- Lead initial client scoping engagements: identify people, processes, and assets that interact with CUI and FCI.
- Determine enclave architecture recommendations in collaboration with Security Engineers.
- Conduct comprehensive gap assessments against all 320 objectives across 110 controls of NIST SP 800-171 Rev 2.
- Create detailed Plans of Action and Milestones (POA&Ms) from gap assessment findings.
- Translate gap assessment findings into specific, actionable remediation tasks mapped to Azure/M365 components.
- Develop and maintain System Security Plans (SSPs) documenting all 110 controls.
- Create and maintain the full CMMC compliance policy library.
- Manage the evidence collection process.
- Conduct internal readiness reviews and mock assessments prior to C3PAO engagement.
- Support clients during C3PAO Level 2 assessments.
- Manage 4-7 concurrent client engagements at various stages of the CMMC lifecycle.
- Train client staff on security policies, acceptable use, CUI handling procedures, and incident reporting obligations.