SECURITY · COMPLIANCE · IT ADVISORY
Cybersecurity, compliance and IT advisory.
Apex BSA Group
Practice area

Governance, Risk & Compliance

Readiness, assessment, evidence and remediation against the frameworks the organization is held to.

Assess

CMMC 2.0 Gap Assessment

Scored assessment against the level you are held to: the fifteen FAR 52.204-21 requirements at Level 1, or all 110 NIST SP 800-171 controls at Level 2.

CMMC Scoping & Boundary Strategy

Defines the regulated-data boundary, makes the segmentation architecture decision (corporate scope-down vs. a dedicated, segmented environment), and documents both for accredited third-party assessor review.

DFARS 252.204-7012 Compliance Review

Review of contractor obligations under DFARS 7012 — incident reporting, media protection, cloud SRG alignment, and subcontractor flow-down.

Supply Chain Risk Management (SCRM)

ICT supplier risk assessment and SCRM program development aligned to NIST 800-161 and FASCSA (FAR Subpart 4.23) requirements.

Assessment Scoring & Submission Support

A scored self-assessment of the 110 NIST 800-171 controls using the government's own methodology, the score and affirmation filed in the system the contracting officer actually checks.

Commercial Regulatory Readiness

Control mapping and evidence for the regimes commercial businesses actually answer to: New York DFS Part 500, GLBA and FFIEC expectations, and PCI DSS where cardholder data is in scope.

Implement

CMMC 2.0 Readiness Engagement

Full cycle — gap through accredited third-party assessment prep.

RMF / ATO Support

Full NIST RMF lifecycle support — system categorization (FIPS 199), control selection and tailoring (NIST SP 800-53 Rev 5), SSP development, SAP/SAR support, POA&M management, and ATO package assembly.

FedRAMP Readiness Advisory

Gap assessment and readiness advisory for cloud service providers pursuing FedRAMP authorization.

STIG / CIS Benchmark Hardening Advisory

Configuration reviewed against DISA STIGs or CIS Benchmarks, ending in deviation documentation, a remediation roadmap and an evidence package that stands up in an authorization submission.

OT Regulatory Mapping & Evidence Program

One control set and one body of evidence that answers every audience asking, mapped across NIST SP 800-82r3 and IEC 62443 so the same artifact serves a regulator, an insurer and a board.

Get in touch

Bring us the deadline you are working to.

Contact

Frameworks
CMMC 2.0NIST SP 800-171 Rev 2DFARS 252.204-7012 / -7019 / -7020 / -7021NIST SP 800-53RMFFedRAMPSOC 2ISO 27001NIST CSF 2.0NY DFS Part 500GLBA / FFIECPCI DSSFERPA / PPRA / CIPA / COPPAAWIA / SDWA 1433CISA CPG 2.0CIRCIA