Services
Services
Four engagements, scoped to the requirement you've actually been given. Most clients need one or two; some need all four in sequence.
NIST SP 800-171 assessment and SPRS scoring
A scored self-assessment against all 110 requirements of NIST SP 800-171, worked through the assessment objectives in SP 800-171A rather than a reading of the control text. The output is a score you can defend, a System Security Plan that describes the system you actually operate, and a POA&M with realistic dates.
If you already have a score posted in SPRS and aren't confident it's accurate, this engagement will tell you before a customer or the DoD does.
CMMC Level 2 readiness
Everything between a scored self-assessment and the C3PAO assessment. We work through the assessment objectives one at a time, assemble the evidence the assessor will ask to see, close the gaps that can be closed, and run a rehearsal so the first time you answer the assessor's questions isn't the one that counts.
We are not a C3PAO and do not conduct certification assessments. The firm that prepares you should not be the one that grades you.
Microsoft enclave design and build
A hardened Microsoft environment scoped to hold CUI and nothing else, so the rest of your business stays outside the assessment boundary. GCC High or Azure Government where the data requires it; a properly configured tenant where it doesn't. The environment is designed against the controls from the start, so the SSP describes what was built.
Nathan has built this environment and taken it through assessment. That is different from having read about it.
Remediation
For findings you already have, whether from a self-assessment, a previous consultant, a C3PAO or a customer audit. We fix them in your environment, working with your IT staff or your MSP, and produce the evidence that they're closed.
Scoped per finding or per POA&M. No retainer required.
Where we stop
What we don't do
Certification assessments
We are not a C3PAO. Readiness work and certification assessment are separate by design, and we keep them that way.
Managed IT
We build the enclave and hand it over with documentation. We don't run your helpdesk, and we work well alongside the MSP that does.
Paper compliance
If a control isn't implemented, it doesn't go into the SSP as implemented.
Not sure which one you need?
Send us the clause from your contract. A scoping call is free and takes about an hour.