CMMC 2.0 — Managed Compliance Program

Network Depot Ongoing Services Framework

39 managed services organized across three delivery categories — click any category to focus.

Organization Seeking Certification (OSC)

PREVEIL

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

GCC

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

GCC VDI

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

C3PAO AUDIT

MANAGED COMPLIANCE

Technical

Hands-on security infrastructure management

13 Services
Endpoint Detection & Response (EDR/XDR)

Managed next-gen AV, behavioral detection, threat containment on all endpoints.

SIEM Management & 24/7 SOC Monitoring

Log ingestion, correlation rule tuning, analyst review, automated alerting

Patch Management

Critical CVEs ≤14 days, high CVEs ≤30 days, monthly patch reporting

Vulnerability Scanning

Weekly internal scans, monthly external scans, CVSS-based remediation tracking

Firewall & Network Security Management

NGFW rule management, IDS/IPS tuning, network segmentation maintenance

Identity & Access Management (IAM)

MFA enforcement, PAM/PIM, account provisioning/deprovisioning, quarterly recertification

Encryption Management

Disk encryption (BitLocker/FileVault), TLS enforcement, key lifecycle management

Backup & Disaster Recovery

Automated encrypted backups, monthly restore tests, immutable offline copies

Email Security

Anti-phishing gateway, SPF/DKIM/DMARC config, DLP policy enforcement

Configuration Compliance Management

CIS/STIG baseline enforcement, drift detection, automated compliance scanning

Mobile Device Management (MDM)

Corporate device enrollment, remote wipe capability, policy compliance enforcement

Unlimited Remote Helpdesk Support

Unlimited tickets for all end users — password resets, software issues, connectivity, device troubleshooting, and general IT support via phone, email, and chat

Security Incident First Response (L1)

Helpdesk-level triage for suspected phishing, malware alerts, and account lockouts — escalated immediately to SOC when thresholds are met

Technical Services
13
Administrative

Governance, documentation & compliance operations

13 Services
System Security Plan (SSP) Maintenance

Living document updates, control implementation narratives, annual full review

Plan of Action & Milestones (POA&M)

Gap tracking, remediation milestones, status reporting, evidence of completion

Policy & Procedure Management

Annual review of 19+ required policies and 12 SOPs, executive approval coordination

SPRS Score Tracking & Submission

Score calculation, DoD portal submission, maintenance after material changes

Evidence Collection & Audit Readiness

Ongoing evidence packaging, compliance artifacts organized for C3PAO assessment

Access Recertification

Quarterly privileged account reviews, user access certifications, exception documentation

Change Management

Security impact analysis, change log maintenance, approval workflows for in-scope systems

Vendor / Third-Party Management

Quarterly ESP reviews, contractual CMMC flow-down verification, risk scoring

CUI Inventory & Data Flow Management

CUI registry updates, data flow diagram maintenance, labeling compliance

Incident Documentation & Reporting

Incident logs, 72-hour DFARS/DIBNet reporting, post-incident reports

Compliance Calendar Execution

Scheduling and tracking of all monthly, quarterly, and annual compliance activities

User Onboarding & Offboarding

Secure device provisioning, compliant account setup, and full access revocation with asset recovery upon departure — completed within 1 business day

Software & License Management

Approved software installation and removal, license tracking, enforcement of application allowlist policy across all in-scope endpoints

Administrative Services
13
Advisory

Strategic guidance, training & certification support

13 Services
vCISO / Security Officer Services

Policy ownership, executive reporting, risk governance, regulatory liaison

Annual Enterprise Risk Assessment

NIST SP 800-30 methodology, risk register, executive risk reporting, remediation prioritization

Security Awareness Training Program

Annual training deployment, quarterly phishing simulations, role-based advanced training

C3PAO Assessment Coordination

Pre-assessment gap analysis, evidence package prep, assessor liaison, post-finding remediation

Penetration Testing Coordination

Annual pen test scoping, vendor management, findings review, remediation tracking

Incident Response Tabletop Exercises

Annual scenario-based exercises, lessons learned report, IRP updates

Disaster Recovery / BCP Testing

Annual DR exercise coordination, RTO/RPO validation, BCP update

Supply Chain Risk Management Advisory

Critical supplier identification, SBOM management, counterfeit component guidance

Cyber Insurance Alignment

Policy review for CMMC alignment, evidence support for renewals, claims coordination

Regulatory Change Monitoring

CMMC rule updates, DFARS/FAR clause changes, NIST framework revisions — client briefings

Subcontractor Flow-Down Guidance

CMMC requirement pass-through review, subcontractor assessments, contractual guidance

Cloud Security Posture Management (CSPM)

FedRAMP authorization validation, cloud misconfiguration monitoring, CASB controls

Executive Quarterly Business Reviews (QBRs)

Strategic compliance roadmap, program performance review, upcoming milestone planning

Advisory Services
13
Hover any service to view description · Click category buttons to filter

Organization Seeking Certification (OSC)

PREVEIL

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

GCC

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

GCC VDI

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

C3PAO AUDIT

MANAGED COMPLIANCE

Technical

Hands-on security infrastructure management

13 Services
Endpoint Detection & Response (EDR/XDR)

Managed next-gen AV, behavioral detection, threat containment on all endpoints.

