Skip to content

CASE STUDY

RIB U.S. COST: Achieving CMMC Certification with Commander Managed GRC 

RIBUSCost_Logo

 

About RIB U.S. COST

Industry: Aerospace, Construction, Contract Management

Services: RIB U.S. Cost is a leading provider of construction cost estimating and project controls, with over 40 years of experience serving both commercial and federal clients. Their expertise spans capital planning, cost management, scheduling, and procurement across all phases of construction. As a defense contractor handling Controlled Unclassified Information (CUI), they prioritized cybersecurity and compliance while maintaining a lean team. To meet CMMC Level 2 requirements without overextending internal resources, they partnered with Summit 7 for managed services through Commander, Guardian, and Vigilance.

Problem: After a 2021 breach involving sensitive government data, RIB U.S. Cost faced growing pressure to strengthen cybersecurity and formalize compliance. Limited internal resources and informal documentation made it difficult to meet NIST SP 800-171 and CMMC standards. Existing IT vendors lacked the expertise to guide them through federal compliance. RIB U.S. Cost needed a scalable, expert-driven solution that wouldn’t require building a large in-house security team.

"Just because we’re certified, it doesn't stop here...Technology is constantly changing. Criminals are getting smarter. That’s why I stay committed to using Commander—even though we’ve achieved it, it’s always changing."

Suzanne Moltzen
CEO, RIB U.S. Cost

RIB US Cost - Construction 2

 

RIB U.S. COST: Achieving CMMC Certification with Commander Managed GRC 

 

Learn how RIB U.S. COST achieved:

  • CMMC Level 2 Certification: See how Summit 7 helped RIB U.S. Cost formalize its cybersecurity program, translating undocumented processes into compliant policies aligned with NIST SP 800-171 and CMMC Level 2 requirements.

  • Breach Recovery and Resilience: Discover how the company turned a costly data breach into a catalyst for long-term security investment, using Summit 7’s managed services to prevent future incidents and build operational resilience.

  • Tailored GRC Support: Learn how Commander guided RIB U.S. Cost through complex compliance requirements with custom documentation, hands-on collaboration, and practical policy development that fit their business model.

  • Security Without Headcount Growth: Explore how RIB U.S. Cost scaled its cybersecurity program without hiring an internal team of specialists, relying instead on Summit 7’s Guardian and Vigilance services for continuous protection and monitoring.

  • Sustained Compliance Commitment: Find out how Summit 7 enabled RIB U.S. Cost to maintain momentum beyond certification, providing ongoing support and expertise as threats evolve and compliance standards shift.

"The Commander team worked closely with my cybersecurity analyst to make sure we had the policies and procedures in place to meet CMMC requirements that flowed with how we do business. We got our [CMMC] certificate in hand, and it was the biggest sigh of relief..."

Suzanne Moltzen
CEO, RIB U.S. Cost

Background

RIB U.S. Cost has been a trusted leader in construction cost estimating and project controls for over 40 years. Founded in a small basement office in Atlanta, the company has grown into a major contributor in the industry, combining technology and industry expertise to deliver exceptional professional services to clients worldwide. 

Their expertise encompasses construction estimating, cost management, scheduling, and value engineering at all phases of a project, including Capital Planning, Pre-Construction, Procurement, and Construction.  

 

The Challenge

Much of the content they handle—particularly drawings coming out of Washington—are marked as Controlled Unclassified Information (CUI). After a data breach in 2021 involving an affiliate’s hard drive containing government data, RIB U.S. Cost experienced a significant financial and personnel burden. Although the company had been working to achieve full compliance with NIST 800-171, CEO Suzanne Moltzen recognized the implementation needed to be accelerated.  She knew her company needed to invest more fully in cybersecurity and compliance if they wanted to continue to lead the way in their industry. But like many small federal contractors, she is pulled in many different directions. 

She said, “I want to get it right, but my attention is always divided. There's always something that needs to be done, so that's why I stay committed to using Commander [Summit 7’s Managed GRC Solution].” 

Additionally, much of the company’s operations and policies lived in her head, so they knew they needed documented, repeatable processes. While they had adopted some cybersecurity best practices, they struggled to demonstrate those efforts on paper, which is an essential step toward compliance with CMMC (Cybersecurity Maturity Model Certification)

“Even if we’re doing the right things, we need to be able to show that we’re doing the right things,” said Moltzen. 

 

The Solution

RIB U.S. Cost partnered with Summit 7 and was among the earliest adopters of their managed services,  Guardian and Vigilance. As their compliance journey evolved, they added Commander, Summit 7’s managed governance, risk, and compliance (GRC) service.  

The Commander team worked closely with RIB U.S. Cost’s internal cybersecurity analyst to tailor policies, procedures, and documentation that not only aligned with CMMC Level 2 but also fit the company’s actual business operations. 

“For me, it took someone to slowly work us through that… translating what my employees needed to do into a written policy,” said Moltzen. “That is where I found Commander to be very useful.” 

 

The Results

RIB U.S. Cost officially received their CMMC Level 2 certification in early 2025. While it brought a moment of relief, Moltzen knows it’s only the beginning of a continuous effort. 

“It was the biggest sigh of relief for a moment because I also realized that just because I’m certified, it doesn’t stop here,” she said. “We have to be committed… especially after going through what happens when you’ve had a breach.” 

The breach in 2021 led to costly forensic recovery—15-hour days and a monthly expense greater than a full year’s worth of Summit 7’s services. 

“We spent more in a month with forensics than I spend in a year now with Summit 7,” Moltzen emphasized. “My number one advice: find the experts, use them, appreciate them.” 

Because of their investment in Commander, RIB also has confidence in the future of their cybersecurity and compliance. 

 

"Just because we’re certified, it doesn't stop here...Technology is constantly changing. Criminals are getting smarter. That’s why I stay committed to using Commander—even though we’ve achieved it, it’s always changing."

Suzanne Molten
CEO, RIB U.S. Cost

S7_logomark

Custom-Built CMMC Solutions on Azure Government

Summit 7 has developed a comprehensive CMMC compliant solution as well as a robust set of managed security tools in its product line to form the CMMC Managed Security Solution. This Managed Security Solution set is designed to support the DIB in their journey to protect critical US data.

The core requirements of the CMMC Managed Security Solution utilize E5 licensing in Microsoft 365 GCC High and multiple security workloads within Azure Government.