Cybersecurity scoped to
the contracts you've already won.
We write the System Security Plan and read the POA&M. We don't pretend to run a 24/7 SOC. ITC supports federal agencies and prime contractors with NIST 800-171 and 800-53 advisory work, ATO package scoping, and zero-trust readiness reviews. Deliverables are written, dated, and survive an Inspector General read.
Services in this practice · advisory, not standing operations
Three engagement shapes. Each delivers a written artifact your contracting officer can read on its own.
NIST 800-171 / 800-53 self-assessment
Control-by-control walkthrough against your CUI boundary. Output is a written System Security Plan with POA&M scaffolding, ready for your 3PAO or sponsoring agency.
SAR & POA&M coordination
We translate between your engineering team and the 3PAO of your choice. Includes control implementation summaries, evidence indexing, and remediation triage with realistic dates.
OMB M-22-09 readiness
Pillar-by-pillar review against the CISA Zero Trust Maturity Model. We scope the path. Implementation of any individual control is per-engagement, not turnkey.
Why a security officer picks us · four reasons
Picked from the four points contracting officers and CISOs actually score on.
800-171 adapted to your CUI boundary
Not generic checklists. Controls mapped against your actual data flows, system inventory, and contract clauses.
NYC + NMSDC MBE
NYC MBE cert MWCERT2022-353 through 2027-05-31. NMSDC-certified MBE through 2027-06-30.
L1 self-assessment, L2 readiness
Level 1 self-assessment supported end to end. Level 2 readiness available on engagement. C3PAO audit itself is out of scope.
Written deliverable per engagement
Every engagement produces an artifact. SSPs, POA&Ms, vendor-risk packets, tabletop after-action reports. Survives an OIG read.
What we do · and what we don't
Honest scope. The line between advisory and operations matters. We stay on the advisory side and tell you which partners we'd recommend on the operations side.
- SSP authoring against your CUI boundary
- POA&M scaffolding, evidence indexing
- Control mapping · 800-171, 800-53, CMMC L1/L2
- Vendor-risk packets & supplier-questionnaire response
- Tabletop exercises with after-action documentation
- Zero-trust roadmap against CISA maturity pillars
- 24/7 SOC operations · we don't run one
- EDR / MDR delivery as a standing service
- CMMC C3PAO formal audit · we coordinate, don't certify
- FedRAMP authorization · we support docs, don't hold
- Penetration testing as a service · introduced via partner
- Forensic incident response retainer
Questions worth asking · before we sign
The three we get asked most often, answered without hedging.
Do you operate a Security Operations Center?
No. ITC is an advisory practice, not a standing SOC. We'll help you select a managed SOC partner, scope the integration, and document the runbook handoff. The 24/7 watch itself stays with your SOC provider.
What CMMC level do you support?
Level 1 self-assessment is supported end to end. Level 2 readiness is available on engagement, mapped to your actual CUI boundary. The C3PAO audit itself is out of scope. We coordinate with the assessor and prepare your evidence package.
Are you a FedRAMP-authorized provider?
No. ITC does not hold a FedRAMP authorization. We support agencies and prime contractors with FedRAMP-facing documentation, vendor-due-diligence packets, and 3PAO coordination. The authorization itself sits with the CSP.
Send the scope. We'll write back the same day.
Indexing on NAICS or PSC? These are the codes this service maps to, each with how it reads in both government and commercial procurement.