Cybersecurity, compliance & authorization for the defense ecosystem

ASSESS • IMPLEMENT • SUSTAIN

Your prime may require demonstrable compliance
before DoW does.

Lead with Level 2 self-assessment and SPRS evidence validation support, implement a secure enclave, and sustain continuous compliance. SOS combines GCC High / Azure Government virtualization, AVD isolation, IaC repeatability, OT integration, and RMF/ATO expertise—with independent C3PAO assessment capability as the assurance layer.

Level 2 + SPRS evidenceContinuous compliance + assuranceIaC-driven turnkey delivery
SECURITY PROGRAM / 001SOS // FIELD NOTES
MISSION
READY
01 / ASSESS
Scope & evidence
02 / IMPLEMENT
Controls & architecture
03 / SUSTAIN
Monitor & improve
IDENTIFYPROTECTDETECTRESPONDRECOVER

10+ yearsof hands-on cybersecurity and compliance experience

C3PAO + RPOassessment and implementation roles with impartiality safeguards

Federal cloudAzure Government and Microsoft 365 GCC High architecture

PRIME-DRIVEN READINESS / DEFENSE SUPPLY CHAIN

Show the evidence.
Implement the boundary.
Keep compliance current.

A prime may ask for demonstrable compliance during supplier qualification, teaming, or subcontract award. SOS helps you align the requested assessment route, CUI boundary, score, and operating evidence with your actual obligations.

01 / SELF-ASSESSMENT & SPRS

Level 2 self-assessment / SPRS validation support

Review scope, requirement-level evidence, scoring rationale, and POA&M eligibility. Reconcile the record before an authorized company representative submits or affirms results in SPRS.

Start the CMMC quick check ↗
02 / IMPLEMENT

Build the enclave that fits.

Implement a bounded GCC High / Azure Government environment with AVD isolation, IaC repeatability, and defined endpoint or specialized-asset interfaces.

Compare enclave boundaries ↓
03 / SUSTAIN

Continuous compliance

Maintain control ownership, configuration reviews, vulnerability follow-up, POA&M status, and current evidence to support customer reviews and applicable affirmations.

See continuous compliance delivery ↓
04 / ASSURANCE

C3PAO assessment capability

Bring independent assessment expertise into the assurance layer when certification is required. Assessment and implementation engagements retain separate responsibilities and impartiality safeguards.

View assessment capabilities ↓

SPRS validation support means reviewing your scope, score, and supporting evidence. SOS does not issue a government SPRS validation. A Level 2 self-assessment does not replace a C3PAO assessment when your contract requires Level 2 (C3PAO).

ASSESSOR PERSPECTIVE / PRACTITIONER DELIVERY

Two roles. Clear responsibilities.

SOS brings the assessment perspective of a CMMC Third-Party Assessment Organization (C3PAO) and the implementation focus of a Registered Practitioner Organization (RPO). Engagements are scoped to preserve assessment impartiality.

C3PAO / ASSESSMENT

Independent CMMC assessments

Structured assessment planning, evidence review, interviews, and testing against the applicable CMMC requirements, with findings documented through the prescribed process.

Discuss an assessment ↗
RPO / IMPLEMENTATION

Readiness and remediation

Practical help defining the CUI boundary, implementing controls, preparing SSPs and POA&Ms, managing evidence, and operating the program over time.

Explore implementation delivery ↗

View Cyber AB Marketplace credentials

Assessment and advisory work are evaluated for conflicts of interest before engagement. A readiness or implementation client should not assume SOS can also perform its certification assessment.

ADJACENT NIST EXPERTISE

Security controls and secure software, built into the program.

These disciplines strengthen the control environment beyond a checklist and connect architecture decisions to operational evidence.

NIST SP 800-53 REV. 5

Security & privacy controls

Control selection, tailoring, implementation, assessment preparation, and continuous monitoring for RMF and ATO programs. SOS connects the control baseline to SSP narratives, inherited responsibilities, POA&Ms, and defensible evidence.

Explore control engineering ↗
NIST SP 800-218

Secure software development

Secure Software Development Framework practices for preparing teams, protecting code, producing well-secured software, and responding to vulnerabilities across the software lifecycle.

