Holdfast Cyber crest Holdfast CyberSecure Today. Defend Tomorrow.
Services

From first assessment to maintained readiness

Six services covering the full CMMC lifecycle. Start anywhere — most suppliers start with the gap assessment, because everything else is scoped from what it finds.

01
Assess

Gap Assessment & SPRS Scoring

A structured evaluation of your environment against all 110 controls of NIST SP 800-171, producing a defensible SPRS self-assessment score and a remediation roadmap prioritized by risk, cost, and contract impact. This is the position report every other decision is built on.

  • Control-by-control evaluation across all fourteen 800-171 families
  • Calculated SPRS score with full scoring rationale you can defend to a prime
  • CUI/FCI scoping review — what's actually in scope, and what can be carved out
  • Prioritized remediation roadmap with effort estimates
02
Document

SSP & POA&M Development

The System Security Plan is the document an assessor reads first — and the one most suppliers get wrong by describing an idealized environment instead of the real one. We write yours to reflect how your business actually operates, paired with a Plan of Action & Milestones that's trackable, dated, and realistic.

  • SSP mapped to your actual network, systems, and personnel
  • POA&M with owners, milestones, and completion criteria per item
  • Alignment between SSP claims and the evidence behind them
03
Formalize

Policy & Documentation

Complete policy coverage across all fourteen NIST 800-171 control families, plus the operational plans assessors expect to see working: incident response, configuration management, and continuous monitoring. Written to your operations — not boilerplate with your logo swapped in.

  • Fourteen control-family policies (AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, SI)
  • Incident Response Plan with defined roles and reporting timelines
  • Configuration Management and Continuous Monitoring plans
  • Policy-to-control traceability so nothing is orphaned at assessment
04
Sustain

Managed Compliance

Compliance decays the day the consultant leaves — unless someone keeps the watch. Managed compliance keeps controls operating, evidence current, and your SPRS posture defensible between assessments, at a fraction of the cost of a compliance hire.

  • Scheduled control reviews and evidence collection cycles
  • POA&M tracking and closure management
  • Change review when your environment or contracts shift scope
  • Annual SPRS score refresh and re-attestation support
05
Prepare

Assessment Support

When the assessment comes — self-assessment or C3PAO — preparation is the difference between a finding and a pass. We package your evidence, rehearse your team, and sit beside you through the engagement. The certifying assessment itself is conducted by an authorized third party; our job is making sure you walk into it ready.

  • Evidence packaging organized by control and assessment objective
  • Mock interviews and readiness rehearsal for your control owners
  • On-call support during the assessment window
06
Advise

Fractional Advisory

Senior security and compliance leadership, scaled to what a small supplier actually needs. Standing guidance for security decisions, customer questionnaires, contract flowdown reviews, and board or ownership reporting — without a six-figure hire.

  • Retained monthly advisory hours with a senior GRC practitioner
  • Customer security questionnaire and flowdown clause review
  • Security roadmap and budget guidance sized to your operation
Holdfast Cyber crest

Not sure where to start? Start with where you stand.

The gap assessment scopes everything else — and it comes with no obligation to continue.

Request a Gap Assessment
Secure Today. Defend Tomorrow.