CMMC tracking for small defense contractors still running it in spreadsheets.
Aegis helps small and mid-size defense contractors track CMMC controls, owners, and progress in one place. Built by engineers with military and Fortune 500 regulated-systems backgrounds, not a generic GRC vendor.
Enterprise GRC tools were not built for a 25-person contractor.
What most small contractors do today
- Track controls in spreadsheets that drift out of date
- Store evidence across shared drives with unclear ownership
- Pay consultants to rebuild the same picture every assessment cycle
- Struggle to show a prime or assessor a clean status view on short notice
What Aegis is for
- One place to see control status across Level 1 or Level 2
- Named owners and notes on each practice
- A path to keep detailed evidence in your own environment
- A tool sized for teams that cannot staff a full GRC program
Your compliance data does not have to live on a startup’s servers.
Defense contractors are right to be careful about where CMMC evidence sits. Detailed notes, system diagrams, and configuration screenshots can include sensitive material.
Aegis handles the workflow layer. Evidence files and detailed notes can stay in storage you control, such as your Microsoft 365 tenant.
What Aegis provides
Control catalog, status tracking, ownership, progress views, licensing, and product updates.
What can stay with you
Evidence files, detailed implementation notes, and other content you treat as sensitive, held in your SharePoint or Azure storage.
Three steps. No enterprise implementation project.
Set your target level
Choose Level 1 or Level 2 and load the control set your contracts require.
Assign and track
Mark status, name an owner, and keep notes on each practice as work moves.
Keep evidence where you want it
Use Aegis for the workflow. Keep sensitive files in storage your organization already trusts.
Three Marines. Same MOS. Still working in IT.
Jakob Hagan, Isaiah Niedrauer, and Armando Nieves met in the Marine Corps in the same cyber and data systems MOS. They stayed friends after service and all remained in IT.
Jakob spent four years in the Marine Corps as a 0651 and 0671. He held a secret clearance and operated in highly secured environments. He then spent four years leading a systems engineering team at one of the largest Fortune 500 healthcare companies in the country, working under strict HIPAA requirements. After that he became the lead of systems engineering and moved into enterprise security architecture at a Fortune 500 telecom subject to SOX and PCI DSS compliance. Across military service and civilian roles, that is ten years of experience building and defending systems in highly regulated environments.
Armando Nieves spent four years in the Marine Corps as a Data System Administrator, then moved into civilian systems administration and IT operations roles supporting business environments. Isaiah Niedrauer also stayed in IT after service. Aegis is the three of them applying that shared background to a narrower problem: helping small defense contractors run CMMC without enterprise GRC tools or spreadsheet chaos.
We are onboarding a small set of design partners.
If you are a small or mid-size defense contractor working toward CMMC Level 1 or Level 2, and you are still running the process in spreadsheets and shared folders, we want to talk. Design partners work directly with the founding team and help decide what gets built next.
Email us to request access