DEFEND

Security & compliance for regulated work.

CMMC and NIST 800-171 readiness, managed detection and response, and incident response, for contractors whose next award depends on their posture.

NIST 800-171 READINESS
110/110
100%
Access Control22/22
Audit & Accountability9/9
Incident Response3/3
System & Comms Protection16/16
Audit-ready

WHAT'S COVERED

From readiness assessment to always-on defense.

CMMC readiness

Gap assessment and a plan of action to reach the level your contracts require.

NIST 800-171

All 110 controls mapped, implemented, and documented against your systems.

Managed detection (MDR)

24/7 threat monitoring and response across endpoints and networks.

Incident response

A plan before you need it, and a team on the line when you do.

Policy & evidence

The written policies and audit evidence assessors actually ask for.

Security awareness

Practical training for your people — the control auditors can't automate.

LEVEL 1 VS LEVEL 2

Two levels. Two very different lifts.

CMMC LEVEL 1 · FOUNDATIONAL

Basic safeguarding of FCI

For contractors who handle Federal Contract Information but not CUI. Level 1 is the 15 basic safeguarding requirements of FAR 52.204-21, verified by an annual self-assessment and executive affirmation.

Access limited to authorized users and devices
MFA-backed identities and unique accounts
Media handled and destroyed properly
Physical access controlled and logged
Boundary protection: firewalls, WAF, segmentation
Patching, anti-malware, and flaw remediation

CMMC LEVEL 2 · ADVANCED

Full NIST 800-171 for CUI

For contractors who store, process, or transmit Controlled Unclassified Information. All 110 NIST 800-171 requirements across 14 control families, with a System Security Plan, POA&M, and — for most contracts — a triennial third-party (C3PAO) assessment.

Everything in Level 1, hardened and audited
Logging, alerting, and 24/7 detection (MDR)
Incident response plan, tested and evidenced
CUI enclave scoping, labeling, and DLP
Risk assessments, training, and config management
Evidence kept audit-ready year-round

THE STACK

Where Microsoft 365, Azure & AWS fit.

Most of the controls live in tools you already license. We configure, monitor, and evidence them.

Defender for Office 365L1 + L2

MICROSOFT 365 · EMAIL & COLLABORATION

Phishing and malware protection where attacks actually start: Safe Links, Safe Attachments, spoof and impersonation protection across Exchange, Teams, and SharePoint.

Defender for Endpoint / BusinessL2

ENDPOINTS · EDR

The engine behind our managed detection: behavioral EDR on every workstation and server, feeding 24/7 alerting, isolation, and response. The 'Defender for Enterprise' tier question is really a licensing question — we map the right SKU to your contract level.

Entra ID + Conditional AccessL1 + L2

IDENTITY · MFA

Unique identities, phishing-resistant MFA, and conditional access policies that block legacy auth and risky sign-ins — the identity controls both levels lean on hardest.

IntuneL2

DEVICES · CONFIGURATION

Device enrollment, hardening baselines, encryption enforcement, and app control — configuration management with evidence you can export for an assessor.

PurviewL2

CUI · LABELING & DLP

Sensitivity labels that mark CUI where it lives, plus data loss prevention that keeps it inside the enclave. For CUI-heavy contracts this often means GCC or GCC High tenancy — we scope that early, because migrating later is expensive.

Azure + SentinelL2

CLOUD · LOGGING & SIEM

Centralized audit logging, retention, and correlation — the Audit & Accountability family made practical, with alerts routed into the same MDR watch floor.

AWS: GovCloud, GuardDuty, CloudTrailL2

CLOUD · WORKLOADS

For AWS workloads: CloudTrail for audit, GuardDuty for detection, and GovCloud regions where contract or ITAR requirements demand US-person handling and FedRAMP High boundaries.

WAF on every site we hostL1 + L2

WEB · BOUNDARY

Web application firewalls (Akamai, AWS WAF) in front of the sites and portals we build and host — boundary protection for the web layer, plus DDoS absorption and bot filtering.

CONTROL DOMAINS

The 14 families, in plain English.

Level 1 touches six families. Level 2 covers all fourteen.

AC
Access ControlL1 + L2

Who can touch what: least privilege, session control, remote access rules.

AT
Awareness & TrainingL2

People know the threats their role attracts, with evidence of training.

AU
Audit & AccountabilityL2

Logs exist, are protected, and can answer 'who did what, when.'

CM
Configuration ManagementL2

Hardened baselines, change control, and no drift you didn't approve.

IA
Identification & AuthenticationL1 + L2

Unique accounts, MFA, and no shared logins anywhere.

IR
Incident ResponseL2

A tested plan, defined roles, and reporting that meets DFARS timelines.

MA
MaintenanceL2

Controlled, logged system maintenance — including who serviced what.

MP
Media ProtectionL1 + L2

CUI on drives, USBs, and paper is marked, controlled, and destroyed properly.

PS
Personnel SecurityL2

Screening before access, and access removed the day someone leaves.

PE
Physical ProtectionL1 + L2

Locked doors, visitor logs, and controlled physical access to systems.

RA
Risk AssessmentL2

Vulnerabilities scanned, risks ranked, and remediation prioritized.

CA
Security AssessmentL2

Controls reviewed on a schedule; the SSP and POA&M stay living documents.

SC
System & Communications ProtectionL1 + L2

Boundary defense: firewalls, WAF, encryption in transit and at rest.

SI
System & Information IntegrityL1 + L2

Patching, anti-malware, EDR, and alerts someone actually watches.

Not sure which level your contracts require? The free assessment answers that in the first call.

WHY IT MATTERS

Your next award can depend on your posture.

We turn a compliance requirement into an operational reality — assessed, implemented, and kept audit-ready year round.

Assessment mapped to your actual environment
Remediation handled by the team that runs it
Evidence kept current, not scrambled pre-audit
Explained in plain English, not auditor-speak

Know where you stand before an auditor does.

A free assessment maps your posture against the standards your contracts require — no obligation.