
Cybersecurity services
What we actually do, in the order we do it.
Every engagement runs through the same five stages. Most clients start at the first one, because most cost overruns start with a boundary that was never properly defined. You can join later if your scope is already settled.
01 — The process
- 01
Scope
Boundary definition and CUI data flow: which systems, people and facilities are in, and what can defensibly be carved out.
- 02
Assess
A gap assessment against NIST SP 800-171, scored the way an assessor scores it, ending in an honest SPRS number.
- 03
Remediate
Policies, the System Security Plan, technical controls, and evidence collected and organized per practice.
- 04
Rehearse
A mock assessment, interview preparation for the people who will be asked, and POA&M closure.
- 05
Sustain
Continuous readiness, annual affirmation support, and planning for re-assessment.
02 — What you can engage us for
CMMC Level 2 readiness
NIST SP 800-171 gap assessment
SSP and POA&M development
Evidence and documentation program
Mock assessment and interview prep
Fractional security advisory
Product and delivery advisory
Start with your scope.
Tell us what you handle and where it lives, and we will tell you what is actually in scope before anyone quotes you for anything.
Talk to us