| CMMC Level 1 & 2 |
DoD contractors and subcontractors handling FCI or CUI — including HII/the federal contracting corridor supply chain firms, NAVSEA subcontractors, and any Washington DC firm with a DoD prime or subcontract. Phase 2 C3PAO certification begins November 2026. |
CUI boundary scoping and network segmentation, patch compliance documentation for all 110 NIST 800-171 practices at Level 2, access control enforcement via Intune and Entra ID, DFARS 72-hour incident reporting support, and System Security Plan (SSP) development with supporting evidence artifacts |
SSP-ready evidence package, CMMC Level 2 gap assessment with remediation roadmap, and C3PAO readiness documentation aligned to the Phase 2 certification timeline |
| HIPAA Security Rule |
Healthcare covered entities and business associates handling Protected Health Information — practices, MedStar Washington Hospital Center-affiliated physician groups, MedStar Health and George Washington University Hospital suppliers, behavioral health providers, and medical billing companies across Washington DC |
24/7 security monitoring for anomalous PHI access, device compliance reporting for Section 164.310 workstation controls, annual HIPAA Security Rule risk assessment aligned to the OCR Risk Analysis Initiative launched October 2024, and technical safeguard implementation across EHR-connected systems |
Annual HIPAA Risk Assessment report with documented evidence, device compliance inventory, and audit-ready evidence folder mapped to HIPAA Security Rule standards and ready for OCR audit response |
| PCI DSS v4.0.1 |
Washington DC organizations processing cardholder data — resort hotels, hospitality businesses, port commercial operations, retailers, and any organization taking card payments outside a fully hosted payment page; v3.2.1 retired March 31, 2024 |
Cardholder Data Environment (CDE) scoping and boundary documentation, Requirement 11.6.1 tamper-detection implementation for payment pages, MFA enforcement for all CDE access per Requirement 8.3.1, patch management for in-scope systems, and ASV scanning coordination |
PCI scope boundary document, CDE device inventory with compliance status, Requirement 11.6.1 implementation evidence, and SAQ-supporting documentation mapped to applicable requirements |
| Cyber Insurance |
All Washington DC businesses carrying cyber liability coverage — underwriters now require specific technical controls as a condition of coverage, with co-insurance penalties for non-compliance; claim denials are routine when documented controls are absent at the time of an incident |
MFA enforcement across Microsoft 365 and remote access, SentinelOne EDR deployment and active SOC monitoring, Datto backup with tested restore verification, patch management with documented currency, and privileged access management baseline implementation |
Controls attestation package answering the underwriter questionnaire line by line, with evidence screenshots and configuration documentation ready for annual renewal submissions |
| Washington DC Code 28-3852 |
All Washington DC organizations that experience unauthorized access to personal information of Washington DC residents — notification to affected individuals and to the Washington DC AG Computer Crime Section (202 North 9th Street, Richmond, DC 23219) is required for every reportable breach, without unreasonable delay, regardless of size |
Incident detection through 24/7 SOC, breach scope assessment to determine notification obligation, documentation of breach timeline and affected records, and support for AG notification and affected individual communication preparation |
Breach timeline and scope report, AG notification draft, affected individual notification letter, and post-incident evidence preservation documentation |
| NIST CSF 2.0 |
Any Washington DC organization seeking a structured security baseline — commonly required by cyber insurance carriers, large enterprise customers in the defense and financial sectors, or boards asking for documented security governance |
CSF 2.0 gap assessment across all six functions (Govern, Identify, Protect, Detect, Respond, Recover), remediation roadmap prioritized by risk, and ongoing monitoring aligned to Detect and Respond functions through co-managed SOC |
CSF maturity scorecard by function, executive summary for board presentation, and 12-month remediation roadmap with assigned owners and measurable milestones |