Design a security program that builds trust, scales with your business, mitigates risk, and empowers your team to work efficiently.
Cybersecurity is evolving — Strike Graph is leading the way.
The future of compliance AI is already here
Find answers to all your questions about security, compliance, and certification.
Find out why Strike Graph is the right choice for your organization. What can you expect?
Find out why Strike Graph is the right choice for your organization. What can you expect?
Atmore, Alabama
For a tribally owned federal contractor scaling past a thousand employees, a single weak link in a System Security Plan can stall every contract that depends on it.
Poarch Creek Indians Federal Services (PCIFS) is a diversified federal services organization providing aviation, engineering, technology, cybersecurity, logistics, facilities management, and manufacturing services to the U.S. federal government and Department of Defense. A tribally owned enterprise of the Poarch Band of Creek Indians, one of the few federally recognized tribes that settled on their original land, PCIFS grew from roughly 20-30 employees in 2020 to more than 1,200 employees across 12-13 subsidiary companies and $290 million in revenue by 2026.
That growth turned CMMC Level 2 compliance from a manageable task into an enterprise-wide problem and PCIFS needed certification applied consistently across every subsidiary, not managed separately on a company-by-company basis. With Strike Graph, PCIFS built a single automated, AI-validated compliance program spanning the entire enterprise.
Scaling compliance across a complex enterprise. Dr. Byrian Ramsey, MISM, CSM, CSPO, ΔMΔ has over 40 years of experience driving large-scale modernization, resilience, and compliance across highly regulated, mission-critical environments. He joined PCIFS in February 2020 when the organization had roughly 20–30 employees. By 2026, the organization had grown to over 1,200 employees and $290 million in sales, creating an urgent need for systematic compliance management. That growth turned CMMC Level 2 compliance under NIST 800-171 Rev. 2 from a manageable task into an enterprise-wide problem spanning 12 to 13 companies.
A costly and inadequate gap analysis. Before coming to Strike Graph, PCIFS had recently paid $1,800 for an external gap analysis that failed to properly and fully assess the organization against CMMC. While some items returned flagged for the team and were resolved immediately, two remained outstanding, both tied to controlled unclassified information (CUI) and PCIFS knew they needed a more comprehensive approach to ensure compliance.
Manual SSP updates were unsustainable. Another challenge for the organization was updating their System Security Plan (SSP) and ensuring it was audit-ready. With a formal mock audit approaching, PCIFS needed its System Security Plan to be complete and audit-ready fast. Byrian explicitly sought software that would allow him to "input all the information, ask me questions, whatever that might be, and really spit that out just as compliant and fast as possible."
Enterprise-wide standardization. With 12–13 different companies under one umbrella, PCIFS needed a single enterprise approach, not individual enclaves, to avoid managing different recertification timelines across subsidiaries.
One person carried both roles. Byrian was already PCIFS's Corporate IT Director when compliance responsibility landed on his desk, too, with no separate function to hand it to. Despite his CMMC training and certifications, every control, every piece of evidence, and every SSP update for a 1,200-employee, 12-13-company enterprise ran through one person, a structural bottleneck no amount of individual expertise could fully absorb.
The core challenge: Scale a manual, single-person compliance function to cover 1,200 employees and 12-13 companies, fix a botched gap analysis, and get the SSP audit-ready, all against a hard deadline.
Byrian Ramsey led the software evaluation process alongside a lead CCA to support, bringing more than 40+ years of IT and infrastructure leadership across highly regulated industries and actively holding DoD Top Secret clearance.
PCIFS was evaluating two platforms in parallel, and the deciding factor was a precise technical distinction: having automation that verifies evidence content against a specific requirement, not just automation that simply tracks whether evidence has been collected.
Strike Graph stood out immediately on this exact point. "So far, yours is the better of the two in what I see for automation," Byrian said. "I want AI to be used in a way that it can double check the evidence, make sure the evidence is compliant and aligns with the requirement."
Their prior gap analysis hadn't failed on tooling per se, it failed because the assessor never asked for the evidence needed to prove compliance in the first place.
The urgency of a mock audit deadline shaped how quickly PCIFS moved. "I'm at a critical stature here to get this done…" Byrian said.
