How Poarch Creek Indians Federal Services is scaling CMMC compliance across 1,200 employees

LOCATION

Atmore, Alabama

INDUSTRY
Federal services, Engineering, Manufacturing, Business Services
SOCIAL
CMMC

For a tribally owned federal contractor scaling past a thousand employees, a single weak link in a System Security Plan can stall every contract that depends on it.

Poarch Creek Indians Federal Services (PCIFS) is a diversified federal services organization providing aviation, engineering, technology, cybersecurity, logistics, facilities management, and manufacturing services to the U.S. federal government and Department of Defense. A tribally owned enterprise of the Poarch Band of Creek Indians, one of the few federally recognized tribes that settled on their original land, PCIFS grew from roughly 20-30 employees in 2020 to more than 1,200 employees across 12-13 subsidiary companies and $290 million in revenue by 2026.

That growth turned CMMC Level 2 compliance from a manageable task into an enterprise-wide problem and PCIFS needed certification applied consistently across every subsidiary, not managed separately on a company-by-company basis. With Strike Graph, PCIFS built a single automated, AI-validated compliance program spanning the entire enterprise.

The Challenge

Scaling compliance across a complex enterprise. Dr. Byrian Ramsey, MISM, CSM, CSPO, ΔMΔ has over 40 years of experience driving large-scale modernization, resilience, and compliance across highly regulated, mission-critical environments. He joined PCIFS in February 2020 when the organization had roughly 20–30 employees. By 2026, the organization had grown to over 1,200 employees and $290 million in sales, creating an urgent need for systematic compliance management. That growth turned CMMC Level 2 compliance under NIST 800-171 Rev. 2 from a manageable task into an enterprise-wide problem spanning 12 to 13 companies.

A costly and inadequate gap analysis. Before coming to Strike Graph, PCIFS had recently paid $1,800 for an external gap analysis that failed to properly and fully assess the organization against CMMC. While some items returned flagged for the team and were resolved immediately, two remained outstanding, both tied to controlled unclassified information (CUI) and PCIFS knew they needed a more comprehensive approach to ensure compliance.

Manual SSP updates were unsustainable. Another challenge for the organization was updating their System Security Plan (SSP) and ensuring it was audit-ready. With a formal mock audit approaching, PCIFS needed its System Security Plan to be complete and audit-ready fast. Byrian explicitly sought software that would allow him to "input all the information, ask me questions, whatever that might be, and really spit that out just as compliant and fast as possible."

Enterprise-wide standardization. With 12–13 different companies under one umbrella, PCIFS needed a single enterprise approach, not individual enclaves, to avoid managing different recertification timelines across subsidiaries.

One person carried both roles. Byrian was already PCIFS's Corporate IT Director when compliance responsibility landed on his desk, too, with no separate function to hand it to. Despite his CMMC training and certifications, every control, every piece of evidence, and every SSP update for a 1,200-employee, 12-13-company enterprise ran through one person, a structural bottleneck no amount of individual expertise could fully absorb.

The core challenge: Scale a manual, single-person compliance function to cover 1,200 employees and 12-13 companies, fix a botched gap analysis, and get the SSP audit-ready, all against a hard deadline.

The evaluation process

Byrian Ramsey led the software evaluation process alongside a lead CCA to support, bringing more than 40+ years of IT and infrastructure leadership across highly regulated industries and actively holding DoD Top Secret clearance.

PCIFS was evaluating two platforms in parallel, and the deciding factor was a precise technical distinction: having automation that verifies evidence content against a specific requirement, not just automation that simply tracks whether evidence has been collected.

Strike Graph stood out immediately on this exact point. "So far, yours is the better of the two in what I see for automation," Byrian said. "I want AI to be used in a way that it can double check the evidence, make sure the evidence is compliant and aligns with the requirement."

Their prior gap analysis hadn't failed on tooling per se, it failed because the assessor never asked for the evidence needed to prove compliance in the first place.

The urgency of a mock audit deadline shaped how quickly PCIFS moved. "I'm at a critical stature here to get this done…" Byrian said.