Take the SSDF readiness review ↗

WHAT WE DO

One partner across the full lifecycle.

Engage SOS for a focused workstream or a coordinated program—from the first CUI boundary discussion through authorization and ongoing operations.

01 / ASSESS

Level 2 self-assessment & SPRS

Scope and evidence review, self-assessment scoring, SPRS record preparation, eligible POA&M tracking, and continuing compliance support.

Explore CMMC services
02 / AUTHORIZE

RMF / ATO & Continuous RMF

NIST SP 800-53 engineering, eMASS support, cloud inheritance, and Continuous Authorization / Continuous RMF connecting telemetry, POA&Ms, and operating evidence.

Explore RMF / ATO
03 / BUILD

Secure enclaves

IaC-driven CUI enclaves in Azure Government and GCC High. Repeatable cloud infrastructure, virtual desktops, identity, data controls, monitoring, and operating procedures support a turnkey deployment model.

Explore secure enclaves
04 / EXTEND

OT & specialized assets

Scope and protect workflows that touch production equipment, labs, CNC systems, and isolated assets, including controlled transfer paths.

Explore OT / RMF support ↗
05 / GOVERN

GRC & documentation

Control ownership, policies, SSPs, POA&Ms, risk registers, inherited-control mapping, and organized evidence for CMMC and RMF programs.

Explore GRC delivery
06 / MONITOR

Continuous compliance

Telemetry, configuration drift, vulnerability follow-up, current control evidence, and POA&M review tied to owners and applicable compliance affirmations.

Explore monitoring
07 / EXECUTE

Task management

Translate findings and obligations into owned tasks, milestones, due dates, dependencies, and review gates that keep implementation moving.

Explore delivery tracking
START HERE

Unsure where to begin?

Tell us what you need to protect and the outcome you’re pursuing. We’ll help identify a practical first step.

Take the CMMC quick check

FOR ENGINEERING, CONSTRUCTION & INTEGRATION PRIMES

Bring OT cybersecurity expertise onto your team.

Define an RMF workstream for SCADA, microgrid and facility control systems. SOS supports boundaries, control implementation, and Continuous Authorization / Continuous RMF alongside your engineering delivery. Technical signals connect to controls, POA&M status, and current authorization evidence.

GOVERN • MONITOR • EXECUTE

Run compliance as an operating program.

Documentation, monitoring, and work tracking should reinforce one another. SOS connects requirements to evidence, findings to owners, and decisions to a visible delivery plan.

01 / GRC & DOCUMENTATION

Keep the record assessment ready.

We build and maintain the system narrative behind the controls, with traceable responsibilities and a clear path from requirement to implementation and evidence.

  • System security plans and boundary descriptions
  • Policies, procedures, control narratives, and inheritance
  • Risk registers, POA&Ms, evidence inventories, and review records
Typical outputA current, reviewable body of evidence
Explore this workstream ↗
02 / CONTINUOUS COMPLIANCE

Keep controls and evidence current.

We define the telemetry, review rhythm, escalation path, and control checks needed after implementation and through authorization or assessment cycles.

  • Sentinel and Defender signal coverage and triage
  • Vulnerability, configuration, and exception follow-up
  • Control-linked telemetry, POA&M status, and evidence refresh
Typical outputFindings, decisions, and trends with ownersConnect to Continuous Authorization / Continuous RMF ↗
Explore this workstream ↗
03 / TASK MANAGEMENT

Turn findings into finished work.

Security work is organized into phases with accountable owners, dependencies, target dates, and formal review points for implementation and sustainment.

  • Remediation backlog and milestone planning
  • Assigned actions, due dates, risks, and status reviews
  • Quality gates linking completed tasks to evidence
Typical outputA visible plan from gap to closure
Explore this workstream ↗

ARCHITECTURE + OPERATING EVIDENCE + ASSURANCE

A technical delivery model with an assessor’s perspective.

SOS connects virtualized government-cloud environments, repeatable infrastructure, operational constraints, and control evidence in one delivery approach.

