Skip to content
CMMC Guidance
Continuous Guidance

The light
stays green.

Certification is a point in time. Your environment is not. Continuous Guidance is stage 04 of the CMMCg Method: the standing engagement that keeps the controls implemented and the score defensible between assessments.

The problem

Scores drift quietly.

Nothing announces itself when compliance lapses. An admin adds a local account. A laptop drops off patch management. Someone disables MFA for a vendor integration and never re-enables it. Logging fills a disk and silently stops.

None of that generates a notification. It surfaces at the next assessment, or in a prime's flowdown questionnaire, and by then the number in the Supplier Performance Risk System (SPRS) has been wrong for months.

Unguided
  1. Day 0Score submitted at 110. Everything implemented.
  2. Day 40MFA exception added for a vendor tool. Nobody logs it.
  3. Day 90Three endpoints fall out of patch compliance.
  4. Day 210Prime requests a current score. It is still 110 on paper.
  5. Day 240Assessment finds 7 controls failing. Actual score: 89.
What stage 04 covers

Six things, running always.

Drift detection

Configuration and asset integrity monitored continuously. A GPO change that breaks a control raises an alert the same day, not at the next audit.

Vulnerability management

Scanning, triage, and remediation tracking mapped to the controls the finding actually touches — so the work is prioritized by score impact.

Evidence refresh

Screenshots, logs, and policy attestations regenerated on a schedule. Your evidence package is current on any given Tuesday.

Incident response

Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 reporting playbooks, run by cleared US analysts, inside the 72-hour window.

Score defense

Every change that would move your SPRS number gets flagged before it moves it. The score is a monitored metric, not an annual event.

Reassessment readiness

When the next assessment comes, the package is already built. Nothing to reconstruct, nothing to remember.

All six land in one place each month. Rather than describe it, here is the report itself — a specimen, for a company that does not exist.

See a sample coverage report
Staffed now

A US-based SOC, and no exceptions to that.

Every analyst who can see your environment is a US citizen working from the United States. No offshore tier-one, no follow-the-sun handoff to a region your Controlled Unclassified Information (CUI) is not permitted to reach. For a defense supplier this is not a preference, it is the requirement.

24/7
Coverage
100%
US-based
0
Offshore access

Get stage 04 running.

Continuous Guidance starts once an assessment has established the baseline. The readiness call is where that begins.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.