Designed for Defense. Powered by Experience.

Cuick Trac helps defense contractors protect CUI through a managed enclave approach designed to simplify evolving cybersecurity and compliance requirements.

Safeguard sensitive information.
Strengthen the supply chain.
Support those who serve.

Who we are

Beryllium launched Cuick Trac in 2018 after years of supporting organizations across the Defense Industrial Base (DIB) through evolving cybersecurity and compliance requirements. Through that experience, we saw firsthand how difficult it was for small and mid-sized contractors to build, maintain, and continuously manage compliant environments for Controlled Unclassified Information (CUI).

Cuick Trac was created to simplify that challenge through a managed enclave approach built specifically for defense contractors navigating DFARS 252.204-7012, NIST SP 800-171, and CMMC Level 2 requirements.

Today, Cuick Trac helps organizations protect CUI within a controlled enclave environment designed to reduce compliance complexity, maintain assessment readiness, and adapt alongside evolving cybersecurity requirements without requiring organizations to continuously rebuild internal infrastructure.

About Beryllium InfoSec

Beryllium

A rare element that when alloyed even 2% with other metals makes them six times stronger than on their own

Where We Operate

• Dallas, TX (Headquarters)
• Minneapolis, MN
• Melbourne, FL

How we do it

We combine managed enclave infrastructure with compliance expertise to simplify CMMC readiness.

Our Mission

We believe cybersecurity compliance should be operationally achievable for defense contractors of all sizes. Our mission is to help organizations protect sensitive government information through a structured, manageable approach to compliance that reduces complexity without disrupting how teams work.

Leadership

Andy Woods
Chief Executive Officer
Greg Coleman
Chief Revenue Officer
Melissa Gibbons
Mike Maslauskas
Head of Finance
Teddi Clayton
Head of Project Management
Kim Derby
Head of Human Resources
Cole Field
Chief Marketing Officer

Frequently Asked Questions

Cuick Trac was created after years of supporting organizations across the Defense Industrial Base (DIB) through evolving cybersecurity and compliance requirements. We saw firsthand how difficult it was for contractors to build and continuously maintain compliant environments for Controlled Unclassified Information (CUI), especially as requirements evolved over time.

Beryllium combines compliance expertise with a fully managed enclave environment (CTME) designed specifically for protecting CUI. Rather than only providing guidance, we help organizations operate within a controlled environment built to simplify ongoing compliance management.

Cuick Trac supports organizations across the Defense Industrial Base, including manufacturers, engineering firms, aerospace companies, research organizations, and defense contractors handling Controlled Unclassified Information (CUI).
Our approach focuses on simplifying compliance through controlled infrastructure, continuously maintained security controls, and operational support designed to reduce complexity as cybersecurity requirements evolve.

No. Cuick Trac is designed as a dedicated enclave environment for handling CUI, allowing organizations to maintain their existing business systems for non-CUI workflows while isolating sensitive government information within a controlled compliance boundary.

The DFARS 252.204-7012 clause says that if you handle Controlled Unclassified Information, you should have implemented NIST SP 800-171 no later than Dec 31, 2017. Since this deadline has passed and many defense organizations don’t meet this current requirement, the DoD developed CMMC. Organizations within the DoD supply chain need a risk-based approach to become compliant, and more importantly, secure their environments where CUI is processed, stored and transmitted.

NIST SP 800-171 is the National Institute of Standards & Technology (NIST) special publication providing 110 recommended security controls for protecting the confidentiality of CUI (Controlled Unclassified Information – a subset of CDI).

 

The Cybersecurity Maturity Model Certification (CMMC) is the standard the Department of Defense (DoD) is using to verify the members of the Defense Industrial Base (DIB) fully meet their cybersecurity requirements, prior to contract awards.

In September, 2020, the DoD released a new interim rule, approved by the Office of Management and Budget (OMB), that requires all contractors subject to DFARS 252.204-7012 within the DoD supply chain, to have an accurate assessment on record, prior to award. The interim rule becomes a bridge between the self-assessment process of DFARS 252.204-7012/NIST SP 800-171, and the verification/certification process of CMMC. The DFARS Interim Rule helps enforce full compliance and the importance it provides to our national security.

The results of Assessments are documented in the Supplier Performance Risk System (SPRS) at https://www.sprs.csd.disa.mil/ to provide DoD Components with visibility into the scores of Assessments already completed; and verify that an offeror has a current (i.e., not more than three years old, unless a lesser time is specified in the solicitation) Assessment, at any level, on record prior to contract award.

The score submitted to SPRS is based on the NIST SP 800-171 DoD Assessment Methodology. If an organization is not able to prove requirements are met, with objective evidence, should not receive credit for that specific requirement. Cuick trac™ provides a significant increase of an SPRS score, making the path to 110 much more manageable.

No. If an organization knows it isn’t compliant, they need to focus on solutions that best fit their business. A Cuick Trac subject matter expert (SME) will help an organization identify CUI data flow, scope and boundary for free. Once the identified users in scope are using the Cuick Trac enclave, the customer and Cuick Trac conduct an assessment of the NIST SP 800-171 controls (and CMMC practices and processes using the latest version of the CMMC Assessment Guides) and create/update the SSP. All remaining gaps become the POA&M (physical and administrative controls outside of the Cuick Trac enclave, if applicable) and shortens the path to completing your plan of full implementation and on-going/continuous compliance.

Besides the risk of failing a future CMMC certification, organizations who fail to prove that they have NIST SP 800-171 fully implemented and continuously monitored, will lose the opportunity to be awarded new DoD contract awards, and potentially face fines or loss of contract.

The Federal government. By law, businesses handling Controlled Unclassified Information (CUI) are required to become, stay and prove DFARS/NIST 800-171 compliance in order to be awarded and keep contracts. Also, primary (prime) contractors have the right to ask for proof of compliance through SSP and POA&M audits and reviews, before selecting sub-contractors.

Yes. Under the DFARS clause, contractors must report cyber incidents within 72 hours of them happening. That’s a difficult thing to accomplish if your business doesn’t have the personnel or resources to always be monitoring your security information and event management solution (SIEM). Cuick Trac has a SIEM monitoring the enclave, and that information is reviewed by Cuick Trac security analysts and reviewed with Cuick Trac customers on a regular basis.

Join Our Team

Cuick Trac is growing—and we’re looking for passionate cybersecurity professionals who understand the strategic needs of defense contractors and want to help them succeed.

Part of the most relevant
industry groups and committees

Partner With a Team That Understands the Mission

Blog

Actionable insights on compliance, cybersecurity, and securing CUI, straight from the front lines of the defense industry.

Open positions

Natoque vel vulputate urna

Pharetra semper quam sit magnis ac habitant lorem massa aliquam laoreet sed odio tincidunt viverra integer ultrices.

Gravida ullamcorper sit

Pharetra semper quam sit magnis ac habitant lorem massa aliquam laoreet sed odio tincidunt viverra integer ultrices.

Vestibulum tristique volutpat

Pharetra semper quam sit magnis ac habitant lorem massa aliquam laoreet sed odio tincidunt viverra integer ultrices.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.