Compliance
CMMC & HIPAA Compliance
Somebody has asked what you comply with. It might be a customer, an auditor, an insurer, or a prime contractor, and the honest answer is that nobody has checked properly.
Who this is for, and what it fixes
A customer or a regulator has asked what you comply with, and the honest answer is that nobody has checked.
If one of these sounds familiar, this is usually the right conversation.
- You handle controlled unclassified information for a defense customer.
- You are a covered entity or a business associate under HIPAA.
- A prime contractor has passed requirements down to you.
- Your insurer or a large customer has sent you a questionnaire you cannot complete.
What you get out of it
- You can show an assessor evidence rather than describing intentions.
- The questionnaire from a customer or an insurer has real answers.
- You know which framework you are actually subject to, and which you are not.
- Evidence is collected as work happens rather than assembled in a panic.
What we do about it
We start with an assessment against the standard that actually applies to you, control by control, and give you a plain reading of where you stand. Not a percentage score, but a list of what is in place, what is partly in place, and what is not.
Then we build the plan. Gaps get an owner, an approach, and an order, because most of them depend on each other and doing them in the wrong sequence wastes money.
Then we do the work and keep the evidence. Compliance is not a project that finishes; it is a set of things you have to keep doing and keep being able to show. We maintain that record so an assessment is a matter of producing it rather than reconstructing it.
What is included
Gap assessment
Scored against the controls that apply to you, with a plain explanation of what each one is actually asking for.
A plan of action
Gaps in a sensible order, with what each one involves, so remediation is a schedule rather than a scramble.
Policy and documentation
The written policies the standard requires, in language your staff can follow.
Technical remediation
The access controls, logging, encryption, and monitoring the standard calls for, implemented rather than described.
Evidence collection
The record kept current as you go, which is the difference between a manageable assessment and a bad month.
Ongoing management
Reviews, updates, and the annual work, so your position does not quietly decay after the first assessment.
How it works, step by step
- We work out what actually applies to youHalf of this work is discovering that two of the four frameworks somebody mentioned are not your obligation at all.
- We assess where you stand against itControl by control, with the answer written down as yes, no, or partly, and no credit given for good intentions.
- We fix the gaps in an order you can affordSome are configuration and are done in an afternoon. Some are projects. You get both lists separately with what each one takes.
- We keep the evidence currentPolicies reviewed, logs retained, and screenshots taken when the thing is true rather than reconstructed the week an assessor asks.
CMMC and HIPAA are different problems
CMMC is assessed against a defined set of practices and, at higher levels, verified by a third party, so the evidence has to be organized for somebody else to read. HIPAA is built around a risk analysis you perform and safeguards you can justify, which gives you more latitude and less to point at. We work in both, and the first conversation is usually about which one you are actually subject to.
Common questions
How is this priced?
The assessment is a fixed quote once we know which framework and how many people and systems are in scope. Remediation is quoted separately, item by item, so you can stage it.
Keeping the evidence current is a monthly figure and it is the part most companies underestimate.
How long does readiness take?
It depends on the standard, your scope, and where you are starting. The assessment itself is usually a few weeks. Remediation can run from a couple of months to considerably longer if the scope is broad. You will get a realistic timeline, not an encouraging one.
Can you certify us?
No, and nobody who prepares you should also be the one to assess you. For CMMC, certification comes from an authorized third-party assessor. We get you ready and we help you through it. Keeping those roles separate protects the value of the certificate.
Do we need to do all of it at once?
No, and trying to usually stalls. The plan sequences the work, and some of it will be quick while some depends on other pieces first. What matters is that the plan is real and progress against it is recorded, which is itself something assessors look for.
Often paired with
What clients usually need alongside this
Cybersecurity
Cybersecurity Services
Layered protection that is watched around the clock, so a bad day stays a bad hour.
Learn moreManaged IT
Managed IT Support
Your staff get help from people who know your systems, and your technology stops being the reason work stops.
Learn moreNetworking
Networking & Infrastructure
Networks that are documented, monitored, and sized for the work you actually do on them.
Learn more