Every kit pairs our consulting-grade documentation with 90 days of your vCISO Agent — trained on 20 years of CISO practice and on the very documents in your kit. Stuck on a control at 9pm? Ask. Not sure what evidence a practice needs? Ask. This isn't a folder of templates — it's a service that works alongside you until you submit.
The documentation we produce on Level 1 consulting engagements — all 17 practices with passing-grade policy language, evidence guidance, and SPRS scoring worksheet — plus 90 days with your vCISO Agent: ask it anything about any document in the kit, any control, anytime. Pro tier adds AI pre-submit review + expert call.
Full NIST 800-171 coverage across all 110 practices. SSP, POA&M, evidence index, pre-authorization checklist — with your vCISO Agent alongside for the whole build. Larger scope — different product.
SSP, POA&M, boundary and data-flow diagrams, CIS/CRM worksheets, and evidence structure — every artifact built the way the PMO and 3PAOs expect to read it, with your vCISO Agent alongside for the whole package.
Scope, Statement of Applicability, risk methodology and register, the full mandatory policy set, and internal audit templates — structured the way certification auditors expect, with your vCISO Agent on call.
For contractors bound by DFARS 252.204-7012 but not yet facing a CMMC assessment. Same practices, lighter documentation burden, same vCISO Agent access.