How a 2-Person IT Team Passed CMMC and Won Their Biggest Contract Ever

by Jon Forisha on Sep 10, 2026

Trenton Systems does 65–70% of its business with the DoD, but ran its entire IT and compliance operation with just two people.

In this RADICL customer testimonial, JohnE Mullin, Trenton's Director of IT, talks about why they chose RADICL over CrowdStrike and SentinelOne for CMMC-required 24/7 monitoring, how RADICL's documentation helped them prove their security controls actually worked during the assessment, and how certification helped land the largest contract in company history.

Check out our Trenton Systems case study here.

Watch the full conversation, or read the transcript below.

Full Trenton Systems Testimonial Transcript

Interviewer: Can you say your name, your title, and explain what Trenton Systems does?

JohnE Mullin: Yes. My name is JohnE Mullin, Director of Information Technology here at Trenton Systems. Trenton Systems is a ruggedized server manufacturer that works with both commercial and DoD customers. We've pretty much switched over now — DoD is about 65 to 70% of our contracts.

Interviewer: And how did you first find RADICL?

JohnE Mullin: I was out looking for a SOC. We were going through our preliminary CMMC audit and was told that we really had to have somebody 24/7 — that I couldn't do it myself. So I went out and started looking at CrowdStrike and some others. During my research, RADICL came up, and I saw that you specifically work with smaller defense industry companies. I thought that would be a better fit than going directly with CrowdStrike and having to compete for attention with larger companies. So that's how I found RADICL, and I jumped on a call and started the relationship.

Interviewer: Okay, awesome. And how long ago was that?

JohnE Mullin: That's probably two, two-and-a-half years — maybe three.

Interviewer: Nice, okay, awesome. And how large is your IT or compliance team?

JohnE Mullin: The IT team — there's two of us. Actually, come Monday there'll be one, but right now there's two of us. So yeah, we're a small team. When I started here five years ago, we were about 60 employees. We're now up to about 100 to 110, so we've grown considerably over the past five years. One of the things we wanted to use to differentiate ourselves was to get CMMC certified, so I started working on that when I was hired. Like I said, I ran into RADICL when I was told that in order to meet CMMC, we had to have 24/7 monitoring, and RADICL fit perfectly into that — the SOC piece, plus working well with smaller businesses.

Interviewer: Excellent. If it weren't for the 24/7 requirement, were you going to try to hit the other controls yourself?

JohnE Mullin: That's what I was attempting to do. I had it set up where I'd get the notifications and everything, and the first question I got was, "Okay, so you're up at 3:00 in the morning if you get an alert?" And I said, "Hopefully I'm not up at 3:00 in the morning."

Interviewer: I know what you mean, yeah.

JohnE Mullin: So that's when they said, really, you need 24/7 to meet CMMC — you really can't do it on your own.

Interviewer: Got it, yeah. And once you started getting into it, to prepare for the assessment — did you find that it was a lot of work even outside of the 24/7 piece?

JohnE Mullin: Yeah, CMMC is definitely the hardest audit I've gone through. There's a lot of detail — making sure you have all the policies and procedures right. And not only did they have to be right, but they had to have the exact CMMC terminology the assessors wanted. That's really where I brought in a company to help with the pre-audit. That's really where we spent a lot of time — going through the policies and procedures I'd written, because there really weren't any before I started here, and then tweaking them to meet what was going to be required and what the assessors were going to be looking for.

Interviewer: Awesome. Okay, so you said when you were looking for a solution, that's when you came across RADICL. Did you shop us against other similar vendors?

JohnE Mullin: We did shop you against a few. I know CrowdStrike was one. SentinelOne was another one we looked at, and there was one other I can't think of off the top of my head. Most of them were larger companies, and I felt that with a smaller company like RADICL, we weren't just going to be a small business that's 30th down the priority list.

One thing that happened while I was talking with both CrowdStrike and RADICL — my first meeting was the day after the CrowdStrike outage that took down all the Windows machines. I was surprised CrowdStrike even jumped on the call with us, but they did. When I went to my manager and said I'd selected RADICL, and that RADICL would be installing CrowdStrike, the first question was, "Didn't they just have a major outage?" And my response was, yes, they did, so hopefully they've got it figured out for the future. We went with it, and we've been very happy. RADICL has been an excellent company to work with — I've really appreciated all the help I've gotten from everybody.

Interviewer: Excellent, awesome. Okay, so when you decided to go with RADICL, what products did you end up getting? Obviously compliance, but did you do the whole suite?

JohnE Mullin: We didn't do the whole suite — we're just on the SOC portion of it. So we have the basics to meet the requirements we have.

