Hexagon US Federal Achieves Perfect Score on CMMC Level 2 Assessment Through Partnership with Summit 7 

Hexagon US Federal was determined to achieve CMMC certification, but their internal IT team was overwhelmed navigating hundreds of technical controls while maintaining daily operations. Trying to give their team relief, they selected the wrong vendor before switching to Summit 7. Without support from Summit 7, Hexagon would have missed its CMMC goals.

About Hexagon US Federal 

Industry: Defense, Intelligence, and Security 

Services: Hexagon US Federal is an independent subsidiary of Hexagon Corporation exclusively focused on bringing the broad range of Hexagon technologies to the US Federal government and its partners. They are headquartered in Chantilly, Virginia. Their core products are Geospatial software and services used to support emergency response platforms, the DoJ, and the DoW. 

Problem: Hexagon US Federal was determined to achieve CMMC certification in order to maintain eligibility for future government contracts. However, their internal IT team was overwhelmed navigating hundreds of technical controls while maintaining daily operations.  

Trying to give their team relief, they found themselves paired with the wrong vendor. Without additional support from Summit 7, Hexagon would have missed its CMMC goals. 

Learn how Hexagon US Federal leveraged Summit 7’s services to reach: 

  • Resilience from threats to them and their customers
  • Readiness for their CMMC assessment
  • A perfect score on their CMMC Level 2 Assessment
  • 24/7 MSP support through Guardian
  • Implementation of NIST and CMMC controls  

Background

When Lisa Vaughn, Executive Director of Information Technology, joined Hexagon US Federal in 2021, she hadn’t heard of CMMC despite her 30 years in IT leadership. She learned the company was pursuing an early adoption of CMMC certification. They were determined to achieve the highest level of certification, but they were starting from square one, meaning Vaughn had her work cut out for her.

Stepping into her new role, Vaughn knew the importance of protecting CUI. The said, “There are many historical events that point to this type of data [CUI] being used against the United States government. It made our country more vulnerable to things like 9/11.”

Vaughn buckled down understanding NIST 800-171 standards as well as where the company stood with them. The more she learned, the more “monumental” she saw getting CMMC certified would be.

Hexagon US Federal’s Challenges

Before partnering with Summit 7, Hexagon US Federal faced massive challenges in achieving CMMC certification due to a lack of dedicated compliance staff and underperforming vendors.

With no dedicated staff for compliance, Hexagon US Federal’s internal IT team struggled to dedicate time to navigate it. The same team carrying their day-to-day mission, manning the help desk, and making sure their internal systems run smoothly was also responsible for becoming CMMC compliant.

Having realized their internal efforts wouldn’t get them certified in the timeline they needed, they selected a vendor based primarily on cost. However, they found that the vendor didn’t have the GovCloud experience they needed.

Solution: Summit 7 Partnership

Knowing noncompliance wasn’t an option, Hexagon US Federal leaned on Summit 7’s expertise in Microsoft GCC High environments and experience with GovCloud-specific configurations.

Hexagon US Federal leveraged these Summit 7 services to get their Level 2 CMMC certification with a perfect score:

Guardian (MSP):

  • Tier 1, 2, and 3 support
  • 24/7 coverage across time zones
  • Helped manage a hybrid-remote workforce

Engineering Projects:

  • Filled technical skill gaps
  • Implemented complex CMMC controls

Gap Remediation:

  • Supported POAM items
  • Assisted during mock assessments and pre-audit readiness

Summit 7 followed through with support during the actual C3PAO assessment to answer questions and validate configurations.

Results

Hexagon earned its CMMC Level 2 Certification with a perfect 110/110 score. They’re no longer at risk of losing bids due to non-compliance. They’re also better positioned for future FedRAMP efforts.

Even during the most tumultuous parts of certification, their internal IT team was free to focus on other organizational goals, keeping their current clients happy.

Contact

Speak With Our Team

Scroll to Top