We Run Compliance Programs for Defense Contractors

Protect Your Revenue.
Secure Your Contracts.

TRANUSA runs CMMC Level 2 compliance programs for Defense Industrial Base contractors. Your customer is not asking which tools you installed. It is asking for a score. We define the boundary, produce the evidence, and operate the program that keeps it defensible: all 110 NIST SP 800-171 controls, DFARS 252.204-7012 and ITAR/EAR.

110
Controls Implemented and Evidenced
SPRS
A Posted Score Is the Deliverable
DIB
Focused Expertise
CMMC Level 2 compliance architecture Seven NIST SP 800-171 control domains: access control, audit and accountability, incident response, system and communications protection, configuration management, identification and authentication, and risk assessment, connected to a central CUI boundary, above a strip of covered frameworks. CMMC L2 110 CONTROLS ACCESS CONTROL AC · 22 Controls AUDIT & ACCT AU · 9 Controls INCIDENT RESP IR · 3 Controls SYSTEM & COMMS SC · 16 Controls CONFIG MGMT CM · 9 Controls IDENT & AUTH IA · 11 Controls RISK ASSESSMENT RA · 5 Controls // COMPLIANCE FRAMEWORKS COVERED NIST SP 800-171CMMC L2DFARS 7012ITAR/EARMS GCC HIGHZERO TRUST

CMMC Level 2 compliance is a condition of your DoD contracts.

CMMC Level 2 requires Defense Industrial Base contractors to implement all 110 practices from NIST SP 800-171. In July 2026 the Department of Defense suspended the move to later CMMC phases pending a program review, but DFARS 252.204-7012 and NIST SP 800-171 remain contractually binding, and self-assessment obligations remain in force. The certification mechanism is under review. The standard is not. TRANUSA closes the gap either way.

Get Your Gap Assessment
Access Control (AC)
Audit & Accountability (AU)
Configuration Mgmt (CM)
Identification & Auth (IA)
Incident Response (IR)
Maintenance (MA)
Media Protection (MP)
Personnel Security (PS)
Physical Protection (PE)
Risk Assessment (RA)
Security Assessment (CA)
System & Comms (SC)
System Integrity (SI)
Awareness & Training (AT)

Your CMMC Level 2 Program
Established, Built, Operated.

Compliance is not a product you install. It is a state that decays. Evidence has to be produced continuously, and someone has to be accountable for producing it. TRANUSA runs that program end to end for Defense Industrial Base contractors. Each phase is separately authorized, so you can stop between any of them.

01 // ESTABLISH
Scoping & the Boundary

Where the assessment boundary sits determines everything that follows: cost, timeline, and whether the position survives scrutiny. This phase produces a documented boundary and a score you own, whoever you continue with.

  • CUI Scoping & Data Flow Mapping
  • Asset & Device Inventory
  • Enclave Boundary Definition & Architecture
  • NIST SP 800-171 Self-Assessment
  • SPRS Score Calculation & Submission
02 // BUILD
Remediation & Evidence

Closing the gap against all 110 NIST SP 800-171 practices, and, just as important, producing the documentation and evidence that proves each one. An implemented control with no evidence behind it does not score.

  • GCC High Enclave Build & Identity
  • Security Control Implementation
  • System Security Plan: All 110 Practices
  • Plan of Action & Milestones (POA&M)
  • Policies, Procedures & Evidence Framework
03 // OPERATE
Running the Program

Compliance decays the day you stop maintaining it. Configurations drift, people join and leave, evidence goes stale. This is the part that keeps a position defensible between assessments, and the part most providers do not do.

  • SSP Kept Current, POA&M Actively Managed
  • Continuous Evidence Collection
  • Monthly Change Advisory Board & Reporting
  • Continuous Monitoring with 24/7 Escalation
  • C3PAO Audit Support & Evidence Packages

Your Compliance Posture Is a
Valuation Input

Most owners think about CMMC as the cost of keeping a contract. It is also a line item on the day somebody looks hard at the company, and that is a different audience asking a different question.

