“It just works,” her lead engineer, Tom, had argued earlier. “Don’t break the pipe because of paperwork.”
It was the day of the mock audit. AeroSync had deployed GlobalSCAPE EFT in a locked-down configuration. Elena sat with an external consultant, Dr. Aris, who was simulating a CMMC assessor. “It just works,” her lead engineer, Tom, had
“We already mapped EFT v8.4 to NIST SP 800-171, Rev 2,” Priya said. “CMMC is just 800-171 with a maturity stick. We’ve done the assessment prep for you. Here—see page 14? For ‘limit failed logon attempts’ (AC.L2-3.1.8), our native lockout policy works out of the box. For ‘session lock’ (AC.L2-3.1.10), you’ll need to enable your Windows GPOs, but we have a configuration script.” Elena sat with an external consultant, Dr
Six months later, AeroSync received their CMMC Level 2 certification. “CMMC is just 800-171 with a maturity stick
The software hadn't done the work for them. They had still written the policies, trained the staff, and secured the endpoints. But GlobalSCAPE had acted as the anchor. It was the fortress where the CUI lived and moved.
Mara’s jaw tightened. “So, a gap.”