar backlogs of DoD work and strong relationships with major defense partners, ITI knew CMMC was not only a compliance framework. It would soon become a barrier to entry for many defense opportunities.
ITI plays an important role in the defense supply chain. The company provides engineering, software, and secure technology solutions that support mission-critical aerospace and defense programs. Its customers depend on ITI to deliver quality work, protect sensitive information, and meet strict requirements on time.
ITI also supports major government contractors, including L3Harris, Boeing, and Lockheed Martin. As CMMC requirements moved closer to enforcement, ITI understood that many prime contractors would pass CMMC Level 2 requirements down to suppliers.
Because ITI supports warfighter technology, the team saw CMMC as more than a compliance checkbox. It was part of protecting mission data, customer trust, and the secure flow of information across the defense supply chain.
ITI needed to make sure its cybersecurity practices, documentation, and evidence were ready for review so the company could continue supporting key defense partners with confidence.
The Starting Point: A Capable Team That Needed the Right Guide
ITI formally began its CMMC journey in the summer of 2020 by assessing its Level 1 readiness. The goal was to master the essentials first while also laying the groundwork for future Level 2 certification.
From the beginning, ITI took a disciplined approach. The company had an internal team capable of owning the work, and they wanted to build long-term cybersecurity maturity inside the organization. They were not looking for a vendor to take over. They needed a trusted partner to help assess, guide, challenge, and support their team.
“What stood out most was their ability to address gaps and deficiencies themselves, with leadership providing the time, investment, and support the team needed to succeed.” – Bobby Padilla, Director of Information Security at Alluvionic
ITI had the internal knowledge and commitment to succeed, but CMMC required a clear understanding of how controls, documentation, evidence, and assessor expectations all fit together.
Why ITI Chose Alluvionic
Like ITI, Alluvionic has a strong reputation in the Central Florida business community with work that extends nationwide. The partnership worked well because both companies viewed CMMC as more than a requirement for future bids. They saw it as part of their responsibility to help protect sensitive defense information and support national security.
ITI also knew Alluvionic was one of the early Registered Practitioner Organizations in the CMMC ecosystem. Alluvionic was preparing for its own CMMC Level 2 certification at the same time, and ultimately achieved certification in March 2025.
Alluvionic also offered the flexibility ITI needed. ITI did not need a one-size-fits-all package or a software-only solution. They needed expert support that complemented their internal team.
Alluvionic served as a trusted reviewer, facilitator, and guide, helping ITI’s qualified staff strengthen readiness, close gaps, and build confidence before assessment.
How Alluvionic Helped
Alluvionic supported ITI through a structured, multi-year readiness journey. The work included:
- CMMC Level 1 readiness assessment
- CMMC Level 1 remediation support
- CMMC Level 2 gap analysis
- Review of all 110 CMMC Level 2 controls
- Mock assessment preparation and facilitation
- CUI scoping support
- Asset inventory development
- Authorized personnel directory development
- System Security Plan updates
- Plans of Action and Milestones development
- Readiness dashboard creation
- Ongoing support during final assessment preparation
This approach gave ITI a clear view of where they stood, what still needed attention, and how to move forward with confidence.
A Methodical Path to CMMC Level 2
ITI did not treat CMMC as a last-minute project. The company moved through a steady, phased journey from Level 1 readiness to full Level 2 certification.
- July 2020: Level 1 gap analysis found 95% readiness
- November 2020: Level 1 remediation achieved 100% compliance
- April 2022: Level 2 gap analysis found 80% readiness
- October 2024: Level 2 mock assessment found 90% readiness
- March 2026: Level 2 C3PAO assessment confirmed 100% compliance
This timeline shows the value of starting early. ITI steadily improved its cybersecurity posture instead of waiting until contract pressure made readiness urgent.
The Turning Point: From Preparation to Assessment Confidence
By late 2024, CMMC momentum was increasing. The final rule was approaching, and C3PAOs were preparing to begin formal third-party assessments. ITI decided it was time for one final readiness step before certification: a mock assessment with Alluvionic.
