Operating under Cybersecurity Maturity Model Certification (CMMC) standards, our client handled Controlled Unclassified Information (CUI) daily but lacked a systematic way to track workforce access to this data. This created a significant compliance blind spot.
The gap extended beyond approximately 180 contingent assignments to a much broader on-site population. Early estimates indicated a further 1,500 to 2,000 additional workers, including facilities and services personnel, accessed secured environments without centralised compliance tracking.
Our client's previous MSP provided no role-based tracking capability. HR, Learning and Development, Cybersecurity and Contingent Workforce teams relied on weekly spreadsheets that broke as roles changed. In a restricted government cloud environment, reporting was manual, fragmented and impossible to verify.
With a critical audit approaching, leadership faced significant exposure. Without CMMC readiness, the organisation risked current and future Department of Defense contracts, regulatory penalties, and reputational damage.A role-based, automated compliance model
Pontoon rebuilt the organisation’s compliance foundation around role clarity, automation and unified governance.
A structured job code framework precisely defined roles involving CUI, trade secrets, and intellectual property. These job codes became the anchor for compliance, removing reliance on manual lists or individual knowledge.
Contractors, previously the largest unmanaged compliance exposure, were fully governed through the VMS. Entry into a sensitive role automatically triggered training and access reviews. When roles changed, access adjusted consistently and in real time.
A central governance model replaced fragmented ownership with a single compliance framework. Reporting shifted from spreadsheet-based reconciliation to on-demand, audit ready visibility.
Scalable, audit ready compliance
The transformation delivered a step change in compliance maturity. The organisation now holds a centralised, accurate view of workers handling CUI, supported by automated workflows that align training and access controls to role requirements.
Audit reporting time was reduced by more than 93%, moving from manual, multi-team reconciliation to a structured model reviewed weekly by HR leadership. Compliance monitoring is faster, more reliable and significantly less manual.
Contractor governance is now embedded into day-to-day operations. Instead of preparing reactively for audits, our client approaches federal scrutiny with confidence.
Beyond addressing immediate risk, the solution established a scalable compliance infrastructure designed to adapt as regulatory requirements evolve.
This case demonstrates that compliance readiness depends on workforce visibility, role clarity and disciplined governance. In highly regulated environments, automation and structure are essential for protecting access, safeguarding contracts and sustaining trust.