CLOUD / ISOLATION

GCC High, Azure Government & AVD

Virtualize approved CUI workflows, restrict local redirection, and define the boundary around the actual services, users, and devices.

Explore enclave patterns ↓
ENGINEERING / REPEATABILITY

IaC & specialized-asset integration

Reproduce approved infrastructure through versioned templates. Design OT, lab, CNC, and equipment handoffs around supported safeguards and operational limits.

Connect the OT boundary ↗
RMF / ASSURANCE

Authorization & assessor expertise

Connect RMF/ATO, control inheritance, assessment preparation, and continuing evidence review across the implementation lifecycle.

Explore Continuous RMF ↗
VALIDATED ENVIRONMENT / EXPERIENCE

DIBCAC-validated environment experience

Bring experience from a DIBCAC-validated environment into boundary design, evidence preparation, and operating discipline.

Discuss the validated scope ↗

DIBCAC validation applies to the environment, assessment scope, and date assessed. It does not confer government endorsement, automatic inheritance, or certification on a customer deployment.

INFRASTRUCTURE AS CODE / TURNKEY DELIVERY

Define it once.
Deploy it consistently.
Scale with the mission.

Use version-controlled infrastructure templates to build an approved Azure Government enclave foundation. Parameters adapt the design to each customer; reviewed changes keep deployment, operations, and evidence connected.

01 / TURNKEY

From design to operation.

Bring infrastructure deployment, security configuration, SSPs, operating procedures, evidence, and handover into one coordinated delivery model.

02 / REPEATABLE

A baseline you can rebuild.

Version templates and environment parameters. Review deployment plans, validate changes, and retain release records so approved configurations can be reproduced.

03 / SCALABLE

Grow from a known foundation.

Extend host pools, capacity, and approved environments through reusable infrastructure patterns while keeping boundaries, access rules, and monitoring explicit.

04 / ELASTIC

Match capacity to demand.

Plan workload-based scaling and operating schedules within approved limits. Align availability, cost, licensing, and security coverage as capacity changes.

A CONTROLLED DEPLOYMENT LIFECYCLE

  1. Define the boundaryAssets, data flows, responsibilities
  2. Version the designTemplates and customer parameters
  3. Review and deployApproved changes and validation
  4. Operate and adaptScaling, drift review, evidence refresh

IaC provisions the cloud foundation. Identity and SaaS policies, endpoint settings, procedures, and operating evidence are configured and validated as part of the complete engagement.

Discuss an IaC-driven deployment ↗

TURNKEY ENCLAVE IMPLEMENTATION

Choose the boundary that fits the work.

Each variant combines an IaC-driven infrastructure foundation with architecture, control ownership, SSP and procedures, evidence, monitoring, and operational support. The diagrams illustrate starting patterns; final boundaries follow actual CUI flows and equipment.

Which variant fits your workflow?

Answer eight practical questions about applications, local work and equipment before choosing a starting boundary.

Find my enclave variant ↗
VARIANT 01 / FULLY VIRTUALIZED

Keep CUI in the cloud workspace

Variant 1 diagram: untrusted laptops connect to a GCC High Azure Virtual Desktop enclave and Microsoft 365 services

Users connect through Windows App with Entra ID, MFA, and Conditional Access. CUI work runs on AVD session hosts and approved GCC High services; local download, clipboard, USB, and print pathways are restricted by policy.

Implementation path
  1. Map CUI applications, users, and cloud services; define the authorization boundary.
  2. Deploy the AVD infrastructure and network foundation from version-controlled IaC; configure identity, collaboration, and protection controls for the approved boundary.
  3. Validate redirection restrictions, monitoring, backup, evidence, and operating procedures.
Best fitWorkflows that can remain in a virtual desktop with no required local CUI processing.
Explore Variant 1 ↗
VARIANT 02 / HYBRID ENDPOINT

Extend trust to approved devices

Variant 2 diagram: untrusted and managed laptops connect to the GCC High virtual workspace

Keep the virtual enclave while adding managed endpoints for approved local work. Intune enrollment, Defender protection, device compliance, Conditional Access, encryption, and controlled peripherals become part of the assessed boundary.

