Home/About

Built for the Defense Supply Chain

An Atlanta-area firm, based in Buford, Georgia, that runs CMMC Level 2 compliance programs for Defense Industrial Base contractors. We do not serve commercial clients. Every method, tool and process is built for the DIB.

Tony Tran, Founder and CTO of TRANUSA, LLC
Tony Tran
Founder & CTO ยท TRANUSA, LLC
MBA  ยท  MS, Information Technology
Technology due diligence across dozens of acquisitions
Teaches cybersecurity and information assurance at community colleges and universities
"I have been the shop carrying the requirement. I have also been the one doing the diligence that finds it missing."

Before TRANUSA, I spent close to twenty years in manufacturing: industrial single-board computers, large-format fine-pitch LED displays, and the aerospace machine shops and CNC operations that build parts for the U.S. military. I know what a shop floor runs on, what a schedule costs, and what happens when a control gets in the way of production.

I have also spent years on the other side of the table, performing technology due diligence on acquisitions. Dozens of them. That work is where you learn what a compliance program is actually worth, because diligence is the one moment when somebody with money at stake reads the documentation instead of taking your word for it. I have opened a System Security Plan that described a system that no longer existed. I have been handed an evidence locker that was a folder of screenshots with no dates on them. Nobody set out to mislead anyone. The program had simply been treated as a project that ended.

In 2025 I moved TRANUSA fully into compliance for the Defense Industrial Base, for one reason. I kept watching small and mid-sized manufacturers get buried under CMMC and NIST SP 800-171 requirements they had no staff to absorb, while depending on DoD work for a large share of their revenue. The requirement was not the problem. Having nobody whose job it was to carry it was the problem.

So we carry it, and we hold ourselves to the same standard. TRANUSA brought its own environment into NIST SP 800-171 compliance, operates its own Microsoft 365 GCC High tenant, and runs its stack in U.S. sovereign cloud with a U.S. Persons-only team. Every control we ask a client to implement, we have implemented ourselves first.

I also hold an MBA and a Master’s in Information Technology, and I teach cybersecurity and information assurance at community colleges and universities. That is not decoration on a bio. Explaining this material to people who have never seen it before is most of what this job actually is. The hard part of compliance is rarely the technology. It is getting a room full of people to understand why the requirement exists, and then keep following it after we leave.

That is also why the tooling is not the pitch. A stack is a week of procurement. A compliance program that survives an assessor, and keeps surviving one, is something else entirely, and it is the only thing your customer is actually asking you for.

Where We Stand

๐Ÿ“
Headquarters
Buford, Georgia · USA
Domestic operations. U.S. Persons-only engineering and monitoring team, with no offshore access to any client environment.
โ˜๏ธ
Infrastructure
Microsoft 365 GCC High
TRANUSA operates its own Microsoft 365 GCC High tenant, the U.S. sovereign Microsoft environment built for CUI and ITAR-controlled data. Never commercial infrastructure.
๐Ÿ”
Team Credentials
CMMC Registered Practitioner (RP) · CISSP
CompTIA A+, Network+, Security+, Linux+ · Microsoft · AWS
Practitioners credentialed through the Cyber AB ecosystem. We hold ourselves to the same standard we set for clients.
โš–๏ธ
Assessor Independence
We Take No Fee From Any C3PAO
Under any circumstances. Your assessor's independence is what makes your certification defensible, and a referral fee flowing the other way is a conflict under the Cyber AB Code of Professional Conduct. We will not put your result at risk for a commission.
๐ŸŽฏ
Focus Area
100% Defense Industrial Base. No Exceptions
We do not serve commercial or non-defense clients. Every methodology, every tool, every process is built for the DIB.

What We Are, and What We Are Not

We hold ourselves to the standard we set

TRANUSA brought its own environment into NIST SP 800-171 compliance, operates its own Microsoft 365 GCC High tenant, and runs its stack in U.S. sovereign cloud with a U.S. Persons-only team. Every control we ask a client to implement, we implemented on ourselves first. That is not a marketing line, it is the reason we can tell you how long something takes and be right.

What we are not

  • We are not a C3PAO. We cannot certify you, and no firm can both prepare and certify the same client.
  • We are not your IT department. Frontline support stays with you; we sit behind it as Tier 2 and Tier 3 for the compliance environment.
  • We do not run a staffed watch floor. Continuous SIEM alerting with 24/7 escalation to on-call engineering is what we operate, and it is what we say.
  • We do not take fees from assessors. Ever.

Book a CMMC Readiness Call

Thirty minutes. We review your contract requirements, identify your top compliance gaps, and give you a realistic timeline to audit readiness. No pitch decks, no obligation.

Book Your Call →
or email CMMC@tranusa.com