Browse Products & Solutions
- Artificial Intelligence Security Assessment - AI Security Assessment - GenAI Security Assessment
- Asset & Expense Management Assessment
- Breach Notification Plan Assessment
- Business Continuity Planning Assessment
- CMMC
- Compliance Assessment
- Compliance Data Center Technology Cyber Security Cloud
- Cyber Risk Assessment
- Cyber Security Insurance Readiness Assessment
- Cyber Security Program Development Assessment
- Dark Web Assessment
- Disaster Recovery Planning Assessment
- Email Threat Assessment
- Governance Program Development
- HIPAA
- HITECH
- HITRUST
- ISSO 27001
- Incident Response Plan Assessment
- Penetration Test - PenTest
- Policy Review Assessment
- Mobile Security Assessment
- Pre Audit Readiness Assessment
- Privacy Assessment
- Readiness Assessment - CMMC, SOC, HITRUST, HIPPA, HITECH, ISO 27001
- Regulatory Compliance Gap Assessment (GDPR, CCPA, CMMC)
- SEC Disclosure
- Security Impact Assessment
- Short Tenure Time Watch
- SOC 1
- SOC 2
- SOC 3
- SOC for Cybersecurity
- SOC for Vendor Supply Chain
- Third-Party Risk Assessment
- Vendor Risk Management Assessment
What You Need To Know
The Cybersecurity Maturity Model Certification (CMMC) is the standard response from the Department of Defense regarding notable compromises within contractors' information systems. It is used for implementing cybersecurity throughout the defense industrial base (DIB), which consists of over 300,000 organizations.
Latest Update
Version 1.0 was published January 31, 2020
Who Requires It?
All Department of Defense contractors require a CMMC certification, including all suppliers in the supply chain, SMBs, commercial contractors, and foreign suppliers.
Assessment
Contractors are responsible for implementing, monitoring, and certifying proper security is in place for protecting their data systems and any important DoD information. However, an independent 3rd party is also required to assess the contractors' compliance.
Framework
Five (5) certification levels are required to confirm proper security:
1. Fundamental Cyber Hygeine - using antivirus applications, employee password update protocols
2. Intermediate Security - protection of Controlled Unclassified Information (CUI) using portions of the S Department of Commerce National Institute of Standards and Technology's (NIST’s) Special Publication 800-171 Revision 2 (NIST 800-171 r2) security requirements.
3. Utilizing all NIST 800-171 r2 Security Requirements in an organization-wide cyber protection plan
4. A review board is in place to evaluate instilled practices, techniques and procedures
5. Set a standard process to detects and respond.
Coyote Brown
vCISO - Virtual CISO - Virtual Chief Information Officer ServicesWe are a Cyber Security Consulting & Advisory Firm composed of highly experienced strategic cybersecurity advisors and consultants helping clients maintain a healthy cyber security posture.
Palo Alto Networks
We’re committed to delivering security without compromisePalo Alto Networks, Inc., operates a multinational cybersecurity company that provides advanced firewalls and cloud-services.
Strike Graph
Get certified. Build trust. Win deals.Strike Graph customers earn audited SOC2 security certifications with confidence.
AppViewX
AppViewX is the Next-Gen Machine Identity Management, Automation and Orchestration platform for Enterprise IT.
BrandShield
Cyber Security Brand Protection, Website Takedowns, Trademark Infringement, Dark Web MonitoringBrandShield provides Cyber Security Brand Protection, Website Takedowns, Trademark Infringement, Dark Web Monitoring and prevents, detects and fights online scams: phishing attacks, fraud, executive impersonations and more.
Deceptive Bytes
Deceptive Bytes provides an Active Endpoint Deception platform that dynamically responds to attacks as they evolve and changes their outcome.
Fortalice Solutions
We transform a reactive security model into a proactive, results-based model.Their highly-skilled practitioners are trained to meet clients where they are – whether that be in the midst of a crisis or proactively seeking cybersecurity services.
Infoblox
Infoblox delivers essential technology to enable customers to manage, control and optimize DNS, DHCP, IPAM (DDI).
Infocyte
Infocyte is a globally trusted leader in proactive threat detection, Microsoft 365 security compliance, and incident response.
Kenna Security
Kenna Security saves you time and money, and helps your Security and IT teams work more efficiently.
Trend Micro
A global leader in cybersecurity that helps make the world safe for exchanging digital information.
Blackpoint Cyber
Managed Detection and ResponseBlackpoint Cyber is a technology-focused cybersecurity company headquartered in Maryland, USA. The company was established by former US Department of Defense and Intelligence security experts and leverages its real-world cyber experience and knowledge of malicious tradecraft to help MSPs safeguard their infrastructure and operations.
Semperis
Semperis is the pioneer of identity-driven cyber resilience for cross-cloud and hybrid environments.
Vanta
Automated security monitoring for compliance certifications: SOC 2, HIPAA, and ISO 27001
Tugboat Logic
Like the immortal tugboat, we're passionate about guiding you through the rough seas of information security and privacy into the calm waters of proven policies, practices and compliance.
Drata
Security Compliance Software - GRC - SOC 2 - ISO27001Gradient Cyber
Trusted Security Operations as a Service.Gradient is a total solution that is a powerful combination of proprietary technology and Sr. Cybersecurity Analysts that make the job of managing security much easier for smaller IT teams; without breaking the bank.
Kiteworks
Email Security, CMMC Certified Email Security, Secure File Transfer, Secure Web Forms, Secure API, DoD Security, DoD Contractor CMMC Security, Secure Content CommunicationKiteworks mission is to empower organizations to manage risk effectively when sending, sharing, receiving, and storing sensitive content. The Kiteworks platform is designed to deliver content governance, compliance, and protection to our customers. Platforms unify, track, control, and secure sensitive content within, into, and out of organizations, enhancing risk management and ensuring regulatory compliance.