
Industry: Industrial & Defense Manufacturing Service Focus: On-Prem Exchange Server Upgrade, Security Hardening & CMMC/DFARS Compliance Engagement Length: 8 Weeks | Downtime: Zero
A 280-employee industrial equipment manufacturer supplying parts to automotive, aerospace, and defense customers was running Exchange Server 2016 — 18 months behind on security patches — and it nearly cost them an $18M defense contract. We came in as the white-label technical team for their MSP partner, upgraded them to Exchange 2019 with zero downtime, closed 23 critical/high vulnerabilities, and got them through a CMMC Level 2 assessment with zero Exchange-related findings. They kept the contract. Then they won $6.2M more in new business because of it.
Here’s how it actually happened.
If you support manufacturers in the defense supply chain, you already know the drill: DFARS and CMMC compliance isn’t optional, and “we haven’t had a breach yet” is not an answer auditors accept.
This particular manufacturer was in that exact spot. Defense contract requirements meant they couldn’t lift-and-shift to the cloud — classified workloads and legacy system dependencies kept them on-prem, full stop. That’s a common reality for a lot of manufacturing and defense clients, and it’s exactly the kind of environment where things quietly fall behind because nobody wants to touch a live mail server.
Their in-house IT team — just three people — was already stretched managing day-to-day operations. Exchange patching kept getting pushed. By the time their MSP partner brought us in, the environment looked like this:
Then came the letter every manufacturer in the defense supply chain dreads: formal notice from the prime contractor that remediation was required to keep the contract. That’s when the timeline stopped being flexible.
Three things had to be true at the same time, or the project wasn’t a success:
And it had to happen with a rollback plan in place, because nobody signs off on a mail migration with no safety net.
We ran this as an 8-week side-by-side upgrade — meaning Exchange 2019 came up right alongside the existing 2016 environment instead of replacing it in place. That approach is the difference between a stressful cutover weekend and a migration nobody even notices.
Before touching mail flow, we replaced the aging hardware:
We added the new Exchange 2019 servers into the existing Database Availability Group (DAG), then moved mailboxes department by department — IT & Admin first, then Engineering, then Manufacturing. Nobody lost access mid-move. Once everything was validated on the new platform, we decommissioned the old 2016 servers.
This is where most of the real risk reduction happened:
If you want a closer look at how we approach this kind of layered hardening across client environments, it’s the same discipline behind our managed security services.
CMMC and DFARS assessments live and die on documentation, so we treated that as a deliverable, not an afterthought:
This is the kind of groundwork that makes security compliance and reporting something you can point to with confidence instead of scrambling to prove after the fact.
We didn’t take “it should work” as an answer:
We wrapped with full architecture and disaster recovery runbooks, hands-on admin training on Exchange 2019 and the new security stack, and documented patch management and incident response procedures — so their three-person team could run this independently going forward, not call us for every routine task.
That last one is worth sitting with. This didn’t just fix a compliance problem — it became a competitive advantage.
If you’re supporting clients under DFARS or CMMC requirements, on-prem Exchange isn’t going away just because the cloud is easier to sell. Classified workloads, legacy dependencies, and contractual requirements keep plenty of manufacturers anchored on-prem — and that means someone still has to patch, harden, and prove compliance on infrastructure most vendors would rather you forget exists.
We built our white-label delivery model around exactly that gap: deep Exchange expertise, a side-by-side migration methodology that doesn’t ask your client to accept downtime, and compliance documentation that holds up when an actual auditor shows up.
What is a side-by-side Exchange upgrade, and why use it instead of an in-place upgrade? A side-by-side upgrade runs the new Exchange version alongside the existing one instead of upgrading in place. New servers join the existing DAG, mailboxes move over in controlled waves, and the old environment is decommissioned only after everything’s validated. It’s the approach most experienced Exchange admins prefer specifically because it avoids the all-or-nothing risk of a single cutover window.
Can you pass CMMC Level 2 with Exchange Server still hosted on-prem? Yes. On-prem Exchange doesn’t disqualify you from CMMC Level 2 — but it does mean encryption, access control, audit logging, and retention policies all need to be configured and documented correctly. In this case, proper hardening and evidence documentation resulted in zero Exchange-related findings.
Why would a company keep Exchange on-prem instead of moving to Microsoft 365? Usually it comes down to classified workload requirements, legacy application dependencies, or contractual/regulatory obligations — all common in defense manufacturing. Cloud migration isn’t always the available option, so hardening what’s already on-prem becomes the priority.
How long does an Exchange 2016-to-2019 upgrade like this typically take? This engagement took 8 weeks end to end, covering infrastructure buildout, phased mailbox migration, full security hardening, compliance documentation, and testing — with production email staying online the entire time.
What’s the real risk of falling behind on Exchange Server patching? Unpatched Exchange servers are a direct path to exploits like ProxyLogon and ProxyShell — both actively used in real-world attacks. Beyond the security exposure, falling behind can also trigger compliance failures that put contracts, certifications, and client trust at risk.
TechMonarch provides white-label managed IT services — including on-prem Exchange upgrades, security hardening, and compliance implementations — for MSPs supporting manufacturing and defense organizations across the U.S.