The flagship program

JumpStart Fed

An engineered CMMC Level 2 program for small defense contractors: the structure, the documents, the mapping, and the evidence discipline, already built. This page is the program in depth.

§ 01 · Structure

Ninety-three steps, in order

The program is a defined sequence from kickoff to assessment-ready. Steps are small enough to finish in a working session and specific enough that nobody has to interpret them. Each one names its task, its owner, and the evidence it should leave behind.

  • What to do. Plain instructions written for a shop without a security team, not for a CISO.
  • Who owns it. Every step is assigned to a named role: owner, IT lead, office manager. Ownership is how small teams actually finish.
  • What it proves. Each step states its evidence expectation, so the assessment file builds itself as you work instead of in a panic at the end.
  • Where you stand. Progress is visible at every point. You can always answer the question "how far along are we?"

§ 02 · Documents

Controlled documents, not empty shells

The document set is the product. Every artifact ships with working sections, instructions, roles, approval fields, revision history, operational columns, and evidence references. Your job is to adapt and operate them, not to write them.

01
The spine

SSP and POA&M

The System Security Plan describes your environment and how each requirement is met. The Plan of Action and Milestones tracks what is not met yet, with owners and dates. Assessors start with these two. So does the program.

02
The rules

Policies and plans

Policy documents for the control families, plus operational plans such as incident response. Written in plain language a small shop can actually follow, with the approval and revision machinery of a managed system.

03
The record

Registers and evidence

Registers for assets, scope, and evidence keep the operational facts in one place, referenced from the documents that rely on them. When something changes in the shop, there is one place to record it.

Everything is version-controlled and searchable. The program includes work surfaces for finding any requirement, document, or evidence item in seconds, because an answer you cannot find is an answer you do not have.

§ 03 · Coverage

One integrated system, mapped to the frameworks that bind you

JumpStart Fed is an ISO 27001 style management system with a federal overlay. That is a deliberate design choice: a management system keeps working after the certificate, while a one-off CMMC binder starts rotting the day it is printed.

All 110 requirements, family by family

Requirement counts vary dramatically across the 14 control families, and the program is weighted the same way, so effort lands where assessors look.

Access Control22
System & Comms Protection16
Identification & Auth11
Audit & Accountability9
Configuration Mgmt9
Media Protection9
System & Info Integrity7
Maintenance6
Physical Protection6
Security Assessment4
Awareness & Training3
Incident Response3
Risk Assessment3
Personnel Security2

Counts per NIST SP 800-171 rev. 2, the version CMMC Level 2 assesses against.

Coverage register Maintained
ISO/IEC 27001

Foundation: the management system everything hangs on

NIST SP 800-171

Federal overlay: safeguarding CUI, all 110 requirements

CMMC Level 2

Assessment target: what your C3PAO certifies against

DFARS 252.204-7012

Contract clause: safeguarding and incident reporting duties

FedRAMP-related

Requirements that follow when cloud services touch CUI

ISO/IEC 27701

Privacy overlay for personal information management

ISO/IEC 27017

Cloud security controls overlay

§ 04 · The line we do not cross

What we do, and what your C3PAO does

Certification is not ours to give, and you should walk away from anyone who implies otherwise. The division of labor is clean.

JumpStart Fed

Gets you assessment-ready

  • Deploys the 93-step program and the controlled document set
  • Guides implementation with plain instructions and clear ownership
  • Defines the evidence each requirement needs and where it lives
  • Leaves you with a complete SSP, a managed POA&M, and evidence on file
Your C3PAO

Performs the assessment

  • An independent, authorized third-party assessment organization
  • Conducts the official CMMC Level 2 assessment
  • Examines your SSP, practices, and evidence firsthand
  • Makes the certification decision. Nobody else does, including us

See if the program fits your shop

A thirty-minute scoping call covers your contracts, your CUI footprint, and a realistic path. Straight answers, from the person who builds these programs.

Book a scoping call
Coming soon

Or start with the free snapshot

The readiness snapshot will show you where you stand against the 110 requirements before you talk to anyone. Get notified when it launches.

Get notified