Our founder has spent years performing technology due diligence on acquisitions, which means reading the documentation of companies that were about to be bought. Diligence is the one moment when somebody with money at stake stops taking your word for it. What turns up is consistent enough to list:

  • No documented assessment boundary, so nobody can say what was ever in scope
  • A System Security Plan describing a system that has since changed
  • An evidence locker that is a folder of undated screenshots
  • A submitted SPRS score nobody can reconstruct the arithmetic for
  • An enclave that exactly one administrator understands

None of that usually kills a transaction. What it does instead is quieter. It becomes a price adjustment, or an amount held back in escrow, or a representation the seller is asked to stand behind personally, or a delay while the work gets done properly at the seller’s cost with a buyer watching. The same findings surface when a prime audits a supplier, when an insurer underwrites a cyber policy, and when a new customer asks for a score before releasing controlled material.

The diligence test and the assessment test are nearly the same test.

Both ask two questions. Can you show me, and can you show me that it has been true for a while. A program built to answer an assessor answers a buyer at the same time, because the evidence and the history are the answer in both cases.

That is the argument for operating a program rather than completing a project, and it holds whether or not you ever sell anything. A documented boundary, a current SSP, an evidence locker with dates and history behind it, and a transition path that works: all of it in your name, all of it yours to hand to whoever asks. It is worth something to your customer today and worth something to a buyer later, and it is the same work either way.

NIST SP 800-171
CMMC Level 2
DFARS 252.204-7012
ITAR / EAR
Microsoft 365 GCC High
U.S. Persons Only Operations
Registered Practitioners

The Score Is the Deliverable.

Compliance is not a product you install. It is a state that decays. Configurations drift, people join and leave, evidence goes stale, and the position that passed last year quietly stops being defensible. Someone has to be accountable for producing evidence continuously, and for most small and mid-sized defense suppliers, nobody is.

That is the job TRANUSA does. We define the assessment boundary, close the gap against all 110 NIST SP 800-171 practices, produce the documentation that proves each one, and then operate the program that keeps it true between assessments. The security platform sits underneath as the mechanism, not as the product.

Tony Tran, Founder and CTO of TRANUSA, LLC
Tony Tran
Founder & CTO · TRANUSA, LLC
MBA  ·  MS, Information Technology
Technology due diligence across dozens of acquisitions
Teaches cybersecurity and information assurance at community colleges and universities
"I have been the shop carrying the requirement. I have also been the one doing the diligence that finds it missing."

Before TRANUSA, I spent close to twenty years in manufacturing: industrial single-board computers, large-format fine-pitch LED displays, and the aerospace machine shops and CNC operations that build parts for the U.S. military. I know what a shop floor runs on, what a schedule costs, and what happens when a control gets in the way of production.

I have also spent years on the other side of the table, performing technology due diligence on acquisitions. Dozens of them. That work is where you learn what a compliance program is actually worth, because diligence is the one moment when somebody with money at stake reads the documentation instead of taking your word for it. I have opened a System Security Plan that described a system that no longer existed. I have been handed an evidence locker that was a folder of screenshots with no dates on them. Nobody set out to mislead anyone. The program had simply been treated as a project that ended.

In 2025 I moved TRANUSA fully into compliance for the Defense Industrial Base, for one reason. I kept watching small and mid-sized manufacturers get buried under CMMC and NIST SP 800-171 requirements they had no staff to absorb, while depending on DoD work for a large share of their revenue. The requirement was not the problem. Having nobody whose job it was to carry it was the problem.

So we carry it, and we hold ourselves to the same standard. TRANUSA brought its own environment into NIST SP 800-171 compliance, operates its own Microsoft 365 GCC High tenant, and runs its stack in U.S. sovereign cloud with a U.S. Persons-only team. Every control we ask a client to implement, we have implemented ourselves first.

I also hold an MBA and a Master’s in Information Technology, and I teach cybersecurity and information assurance at community colleges and universities. That is not decoration on a bio. Explaining this material to people who have never seen it before is most of what this job actually is. The hard part of compliance is rarely the technology. It is getting a room full of people to understand why the requirement exists, and then keep following it after we leave.

That is also why the tooling is not the pitch. A stack is a week of procurement. A compliance program that survives an assessor, and keeps surviving one, is something else entirely, and it is the only thing your customer is actually asking you for.

Book a CMMC Readiness Call

Thirty minutes. We review your contract requirements, identify your top compliance gaps, and give you a realistic timeline to audit readiness. No pitch decks, no obligation.

Book Your Call →
or email CMMC@tranusa.com