Implementation path
  1. Identify which tasks require local CUI processing and which users and devices are authorized.
  2. Harden and enroll endpoints; define access, storage, transfer, printing, and recovery rules.
  3. Test cloud-to-device data flows and collect endpoint and policy evidence.
Best fitTeams that need approved local applications or peripherals alongside cloud collaboration.
Explore Variant 2 ↗
VARIANT 03 / SPECIALIZED ASSETS

Control the equipment handoff

Variant 3 diagram: managed engineering endpoint and controlled media transfer to isolated OT and CNC equipment

Extend the hybrid model to isolated lab, CNC, OT, or other specialized assets through an explicitly designed transfer process. The air gap and media workflow are documented, with roles and safeguards matched to the equipment's capabilities.

Implementation path
  1. Trace files to and from equipment and classify each asset and transfer point.
  2. Design approved media handling, malware checks, custody, physical controls, and exceptions.
  3. Validate the handoff with operators and document evidence and residual risk.
Best fitEngineering or production workflows where isolated equipment must receive or produce controlled information.
Explore Variant 3 ↗
Turnkey deliveryVersion-controlled IaC and deployment · SSP and procedures · security monitoring · evidence collection · assessment or authorization support · ongoing administration

YOUR NEXT STEP / CUSTOMER TOOLKIT

Turn readiness into a workable plan.

Explore the next security baseline, review your software practices, and connect reported gaps to evidence, owners and actions. View and download results without entering contact details.

SECURE SOFTWARE / NIST SSDF

Review how you build software.

Assess 19 practices across preparation, code protection, secure production and vulnerability response. See task references, charts and improvement priorities.

Take the SSDF readiness review ↗
NIST 800-171 REV. 3 / TRANSITION

Prepare for your next baseline.

Review 97 active requirements, inspect assessment objectives and use NIST’s Rev. 2 change analysis to identify transition decisions and evidence to revisit.

Open Rev. 3 readiness & transition ↗
EVIDENCE / REMEDIATION ROADMAP

Give every gap a next action.

Bring your CMMC, Rev. 3 or SSDF results into an evidence register. Assign role owners, dates and corrective actions, then download your working plan.

Build my evidence & action plan ↗

Self-reported planning tools, not verified assessment findings. The CMMC Level 2 review uses Rev. 2; the Rev. 3 tool is a separate readiness and transition review.

SECURITY ARCHITECTURE / INTERACTIVE

Seven controls. One coherent boundary.

Explore how identity, network, data, endpoints, detection, and cloud applications work together in a GCC High enclave. Select a numbered control to inspect its architecture.

01 / IDENTITY & ACCESS

Device trust before access

Intune manages device configuration and reports compliance signals to Microsoft Entra ID. Conditional Access uses those signals with identity, location, and sign-in risk to decide whether users may reach approved cloud resources. Policies are designed around each user and CUI workflow.

Intune device compliance, Entra Conditional Access, and protected Microsoft 365 accessUse Enlarge diagram to inspect the image, or select the diagram to discuss it ↗

GCC HIGH / AZURE GOVERNMENT ENCLAVE

Follow the CUI. Inspect the controls.

See how a virtual desktop keeps CUI processing inside the enclave, how GCC High collaboration fits alongside Azure Government, and how security telemetry supports continuous compliance.

CUI WORKSPACE / BOUNDARIES + FLOWS

See where the data goes.
See what protects it.

