Managed IT and Managed Security · Leesburg, VA

Compliance

Compliance Is Delivered by Our Compliance Division, Capital Cyber Compliance.

CMMC, NIST SP 800-171 and the documents an assessor asks for are the work of Capital Cyber Compliance. We stay on the IT and security that those controls depend on.

Capital Cyber runs the IT and the security. Its Compliance Division, Capital Cyber Compliance, delivers the compliance work.

Compliance: the documents and the systems kept in stepTwo panels joined by one team. On the left, the documents an assessor asks for, written by the Compliance Division, Capital Cyber Compliance: System Security Plan, policies and POA&M. On the right, the systems Capital Cyber runs: monitoring, backups and the help desk.THE DOCUMENTSTHE SYSTEMSSystem Security PlanPoliciesPOA&MMonitoringBackupsHelp deskCompliance DivisionCapital CyberOne team

Why One Team

The People Who Write It and the People Who Run It.

A compliance report starts aging the day it is delivered, and a control on paper is not the same as a control in behavior. Keeping the people who write the documentation and the people who run the systems in one company is how the gap between the two stays closed. Capital Cyber Compliance is not an Authorized C3PAO, on purpose: it means the same firm can remediate what it assessed and then stay on to run it.

CMMC and NIST SP 800-171

AT CAPITALCYBERCOMPLIANCE.COM

CMMC Level 2 Gap Assessment

Where you stand against all 110 requirements of NIST SP 800-171, with your SPRS score and what closing each gap takes. Its price is published on the Capital Cyber Compliance site.

CMMC and CUI Services

Program leadership, System Security Plans, policy and POA&M development, CUI enclave design, a fractional CISO and supply chain risk management.

CMMC In A Container

The managed program: a compliant environment, the policy set, and the ongoing work, run with you. Priced on its own page.

Level 1 or Level 2?

Level 1 is the 15 requirements of FAR 52.204-21, for Federal Contract Information. Level 2 is for Controlled Unclassified Information. Your contract decides which one you have.

CMMC Terms

SPRS, POA&M, C3PAO, CUI and the other words your prime and your contract use as if everyone knows them, each in plain language.

CMMC Case Studies

CMMC engagements, named, with the numbers beside them.

Other Frameworks

CyberCert SMB1001, HIPAA and the FTC Safeguards Rule.

Commercial clients ask us about these too. CyberCert SMB1001 certification, Bronze through Diamond, has its own pages on this site, and so do the HIPAA Security Rule and the FTC Safeguards Rule, each explained from the regulation's own text. Formal compliance engagements are delivered by our Compliance Division, Capital Cyber Compliance.

CyberCert SMB1001 Overview · Bronze · Silver · Gold · Platinum · Diamond

HIPAA Security Rule · FTC Safeguards Rule

Dental Practices and HIPAA · Accounting Firms and the FTC Safeguards Rule · Contact Capital Cyber Compliance

Ready for the Compliance Work?

Capital Cyber Compliance publishes its prices and its engagements on its own site.

Capital Cyber Compliance