The challenge behind the engagement.
This service is for a federal system owner or contractor building or renewing an authorization package under the Risk Management Framework. We start from where you are: your system’s impact level, the information it handles, its boundary, and any controls you inherit from a provider. We choose and tailor the right control baseline for your system, apply any agency-specific additions, and fold in the latest control updates. We assess each control with the official examine, interview, and test procedures and write implementation statements backed by real configuration evidence and a clear provider-responsibility split. Then we assemble the full package: the system security plan, the assessment plan and report, the remediation plan, the risk assessment, and a continuous-monitoring plan, in the format your agency’s tool accepts. Your authorizing official decides; we do not issue the authorization.
System security officers, program managers, and contractors who must deliver an authorization package to an authorizing official for a federal system. Also teams that need a current control set for a new system, an agency-specific addition, or a renewal.
What we do.
What you can use.
Categorize the system and pick the baseline
We begin with the mission owner’s impact-level decision, the information the system handles, the boundary diagram, and any prior authorization artifacts. We select the right control baseline, apply agency additions and the parameters your agency sets, mark what is inherited from your hosting provider, and deliver a tailored control set.
Assess and implement control by control
For each control we run the official examine, interview, and test procedures with its owner and record the determination. We write the implementation statement against live evidence: hardening results, infrastructure defined as code, access policies, and how logging is configured. Gaps land in the remediation plan with an owner, a milestone, and a fix.
Assemble the package for your authorizing official
You receive the system security plan, the assessment plan and report, the remediation plan, the risk assessment, and the contingency, incident-response, and continuous-monitoring plans, entered in your agency’s tool or exported in the machine-readable format it accepts. After remediation we reassess the closed controls and update the report with dated evidence.
Who it’s for.
When you need it.
- Information system security officers assembling an RMF authorization package for a federal system
- Program managers who must deliver an SSP, SAP, SAR, and POA&M to an authorizing official
- Contractors operating a federal system that needs a Release 5.2.0 control set
- Teams entering packages through eMASS, Xacta, or ServiceNow for agency review
- A new system must be categorized and authorized before it goes live
- An existing authorization is up for renewal or a significant change occurred
- An agency overlay or ODP decision pulls in the Release 5.2.0 additions
- Your authorizing official expects a machine-readable package for the agency GRC tool
What the scope can include.
- 01
Review the impact level, the information types, and the authorization boundary
- 02
Select and tailor the control baseline with agency additions and set parameters
- 03
Fold in the latest control updates where your agency or an addition selects them
- 04
Assess each control with the official procedures and written determinations
- 05
Map inherited controls and write the provider-responsibility split for hosted services
- 06
Assemble the package for your agency’s tool, with a machine-readable export where accepted
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
One system at the Low baseline, mostly cloud-hosted
About 120–200 hoursOne system at the Moderate baseline with several connected services
About 220–360 hoursHigh baseline, or several systems sharing one authorization package
About 360–600 hours- Baseline selected (Low, Moderate, or High) and resulting control count
- Number of systems and inherited controls from a cloud provider
- Existing policies, procedures, and evidence
- Agency-specific overlays or tailoring requirements
2–5 months depending on baseline and number of systems
Independent control assessment and the authorizing official's review are separate; third-party assessments of a Low system are quoted around $10,000–$20,000 and rise steeply at Moderate and High.
Get a fixed quote for your scopeRanges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Categorization memo and tailored control set with parameters and inheritance marked
- Assessment plan and report with a determination for every control
- System security plan, remediation plan, risk assessment, and continuous-monitoring plan
- Machine-readable package files when your agency or its platform accepts them
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Do we need to adopt the latest control release now?
Check your agency’s direction first, then plan for it either way. The most recent update added a few new controls and revised one, and updated the matching assessment procedures, but it did not change the baselines. So an existing moderate or high package does not grow on its own; the new controls matter when your agency or an added control set selects them. We record the change in your tailored control set, note which items your authorizing official has adopted, and keep your plan consistent with the official versions of the catalog.
How much can we inherit from our cloud hosting provider?
Much of the physical, environmental, and infrastructure controls, and less of what you configure yourself. The provider’s authorization package and responsibility matrix state which controls are fully inherited, shared, or entirely yours. We read that matrix against your architecture, mark each control in your plan as inherited, shared, or customer, and write the customer half of every shared control, such as the access policies, key management, and logging you configure. Authorizing officials expect that split to be explicit, and an inheritance claim without the provider’s authorization behind it is one an assessor will challenge.
- 32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program (Federal Register final rule)
- Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements
- NIST SP 800-171 Rev. 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations
- FedRAMP Consolidated Rules for 2026
- FedRAMP 20x
- GovRAMP FAQs
