How Fitz-Thors Achieved CMMC Level 2, Gained a Competitive Edge, and Satisfied Flow-Down Requirements Along the Way
When a prime contractor calls and says, "we need your manufacturing capacity, and we need you CMMC certified," most subcontractors hear a burden. Fitz-Thors heard an opportunity.
The Alabama-based engineering and manufacturing firm was newer to the defense space than most. Ownership had long wanted to move into defense contracting, and when they finally committed, they did something a lot of small subcontractors don't: they decided to get ahead of the compliance curve instead of waiting to be forced across it.

This is the story of how they did it, and why getting certified early turned a regulatory hurdle into a business advantage.
Who Is Fitz Thors?
Founded in 2007 by two University of Alabama engineering graduates, Arnar Thors and Matt Fitzgerald, Fitz Thors has grown from a two-person design shop into a family of complementary businesses based in Bessemer, Alabama. Today the company delivers end-to-end engineering and manufacturing: product development, engineering services, prototyping, CNC machining and fabrication, for defense, aviation, medical devices, and manufacturing facilities. In short, when off-the-shelf solutions don't cut it, Fitz Thors designs and builds the custom equipment, tooling, and parts that manufacturers and innovators need.
That blend of precision engineering and hands-on manufacturing, backed by a shop floor of 3- & 5-axis CNC mills, lathes, a waterjet, a gantry router, and a CMM is exactly what makes Fitz Thors attractive to defense primes looking for capable, U.S.-based suppliers. It's also what made the company's path to CMMC compliance a little more interesting than most.
The Challenge: Getting Ahead of CMMC Flow-Down Requirements
Fitz Thors operates as a subcontractor today, and the company was taking its first serious foray into defense work. Richard Lloyd, IT manager with Fitz Thors, described a deliberate "how are we going to make this happen" phase as the team planned its jump into the defense contracting pool. Early on, they discovered the looming requirement for CMMC. Level 1 was never a realistic fit for a business handling Controlled Unclassified Information (CUI), so Level 2, with its full set of 110 NIST SP 800-171 controls, was the obvious target.
What set Fitz Thors apart was why they moved, and how early. Rather than treat certification as a box to check once a customer forced the issue, they saw getting it done early as a competitive play. As Lloyd put it, achieving Level 2 as soon as possible would "put us in a really good position compared to our competition." In a defense industrial base where the vast majority of suppliers are still working through self-assessment, a completed third-party certification is a genuine differentiator, and Fitz Thors wanted that edge.
Getting ahead of certification solved something else at the same time: CMMC flow-down requirements. Under the DFARS clauses that govern the program, prime contractors must ensure that any subcontractor storing, processing, or transmitting CUI holds the appropriate CMMC level before work is awarded. By achieving Level 2 proactively, Fitz Thors satisfied that flow-down obligation not just for the primes it already worked with, but for any future prime it might want to win work from. The requirement that trips up unprepared subcontractors was, for Fitz Thors, already handled.
The payoff showed up fast, and in concrete terms. One prime had a contract ready to go but wouldn't release it until Fitz Thors could prove certification. As Lloyd described it: "They wanted that third-party CMMC certification to be complete and submitted before they would hand it to us. So the day we got the certificate from the C3PAO that did the assessment, I made that certificate available to our salespeople that were working that contract, and we got the contract the next day."
A second, much larger prime, already operating at a high CMMC level with a facility clearance, actively encouraged Fitz Thors down the same path because it needed the company's manufacturing capacity in its supply chain. And notably, these primes weren't waiting for the DoD's phased rollout to force the issue. As Lloyd put it, "whether it's paused as a requirement or not, for their own security, for their own peace of mind, they want to know that we've taken that additional step of not just doing self-assessment but actually going through and being third-party assessed."
That is flow-down working exactly as designed: a compliance obligation moving down the supply chain and tying a subcontractor's certification status directly to its ability to win work. Fitz Thors simply got there first.