GCC High enclave: four data and control paths across a layered CUI boundaryAn access device and AVD broker sit outside the logical CUI processing boundary. Entra identity controls gate access. Azure Government hosts process CUI and exchange approved data with separate Microsoft 365 GCC High SaaS. Outbound host service connectivity supports the remote session. Security signals feed continuous compliance and authorization evidence. Four numbered paths use separate colors.GCC HIGH + AZURE GOVERNMENTA clear boundary. Four distinct flows.Reference design • Variant 1 • Service configuration and responsibilities must be validated.LOGICAL CUI WORKSPACE BOUNDARYSeparate service environments — not one shared network or inherited certificationIDENTITY + ACCESS POLICYEntra ID · MFA · Conditional AccessApproved identities and conditions · Intune signals for managed devicesAZURE GOVERNMENTCustomer VNet / controlled subnetAVD host poolMulti-session VMsCUI work / appsDedicated VMsEngineering / GPUIsolated sessionsSession controls: clipboard · drives · USB · printNSGs · NAT / approved outbound endpointsEncrypted disks + Azure BackupIaC baseline · configuration and change reviewMICROSOFT 365 GCC HIGHSeparate SaaS environmentSharePoint · OneDriveExchange · TeamsPurview labels · DLP · retentionSharing rules · customer responsibilitiesACCESS DEVICEWindows AppRemote display + inputOutside CUI workspaceAVD SERVICEBroker / gatewaySession establishmentRelayed reference pathLOCAL CUI EXPORTBlocked by configuredsession restrictions1223CUI / TLSApprovedworkflowsSECURITY TELEMETRY → CONTROL REVIEW → AUTHORIZATION EVIDENCEDefender / SentinelIdentity, host & SaaS signalsControl + risk reviewFindings · owners · decisionsSSP / POA&M / evidenceContinuous compliance / RMF4OPERATING FOUNDATIONVersion-controlled IaC · approved change · evidence refresh · defined customer / provider responsibilitiesREMOTE SESSIONHosts initiate outboundservice connectivity.No inbound RDP listeneris implied on the hosts.

Swipe across the map to inspect each boundary, or use the numbered steps below.

Four paths, one logical boundary.

Purple is identity policy; blue is the remote session; teal is approved CUI collaboration; amber is telemetry and evidence. The outer frame groups the CUI workspace logically. Azure Government and GCC High retain separate service boundaries.

1 / Verify identity

Entra ID, MFA and Conditional Access evaluate the user and access conditions. Managed-device compliance and untrusted-device access are separate policy decisions.

2 / Open an isolated session

Windows App reaches the AVD service. Session hosts initiate outbound service connectivity. Only display and input are intended at the access device; configured redirection restrictions protect the CUI workspace.

3 / Process and collaborate

CUI is processed on multi-session or dedicated hosts and exchanged with approved SharePoint, OneDrive, Exchange and Teams workflows. Network egress, labels, DLP and sharing policies serve different purposes.

4 / Keep evidence current

Review identity, host, application and configuration signals against controls. Validate findings, track POA&M actions and refresh SSP/authorization evidence; telemetry does not automatically establish compliance.

Moving packets illustrate flows, not live traffic.

Logical reference architecture, not a physical topology, certification or promise of control inheritance. Validate government-cloud service availability, licensing, endpoints, session controls and customer/provider responsibilities for the implementation. This view illustrates a relayed AVD session; other approved transport configurations require their own validation.

Discuss your GCC High enclave · Read the GCC High data-flow guide

VARIANT 1 / THE ENCLAVE, ASSEMBLED

Build the boundary.
Layer by layer.

Watch a fully virtualized CUI enclave take shape across Azure Government and Microsoft 365 GCC High. Select a layer to explore the control it adds.

01 / 09Infrastructure
Variant 1: a layered Azure Government and GCC High CUI enclaveAn access device reaches an Azure Virtual Desktop session through the AVD service. Session hosts reside in an Azure Government subnet and connect to separate Microsoft 365 GCC High applications. Identity, session restrictions, data protection, monitoring, and governance are added progressively. This is a logical control view, not a network deployment blueprint. ACCESS DEVICEILLUSTRATIVE CUI PROCESSING BOUNDARY Windows AppRemote session accessDevice scope is evaluatedin the SSP 01 / INFRASTRUCTUREAzure GovernmentSubscription · resource group · VNetManaged disks + Azure Backup 02 / PRIVATE SUBNET + NSGNAT Gateway / egressApproved endpoints AVDserviceTLSAVD host poolWindows 11 multi-session · Windows appsReverse connect / no public IP on session hosts 04 / APPLICATIONSMicrosoft 365 GCC HighSharePoint · OneDriveTeams · ExchangeTLSSeparate SaaS service environment 05 / AUTHENTICATION + AUTHORIZATIONEntra ID · MFA · Conditional Access · least privilege 06 / DEVICE + SESSIONIntune-managed enclave hostsBlock clipboard, USB, printBlock local file redirection 07 / DATACUI labels + DLP · approved storage · encryption · backupCUI / Purview labels + DLP 08 / DETECT + RESPONDDefender XDR + Sentinel · review · response 09 / GOVERNANCE · SSP · EVIDENCE · CONTROL OWNERS
LAYER 01 / INFRASTRUCTURE

