Three SaaS products live · OpsTicket · Winrove · OnboardIQ·SAM.gov UEI PR9KWJPM4JU9 · CAGE 91CE1
IT Custom SolutionFour Practices, One Firm · Est. MMXXI
§ SAM.gov UEI · PR9KWJPM4JU9§ CAGE · 91CE1§ NYC MBE · MWCERT2022-353
§ Cybersecurity & compliance · NIST-aligned advisory

Cybersecurity scoped to
the contracts you've already won.

We write the System Security Plan and read the POA&M. We don't pretend to run a 24/7 SOC. ITC supports federal agencies and prime contractors with NIST 800-171 and 800-53 advisory work, ATO package scoping, and zero-trust readiness reviews. Deliverables are written, dated, and survive an Inspector General read.

§ Practice lead
Lu Fagbure · Founder & Director
§ Federal posture
UEI PR9KWJPM4JU9 · CAGE 91CE1
§ 01

Services in this practice · advisory, not standing operations

Three engagement shapes. Each delivers a written artifact your contracting officer can read on its own.

§ A · Gap analysis

NIST 800-171 / 800-53 self-assessment

Control-by-control walkthrough against your CUI boundary. Output is a written System Security Plan with POA&M scaffolding, ready for your 3PAO or sponsoring agency.

§ B · ATO scoping

SAR & POA&M coordination

We translate between your engineering team and the 3PAO of your choice. Includes control implementation summaries, evidence indexing, and remediation triage with realistic dates.

§ C · Zero-trust

OMB M-22-09 readiness

Pillar-by-pillar review against the CISA Zero Trust Maturity Model. We scope the path. Implementation of any individual control is per-engagement, not turnkey.

§ 02

Why a security officer picks us · four reasons

Picked from the four points contracting officers and CISOs actually score on.

§ NIST

800-171 adapted to your CUI boundary

Not generic checklists. Controls mapped against your actual data flows, system inventory, and contract clauses.

§ MBE

NYC + NMSDC MBE

NYC MBE cert MWCERT2022-353 through 2027-05-31. NMSDC-certified MBE through 2027-06-30.

§ CMMC

L1 self-assessment, L2 readiness

Level 1 self-assessment supported end to end. Level 2 readiness available on engagement. C3PAO audit itself is out of scope.

§ Documentation

Written deliverable per engagement

Every engagement produces an artifact. SSPs, POA&Ms, vendor-risk packets, tabletop after-action reports. Survives an OIG read.

§ 03

What we do · and what we don't

Honest scope. The line between advisory and operations matters. We stay on the advisory side and tell you which partners we'd recommend on the operations side.

In scope
  • SSP authoring against your CUI boundary
  • POA&M scaffolding, evidence indexing
  • Control mapping · 800-171, 800-53, CMMC L1/L2
  • Vendor-risk packets & supplier-questionnaire response
  • Tabletop exercises with after-action documentation
  • Zero-trust roadmap against CISA maturity pillars
Out of scope
  • 24/7 SOC operations · we don't run one
  • EDR / MDR delivery as a standing service
  • CMMC C3PAO formal audit · we coordinate, don't certify
  • FedRAMP authorization · we support docs, don't hold
  • Penetration testing as a service · introduced via partner
  • Forensic incident response retainer
§ 04

Questions worth asking · before we sign

The three we get asked most often, answered without hedging.

§ Q · 01

Do you operate a Security Operations Center?

No. ITC is an advisory practice, not a standing SOC. We'll help you select a managed SOC partner, scope the integration, and document the runbook handoff. The 24/7 watch itself stays with your SOC provider.

§ Q · 02

What CMMC level do you support?

Level 1 self-assessment is supported end to end. Level 2 readiness is available on engagement, mapped to your actual CUI boundary. The C3PAO audit itself is out of scope. We coordinate with the assessor and prepare your evidence package.

§ Q · 03

Are you a FedRAMP-authorized provider?

No. ITC does not hold a FedRAMP authorization. We support agencies and prime contractors with FedRAMP-facing documentation, vendor-due-diligence packets, and 3PAO coordination. The authorization itself sits with the CSP.

§ 05
§ Next step

Send the scope. We'll write back the same day.

§ SAM ·Active through 2027-06-11
§ Procurement codes for this service

Indexing on NAICS or PSC? These are the codes this service maps to, each with how it reads in both government and commercial procurement.

NAICS 541512NAICS 541519PSC DJ01PSC R425

Analytics cookies? Details: cookies policy or privacy policy.