Around Annandale, Centreville, and Chantilly, Virginia — a corridor with one of the largest concentrations of Korean-American-owned IT staffing, systems integration, and professional services firms in the country — a specific business model has quietly powered a lot of family wealth: win a subcontract under a large defense prime or federal systems integrator, place skilled engineers or provide a service, and renew year after year on the strength of good work and a good relationship. That model still works. What has changed underneath it is that 'good work' is no longer sufficient by itself. Every prime contractor is now required to flow down cybersecurity requirements to its subcontractors, and a growing number of them are actually checking — which means a subcontractor's own IT setup, not just its people, has become part of what gets evaluated at renewal time.
What changed: CMMC is no longer a large-prime problem
The Cybersecurity Maturity Model Certification (CMMC) program exists because the DoD found, repeatedly, that sensitive information was leaking through the weakest link in a long subcontractor chain, not through the prime itself. The fix was to push the requirement down: any company handling Federal Contract Information needs baseline safeguards (CMMC Level 1, self-assessed), and any company handling Controlled Unclassified Information needs a more rigorous set of controls aligned to NIST SP 800-171 (CMMC Level 2, often requiring third-party assessment). For a small Korean-American subcontractor, the practical effect shows up quietly — a prime's annual vendor questionnaire suddenly asks for a System Security Plan you do not have, or a new task order requires an attestation your current setup cannot support. Nobody tells you the subcontract did not renew because of this. It just does not renew, and the reason sits buried in a compliance review you were never part of.
What we typically find when we look at a subcontractor's actual setup
Common gaps between what CMMC/NIST SP 800-171 requires and how a growing subcontractor is actually running today:
- No documented System Security Plan (SSP) or Plan of Action & Milestones (POA&M) — the two documents every assessment starts with, often nonexistent because nobody was ever asked for them before.
- CUI mixed with everything else — contract deliverables, emails, and general company files sitting in the same shared drive or inbox as data that actually requires controlled handling.
- No multi-factor authentication enforced company-wide, or MFA on some systems but not the ones actually touching contract data.
- Access that outlives the assignment — an engineer rotated off a contract eight months ago whose access to that contract's shared resources was never revoked.
- No real incident response plan — if a laptop is lost or a phishing email is clicked, there is no documented, rehearsed process, which is itself a specific control assessors check for.
What a CMMC-ready AWS architecture actually includes
This is not about buying a certification — no vendor, including us, sells you a CMMC certificate. What a properly designed AWS environment does is put the technical controls in place that a System Security Plan documents and a Certified Third-Party Assessor Organization (C3PAO) verifies, for Level 2 engagements that require it.
Concrete pieces of a compliance-aligned AWS setup, and the control each one supports:
- Data classification and boundary design — CUI, FCI, and unrestricted company data are identified and separated first, before any infrastructure decision, since this determines whether GovCloud is actually required or commercial AWS with proper controls is sufficient.
- AWS GovCloud (US) for CUI workloads — meets the FedRAMP Moderate-equivalent baseline and data residency requirements DFARS 252.204-7012 calls for when CUI is genuinely in scope.
- IAM with mandatory MFA and least-privilege access — every user's access is scoped to exactly what their current contract role requires, reviewed on a schedule, and revoked immediately when a role or assignment ends.
- Encryption at rest and in transit (KMS-managed keys) — a specific, checkable control under NIST SP 800-171, not a general best practice left to chance.
- CloudTrail logging and centralized monitoring — an auditable record of who accessed what and when, which is both a required control and what makes an incident response plan actually executable instead of theoretical.
- Documented System Security Plan and POA&M — the AWS architecture is only half the requirement; the written documentation describing it, kept current, is what an assessor actually reviews first.
Why this needs a partner fluent in both the compliance language and yours
CMMC and NIST SP 800-171 work is dense enough that most subcontractors reasonably bring in outside help — the question is whether that help can also explain, in Korean when needed, why a specific control matters to a business owner who did not build a career in federal compliance. A large compliance-only consultancy will hand you a control matrix and a bill; what a small Korean-American-owned firm in Annandale or Centreville often actually needs is someone who can sit down, explain in plain terms what CUI means for the specific contract you are on, and build the AWS environment and documentation together rather than handing over a report and disappearing. We treat this the same way we treat every engagement — one point of contact, in Korean or English, from the initial data-classification conversation through ongoing monitoring, reachable on KakaoTalk.
How an engagement actually runs
We start with a data-classification and gap assessment — walking through your actual contracts to determine what data you handle (FCI, CUI, or neither), then mapping your current environment against NIST SP 800-171 to identify what is already in place versus missing. From there we design the architecture around your actual scope rather than defaulting to the most expensive option, and remediate in phases: access control and MFA first, since those close the highest-risk gaps fastest and require no data migration, then encryption and logging, then GovCloud migration for CUI workloads if your classification work shows it is required, finishing with the System Security Plan and POA&M documentation an assessor will actually read. Your team keeps working throughout — this is staged remediation, not a weekend cutover. Once in place, monitoring, access review, and documentation updates continue as an ongoing service, since CMMC compliance is an annual affirmation, not a one-time project.