Scope and boundary validation
Trace where CUI genuinely enters, rests, and leaves. Define the assessment boundary and the
asset categories, and document why each system is in or out — because that reasoning is
itself something the assessor reads.
SSP that matches the environment
A System Security Plan describing your real architecture, control by control, with the
implementation statement tied to the system that actually performs it.
Evidence assembly
Identify the artifact each practice produces, confirm it exists and is dated, and organize it
so an assessor can find it without a guided tour.
Control-by-control walkthrough
All 110 practices reviewed against implementation and evidence, with gaps separated into
fix-before, POA&M-eligible, and not-applicable-and-here-is-why.
Mock assessment
A rehearsal in the assessment's own shape — the questions asked, the evidence requested, the
people interviewed — so the first time your team answers an assessor is not the real one.
SPRS and C3PAO coordination
Score calculation and submission support, plus coordinating scheduling and logistics with the
C3PAO you select. We do not select one for you or take a fee for the referral.