CMMC LEVEL 2 / PERSONNEL AND ACCESS

U.S. persons, logged and audited, by name.

Access to the compliant environment is restricted to U.S. persons. Every export-controlled program has a personnel list on file, and every session is logged.

ISO9001:2015 certified/CMMC LEVEL 2Compliant environment/ITARControlled programs supported/CAGE5LA13/UEILY7KDRALJX98/FOUNDED1998/CUSTOMERS200+ programs since 1998/LOCATIONSMichigan + New Jersey/ISO9001:2015 certified/CMMC LEVEL 2Compliant environment/ITARControlled programs supported/CAGE5LA13/UEILY7KDRALJX98/FOUNDED1998/CUSTOMERS200+ programs since 1998/LOCATIONSMichigan + New Jersey/

ACCESS LIFECYCLE

Four stages, and the paper each one leaves behind.

Access lifecycle for CUI-touching programs: what each stage produces, who owns it, and how often it runs.
Stage 01Vet 02Authorize 03Log 04Revoke
Artifact Status check Signed addendum Session log Disabled account
Who owns it Security Program manager IT Security
Cadence On assignment Per program Continuous On departure or quarterly

Access is a named list, not a department. Every stage above produces an artifact somebody can audit.

WHO TOUCHES THE WORK

Access is a named list, not a department.

On export-controlled programs, the question is never “which team” but “which people.” Here is how we answer it, person by person, program by program.

U.S. PERSONS

U.S. persons only, by definition.

Everyone with access to the compliant environment meets the U.S. person definition in ITAR §120.15. This is a staffing rule, not a paperwork exercise, and it applies before any program access is granted.

PER-PROGRAM LIST

A roster on file for every program.

Each export-controlled program carries its own authorized personnel roster. If a name is not on the list for that program, that person does not open its files. Each authorized person also signs a data-handling addendum on top of the standard NDA.

REVOCATION

Offboarding is a procedure, not a habit.

When someone rolls off a program or leaves the company, a documented revocation procedure removes their access. Accounts are disabled, the roster is updated, and the change is logged.

HOW WE RUN THIS LAYER

Four steps in the life of an authorized person.

From first vetting to final revocation, access follows the same documented path on every program.

Vet

Confirm U.S. person status and program need before any access request moves forward.

Authorize

Add the person to the program roster and collect the signed data-handling addendum.

Log

Record every session in the environment at the session level, continuously.

Revoke

Run the documented offboarding procedure the day access is no longer needed.

THE ACCESS RULE, IN ONE LINE

The list is short on purpose.

The easiest access model to defend is a small one. We keep the roster for each export-controlled program as short as the work allows, and we review access quarterly instead of waiting for a problem to force the question.

To be plain about scope: ADAPT runs a CMMC Level 2 compliant environment built to the 110 NIST SP 800-171 rev 2 practices. We have not completed a C3PAO assessment, so we do not claim certification. The personnel controls on this page are how the environment is actually staffed and operated today.

Brian Smith, Director of Engineering

StaffingU.S. persons only
Program listOn file per contract
Session loggingContinuous
Access reviewQuarterly
Data-handling addendumOn top of NDA
ISO9001:2015
CMMC L2Compliant
CAGE5LA13
UEILY7KDRALJX98
FOUNDEDMay 1998

TALK TO AN ENGINEER

Tell us what you are building.

Send the program brief. An engineer on our team will read it and respond within one business day. Not a sales coordinator. Not a routing form.

Response

One business day. Senior engineer, not a sales coordinator.

Michigan HQ

2901 Auburn Road, Suite 100
Auburn Hills, MI 48326

New Jersey

196 Princeton-Hightstown Road, Suite 15
West Windsor, NJ 08550