Case Study

State Regulatory Agency Achieves CMMC Level 2 Certification

A state regulatory agency with 150 staff modernized legacy systems, implemented all 110 NIST 800-171 controls, and achieved CMMC Level 2 certification with Katalyst managed security, compliance, and infrastructure services.

Government & RegulatoryComplianceManaged Security & MDRManaged Infrastructure
Level 2
CMMC certification
100%
NIST 800-171 controls
85%
legacy modernization
Established
incident response

The Challenge

Our client is a North Carolina state regulatory agency responsible for environmental oversight and natural resource protection. With 150 staff across a headquarters in Raleigh and six regional offices, the agency manages environmental permitting, compliance monitoring, and enforcement for thousands of regulated facilities statewide. The agency handles Controlled Unclassified Information related to federal environmental programs administered on behalf of the EPA, making CMMC compliance a contractual requirement for continued federal partnership.

When the agency underwent a CMMC readiness assessment, the results were sobering. Of the 110 security practices required for CMMC Level 2, the agency met fewer than 40. The gaps were systemic. Legacy systems, some running operating systems that had been end-of-life for years, formed the backbone of critical workflows. The permitting database ran on a Windows Server 2012 instance that could not be patched, and field inspectors used aging laptops with local data stores that were never backed up and rarely updated.

The agency had no formal incident response plan. When a phishing attack compromised two employee accounts six months earlier, the response was ad hoc, the IT team disabled the accounts and changed passwords, but conducted no investigation into what data may have been accessed. No lessons were documented and no report was filed. Leadership acknowledged that if the same attack targeted CUI, the lack of response capability could jeopardize the federal partnership.

Network security was minimal. All offices shared a flat network with no segmentation between user workstations, servers, and guest Wi-Fi. Remote access for field inspectors relied on a legacy VPN with no multi-factor authentication. There was no centralized logging, no SIEM, and no security monitoring of any kind. The IT team of four was stretched thin managing day-to-day operations and had neither the bandwidth nor the specialized expertise to tackle a compliance program of this scope.

The Solution

Katalyst partnered with the agency's IT leadership to design and execute a comprehensive CMMC compliance and infrastructure modernization program. The engagement combined our Compliance services for NIST 800-171 implementation, Managed Security & MDR for continuous monitoring, and Managed Infrastructure for legacy system modernization.

NIST 800-171 implementation

Katalyst's compliance team conducted a detailed assessment of all 110 NIST 800-171 security requirements, mapping each to the agency's current state and developing a remediation plan organized into three priority tiers. We worked alongside the agency's IT team and leadership to implement every required control.

Access control policies were overhauled with role-based access, multi-factor authentication, and least-privilege principles applied across all systems. Audit and accountability controls were established with centralized logging, tamper-evident audit trails, and automated alerting for security-relevant events. Configuration management baselines were defined for all system types, with automated compliance checking to detect drift. Media protection, physical security, and personnel security controls were documented and implemented in coordination with the agency's HR and facilities teams. Each control implementation was documented in a System Security Plan and supported by evidence artifacts organized for assessor review.

Legacy infrastructure modernization

Under Managed Infrastructure, Katalyst modernized 85% of the agency's legacy systems. The permitting database was migrated from the unsupported Windows Server 2012 instance to a modern, fully patched environment with automated backup and high availability. Field inspector laptops were replaced with managed devices enrolled in Katalyst's endpoint management platform, with encrypted local storage, always-on VPN connectivity, and centralized policy enforcement. Network architecture was redesigned with proper segmentation, separating server infrastructure, user workstations, field devices, and guest access into distinct zones. Zero Trust Network Access replaced the legacy VPN, providing secure, identity-verified access to specific applications rather than broad network access.

Managed detection and response

Katalyst's Managed Security & MDR service and 24/7 SOC now provide the agency with the continuous monitoring and incident response capability it lacked. SIEM technology aggregates logs from all seven locations, correlating events and alerting our security analysts to potential threats in real time. A formal incident response plan was developed, tested through tabletop exercises, and integrated with state-level cyber incident reporting requirements.

Zero-trust architecture

Katalyst implemented a zero-trust security model across the agency's environment. Every access request is verified against user identity, device health, and contextual risk factors before being granted. This approach is particularly important for the agency's distributed workforce of field inspectors who access agency systems from regulated facilities, remote offices, and mobile locations across the state.

The Results

After 14 months of systematic remediation, the agency underwent a formal CMMC Level 2 assessment and achieved certification. All 110 NIST 800-171 security practices were implemented and documented, with the assessor noting the thoroughness of the agency's System Security Plan and evidence packages.

The legacy modernization effort transformed the agency's technology foundation. The 85% of legacy systems that were modernized now run on supported platforms with automated patching, centralized management, and proper backup. The remaining 15%, specialized environmental monitoring systems with vendor dependencies, are isolated in segmented network zones with compensating controls documented in the plan.

The agency now has a fully operational incident response capability for the first time in its history. The formal plan has been tested through three tabletop exercises, and the MDR service has detected and contained 47 security events in the first six months, all resolved before they could impact operations or CUI.

Federal agencies are increasingly requiring CMMC compliance from their state partners, and we were not prepared. Katalyst didn't just help us check boxes, they modernized our infrastructure, built a real security program, and gave us the monitoring and response capability that a regulatory agency handling sensitive data must have. Our federal partners have confidence in our security posture for the first time.

Chief Information Officer · State Regulatory Agency

Key Takeaways

  • CMMC Level 2 requires comprehensive implementation of all 110 NIST 800-171 controls. There are no shortcuts, and partial compliance is not an option for organizations handling CUI.
  • Legacy modernization and compliance go hand in hand. You cannot implement modern security controls on unsupported, unpatched systems, so engineering capability is essential for agencies with technical debt.
  • Managed security and MDR provide the continuous monitoring that CMMC requires. Compliance is an ongoing operational commitment, not a point-in-time achievement.
  • Zero-trust architecture is especially valuable for government agencies with distributed workforces, replacing the perimeter model that legacy VPNs cannot adequately support.

Facing a CMMC or NIST 800-171 requirement?

Let's talk about a remediation plan that modernizes your environment and gets you to certification.