Interviewer: Nice, okay. And I think it was mid-June, about two months ago, that you guys passed your assessment?

JohnE Mullin: That is correct. We had the audit the last week of May, first week of June, and got certification authorized — I think it was right before July. So very happy with that. It was a tough five years, but I got through it. That was my major goal when I got here, and I was very happy with all the support I got. I worked with Josh quite a bit at RADICL to get documentation the assessors wanted. The response was excellent — they jumped on the line right away. Matter of fact, Josh was at the airport one time when we called, and he jumped on the line real quick and showed us what we needed. The assessors said yes, and that was it.

Interviewer: That's awesome, congratulations, that's huge!

JohnE Mullin: Thank you.

Interviewer: We're thrilled for you guys. Can you tell me more about how that process went? Did you do a mock assessment, or was there anything that surprised you once the assessment actually came?

JohnE Mullin: Well, there were a couple things. Like I said, I started here five years ago, and there wasn't an IT department. So the first thing I had to do was create the policies and procedures. After that, I worked with a local organization, the Georgia MEP, and they came on board and helped assess where we stood. They made some suggestions, and I made those changes. They came back about a year and a half later to verify everything was in place. We thought we were in good shape, and we went through our first audit in September of last year, right before CMMC was finalized — we were doing a NIST 800-171 self-assessment — and right out of the gate we found an issue, so they told me, "This pretty much means you won't pass."

So we went through and identified what it was, and it came down to two items. One, we were allowing the use of personal systems, so we removed that. The second was that we use PreVeil for our CUI enclave, and there's a setting that allowed you to copy files to the desktop, which I thought was covered because those desktops have full-disk encryption. They're encrypted and everything, but the assessors came back and said no — even though our policy says you can't copy it to a USB or elsewhere, once it's on the PC, somebody could still copy it. So we ended up working with PreVeil to make it fully cloud-based. When they came back for the reassessment, they said, "Yep, that's what we're looking for." And they saw the policy that we no longer allow personal systems onto the network — I showed them where we'd blocked that. Once those two things were resolved, it was just a matter of going through everything else.

Interviewer: Great, okay. So you had that experience already, so you sort of knew what to expect. And then when you started working with RADICL, you mentioned we were very communicative and Josh was able to hop on at all hours. How else did our team help you guys?

JohnE Mullin: Well, there are a couple things. One, some of the testing you did covered systems that weren't even flagged on our end. That was good, because I could show the assessors that we do proactive testing, and they liked that. The other thing is just the responses I get back from your group — I could show the assessors documentation where someone tried loading a USB drive that had some kind of malware on it, and it was blocked. They contacted me, and I could show exactly what we did to eliminate it. I had all the documentation from RADICL showing exactly the steps: they identified the USB drive, identified that it had malware on it, blocked it, and contacted me. I then followed up to determine whether it was a valid use case or not. All of that documentation — the assessors really appreciated it because it showed them we were doing what we said we were doing.

Interviewer: Awesome, awesome, so glad to hear that, that's great.

JohnE Mullin: And that's also — I mentioned malware there, but because we work on servers, we do our own BIOS work and things like that. So there's a lot of stuff we use that gets flagged as malware, because we're doing a lot with different BIOS builds. RADICL would contact me and say, "Hey, this user is using this program, it's touching your BIOS — it doesn't look like malware, but we've blocked it. Can you verify?" And again, I could show the assessors that yes, we get notified whenever something doesn't look right, and this is the procedure I follow to contact the user, verify they're actually using it, confirm what it's being used for, and then report back to RADICL, and they'll add it to a whitelist. I can show all of that documentation to the assessors.

Interviewer: Excellent. And their response to that was...

JohnE Mullin: They were happy, because that's something that, from talking with assessors, they don't get a lot of — usually they just get told, "Oh, RADICL protects us." And they'll ask, "Okay, how do they protect you?" and there's nothing to point to. But with RADICL, I can show exactly what happened. We can go through the portal, and I can show them: this is where you contacted me, this is my procedure for what I do when I'm contacted, and here's the end of the conversation where I said yes, please whitelist this, it's a program we do use.

Interviewer: That's great, that's great. Yeah, cybersecurity is always a funny thing, right — like, "we keep people safe, prove it."

JohnE Mullin: Well, it's like — the absence of being hacked is how you prove it. And that was the thing, they were like, "Well, do you have any more examples?" And I said, "Well, no, this is the only time we've had it, and it was an issue that somebody brought in on their own — that's the only thing we've caught." They said, "Well, how do you know—" and I said, "I can't prove a negative. I can't prove they've caught everything else if there's nothing there." So it was good that I had that one instance so they could see we were actually doing it. But the first time we were assessed, it wasn't RADICL — we used Redspin for that assessment, and I had nothing to show. They said, "Well, you're not going to be able to pass this, because you have no way to prove you're doing it." And I thought, "What am I going to have to do, put a virus on my own network just to prove you caught it?" And it turns out that's basically what happened.