SIEM Management & 24/7 SOC Monitoring

Log ingestion, correlation rule tuning, analyst review, automated alerting

Patch Management

Critical CVEs ≤14 days, high CVEs ≤30 days, monthly patch reporting

Vulnerability Scanning

Weekly internal scans, monthly external scans, CVSS-based remediation tracking

Firewall & Network Security Management

NGFW rule management, IDS/IPS tuning, network segmentation maintenance

Identity & Access Management (IAM)

MFA enforcement, PAM/PIM, account provisioning/deprovisioning, quarterly recertification

Encryption Management

Disk encryption (BitLocker/FileVault), TLS enforcement, key lifecycle management

Backup & Disaster Recovery

Automated encrypted backups, monthly restore tests, immutable offline copies

Email Security

Anti-phishing gateway, SPF/DKIM/DMARC config, DLP policy enforcement

Configuration Compliance Management

CIS/STIG baseline enforcement, drift detection, automated compliance scanning

Mobile Device Management (MDM)

Corporate device enrollment, remote wipe capability, policy compliance enforcement

Unlimited Remote Helpdesk Support

Unlimited tickets for all end users — password resets, software issues, connectivity, device troubleshooting, and general IT support via phone, email, and chat

Security Incident First Response (L1)

Helpdesk-level triage for suspected phishing, malware alerts, and account lockouts — escalated immediately to SOC when thresholds are met

Technical Services
13
Hover any service to view description · Click category buttons to filter

Organization Seeking Certification (OSC)

PREVEIL

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

GCC

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

GCC VDI

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

C3PAO AUDIT

MANAGED COMPLIANCE

Administrative

Governance, documentation & compliance operations

13 Services
System Security Plan (SSP) Maintenance

Living document updates, control implementation narratives, annual full review

Plan of Action & Milestones (POA&M)

Gap tracking, remediation milestones, status reporting, evidence of completion

Policy & Procedure Management

Annual review of 19+ required policies and 12 SOPs, executive approval coordination

SPRS Score Tracking & Submission

Score calculation, DoD portal submission, maintenance after material changes

Evidence Collection & Audit Readiness

Ongoing evidence packaging, compliance artifacts organized for C3PAO assessment

Access Recertification

Quarterly privileged account reviews, user access certifications, exception documentation

Change Management

Security impact analysis, change log maintenance, approval workflows for in-scope systems

Vendor / Third-Party Management

Quarterly ESP reviews, contractual CMMC flow-down verification, risk scoring

CUI Inventory & Data Flow Management

CUI registry updates, data flow diagram maintenance, labeling compliance

Incident Documentation & Reporting

Incident logs, 72-hour DFARS/DIBNet reporting, post-incident reports

Compliance Calendar Execution

Scheduling and tracking of all monthly, quarterly, and annual compliance activities

User Onboarding & Offboarding

Secure device provisioning, compliant account setup, and full access revocation with asset recovery upon departure — completed within 1 business day

Software & License Management

Approved software installation and removal, license tracking, enforcement of application allowlist policy across all in-scope endpoints

Administrative Services
13
Hover any service to view description · Click category buttons to filter

Organization Seeking Certification (OSC)

PREVEIL

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

GCC

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

GCC VDI

Onboarding

Policy Creation

Implementation

Evidence Gathering

Complete Documentation

C3PAO AUDIT

MANAGED COMPLIANCE

Advisory

Strategic guidance, training & certification support

13 Services
vCISO / Security Officer Services

Policy ownership, executive reporting, risk governance, regulatory liaison

Annual Enterprise Risk Assessment

NIST SP 800-30 methodology, risk register, executive risk reporting, remediation prioritization

Security Awareness Training Program

Annual training deployment, quarterly phishing simulations, role-based advanced training

C3PAO Assessment Coordination

Pre-assessment gap analysis, evidence package prep, assessor liaison, post-finding remediation

Penetration Testing Coordination

Annual pen test scoping, vendor management, findings review, remediation tracking

Incident Response Tabletop Exercises

Annual scenario-based exercises, lessons learned report, IRP updates

Disaster Recovery / BCP Testing

Annual DR exercise coordination, RTO/RPO validation, BCP update

Supply Chain Risk Management Advisory

Critical supplier identification, SBOM management, counterfeit component guidance

Cyber Insurance Alignment

Policy review for CMMC alignment, evidence support for renewals, claims coordination

Regulatory Change Monitoring

CMMC rule updates, DFARS/FAR clause changes, NIST framework revisions — client briefings

Subcontractor Flow-Down Guidance

CMMC requirement pass-through review, subcontractor assessments, contractual guidance

Cloud Security Posture Management (CSPM)

FedRAMP authorization validation, cloud misconfiguration monitoring, CASB controls

Executive Quarterly Business Reviews (QBRs)

Strategic compliance roadmap, program performance review, upcoming milestone planning

Advisory Services
13
Hover any service to view description · Click category buttons to filter

Managed Compliance support is operational and defensible.

Every ticket, change, and configuration is handled within our compliant environment.