CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

Cybersecurity Consulting, a Capital Cyber practice

CISO level leadership for CMMC, NIST SP 800-171 and federal authorization, with a program for ITAR technical data.

Senior security leadership for defense contractors and federal programs, scoped to your company and delivered by the Capital Cyber team.

Plan reviews, mock assessments, program leadership, enclave design and authorization work, with one written scope and one accountable lead for each engagement.

Book a 30 minute call

What does this practice do?

We lead the security programs defense contractors and federal programs are measured on: CMMC Level 2 certification runs, SSP and POA&M reviews, CUI enclaves, a program for ITAR technical data, RMF authorizations, insider threat and audit programs, and incident response readiness.

CMMC Level 2 program leadership

Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.

SSP and POA&M review and assessor readiness

Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.

CUI enclave design

CUI enclave design in Microsoft Azure and M365 GCC High, with a defined authorization boundary, for defense contractors.

C3PAO readiness and mock assessment

CMMC Level 2 mock assessment and C3PAO readiness, including C3PAO selection, for defense contractors preparing for certification.

vCISO and security program leadership

Virtual CISO and security program leadership for defense contractors and federal integrators, including supplier cyber readiness.

RMF, ATO and continuous authorization

RMF, ATO and continuous authorization leadership for federal programs and integrators, across NIST SP 800-53 and CNSS 1253.

Insider threat and enterprise audit

Insider threat, enterprise audit and user activity monitoring program design for federal programs and defense contractors.

Incident response and tabletop exercises

Incident response planning and tabletop exercises for defense contractors, including DFARS 252.204-7012 reporting readiness.

ITAR cybersecurity program

Cybersecurity programs for ITAR controlled technical data, built on NIST SP 800-171 and DFARS 252.204-7012, from Capital Cyber.

Who is it for?

Small and mid sized defense contractors and federal integrators that need CISO level leadership for CMMC, NIST SP 800-171 and federal authorization work without a full time CISO, and federal programs that need enterprise audit, insider threat or RMF leadership.

Which frameworks do we cover?

CMMC (32 CFR Part 170)NIST SP 800-171 Rev 2NIST SP 800-171ANIST SP 800-53 and 53ARisk Management FrameworkCNSS 1253DFARS 252.204-7012Microsoft GCC High enclavesITAR technical dataNIST SP 800-61 incident response

How does an engagement start?

  1. A 30 minute call about your contracts, your deadline and where your CUI lives.
  2. A written scope that names the engagement, the deliverables and who does what.
  3. A kickoff with your leadership and your IT provider in the room.

How the practice works

What will we not promise?

A certification result. The C3PAO or the authorizing official decides that, and nobody who leads this work honestly can promise it. We promise the work: a plan that covers every requirement, evidence for everything that is implemented, and a written record of the risks your leadership chose to accept.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.