There were certain things like that, even other items outside RADICL's scope, where the question kept coming up: how do you prove a negative? One example — we say we only use PreVeil for CUI data. How do you prove that? I do have a DLP that checks for CUI, so if something is CUI and someone tries to move it outside the proper channel, it would flag. But they'd say, "How do you know they're not just finding a way around your DLP?" I'm showing you what I'm doing, but something could still slip through — but that's true of any security control. Something new comes out today, you may not catch it the first time it appears. So, like I said, it was a very challenging assessment because there was a lot of that kind of thing — I'm not sure how you prove something like that. And of course, they say it's a maturity model, so you should be showing this over a certain amount of time, and I'm like, "But we've only been doing this for the last five years, I don't have data older than that. We had this one instance, we caught it — what else do you want?" The assessors this last time were very good, though — they understood. They saw everything Josh provided that showed, yes, we are capturing it.

Interviewer: Nice. And can you say more — you mentioned you tried to hack yourself to prove it worked?

JohnE Mullin: That was what I was saying I was going to have to do in order to actually generate a finding. But we ended up having a real finding anyway, so I didn't have to. But yeah, I was trying to think of what I could put on the system that you all would catch and I could point to as a virus or malware. So we ended up having something, so it wasn't an issue. But I was trying to figure out how to prove we do it without causing a problem on my own system.

Interviewer: We should really add that to our service offering — like a random, safe third-party test to prove it's working.

JohnE Mullin: Yeah, that could work — maybe something nondestructive you could push out that would show CrowdStrike picks it up and identifies it. It's a good idea. Honestly, the best-case scenario is I never have to talk to you — you're doing your job, and I don't have to worry about it. But trying to answer some of those "prove the negative" questions in an audit is difficult.

Interviewer: Exactly. I mean, essentially it's insurance, right?

JohnE Mullin: Yeah, yeah.

Interviewer: So — do you feel like it's a competitive advantage now that you're CMMC certified?

JohnE Mullin: Really, yes. We're one of, I think they said, about 1,100 companies certified — and there are something like 50,000 vendors in the DIB. So we're definitely treating it as a competitive advantage. We've had some of our contractors ask, "Are you going to get CMMC, when do you think you'll have it?" And now we can say, here's our certificate. We have it, and they say, "Great." I'm still waiting to see — I haven't verified yet — whether I no longer have to fill out these yearly security questionnaires. I'm hoping now I can just say, "Here's my certificate, I meet all the requirements," instead of spending an hour going through everyone's individual questionnaire.

Interviewer: Yeah, really? That would be nice. Do you know — it's been two months — do you know if there are any contracts you've won as a result of being certified?

JohnE Mullin: I know we just won one, and they did ask about CMMC, though I'm not certain we won it because of that. But it was a $70 million contract, or thereabouts. I think it was a fairly large contract for us, and they were like, "Oh great, you have your CMMC, that meets our security requirements." So I'll count that as a win because we were certified. And I know some of the newer contracts coming in still ask about it, even though they've put a hold on CMMC — as a matter of fact, last week I had to send our head of sales the certificate because we're working with a major prime, and they asked about it. We provided it to them, and we actually got the contract last week. I think they said that's the largest contract in our history. So it's definitely helping out. Even with CMMC being on hold right now, having the opportunity to show that we meet all these requirements is beneficial. It's definitely a competitive advantage.

Interviewer: That's fantastic. Yeah, I was going to ask about that, with it being on pause — there are so many companies that are probably a few months behind you who are now wondering if they should keep going.

JohnE Mullin: Well, truthfully, most of these requirements were already in all the contracts — under DFARS clauses 7012, 7019, and 7020 — so you were supposed to be meeting them anyway. The difference is that used to be self-attested. And the reason they moved to CMMC is that companies would self-report a perfect score of 110, and then an assessor would come in and find you're actually more like negative 40. So that was the whole purpose of CMMC — to bring in third-party assessment. But the requirements themselves have been there — I'm not sure exactly when NIST 800-171 came out, but it's been around a while.

Interviewer: Yep. And CMMC has been "coming soon" for a long time.

JohnE Mullin: Yeah, I'd say at least five years, because that's why I was hired — to get us ready for this. When I came on board it was still CMMC version 1 — they had just released it and then paused it. Then they went to version 2, and it was recently that they finally finalized the rule. And I think it was just about a week after we got our CMMC certification that they came back and said it's on hold again.