Why PCIFS chose Strike Graph:
For an organization managing compliance across a dozen-plus companies, the appeal of Strike Graph was consolidation, speed, and accuracy. Rather than manage multiple vendors or rebuild a broken assessment from scratch, PCIFS found Strike Graph, a platform that combines automation, AI-native evidence validation, and an enterprise-ready compliance structure ready to scale with the organization rather than against it.
As Byrian put it, the goal was software that could "input all the information, ask me questions, whatever that might be, and really spit that out just as compliant and fast as possible."
Strike Graph provided PCIFS with a single enterprise-wide compliance management solution, replacing scattered, manual processes.
|
Capability |
What PCIFS needed |
How Strike Graph delivered |
|---|---|---|
|
Automated SSP generation |
Software that accepts inputs and outputs a compliant SSP quickly |
The platform auto-builds the SSP from the control library as controls are implemented |
|
AI evidence validation |
AI to "double check" evidence for compliance alignment |
Verify AI tests uploaded evidence against control descriptions and flags mismatches |
|
Enterprise-wide deployment |
One policy, one configuration across all locations and companies |
Strike Graph's federated model supports parent-subsidiary structures with shared controls |
|
Self-assessment and SPRS scoring |
Ability to run self-assessments and generate SPRS scores |
Built-in self-assessment for CMMC Level 2, with SPRS scoring and POA&M tracking |
|
Unlimited users |
No per-seat restrictions across 1,200 employees |
Strike Graph does not charge per seat |
|
Security posture |
A zero-trust, independently audited vendor |
SOC 2 Type 2 audited, HIPAA compliant, zero-trust architecture |
The decision to standardize was deliberate. "We're not doing it as an enclave in each individual location," Byrian said. "We're doing one enterprise. Everything's interconnected, so one policy or configuration will be consistent across all locations, companies, and users. It's absolutely enterprise-wide, one shop stopping, and we're good to go."
A stalled compliance effort became fully CMMC compliant in 21 days. Where a prior vendor had left PCIFS with an incomplete assessment and unresolved control gaps, the team built a complete CMMC Level 2 control set from the ground up, reaching 100% coverage of all applicable controls.
A full gap analysis replaced the previous assessment that barely scratched the surface. Strike Graph's self-assessment runs against the complete CMMC Level 2 framework and PCIFS can now run it as often as needed to see exactly if a gap exists, what evidence is missing, and how it affects the organization's score.
The SSP is now a living report instead of a standalone project. Byrian's ask was software that could "input all the information, ask me questions, whatever that might be, and really spit that out just as compliant and fast as possible." Strike Graph's SSP report pulls directly from the control library PCIFS is already building out, mapping each operation to its NIST 800-171 requirement in real time. The SSP reflects the organization's actual compliance posture at any given moment and is ready to export whenever needed, without PCIFS having to reconstruct or update it by hand ahead of every audit.
Verify AI became the team's built-in auditor. Byrian's original ask was for AI that could "double check the evidence, make sure the evidence is compliant and aligns with the requirement.” Verify AI now does exactly that, automatically testing every piece of evidence PCIFS uploads against the control it's meant to satisfy. Verify AI catches mismatches as they happen, well before a real audit puts that evidence to the test.
Distributing responsibility without rising costs. Because Strike Graph charges a flat rate regardless of user count, PCIFS no longer had a cost reason to limit access. Instead, access to the platform is opened up to the managers who actually own each piece of the control set. Control ownership, evidence collection, and control operation now sit directly with the people responsible for each area, which means evidence comes from the person closest to the work rather than a single point of failure that could stall the entire compliance program if one person is unavailable.
Strike Graph’s pre-audit security packet not only streamlined and simplified our SOC 2 compliance efforts, but it even helped us earn the confidence of a valued customer.
Chief AI Officer, Foundation AI
Fill out a simple form and our team will be in touch.
Experience a live customized demo, get answers to your specific questions , and find out why Strike Graph is the right choice for your organization.
Fill out a simple form and our team will be in touch.
Experience a live customized demo, get answers to your specific questions , and find out why Strike Graph is the right choice for your organization.