Wēlr
Defense & aerospace · Defense depots & sustainment

Sustainment posture without the audit-week project.

Defense depots and sustainment programs — NAVAIR FRCs, Army depots, Air Force ALCs, DLA centers, and the sustainment contractors who execute depot-level work under their standards (Vertex, Sikorsky Support Services, AAR Government, M1 Support Services, L3Harris, Amentum) — operate weapon systems and ground-support equipment across multi-decade lifecycles. Your internal posture sits under AS9100D for engineering scope and AS9110 for maintenance execution; CMMC 2.0 governs the data architecture; CUI and ITAR scoping has to be enforced at the row, not by training. Your DCMA assessor wants continuous evidence, not annual reconstruction. Wēlr is the sustainment record where configuration management, modification execution, controlled-data scoping, and CMMC evidence converge.

AS9100D · AS9110MIL-STD-1916 · MIL-STD-130CMMC 2.0 Level 2NIST SP 800-171 r2CUI · ITAR · EAR
The service gap

Four pains the DCMA assessor will surface.

  • 01

    TMDE calibration and configuration baselines drift independently.

    Test, measurement, and diagnostic equipment recertification runs in one system; configuration management runs in another. Drift between them surfaces at the joint inspection, not before — and the platform that signed off a service event last quarter wasn't using the qualified TMDE the configuration baseline assumed.

  • 02

    Modification work orders execute outside the configuration record.

    Engineering change proposals approve a modification; the modification work order executes in the CMMS; the as-built configuration update happens by hand. Drift between approved-baseline and as-built is a process gap — and the assessor finds it.

  • 03

    Controlled-data access is policy-enforced, not architectural.

    CUI, ITAR, and program-clearance scoping is enforced by user training and document-marking. The platform doesn't know what data the user is allowed to see — citizenship, geography, and program-clearance attributes don't live on the record.

  • 04

    Sustainment program audits collect evidence after the fact.

    Annual program audits and CMMC assessments become document-collection projects. The day-to-day operating posture and the audit posture are different artifacts — and the gap shows up at the worst moment.

What Wēlr brings

Four primitives. One sustainment record.

01CAPABILITY

TMDE-aware calibration record

Calibration cycles for TMDE and configuration baselines share one record. The work order that closes against an out-of-tolerance TMDE flags the baseline impact automatically; drift between calibration interval and configuration commitment surfaces before the joint inspection.

02CAPABILITY

Controlled-baseline modification execution

ECP approval, modification work order, and as-built configuration update are one workflow. Drift between approved-baseline and as-built is a system error, not a process gap. Concurrent QA enforcement at the API.

03CAPABILITY

CUI / ITAR data architecture

Separate DEK namespace for ITAR and CUI. Citizenship, geography, and program-clearance attributes on every record. Access decisions made at the database row, not at the application layer. CMMC 2.0 AC-2 / AC-3 / AC-6 enforcement structural.

04CAPABILITY

Continuous CMMC 2.0 evidence

NIST SP 800-171 r2 control evidence — 3.4.3 (CM-3) configuration change control, 3.3.1 / 3.3.2 (AU-2 / AU-3) audit event capture, 3.1.1 (AC-2) account management — is produced by normal operation, not collected the week of the assessment. DCMA-ready continuously.

Vs. the alternatives

Why not extend the program's existing depot stack?

Most sustainment programs run a CMMS plus document-control plus a separate CMMC evidence collection cycle. Three regimes, three audit trails, one DCMA assessor.

CapabilityWēlr DoD-enclave build
18+ mo · cleared engineers · IL5/IL6 host
Commercial CMMS + DCS
Maximo + SharePoint + manual CMMC
TMDE + configuration baseline on one recordFirst-class modelCustom integrationTwo systems, reconciled
ECP → modification → as-built reconciliationSingle workflowManual reconciliationManual paperwork
CUI / ITAR data scoping enforcementDatabase row-levelCustom row-level workApplication-layer + training
Continuous CMMC 2.0 Level 2 evidence postureBy defaultAnnual projectManual collection cycle
Time to DCMA-ready postureWeeks (founding cohort)18+ months6+ months reconstruction
The artifact your DCMA assessor reads

ECP → MWO → as-built — baseline drift = 0 on the same record.

An engineering change proposal approves a sight-unit upgrade. The local CCB classifies and signs; the MWO issues with the kit pull list and IUIDs; the depot work order dispatches; the modification executes with kit IUIDs matched to the issued pull list; the QA signature lands; the as-built configuration baseline updates. The drift between approved-baseline and as-built is zero — and the CMMC 2.0 evidence is logged as a byproduct, not as an audit-week project.

  • ECP classification, MWO issuance, work order, and as-built update in one workflow — Class I or Class II routing supported
  • Kit IUID traceability from issue through install · removed-component disposition recorded against the MWO
  • Concurrent QA enforcement at the API · NIST 800-171 3.4.3 (CM-3) · 3.1.1 (AC-2) · 3.3.2 (AU-2) layered controls structural
  • CUI / ITAR scoping enforced at the database row — not by user training or document marking
Illustrative · example evidence
Configuration baseline · Vehicle USA-04781
ECP → MWO → as-built · baseline drift = 0 at modification close
BASELINE-USA-04781AS9100D · AS9110 · CMMC 2.0 · DCMA
  1. D+00ECPECP-2284 approved · Class II · local CCB · classification recorded
  2. D+08MWOMWO-44912-A issued against ECP-2284 · kit list released · IUIDs assigned
  3. D+30WO OPENWO-44912 dispatched · depot bay 7 · cleared technicians only
  4. D+32EXECKit install · OB-7821 (removed) → BIN-3018 · OB-9904 (installed) · IUIDs match issued pull list
  5. D+32QA SIGNConcurrent QA · NIST 800-171 3.4.3 (CM-3) enforced · technician 4118
  6. D+32AS-BUILTBaseline updated · drift-to-ECP = 0 · cleared for return-to-service
  7. D+32EVIDENCENIST 800-171 3.3.1 / 3.3.2 (AU-2 / AU-3) audit-event evidence logged · DCMA-ready
Decision-maker's checklist

If any of these are true, we should talk.

  • Your TMDE calibration and configuration baselines drift independently, and you find out at joint inspection.
  • An ECP-approved modification reaches as-built reconciliation through manual paperwork — and sometimes the reconciliation doesn't close.
  • CUI, ITAR, and program-clearance scoping is enforced by user training and document marking, not at the database row.
  • Your CMMC 2.0 evidence collection is an annual project, and the day-to-day operating posture and the audit posture are different artifacts.
  • A DCMA assessment or internal program review found a gap the team traced to evidence that lived in multiple systems and couldn't be reconciled inside the response window.
Founding partner program — accepting applications

A small founding cohort is shaping Wēlr for defense depots & sustainment.

Founding partners get preferential pricing, a direct line to engineering, and meaningful influence over the Defense & aerospace roadmap. Limited to a small cohort per vertical.

  • Preferential pricing
  • Direct line to engineering
  • Roadmap influence
  • Limited cohort
Apply to the founding sustainment cohort
Next step

Ready to stop stitching service evidence together?

If your team is juggling PDFs, support packages, work orders, customer updates, and QA evidence across five systems, Wēlr is worth a look.

Welr LLC · Delaware