Kampi Components Co., Inc.,
CyberSheath helped Kampi Components achieve CMMC Level 2 certification by addressing noncompliant service providers and coordinating a complex multivendor environment.
CASE STUDY
Client

Kampi Components Co., Inc., is a military parts distributor based in Fairless Hills, Pennsylvania. Founded in 1984, Kampi provides distribution and logistical support for government and defense contractors, including procurement, inspection, testing, packaging and transportation of military equipment and replacement parts. The company employs about 65 people and operates from a 36,000-square-foot facility, serving a long-standing role within the Defense Logistics Agency and broader Department of Defense/War (DOD/DOW) supply chain.
Situation
When the DOD/DOW conducted an unexpected DIBCAC High Assessment at Kampi’s facility, the company faced immediate pressure to achieve full CMMC Level 2 compliance. The audit revealed gaps that needed addressing before Kampi could pursue formal certification.
The company had not yet completed its planned migration from a commercial cloud infrastructure to Microsoft’s Government Community Cloud (GCC High). Kampi also relied on multiple managed service providers (MSPs) for various IT functions, including a major MSP handling help desk support and network operations center services. None of these external service providers were CMMC compliant, and some had no plans to pursue certification or support the compliance requirements. Under CMMC requirements, noncompliant service providers with access to Controlled Unclassified Information (CUI) environments become compliance obstacles that can prevent successful certification.
As a distribution company with warehouse operations handling military materials, Kampi also needed comprehensive physical security controls, including visitor management, access control systems, secure storage for CUI in both digital and physical formats, and monitoring capabilities across its entire facility.
Process
Following the government audit, Kampi engaged CyberSheath to develop a comprehensive compliance strategy. CyberSheath’s initial gap assessment aligned closely with the government’s findings, confirming the scope of work and establishing a clear road map to certification.
The collaborative process included:
- Cloud infrastructure migration: Moving Kampi’s entire environment from commercial cloud services to GCC High while maintaining operational continuity.
- Service provider remediation: Evaluating all external service providers’ compliance status and determining remediation paths.
- Physical security implementation: Establishing comprehensive controls across Kampi’s facility, including infrastructure security, visitor management systems, badge readers, surveillance cameras, alarm systems and secure storage for physical CUI materials.
- Documentation preparation: Developing a System Security Plan (SSP) and Plan of Action and Milestones (POAM) aligned to CMMC assessment requirements.
Solution
CyberSheath implemented a GCC High managed services solution that provided the FedRAMP-authorized platform Kampi needed for handling CUI. The solution created a fully compliant technology environment by eliminating noncompliant service providers and implementing controls across both digital and physical operations.
For Kampi’s warehouse and office operations, CyberSheath worked with the company to plan and implement security controls for the entire 36,000-square-foot facility with monitoring, access controls and procedures for handling CUI materials in all formats.
Results
Kampi achieved CMMC Level 2 certification with a perfect score of 110 out of 110 points with the certification assessment conducted by Cybersec Investments. The certification proceeded smoothly without unexpected challenges.
“CyberSheath became a true extension of our team throughout this process. When we discovered the extent of our service provider challenges, our partners at CyberSheath rolled up their sleeves and worked alongside us to solve them. Through their managed compliance and security services, they provided hands-on remediation, day-to-day guidance, and continuous monitoring. Their expertise and ongoing managed support gave us confidence that we were making the right decisions for our business while meeting every compliance requirement.”
- Penny Jackson, Information Technology Operations Security & Compliance Manager at Kampi Components
Despite the complexity of removing service providers from the environment with less than 30 days to assessment, rapid execution ensured Kampi met its certification timeline. The company maintained full operational continuity throughout the compliance process with no disruption to its distribution services.