Why PCIFS chose Strike Graph:

  • Automation and AI-native evidence validation that the prior gap analysis never delivered
  • Unlimited users at a flat annual cost
  • A platform built to support CMMC Level 2 self-assessment and SPRS scoring

The solution: Why Strike Graph was selected

For an organization managing compliance across a dozen-plus companies, the appeal of Strike Graph was consolidation, speed, and accuracy. Rather than manage multiple vendors or rebuild a broken assessment from scratch, PCIFS found Strike Graph, a platform that combines automation, AI-native evidence validation, and an enterprise-ready compliance structure ready to scale with the organization rather than against it.

As Byrian put it, the goal was software that could "input all the information, ask me questions, whatever that might be, and really spit that out just as compliant and fast as possible."

Strike Graph provided PCIFS with a single enterprise-wide compliance management solution, replacing scattered, manual processes.

Capability

What PCIFS needed

How Strike Graph delivered

Automated SSP generation

Software that accepts inputs and outputs a compliant SSP quickly

The platform auto-builds the SSP from the control library as controls are implemented

AI evidence validation

AI to "double check" evidence for compliance alignment

Verify AI tests uploaded evidence against control descriptions and flags mismatches

Enterprise-wide deployment

One policy, one configuration across all locations and companies

Strike Graph's federated model supports parent-subsidiary structures with shared controls

Self-assessment and SPRS scoring

Ability to run self-assessments and generate SPRS scores

Built-in self-assessment for CMMC Level 2, with SPRS scoring and POA&M tracking

Unlimited users

No per-seat restrictions across 1,200 employees

Strike Graph does not charge per seat

Security posture

A zero-trust, independently audited vendor

SOC 2 Type 2 audited, HIPAA compliant, zero-trust architecture

 

The decision to standardize was deliberate. "We're not doing it as an enclave in each individual location," Byrian said. "We're doing one enterprise. Everything's interconnected, so one policy or configuration will be consistent across all locations, companies, and users. It's absolutely enterprise-wide, one shop stopping, and we're good to go."

The results

A stalled compliance effort became fully CMMC compliant in 21 days. Where a prior vendor had left PCIFS with an incomplete assessment and unresolved control gaps, the team built a complete CMMC Level 2 control set from the ground up, reaching 100% coverage of all applicable controls.

A full gap analysis replaced the previous assessment that barely scratched the surface. Strike Graph's self-assessment runs against the complete CMMC Level 2 framework and PCIFS can now run it as often as needed to see exactly if a gap exists, what evidence is missing, and how it affects the organization's score.

The SSP is now a living report instead of a standalone project. Byrian's ask was software that could "input all the information, ask me questions, whatever that might be, and really spit that out just as compliant and fast as possible." Strike Graph's SSP report pulls directly from the control library PCIFS is already building out, mapping each operation to its NIST 800-171 requirement in real time. The SSP reflects the organization's actual compliance posture at any given moment and is ready to export whenever needed, without PCIFS having to reconstruct or update it by hand ahead of every audit.

Verify AI became the team's built-in auditor. Byrian's original ask was for AI that could "double check the evidence, make sure the evidence is compliant and aligns with the requirement.” Verify AI now does exactly that, automatically testing every piece of evidence PCIFS uploads against the control it's meant to satisfy. Verify AI catches mismatches as they happen, well before a real audit puts that evidence to the test.

Distributing responsibility without rising costs. Because Strike Graph charges a flat rate regardless of user count, PCIFS no longer had a cost reason to limit access. Instead, access to the platform is opened up to the managers who actually own each piece of the control set. Control ownership, evidence collection, and control operation now sit directly with the people responsible for each area, which means evidence comes from the person closest to the work rather than a single point of failure that could stall the entire compliance program if one person is unavailable.

  • copy-link-icon

    Copy URL

  • facebook-icon
  • linkedin-icon

Strike Graph’s pre-audit security packet not only streamlined and simplified our SOC 2 compliance efforts, but it even helped us earn the confidence of a valued customer.

VENKI PAGIDIMARRI

Chief AI Officer, Foundation AI

Are you ready to build trust through cybersecurity?