COMPLIANCE

Two letters from a customer can put you in scope.

Most firms do not go looking for a compliance requirement. It arrives — in a contract clause, on an insurance application, or in a security questionnaire from a customer who just got audited. Then somebody has ninety days to produce what should have taken a year to build. This page is about getting there before that letter shows up.

DEFENSE SUPPLY CHAIN

CMMC, and which level actually applies

The level is set by the kind of government information that lands in your systems — not by your size or the size of the contract. Level 1 is fifteen requirements from FAR 52.204-21, self-assessed, with a senior official affirming it in SPRS. No plan of action is permitted at that level, so every one of the fifteen has to be met on the day. Level 2 is the 110 requirements of NIST SP 800-171 and a score out of 110 that primes read long before any certificate exists.

Open the CMMC Level Map
FTC SAFEGUARDS

The written plan your regulator already assumes you have

Tax preparers, accountants, auto dealers, mortgage brokers, appraisers, consumer lenders — the FTC Safeguards Rule reaches all of them, and it asks for a written information security plan with a named person responsible for it. Most firms have downloaded IRS Publication 5708 and never filled it in. A template is not a plan, and that gap shows the first time an insurer or a customer asks for the real thing.

Get the WISP template
WHAT WE DO

Readiness, implementation, documentation

Scoping first, because scoping decides the cost of everything after it — a firm that keeps regulated information in one defined place has a small problem, and one that lets it spread across email, file shares and quoting has an expensive one. Then the gap work, the controls, the evidence, and the written plan that has to survive somebody reading it. We stay for the annual revisit, because this is a date on a calendar, not a project with an end.

WHERE THE LINE IS

We implement. Somebody else certifies.

The firm that builds your controls cannot be the firm that certifies them. At CMMC Level 2 the certification assessment belongs to an authorized third party; at Level 3 it belongs to the government. Cybertitans is not an assessor, an auditor or a C3PAO and does not claim to be. What we do is get you to the point where that assessment is survivable — and tell you plainly when you are not there yet.

START HERE

Twenty minutes, no access to your systems

Answer a short questionnaire. I review it along with a few passive checks on your domain from public records. Then we spend twenty minutes on what I found. Nothing installed, nobody calling you afterward.

Book the 20 minutes

Reference material, not legal advice — the contract clause governs.