CMMC
Readiness for Level 1 and Level 2 against NIST SP 800-171: scoping, gap assessment, System Security Plan development, remediation, and mock assessment. Where the program currently stands is set out on the CMMC page.
See also: CMMC Readiness
Readiness services
Someone has told you to prove your security, and a contract or a deal is waiting on the answer. We get you ready, and we are independent of whoever grades you, so the advice you get is not shaped by anything except passing.
A prime sends a flow-down. A customer sends a questionnaire. An agency names a standard in a solicitation. However it reached you, the deadline belongs to someone else now and the evidence does not exist yet.
The work is the same shape across every framework (scope the environment, measure it honestly, close what is missing, prove the rest) even though the control sets differ enormously. What changes between CMMC and SOC 2 is the evidence an assessor expects and the vocabulary they expect it in.
What we do
Readiness for Level 1 and Level 2 against NIST SP 800-171: scoping, gap assessment, System Security Plan development, remediation, and mock assessment. Where the program currently stands is set out on the CMMC page.
See also: CMMC Readiness
Readiness for cloud service providers pursuing federal certification, across both the 20x path and legacy Rev5. Current program status and terminology are set out on the FedRAMP page.
See also: FedRAMP Readiness
Control implementation and assessment support for federal systems and for organizations inheriting federal control requirements through a contract. Also the underlying catalog that FedRAMP baselines draw from, so the two engagements often run together.
Risk-based program development for organizations that need a defensible security posture without a specific certification driving it. Frequently the right starting point when a customer questionnaire has arrived and there is no program to point at yet.
Security and privacy readiness for covered entities, business associates, and health technology companies. HIPAA sets the obligation; HITRUST provides a certifiable framework that satisfies customers who want more than an attestation.
Scoping and readiness for organizations that store, process, or transmit cardholder data. As with CMMC, most of the cost is determined by how much of your environment falls in scope, and reducing that scope is the work that saves the most money.
Information Security Management System development and readiness for certification audit: risk assessment methodology, Statement of Applicability, control implementation, and the internal audit and management review evidence a certification body expects to see operating.
Readiness for Trust Services Criteria examination. Type 1 tests design at a point in time; Type 2 tests operating effectiveness over a period, which means evidence collection has to be running well before the audit window opens. Planning that window is most of the value.
Process
Determine what is actually in scope. This governs the cost of everything downstream, and an environment scoped too broadly is the most common reason compliance programs run over budget.
Measure the environment against the control set and produce a scored gap register: specific findings tied to specific requirements, not a maturity rating.
Write the policies, procedures, and system documentation the framework requires, describing your environment as it is rather than as a template imagines it.
Close gaps in priority order, tracking remediation items and collecting the evidence that proves each control operates.
Run a mock assessment against the same procedures a real assessor uses, so the first graded run is not the one that counts.
Deliverables
Every engagement produces documentation you can hand to an auditor, a customer, or your own board without translating it first.
FAQ
No. We prepare organizations to be assessed and never perform the assessment, whichever framework is involved. Certification and attestation are done by accredited certification bodies, licensed CPA firms, or authorised assessors depending on the standard.
That separation is the point. Nothing about our advice is shaped by wanting to grade you later.
It should not be. Most frameworks share a large proportion of their underlying controls, and the expensive part is evidence rather than policy.
Mapping shared controls once and collecting evidence once means a second framework is largely a reporting exercise rather than a second programme. Running them as separate projects is how organizations end up audited twice for the same work.
Scope drives it more than anything else, followed by how much of the work your team absorbs versus how much we do. A scoped environment with an existing IT function is a materially different engagement from an enterprise-wide effort with no dedicated security staff.
The floor is set by evidence. Some requirements need a period of operating history, and that cannot be compressed with budget.
Scope, before anything else. It governs the cost of everything downstream, and it is the one decision that is expensive to revisit later.
The first conversation is usually about narrowing it, including telling you when a smaller engagement is the right answer.
Tell us which framework and what triggered it. The first conversation is usually about narrowing scope.