Prevco Strengthens Cybersecurity and Protects Defense Contracts with Arizona MEP
Prevco Subsea Housings engineers and manufactures subsea housings, pressure relief valves and other subsea enclosures used in demanding environments. The company serves customers in defense, oil and gas, environmental monitoring and offshore renewable energy markets and works with several top defense prime contractors.
Because these customers require strict protection of federal Controlled Unclassified Information (CUI), the U.S. Department of Defense now requires companies in the defense supply chain to comply with the Cybersecurity Maturity Model Certification (CMMC). To remain competitive and maintain key defense contracts, Prevco needed to achieve CMMC Level 2 compliance aligned with the National Institute of Standards and Technology (NIST) SP 800-171 standard on protecting CUI.
The Challenge
Like many small manufacturers, Prevco faced the complex CMMC compliance process with limited internal IT resources. While the company worked with a managed IT provider for its technology needs, meeting the detailed documentation, policy and process requirements associated with CMMC presented a significant challenge. Prevco needed expert guidance to understand the 110 security controls required under NIST SP 800-171 and determine what steps were necessary to meet the new federal cybersecurity requirements.
Arizona MEP’s Role
Prevco first connected with Arizona Manufacturing Extension Partnership (Arizona MEP) through one of the organization’s leadership development programs. After learning about Arizona MEP’s cybersecurity and CMMC services, the company enlisted their support to guide the compliance process.
Arizona MEP’s cybersecurity experts worked closely with Prevco to evaluate its existing systems and practices against the NIST SP 800-171 requirements. The team walked Prevco through the 110 security controls, identifying gaps and helping the company develop the policies, procedures and documentation required for compliance.
Although Prevco was already following many sound cybersecurity practices, Arizona MEP helped formalize and document those processes to meet CMMC requirements. The team also
helped coordinate improvements with the company’s managed IT provider to ensure systems, backups and security protocols aligned with federal standards.
Results and Impact
Through the project, Prevco strengthened its cybersecurity posture and increased awareness of data protection practices across the organization. The company updated its employee handbook, implemented annual training on handling CUI and introduced stricter controls on who can access sensitive data. Systems were upgraded to secure government-level cloud environments and encrypted information-sharing practices were implemented.
“There is no way we could have done this ourselves,” said Liz Francis, Project Administrator, Prevco. “Without Arizona MEP’s assistance, the process would have been overwhelming. They helped us understand the requirements and put the right systems and processes in place.”
Prevco is now preparing for its third-party CMMC Level 2 audit while continuing to strengthen its cybersecurity framework. The project helped the company retain defense-related revenue and six jobs, and it invested $50,000 to upgrade IT infrastructure.