CMMC From Scratch: What No One Tells a Non-Security Hire, With Danielle Palmer

“I asked them at least 15 times over the years: are we sure we still want to do this? And they kept saying yes. So here we go.” 

Who They Brought In 

Danielle Palmer is the Senior Operations Manager at Fraym, a geospatial analytics company based in Arlington, Virginia with a fully remote global team spanning Canada, Ireland, Germany, and beyond. Fraym works with clients like the Gates Foundation on gender equity and economic development in Africa, and with the federal government including the National Geospatial Agency on defense-related analytics. The company is approaching its tenth year and has grown from delivering PowerPoint decks to building interactive, manipulable data dashboards at a global scale. Danielle came to Fraym from over a decade at Apple in technical support, with no cybersecurity background and no compliance experience. She has spent the last three-plus years inside one of the messiest, most instructive CMMC journeys a small company can have, and she is still standing. 

What Got Loud 

  • What it actually looks like to navigate CMMC as a team of one with no security background, no predecessor documentation, and a scope that keeps shifting under you 
  • Fraym’s original MSP got acquired mid-journey, decided not to pursue CMMC, and employed non-US-based technicians. Danielle had to pivot immediately or stay stuck 
  • Why being entirely cloud-based with a 75/25 Mac-PC split makes Fraym nearly impossible for most consultants to work with, and how that narrows the vendor pool fast 
  • CMMC scope is not a document. It is a living argument. Google was in scope, then it was not. Workstations were in scope, then they were not. The line keeps moving 
  • Two leadership changes in one year, including a CEO departure and the loss of the primary security officer, forced a full reassignment of admin responsibilities with no roadmap 

The Rundown 

Danielle’s CMMC story starts in January 2022 when she was hired specifically for her Mac technical experience and handed an additional task on day one: figure out whether Fraym needed to comply with CMMC, what that would require, and how to get there. She had never heard of CMMC. She had no security background. What she did have was the technical instincts from a decade at Apple and the operational discipline to start asking the right questions even when nobody could give her straight answers. 

The first major problem was scope. Fraym is not a traditional enterprise. They are entirely cloud-based with no on-premise servers. Their product runs on AWS. Their storage moved from Dropbox to Box. Their team runs 75 percent Mac and 25 percent PC, and they are global. Most CMMC consultants are built for Microsoft-heavy, on-premise environments and simply do not know what to do when faced with a setup like Fraym’s. “Very few people were familiar with our setup,” Danielle says. “Some people are just absolutely only Microsoft and that’s all they know. So they’re just not going to be able to work with us.” Finding a thought partner who could actually see their environment clearly took longer than it should have. 

The MSP transition is where the episode gets operational. Fraym’s original MSP was pursuing CMMC. Then they were acquired by a larger organization that decided not to pursue it and employed non-US-based technicians. Both of those facts made them immediately incompatible with what Fraym needed. The pivot had to happen fast, right as their contract was expiring. What made it harder is that the acquired MSP had not documented what they had done. The technician who had set up most of Fraym’s systems was gone. Danielle describes the transition as archaeology. “They were finding tools on our computers from the old MSP, installed and not even known about.” Cyberlynx came in through a conference introduction from Matt Connor and has been the right fit since. 

The scope conversation is the one that anyone navigating CMMC for a non-traditional organization will recognize immediately. Is Google in scope because contract information arrives via email? It was, then it was not. Are workstations in scope? That answer moved too. FCI, Federal Contract Information, sounds clear until someone describes all their quality data as FCI and it is not. Danielle is direct about what this costs: “I’ve been on version 22.5 of my documentation.” The DoD keeps moving and the organizations following it have to move with it, often mid-implementation. 

The personnel piece is what takes this episode beyond a standard compliance story. Two leadership changes in rapid succession, including a CEO departure and the exit of the person who had effectively been the security officer, forced Danielle to restructure the entire approval and implementation chain with no overlap and no documentation handoff. She is now the implementer. The VP of finance is the approver. Neither role was designed for this. Her honest take: “I’m a team of one. There is no other team with me. And that’s not enough for division of admin responsibilities.” 

Real Talk 

If your CMMC journey is messy, inconsistent, and more expensive than anyone told you it would be, Danielle’s experience is not a warning. It is a map. The companies that make it through are the ones who stay in the room and keep asking the question even when the answer keeps changing. 

Catch It 

Listen to the full episode on Apple Podcasts, Spotify, or wherever you get your podcasts. If this conversation made you think twice about your own security posture, let’s talk. Visit socsoter.com

If your Microsoft 365 environment hasn’t been reviewed lately, let’s fix that before someone else does it for you. Visit www.SOCSoter.com