The Solution: A Compliant Enclave, Built and Managed
Fitz Thors began the way many thoughtful companies do, by getting the right partners in place early. Referred to Cape Endeavors by a trusted partner, the team found the fit they were looking for.
The decision came down to responsiveness. Fitz Thors weighed several providers, and in a market where nearly everyone is overloaded trying to meet CMMC deadlines, the Cape Endeavors team stood out for attentiveness and genuine relationship-building. That was the deciding factor even when pricing across vendors was competitive.
The technical answer to Fitz-Thors' challenge was a NIST 800-171 / CMMC Level 2 compliant enclave: a hardened, isolated environment on Microsoft 365 and Azure Government Cloud where all CUI could live, be worked, and be protected. Because Fitz-Thors had no existing CUI when they started, they built the enclave first, creating a secure repository ready to receive sensitive data the moment their first contracts landed. No messy migration, no legacy data to untangle.
A Turning Point: Knowing When Not to Go It Alone
The original plan was for Cape Endeavors to build the enclave and hand it over for Fitz-Thors to self-manage, with advisory support through the assessment. Then reality set in.
With a small IT team supporting not just the three Fitz-Thors companies but six others as well, Lloyd reached an honest conclusion while digging into what day-to-day enclave operation actually demanded: one person could not run the enclave, document everything to assessment standard, and hold down every other IT responsibility without something breaking. Trying to do it all would have put the assessment itself at risk.
So, in the week of the assessment kickoff, he brought ownership together and made the case to change course. They listened. The two companies renegotiated a managed-services engagement, wiped the environment back to a clean baseline, and rebuilt it the right way with Cape at the controls.
That decision, recognizing the limits of a one-person shop and leaning on a dedicated team, became the single most important move in the whole journey.
The Result: 110 out of 110, and a Contract the Next Day
Working closely with a dedicated engineering team and a project manager who kept every milestone on schedule, Fitz-Thors hit its targets and reached a perfect 110-out-of-110 self-assessment score. Just as important, the enclave was genuinely usable. The team could conduct real business inside it, not just pass a test.
Then came the assessment, conducted by a very reputable C3PAO. Fitz-Thors is, by its own cheerful admission, very good at throwing curveballs. Almost all of the company's CUI would stay neatly inside the enclave, but there was one wrinkle: G-code driving the shop floor machinery. Whether G-code counts as CUI is genuinely ambiguous, so out of an abundance of caution, Fitz Thors wanted to treat it as CUI. That meant safely moving it from the enclave to physical CNC machines, mills, lathes, a waterjet, and a gantry router without dropping it onto an uncontrolled USB drive and defeating the entire purpose of the enclave.
Together, the team engineered a solution. It worked so well that the C3PAO made a point of coming on site specifically to see it and told Fitz-Thors it was a genuinely novel approach they hadn't seen anywhere else.
The payoff was immediate and tangible. The day the C3PAO certificate came through, Fitz-Thors handed it to the sales team working that waiting contract. They won the contract the next day. The early bet on getting ahead of certification had paid off exactly as ownership hoped: certification wasn't just a cost of entry, it was a differentiator that competitors, still stuck at the self-assessment stage, couldn't match.
Looking Ahead
Fitz-Thors is early in its defense journey, with active subcontracts and a growing CUI footprint. The company has an incident response plan built alongside Cape, a trained response team, and a managed enclave it can trust, so its small IT team can focus on the business instead of lying awake wondering whether the environment is still in compliance.
The company's advice to other subcontractors staring down the same requirements is blunt: if you're a one-person IT shop, don't try to manage the enclave yourself. Lean on the people who do this for a living. In Lloyd's words, this is major-league baseball, and you can't play it with a sandlot team.
The Takeaway for Subcontractors
Fitz-Thors' story captures the new reality of the defense supply chain. CMMC flow-down requirements aren't a distant regulatory abstraction; they show up as a prime holding a contract until your certificate is in hand. The subcontractors who treat certification as a proactive investment, and who partner with a team that can build and run a compliant environment, don't just check a box. They win the work.


Comments