The light
stays green.
Certification is a point in time. Your environment is not. Continuous Guidance is stage 04 of the CMMCg Method: the standing engagement that keeps the controls implemented and the score defensible between assessments.
Scores drift quietly.
Nothing announces itself when compliance lapses. An admin adds a local account. A laptop drops off patch management. Someone disables MFA for a vendor integration and never re-enables it. Logging fills a disk and silently stops.
None of that generates a notification. It surfaces at the next assessment, or in a prime's flowdown questionnaire, and by then the number in the Supplier Performance Risk System (SPRS) has been wrong for months.
- Day 0Score submitted at 110. Everything implemented.
- Day 40MFA exception added for a vendor tool. Nobody logs it.
- Day 90Three endpoints fall out of patch compliance.
- Day 210Prime requests a current score. It is still 110 on paper.
- Day 240Assessment finds 7 controls failing. Actual score: 89.
Six things, running always.
Drift detection
Configuration and asset integrity monitored continuously. A GPO change that breaks a control raises an alert the same day, not at the next audit.
Vulnerability management
Scanning, triage, and remediation tracking mapped to the controls the finding actually touches — so the work is prioritized by score impact.
Evidence refresh
Screenshots, logs, and policy attestations regenerated on a schedule. Your evidence package is current on any given Tuesday.
Incident response
Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 reporting playbooks, run by cleared US analysts, inside the 72-hour window.
Score defense
Every change that would move your SPRS number gets flagged before it moves it. The score is a monitored metric, not an annual event.
Reassessment readiness
When the next assessment comes, the package is already built. Nothing to reconstruct, nothing to remember.
All six land in one place each month. Rather than describe it, here is the report itself — a specimen, for a company that does not exist.
See a sample coverage reportA US-based SOC, and no exceptions to that.
Every analyst who can see your environment is a US citizen working from the United States. No offshore tier-one, no follow-the-sun handoff to a region your Controlled Unclassified Information (CUI) is not permitted to reach. For a defense supplier this is not a preference, it is the requirement.
Get stage 04 running.
Continuous Guidance starts once an assessment has established the baseline. The readiness call is where that begins.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.