Vigilant Cybersecurity

Services

Service Packages for Defense Contractors

Vigilant Cybersecurity offers four core engagement types for small and mid-sized defense contractors.

Each offering is scoped to a different point in your compliance journey. Start with a Gap Assessment if you're not sure where you stand, commit to a CMMC Readiness engagement when you're ready to close the gaps, bring in vCISO Services for ongoing leadership, or stay assessment-ready year-over-year with Compliance Sustainment.

CMMC Readiness

For defense contractors and subcontractors that need to meet CMMC Level 1 or Level 2 requirements.

A full engagement that takes your organization from current state through assessment-ready, built on NIST SP 800-171 and the CMMC program (32 CFR Part 170).

Typical engagement: 3–6 months, depending on starting posture and target level.

What's included

  • Right-sized scope and system boundary definition
  • Comprehensive NIST SP 800-171 / CMMC gap analysis with prioritized remediation roadmap
  • All required compliance artifacts — SSP, POA&M, policies, and evidence packages
  • Assessment-ready posture at engagement close

Gap Assessment

For organizations that need to understand where they stand before committing to a full readiness program.

A focused engagement that gives you an honest, prioritized picture of your compliance posture and the cost and timeline to close the distance.

Typical engagement: 2–4 weeks.

What's included

  • Current-state assessment against CMMC, NIST SP 800-171, or your applicable framework
  • Prioritized findings report
  • Draft Plan of Action & Milestones (POA&M)
  • Remediation cost and timeline estimates

vCISO Services

For organizations that need senior security leadership without a full-time CISO's salary.

We embed as your fractional security executive — owning your program roadmap, advising leadership and the board, and managing your compliance posture on a sustainable cadence.

Typical engagement: Monthly retainer, ongoing.

What's included

  • Strategic security roadmap ownership
  • Compliance program oversight (CMMC, HIPAA, NIST)
  • Executive and board reporting
  • Incident response coordination
  • Vendor and third-party risk oversight

Compliance Sustainment

For organizations that have already achieved CMMC, HIPAA, or NIST SP 800-171 readiness and need to maintain it year-over-year.

Compliance isn't a one-time project — it's an annual cycle of self-assessments, affirmations, evidence collection, control reviews, and POA&M closure. Sustainment engagements keep your program assessment-ready between assessments without putting a full vCISO on retainer.

Typical engagement: Annual or quarterly cadence, scoped to your framework and assessment cycle.

What's included

  • Annual self-assessment execution and documentation
  • Annual affirmation preparation
  • Evidence collection and artifact management
  • Control drift detection and remediation guidance
  • POA&M tracking and closure support
  • Reassessment preparation
  • Ad-hoc compliance advisory as questions arise

Inside a CMMC Readiness engagement

Every CMMC Readiness engagement follows the same six-phase methodology, scaled to your organization's size and level requirement. Gap Assessment engagements cover phases 1 and 2; vCISO Services span the full lifecycle as part of ongoing security leadership.

Which phases each engagement covers
Engagement01 Scope02 Gaps03 Plan04 Implement05 Document06 Validate
Gap AssessmentPhases 1–2
CMMC ReadinessAll six phases
vCISO ServicesFull lifecycle, as ongoing leadership
  1. Discovery & Scoping

    We begin by understanding your business structure, regulatory exposure (FCI or CUI), IT environment, and organizational goals. This phase defines your system boundary and establishes the scope for your compliance engagement — so nothing is over-built and nothing is missed.

  2. Gap Analysis

    Your current practices are assessed against CMMC Level 1 or Level 2 requirements. We identify which requirements are met, which are missing, and the realistic level of effort to close each gap — producing a clear, prioritized findings report your team can act on.

  3. Remediation Planning

    Based on your gap assessment, we build a risk-based remediation roadmap covering technical fixes, policy development, training requirements, and timelines. For Level 2 engagements, a draft Plan of Action and Milestones (POA&M) is produced to guide implementation.

  4. Implementation & Hardening

    We apply and verify technical controls — access management, endpoint protection, secure configurations, backup and recovery — alongside administrative safeguards including policies, procedures, and security awareness training aligned to CMMC requirements.

  5. Documentation & Evidence

    We prepare or update the compliance artifacts required for a self-assessment or third-party assessment: System Security Plan (SSP), security policies, POA&M, training records, access control documentation, and supporting evidence packages.

  6. Validation & Readiness Confirmation

    A final structured review confirms all requirements are addressed and evidence is complete. You leave this phase with a documented, defensible compliance posture — and a clear picture of what ongoing maintenance requires.

Led personally. Built to last.

Vigilant Cybersecurity was founded to give Alaska's small and mid-sized defense contractors a path to real, sustainable compliance — without the cost, complexity, or disconnect of a national firm. Whichever engagement type fits your situation, you'll work directly with the practitioner doing the work, and you'll come away with a security posture your team can maintain after the engagement ends.

Hutch will not serve on a CMMC assessment of any organization Vigilant Cybersecurity has advised. Advisory and assessment work are kept separate, consistent with CMMC's conflict-of-interest rules.

Not ready for a call?

Start with the free CMMC Resource Starter Kit

Level 1 readiness resources, funding options, and where Alaska contractors can get free help, including APEX Accelerators and Project Spectrum.

Send me the Starter Kit

Not sure where to start?

A free consultation is the fastest way to figure out which engagement fits your situation. Bring your contract requirements, your timeline, or just your questions — we'll talk through it together.

Schedule a Complimentary Scoping Call

Or reach a practitioner directly: (907) 229-5222 · consultations@vigilantcybersecurity.net