Skip to content
Noorad
Network cabling running through a rack of servers in a dark equipment room.

Cybersecurity services

What we actually do, in the order we do it.

Every engagement runs through the same five stages. Most clients start at the first one, because most cost overruns start with a boundary that was never properly defined. You can join later if your scope is already settled.

01 — The process

  1. 01

    Scope

    Boundary definition and CUI data flow: which systems, people and facilities are in, and what can defensibly be carved out.

  2. 02

    Assess

    A gap assessment against NIST SP 800-171, scored the way an assessor scores it, ending in an honest SPRS number.

  3. 03

    Remediate

    Policies, the System Security Plan, technical controls, and evidence collected and organized per practice.

  4. 04

    Rehearse

    A mock assessment, interview preparation for the people who will be asked, and POA&M closure.

  5. 05

    Sustain

    Continuous readiness, annual affirmation support, and planning for re-assessment.

02 — What you can engage us for

CMMC Level 2 readiness

The full engagement, scope through assessment day. We take you from an unverified SPRS score to a defensible one, with the evidence to back every requirement, and hand you to a C3PAO ready.

NIST SP 800-171 gap assessment

Your current state against all 110 requirements, scored the way an assessor scores it, with a prioritized remediation plan and an honest SPRS number.

SSP and POA&M development

A System Security Plan written to match how your environment actually operates, and a POA&M that is either closed or defensibly dated.

Evidence and documentation program

Policies, procedures and artefacts collected and organized per practice, so nothing has to be reconstructed the week before an assessment.

Mock assessment and interview prep

A dry run against the real scoring method, plus preparation for the people who will actually be asked the questions.

Fractional security advisory

Virtual security leadership for contractors without a full-time security lead. Standing advice on decisions as they come up, not a one-off report.

Product and delivery advisory

A secondary advisory line, separate from our cybersecurity practice.

Start with your scope.

Tell us what you handle and where it lives, and we will tell you what is actually in scope before anyone quotes you for anything.

Talk to us