SECURITY & COMPLIANCE OPERATIONS // FEDRAMP · CMMC · NIST · ISO 27001
// COMPLIANCE KITS — DOCUMENTS + YOUR vCISO AGENT

Kits that
answer back.

Every kit pairs our consulting-grade documentation with 90 days of your vCISO Agent — trained on 20 years of CISO practice and on the very documents in your kit. Stuck on a control at 9pm? Ask. Not sure what evidence a practice needs? Ask. This isn't a folder of templates — it's a service that works alongside you until you submit.

COMING SOON

CMMC Level 1 Kit + Agent

Consulting deliverables + a vCISO Agent that answers back

The documentation we produce on Level 1 consulting engagements — all 17 practices with passing-grade policy language, evidence guidance, and SPRS scoring worksheet — plus 90 days with your vCISO Agent: ask it anything about any document in the kit, any control, anytime. Pro tier adds AI pre-submit review + expert call.

IN DEVELOPMENT

CMMC Level 2 Kit + Agent

For CUI handlers preparing for C3PAO

Full NIST 800-171 coverage across all 110 practices. SSP, POA&M, evidence index, pre-authorization checklist — with your vCISO Agent alongside for the whole build. Larger scope — different product.

COMING SOON

FedRAMP Moderate Kit + Agent

ATO-grade documentation for cloud service providers

SSP, POA&M, boundary and data-flow diagrams, CIS/CRM worksheets, and evidence structure — every artifact built the way the PMO and 3PAOs expect to read it, with your vCISO Agent alongside for the whole package.

COMING SOON

ISO 27001 Kit + Agent

Certification-grade ISMS for the 2022 revision

Scope, Statement of Applicability, risk methodology and register, the full mandatory policy set, and internal audit templates — structured the way certification auditors expect, with your vCISO Agent on call.

IN DEVELOPMENT

NIST 800-171 Kit + Agent

For DFARS 7012 without CMMC urgency

For contractors bound by DFARS 252.204-7012 but not yet facing a CMMC assessment. Same practices, lighter documentation burden, same vCISO Agent access.