CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

Services

Which engagement does your company need?

Most defense contractors start with one of three: CMMC Level 2 program leadership, an SSP and POA&M review, or a vCISO. Federal programs usually start with RMF and ATO work or an insider threat and enterprise audit program. Engagements are scoped to your company and delivered by the Capital Cyber team.

Not sure where you fit? Book a call and we will tell you which engagement fits, or that none does.

Book a 30 minute call

What does each engagement cover?

CMMC Level 2 program leadership

Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.

SSP and POA&M review and assessor readiness

Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.

CUI enclave design

CUI enclave design in Microsoft Azure and M365 GCC High, with a defined authorization boundary, for defense contractors.

C3PAO readiness and mock assessment

CMMC Level 2 mock assessment and C3PAO readiness, including C3PAO selection, for defense contractors preparing for certification.

vCISO and security program leadership

Virtual CISO and security program leadership for defense contractors and federal integrators, including supplier cyber readiness.

RMF, ATO and continuous authorization

RMF, ATO and continuous authorization leadership for federal programs and integrators, across NIST SP 800-53 and CNSS 1253.

Insider threat and enterprise audit

Insider threat, enterprise audit and user activity monitoring program design for federal programs and defense contractors.

Incident response and tabletop exercises

Incident response planning and tabletop exercises for defense contractors, including DFARS 252.204-7012 reporting readiness.

ITAR cybersecurity program

Cybersecurity programs for ITAR controlled technical data, built on NIST SP 800-171 and DFARS 252.204-7012, from Capital Cyber.

How is this different from a managed service?

These are consulting engagements: senior leadership, assessment, design and program direction. Your MSP or MSSP keeps running your systems day to day, and we direct the security work they do so it meets the framework you are held to.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.