Managed IT and Managed Security · Leesburg, VA

Case Study

Iron Lift: From CMMC Level 1 Guidance to a Level 2 Self-Assessment.

A construction company that needed CMMC to stay competitive for government work, with no cybersecurity or compliance team in-house.

Government contractor · Massachusetts

A speaker on camera in the Iron Lift video case study
Video: CMMC Compliance Case Study, Iron Lift and Capital Cyber (YouTube)
110 of 110CONTROLS MET (SELF-ASSESSMENT)
Level 2CMMC SCOPE
2026-09-15STANDING AS VERIFIED

The Client

Iron Lift LLC is a construction company specializing in steel and precast concrete erection, serving both private and government-funded projects. It is led by President Jenna Rahkonen.

The Challenge

Iron Lift needed to meet CMMC requirements to stay competitive in government contracting. The process was unfamiliar and full of regulatory language, and the company had no dedicated cybersecurity or compliance team in-house.

It needed a plan it could afford that would not disrupt daily operations.

What We Did

Step-by-step CMMC Level 1 guidance, the 15 requirements of FAR 52.204-21, with biweekly progress reviews.IT security and managed services alongside the compliance work.For Level 2, we wrote the System Security Plan and ran evidence collection. That compliance work is delivered by Capital Cyber Compliance.

“Capital Cyber made the entire CMMC process manageable. Their expertise in federal regulations gave us confidence, and their step-by-step approach meant we were never left guessing. They didn't just help us check a box, they made our business more secure and more competitive.”

Jenna Rahkonen, President, Iron Lift LLC

Talk It Through in 30 Minutes.

Pick a time. Tell us what you protect and who asks about it.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call