Because ITI had been preparing for years, the company was not starting from scratch. They had already made major progress. The mock assessment helped confirm where they stood, identify remaining gaps, and give the team a clear path for final preparation.
“After putting in the work to close gaps, ITI made the smart decision to complete a mock assessment before the formal C3PAO assessment, giving them the opportunity to reassess readiness, validate evidence, and enter the certification process with confidence.” – Bobby Padilla, Director of Information Security at Alluvionic
During the mock assessment, Alluvionic conducted interviews to evaluate compliance details across all 110 CMMC Level 2 controls. Findings were summarized in a visual dashboard that gave ITI a practical view of its readiness.
Alluvionic also supported a Controlled Unclassified Information, or CUI, scoping exercise to help clarify what needed to be protected. The team developed an asset inventory, an authorized personnel directory, an updated System Security Plan, and clear Plans of Action and Milestones.
ITI completed the mock assessment ahead of schedule. The results showed a significant increase in readiness compared to the previous gap analysis, moving from 80% implementation to 90% readiness.
With only the final gaps left to close, ITI continued working toward certification while Alluvionic remained available for questions, guidance, and final assessment preparation.
In March 2026, years of steady work paid off. What had once been a long, challenging journey became a moment of celebration. After more than five years of progress, a dedicated internal team, and trusted consulting support from Alluvionic, ITI achieved its goal: CMMC Level 2 certification.
Results and Business Impact
ITI’s methodical approach produced clear, measurable results:
- Achieved CMMC Level 2 certification in March 2026
- Earned a perfect 110/110 score
- Improved its SPRS score from 71 to 110
- Completed 100% of CMMC readiness efforts on time with Alluvionic’s partnership
- Strengthened readiness for prime contractor and DoD cybersecurity expectations
- Protected its ability to pursue and support multi-million-dollar defense opportunities
At the time, ITI was among the ~1% of defense contractors to achieve CMMC Level 2 certification through a C3PAO, placing the company ahead of many organizations still preparing for assessment.
What Other Contractors Can Learn
ITI Engineering’s journey offers clear lessons for other small and mid-sized defense contractors.
Start before the deadline feels urgent.
CMMC takes time. Companies need to clarify scope, close gaps, prepare evidence, and make sure their practices match their documentation. Waiting until requirements appear in contracts can create unnecessary risk.
Use a gap analysis to get grounded.
A CMMC Level 2 gap analysis helps leaders understand what is working, what is missing, and where to focus first. It gives the organization a practical starting point instead of relying on assumptions.
Do not assume tools equal readiness.
Software can help, but CMMC readiness also requires clear processes, accurate documentation, organized evidence, and people who understand their roles.
Choose a partner that fits your team.
ITI did not need Alluvionic to replace its internal staff. They needed a trusted expert to guide, validate, and strengthen the team’s work. The right partner should meet the organization where it is and provide the level of support it actually needs.
“Alluvionic’s firsthand experience with CMMC Level 2 certification gave us confidence that we were receiving practical, proven guidance. They worked alongside our team to create an approach that was realistic, effective, and sustainable—helping us successfully achieve our own CMMC Level 2 certification.” – Caity Ayers, Quality Director at ITI Engineering
Celebrate progress, but keep improving.
Every improvement in an SPRS score, every closed gap, and every completed milestone brings a company closer to certification. But certification is not the finish line. CMMC is a maturity model, which means organizations must continue maintaining and improving their cybersecurity practices after certification.
The Bottom Line
For ITI, CMMC Level 2 certification was not just about passing an assessment. It was about protecting customer trust, strengthening its role in the defense supply chain, and continuing to support mission-critical work with confidence.
By starting early, staying disciplined, and partnering with Alluvionic for the right level of expert support, ITI turned a complex certification journey into a clear, methodical path forward.
Ready to Prepare for CMMC Level 2?
Preparing for CMMC Level 2 does not have to mean starting from scratch or handing off your entire cybersecurity program. Alluvionic helps defense contractors assess their readiness, close gaps, prepare evidence, and move toward certification with confidence.
Schedule a CMMC Level 2 readiness consultation with Alluvionic.



