Compliance you can explain to an auditor
CMMC, NIST SP 800-171 and HIPAA work, from the first scoping conversation to the evidence in front of an assessor. We have CMMC Registered Practitioners on the team, and the controls behind the paperwork are ones we run every day.
This is probably for you if
- A Department of Defense contract has flowed CMMC requirements down to you
- You handle controlled unclassified information, patient data or client financials
- You have policies on paper that nobody has tested
What you get out of it
A clear picture
You learn which requirements actually apply to you before you spend a dollar.
Gaps closed in order
We work the list by risk and effort, so progress is visible from the start.
Evidence on hand
Documentation and records stay current, so an audit isn’t a scramble.
What’s included
Everything below is part of the service. If something you need isn’t here, ask — we’d rather tell you honestly whether it’s a fit.
- CMMC level determination and scoping
- Gap assessment against CMMC and NIST SP 800-171
- System Security Plan (SSP) and POA&M
- Control implementation, with our security team doing the work
- HIPAA risk assessment and safeguards
- Written policies and procedures
- Staff training and training records
- Evidence collection and retention
- Assessment and audit support
- Annual review as requirements change
How it works
1
Scope
We determine which requirements apply and what’s in scope — often smaller than people fear.
2
Assess and plan
A gap assessment, then a remediation plan ordered by risk, cost and effort.
3
Remediate and maintain
We implement the controls, document them, and keep the evidence current.
Let’s talk. A real conversation, not a sales call.
Fifteen minutes is usually enough to know whether we’re the right fit. If we’re not, we’ll tell you — and point you to someone who is.