We Run Compliance Programs for Defense Contractors

Protect Your Revenue.
Secure Your Contracts.

TRANUSA runs CMMC Level 2 compliance programs for Defense Industrial Base contractors. Your customer is not asking which tools you installed. It is asking for a score. We define the boundary, produce the evidence, and operate the program that keeps it defensible — all 110 NIST SP 800-171 controls, DFARS 252.204-7012 and ITAR/EAR.

110
Controls Implemented and Evidenced
SPRS
A Posted Score Is the Deliverable
DIB
Focused Expertise
CMMC Level 2 compliance architecture Seven NIST SP 800-171 control domains — access control, audit and accountability, incident response, system and communications protection, configuration management, identification and authentication, and risk assessment — connected to a central CUI boundary, above a strip of covered frameworks. CMMC L2 110 CONTROLS ACCESS CONTROL AC — 22 Controls AUDIT & ACCT AU — 9 Controls INCIDENT RESP IR — 3 Controls SYSTEM & COMMS SC — 16 Controls CONFIG MGMT CM — 9 Controls IDENT & AUTH IA — 11 Controls RISK ASSESSMENT RA — 5 Controls // COMPLIANCE FRAMEWORKS COVERED NIST SP 800-171CMMC L2DFARS 7012ITAR/EARMS GCC HIGHZERO TRUST

CMMC Level 2 compliance is a condition of your DoD contracts.

CMMC Level 2 requires Defense Industrial Base contractors to implement all 110 practices from NIST SP 800-171. In July 2026 the Department of Defense suspended the move to later CMMC phases pending a program review — but DFARS 252.204-7012 and NIST SP 800-171 remain contractually binding, and self-assessment obligations remain in force. The certification mechanism is under review. The standard is not. TRANUSA closes the gap either way.

Get Your Gap Assessment
Access Control (AC)
Audit & Accountability (AU)
Configuration Mgmt (CM)
Identification & Auth (IA)
Incident Response (IR)
Maintenance (MA)
Media Protection (MP)
Personnel Security (PS)
Physical Protection (PE)
Risk Assessment (RA)
Security Assessment (CA)
System & Comms (SC)
System Integrity (SI)
Awareness & Training (AT)

Your CMMC Level 2 Program
Established, Built, Operated.

Compliance is not a product you install. It is a state that decays — evidence has to be produced continuously, and someone has to be accountable for producing it. TRANUSA runs that program end to end for Defense Industrial Base contractors. Each phase is separately authorized, so you can stop between any of them.

01 // ESTABLISH
Scoping & the Boundary

Where the assessment boundary sits determines everything that follows — cost, timeline, and whether the position survives scrutiny. This phase produces a documented boundary and a score you own, whoever you continue with.

  • CUI Scoping & Data Flow Mapping
  • Asset & Device Inventory
  • Enclave Boundary Definition & Architecture
  • NIST SP 800-171 Self-Assessment
  • SPRS Score Calculation & Submission
02 // BUILD
Remediation & Evidence

Closing the gap against all 110 NIST SP 800-171 practices, and — just as important — producing the documentation and evidence that proves each one. An implemented control with no evidence behind it does not score.

  • GCC High Enclave Build & Identity
  • Security Control Implementation
  • System Security Plan — All 110 Practices
  • Plan of Action & Milestones (POA&M)
  • Policies, Procedures & Evidence Framework
03 // OPERATE
Running the Program

Compliance decays the day you stop maintaining it. Configurations drift, people join and leave, evidence goes stale. This is the part that keeps a position defensible between assessments — and the part most providers do not do.

  • SSP Kept Current, POA&M Actively Managed
  • Continuous Evidence Collection
  • Monthly Change Advisory Board & Reporting
  • Continuous Monitoring with 24/7 Escalation
  • C3PAO Audit Support & Evidence Packages
NIST SP 800-171
CMMC Level 2
DFARS 252.204-7012
ITAR / EAR
Microsoft 365 GCC High
U.S. Persons Only Operations
Registered Practitioners

The Score Is the Deliverable.

Compliance is not a product you install. It is a state that decays. Configurations drift, people join and leave, evidence goes stale, and the position that passed last year quietly stops being defensible. Someone has to be accountable for producing evidence continuously — and for most small and mid-sized defense suppliers, nobody is.

That is the job TRANUSA does. We define the assessment boundary, close the gap against all 110 NIST SP 800-171 practices, produce the documentation that proves each one, and then operate the program that keeps it true between assessments. The security platform sits underneath as the mechanism, not as the product.

Tony Tran, Founder and CTO of TRANUSA, LLC
Tony Tran
Founder & CTO · TRANUSA, LLC
MBA  ·  MS, Information Technology
Teaches cybersecurity and information assurance at community colleges and universities
"I spent the better part of twenty years in the shops that build these parts. I have been the person on the other side of the requirement."

Before TRANUSA, I spent close to twenty years in manufacturing — industrial single-board computers, large-format fine-pitch LED displays, and the aerospace machine shops and CNC operations that build parts for the U.S. military. I know what a shop floor runs on, what a schedule costs, and what happens when a control gets in the way of production.

In 2025 I moved TRANUSA fully into compliance for the Defense Industrial Base, for one reason. I kept watching small and mid-sized manufacturers get buried under CMMC and NIST SP 800-171 requirements they had no staff to absorb — while depending on DoD work for a large share of their revenue. The requirement was not the problem. Having nobody whose job it was to carry it was the problem.

So we carry it, and we hold ourselves to the same standard. TRANUSA brought its own environment into NIST SP 800-171 compliance, operates its own Microsoft 365 GCC High tenant, and runs its stack in U.S. sovereign cloud with a U.S. Persons-only team. Every control we ask a client to implement, we have implemented ourselves first.

I also hold an MBA and a master’s in information technology, and I teach cybersecurity and information assurance at community colleges and universities. That is not decoration on a bio. Explaining this material to people who have never seen it before is most of what this job actually is — the hard part of compliance is rarely the technology, it is getting a room full of people to understand why the requirement exists and then keep following it after we leave.

That is also why the tooling is not the pitch. A stack is a week of procurement. A compliance program that survives an assessor, and keeps surviving one, is something else entirely — and it is the only thing your customer is actually asking you for.

Book a CMMC Readiness Call

Thirty minutes. We review your contract requirements, identify your top compliance gaps, and give you a realistic timeline to audit readiness. No pitch decks, no obligation.

Book Your Call →
or email CMMC@tranusa.com