Case Study IT Contractor Goes from Failed Gap Assessment to CMMC Level 2 How PSI Pax rebuilt a non-compliant environment, stood up a fully managed security program, and passed CMMC Level 2 on the first try. PSI Pax, a women-owned IT and financial services firm serving the Department of Defense and civilian agencies, had been preparing for CMMC for years. A failed gap assessment, a painful MSSP transition, and mounting technical debt left their three-person IT team stretched thin and running out of options. This case study outlines how Sentinel Blue addressed a non-compliant GCC High environment, delivered a fully managed security and compliance program scaled to a small team, and helped PSI Pax achieve their CMMC Level 2 certification on the first try.
Key Outcomes
CMMC Level 2 certified on the first try
Among the first 1,000 contractors to achieve CMMC Level 2
Rebuilt in a clean, fully cloud-based GCC High enclave
Fully managed SOC, endpoint, and compliance program
Assessment completed in a single day
" This was something I'd been sweating about for three years. When assessment week came, I thought it was going to take all week. We were done on the first day.
Debra Hill-Cherry Chief Information Officer, PSI Pax
About the Case Study PSI Pax is a women-owned IT and financial services business based in Maryland, serving customers across the Department of Defense and civilian and state agencies. Their work spans systems modernization and integration, program and financial management, data analytics and business intelligence, and cybersecurity. Staying compliant wasn't a checkbox for PSI Pax — it was central to their ability to keep doing business with their core customers. Despite years of preparation, a gap assessment in late 2024 exposed serious network security gaps their three-person IT team couldn't close alone. A prior MSSP engagement had already taken them through a GCC High migration, but a last-minute architectural change caused them to fail another gap assessment. PSI Pax needed a true partner, not another vendor. Sentinel Blue rebuilt their environment, handled the full compliance program, and got PSI Pax certified on the first try — in a single day.
What the Case Study Covers
Failed gap assessments and what went wrong
GCC High rebuild and architecture cleanup
Managed SOC and endpoint protection
SSP, POA&M, and evidence package preparation
CMMC Level 2 assessment execution
Ongoing compliance and security partnership
📋
Case Study Download the PSI Pax Case Study The full story of how a women-owned DoD contractor overcame failed assessments, a troubled MSSP transition, and years of technical debt to achieve CMMC Level 2 certification on the first try.
Get Started Ready to Get to Work? So Are We. Whether your organization is preparing for a first CMMC assessment, recovering from a failed one, or looking for a managed security partner that can carry the compliance weight your internal team can't, Sentinel Blue is ready to help.
100% first-try CMMC Level 2 certification rate
CMMC Third-Party Assessment Organization (C3PAO)
U.S. persons only, operating from U.S. soil
Purpose-built for the Defense Industrial Base