Compliance

CMMC & HIPAA Compliance

Somebody has asked what you comply with. It might be a customer, an auditor, an insurer, or a prime contractor, and the honest answer is that nobody has checked properly.

Who this is for, and what it fixes

A customer or a regulator has asked what you comply with, and the honest answer is that nobody has checked.

If one of these sounds familiar, this is usually the right conversation.

  • You handle controlled unclassified information for a defense customer.
  • You are a covered entity or a business associate under HIPAA.
  • A prime contractor has passed requirements down to you.
  • Your insurer or a large customer has sent you a questionnaire you cannot complete.

What you get out of it

  • You can show an assessor evidence rather than describing intentions.
  • The questionnaire from a customer or an insurer has real answers.
  • You know which framework you are actually subject to, and which you are not.
  • Evidence is collected as work happens rather than assembled in a panic.

What we do about it

We start with an assessment against the standard that actually applies to you, control by control, and give you a plain reading of where you stand. Not a percentage score, but a list of what is in place, what is partly in place, and what is not.

Then we build the plan. Gaps get an owner, an approach, and an order, because most of them depend on each other and doing them in the wrong sequence wastes money.

Then we do the work and keep the evidence. Compliance is not a project that finishes; it is a set of things you have to keep doing and keep being able to show. We maintain that record so an assessment is a matter of producing it rather than reconstructing it.

What is included

Gap assessment

Scored against the controls that apply to you, with a plain explanation of what each one is actually asking for.

A plan of action

Gaps in a sensible order, with what each one involves, so remediation is a schedule rather than a scramble.

Policy and documentation

The written policies the standard requires, in language your staff can follow.

Technical remediation

The access controls, logging, encryption, and monitoring the standard calls for, implemented rather than described.

Evidence collection

The record kept current as you go, which is the difference between a manageable assessment and a bad month.

Ongoing management

Reviews, updates, and the annual work, so your position does not quietly decay after the first assessment.

How it works, step by step

  1. We work out what actually applies to youHalf of this work is discovering that two of the four frameworks somebody mentioned are not your obligation at all.
  2. We assess where you stand against itControl by control, with the answer written down as yes, no, or partly, and no credit given for good intentions.
  3. We fix the gaps in an order you can affordSome are configuration and are done in an afternoon. Some are projects. You get both lists separately with what each one takes.
  4. We keep the evidence currentPolicies reviewed, logs retained, and screenshots taken when the thing is true rather than reconstructed the week an assessor asks.

CMMC and HIPAA are different problems

CMMC is assessed against a defined set of practices and, at higher levels, verified by a third party, so the evidence has to be organized for somebody else to read. HIPAA is built around a risk analysis you perform and safeguards you can justify, which gives you more latitude and less to point at. We work in both, and the first conversation is usually about which one you are actually subject to.

Common questions

How is this priced?

The assessment is a fixed quote once we know which framework and how many people and systems are in scope. Remediation is quoted separately, item by item, so you can stage it.

Keeping the evidence current is a monthly figure and it is the part most companies underestimate.

How long does readiness take?

It depends on the standard, your scope, and where you are starting. The assessment itself is usually a few weeks. Remediation can run from a couple of months to considerably longer if the scope is broad. You will get a realistic timeline, not an encouraging one.

Can you certify us?

No, and nobody who prepares you should also be the one to assess you. For CMMC, certification comes from an authorized third-party assessor. We get you ready and we help you through it. Keeping those roles separate protects the value of the certificate.

Do we need to do all of it at once?

No, and trying to usually stalls. The plan sequences the work, and some of it will be quick while some depends on other pieces first. What matters is that the plan is real and progress against it is recorded, which is itself something assessors look for.

  • Fast Track 50 Emerging Business Award, 2025
  • Top 3 Computer Support, Lake County, 2025
  • CyberCert SMB1001 Bronze
  • MSPAlliance member
  • Microsoft Partner
  • Dell Partner
  • Lenovo Partner
  • More than 20 years of experience
  • Managed services since 2010
  • Based in Northeast Ohio
  • Offices in Lake and Summit counties
  • Owner operated and independent
  • CMMC and HIPAA experience