← Back to Case Studies
Case Study

Antech Systems Achieves CMMC Level 2 with a Clearer, More Defensible Compliance Program

Meet a Critical Deadline and Build Confidence in Compliance

Antech® is a small business that solves complex challenges through custom software development, engineering, and design, primarily for the U.S. Navy. The company had been managing Controlled Unclassified Information for nearly a decade when early NIST SP 800-171 requirements began changing cybersecurity expectations for defense contractors. By 2020, Antech had moved to GCC High and established a strong technical foundation.

However, as CMMC requirements evolved, Antech needed more than secure systems. The company needed confidence that its controls were correctly scoped, properly documented, and supported by the evidence assessors would expect.

Antech’s immediate goals were to:

  • Complete its CMMC Level 1 self-attestation by the end of the year
  • Achieve CMMC Level 2 certification in 2026
  • Protect its ability to pursue and retain defense contracts
  • Avoid unnecessary technology investments and operational complexity
  • Confirm that its security controls satisfied the actual requirements
  • Build an organized body of evidence that could withstand an assessment

“If you just tell me what you want, I’ll do the darn thing. But the CMMC requirements just haven’t been that clear.”

Frank Cooney, Executive Vice President of Business Services

Strong Technology, but Uncertainty About the Evidence

Before engaging Defense Cybersecurity Group, Antech had already invested significant time and resources in cybersecurity compliance.

The company had implemented GCC High, developed internal controls, and worked with a consultant during the COVID-19 pandemic to formalize parts of its documentation. Antech’s IT Director and his team also built systems they believed aligned with the intent of the requirements.

The challenge was not a lack of effort or technical capability. It was determining whether Antech’s work matched what assessors would ask the company to demonstrate.

In several areas, Antech had implemented solutions that were technically sound, but they were difficult to document and defend during an assessment.

The size of Antech’s CUI environment added to the challenge. The company received more than 70,000 CUI documents per quarter from one customer alone. Isolating CUI within a small enclave or single secure room was not practical.

Without a clear understanding of where the requirements stopped, Antech risked continuing to expand its compliance scope, documentation workload, and technology spending.

Why Antech Chose Defense Cybersecurity Group

Antech’s decision to work with DCG began with trust.

Cooney had followed DCG CEO Vincent Scott through NDIA channels, LinkedIn, and the DCG website. What distinguished Scott’s guidance was its specificity. Rather than offering general interpretations, he connected his recommendations to exact regulatory provisions that Antech could independently verify.

“Vincent references specific things, DFARS 7020, specific provisions, and you can go look them up in real time. You can trust what he’s saying because he gives you the citation.”

Rick Peters, IT Director

That credibility was especially important within a technically sophisticated organization. When employees questioned a requirement or raised concerns about its effect on their work, Cooney and Peters needed more than a consultant’s opinion. They needed an authoritative explanation supported by the regulations.

“When someone pushed back, we could say this is exactly why, and here are the references. If it wasn’t coming from an expert or trusted source, I don’t think it would have had the same effect.”

Rick Peters, IT Director

The relationship progressed after Cooney read a DCG article about documentation practices. Antech then enrolled Peters in DCG’s assessor training. Over approximately six weeks, Peters developed a much stronger understanding of how assessors interpret requirements, review evidence, and conduct interviews.

The training confirmed that DCG could provide what Antech needed: practical guidance grounded in both the regulations and the assessment process.

The DCG Approach: Focus on What Antech Needed to Prove

Antech engaged DCG and began with a Readiness Evaluation at Level 2, and DCG then guided the company through Level 2 readiness.

The central focus was the distinction between operating a cybersecurity program and proving that the program satisfies each requirement.

DCG helped Antech define the exact scope of each requirement and identify the evidence needed to support it. This prevented the company from confusing additional costly complexity with stronger compliance.

The Outcome: An Exceptionally Smooth CMMC Assessment

Before the formal assessment, Antech completed an optional readiness review with the assessor. In hindsight, Peters said he would consider that step essential.

“It felt like a mock audit, so we felt much more confident when it came time for the real thing.”

Rick Peters, IT Director

The formal assessment was scheduled across four days. After the inbrief and two days of interviews, the assessors told Antech that the planned Thursday follow-up session was unnecessary. Antech passed with a perfect 110 SPRS score and was certified at CMMC Level 2 within its required timeframe.

Immediate Business Impact

The value of the certification became clear almost immediately.

Antech received its Level 2 certification on a Friday. The following Monday, Peters was able to use it during a discussion with a Government customer.

Later that same day, Antech received a solicitation that required CMMC certification. Within one business day, the certification supported both an existing Government customer and a new business opportunity.

The Lasting Result: A More Efficient Path Forward

Antech gained more than a certification. The company developed a clearer understanding of what CMMC requires, how to scope its controls, and how to prepare evidence that assessors can evaluate efficiently.

The engagement also helped Antech avoid unnecessary spending, reduce compliance complexity, correct risks before the assessment, and establish a stronger foundation for future requirements.

“If we had talked to them sooner, we would have saved more money. That’s a fact.”

Rick Peters, IT Director

DCG continues to help Antech look beyond its initial certification. DCG has assisted with developing plans for new implementations while remaining CMMC compliant, and has begun preparing the company for future requirements, including NIST SP 800-171 Revision 3, the Secure Software Development Framework, and its CMMC reassessment in three years.

“Our assessor said we were one of the smoothest and best assessments they had ever seen. That’s a testament to DCG and how they helped us get there.”

Frank Cooney · Executive Vice President of Business Services, Antech Systems
Ready to Talk?

The First Conversation Is Free.
And It Will Tell You the Truth.

If something you read here raised a question about your specific situation, the next step is a conversation with DCG. We will tell you honestly what we see before we tell you anything about our services.

Book a Free Consultation