FCI vs. CUI determination: We identify if you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to determine your required level.
Score estimation: Receive a preliminary Supplier Performance Risk System Score (SPRS Score) estimate.
The outcome: A clear roadmap. Take the action plan and execute it yourself, or waive the fees by enrolling in our Managed Service.
System Security Plan (SSP): We develop this critical document describing your system boundaries and operational environment.
Closing the gaps: We implement the technical controls required to meet NIST SP 800-171 standards.
Plan of Action & Milestones (POA&M): We create a compliant Operational Plan of Action for non-critical gaps, allowing you to achieve a Conditional CMMC Status while work continues.
For Level 1: We guide you through the required annual Self-Assessment to submit your results to SPRS.
For Level 2: We prepare you for the C3PAO (Certified Third-Party Assessment Organization) assessment, organizing evidence and ensuring your Security Protection Data is ready.
Continuous monitoring: We perform required ongoing monitoring to ensure controls remain effective.
Annual affirmation: We manage the data required for your Affirming Official to submit the mandatory annual affirmation.