Establish the government-cloud foundation.

Provision the Azure Government subscription, resource group, virtual network, managed disks, and backup resources. Record the boundary and the provider responsibilities inherited by the customer.

Evidence to maintainResource inventory, configuration baseline, shared-responsibility record.

A reference pattern for CMMC Level 2 readiness. Certification depends on the organization’s complete implementation, scope, operating practices, and assessment. The layers are logical safeguards, not additional physical networks.

HOW WE WORK

Make the boundary clear. Make the controls real.

We connect architecture decisions with the documents, evidence, and operating routines that an assessment or authorization depends on.

01

Define

Map data, users, systems, dependencies, requirements, and ownership.

02

Design

Select the boundary, inherited controls, technical safeguards, and procedures.

03

Prove

Deploy approved infrastructure through IaC, implement controls, and assemble testable evidence and authorization artifacts.

04

Sustain

Track changes, findings, vulnerabilities, monitoring, and recurring reviews.

FIND YOUR PATH

What are you working toward?

Choose the outcome closest to your current need. This is a starting point for a conversation, not an assessment or compliance determination.

RECOMMENDED START

CMMC scope and readiness review

Start with your contracts, CUI flows, asset categories, and existing controls. Then prioritize gaps and evidence before selecting implementation work.

  • Boundary and CUI flow review
  • Control and evidence baseline
  • Remediation roadmap
Discuss this path

WHO WE SERVE

Built for teams with real delivery constraints.

Defense contractors and subcontractors, research organizations, professional services firms, and federal program teams that must protect sensitive work while keeping operations productive. We tailor scope to the actual system and mission.

LET’S TALK

Bring us your boundary, deadline, or challenge.

Share the requirement, the systems involved, and your target date. We’ll help frame the right next conversation.

CMMC / CLOUD / AUTHORIZATION

Plan the right boundary and evidence.

Questions defense suppliers and prime contractors ask before choosing a compliance and enclave partner.

How does SOS support CMMC Level 2 self-assessment and SPRS?

SOS reviews the CUI boundary, NIST SP 800-171 Rev. 2 requirement evidence, scoring rationale and corrective actions. An authorized company representative submits and affirms the SPRS record. Self-assessment support is distinct from government validation and does not replace a required C3PAO assessment. Start the CMMC readiness check.

Does GCC High make an organization CMMC compliant?

Cloud selection is one part of the design. Customer responsibilities still include access policy, CUI workflows, configuration, people, procedures and operating evidence. SOS combines GCC High, Azure Government and AVD isolation with repeatable IaC deployment and continuous compliance. Compare enclave fit for your workflows.

Can an enclave support OT and specialized assets?

Yes, when the actual transfer and operational requirements can be met. A hybrid boundary can include a managed transfer station, segmented networks, defined media handling and isolated equipment. Asset limitations and operator safety must shape the design. Review OT cybersecurity and RMF/ATO support.

What changes with Continuous Authorization / Continuous RMF?

The service connects technical telemetry to NIST 800-53 control review, POA&M status and current authorization evidence throughout operations. SOS supports the evidence and risk workflow; the authorizing official retains authorization decisions. See the telemetry-to-control model.

Is NIST SP 800-171 Rev. 3 the same as the CMMC Level 2 assessment?

These are separate planning paths on this site. The CMMC Level 2 tool uses Rev. 2. The Rev. 3 review helps identify transition requirements and evidence to revisit; it is not a verified assessment. Explore Rev. 3 readiness or review secure software practices with the NIST SSDF tool.