Interviewer: Yeah.

JohnE Mullin: My boss said, "Oh, that's great timing," but we have it — I can still show them the certificate. And one thing I found out that I didn't know about CMMC — my understanding is there's no public database for a prime contractor to check whether you're CMMC certified. You just put it into SPRS. I have to enter it into SPRS along with the 110 score, but there's nothing there that actually flags "you're CMMC certified." I thought that was strange, but the assessors told me that at our out-briefing — apparently one of the things the CMMC standards board discussed was not publishing who is CMMC certified. And the assessor said, "I would put it on a billboard on the highway that you're CMMC certified," because there's no other place people can look it up. So if you're a prime looking at SPRS, you're so used to everybody just listing a 110 that you don't know what we've actually had to do over the last five years to earn this. So now my email signature has the CMMC certification on it, and I think our team has started posting on LinkedIn saying we're CMMC certified. We're trying to get the word out.

Interviewer: That's so strange, I didn't know there wasn't a database — seems like a thing they should build.

JohnE Mullin: Yeah, I didn't know it either. I figured whatever the CMMC accreditation body is called, they would at least have a public list — so if somebody said, "I want to work with a CMMC-certified company," they could look at that board's portal and see everybody who's certified. They told me, no, that's not the case.

Interviewer: That's so strange — with how much work goes into it, that shouldn't be a secret, you should shout it from the rooftops.

JohnE Mullin: I think their thought process was, "Oh, you're CMMC certified, so now I'm going to specifically target you to see whether you've actually done it." But you're working in the defense industry — you're going to be attacked anyway. It's not like being certified suddenly puts a target on my back that wasn't already there. I really don't know why they're not publishing it for people to see.

Interviewer: Yeah. It'll be fascinating to see whatever they decide the future of the program is — obviously we're biased, but we think there's a lot of validity to it.

JohnE Mullin: So we'll see.

Interviewer: Yep. There's definitely a lot in there that you'd want people to know you've done. Alright — just a few more for you, thank you for your time. What's your favorite part of RADICL, or of working with RADICL?

JohnE Mullin: Just the relationship we've built. If I run into something, I can reach out to Josh, or go into the portal and put in a request, and I know I'm not waiting days for somebody to get back to me — it's quick. Like I said, we met with Josh at the beginning of our audit, and as we were finishing up, the assessors said, "Oh, we have a question about this." So I reached out — Josh was actually getting ready to go on vacation, at the airport, and he dialed in anyway. I pulled up the portal and said, "This is what you're looking for." He confirmed it, I took a screenshot, and the assessors were thrilled, because they really weren't sure we'd be able to get that answer. From when he got on the call to having it resolved was maybe 30 minutes. So that's really what I've enjoyed about working with RADICL — I know I can trust you, and if I have any issue, I can reach out to pretty much anybody on the team. Put in a ticket and it gets taken care of.

Interviewer: That's great, I love that. This next one is going to sound a little redundant, but bear with me — it's just for the sound bite. Would you recommend RADICL, and if so, why?

JohnE Mullin: I definitely recommend RADICL. Just the responsiveness we get. I was concerned when I was looking at going directly with CrowdStrike — like I said, we just had the CrowdStrike outage that took down all the Windows machines, and I know some smaller companies that use CrowdStrike directly had to wait a while for CrowdStrike to reach out, because of course CrowdStrike was busy with Delta, Microsoft, and everybody else. I don't feel like I have that issue with RADICL. I know I can contact RADICL, and it doesn't matter whether it's just me, or a company with hundreds of people behind them — they're willing to help.

Interviewer: Excellent. Alright, this is my last one for you — do you have any advice for organizations looking at compliance or cybersecurity, whether that's CMMC or just 24/7 SOC like we've been talking about?

JohnE Mullin: Yeah — really, my advice is to start now. It's a very large, very difficult audit, and it's going to take you time. What I'd suggest is finding partners who can take on a piece of it and help out — if you try to do it all yourself, you're going to have a hard time. Reach out to companies like RADICL that specifically work with defense industry companies — they can help you get through a lot of those issues.

Interviewer: Excellent. Okay, thank you again for your time. Is there anything else you think I should include that we didn't cover?

JohnE Mullin: Just — RADICL is a great company. Like I said, I really appreciate all the hard work and keeping us safe.

Interviewer: Excellent. Alright, well, congratulations again on passing your assessment, and — yeah, thank you for your time. This was great.

JohnE Mullin: I really appreciate it.

Interviewer: No problem, thank you very much, look forward to it. Alright, have a good one.

JohnE Mullin: You too, bye.

Get Email Notifications

No Comments Yet

Let us know what you think