CMMC Level 2 · Defense Industrial Base · Leesburg, VA+1 571 410-3066
Capital Cyber Compliance

Fractional CISO

A CISO for the business, part-time.

The security leadership role that owns your CMMC program from inside the business, part-time. Scoped per client.

Fractional CISO for defense contractors: a part-time security and compliance leader who owns the CMMC program from inside the business, chairs the reviews, and speaks to the program when a prime asks.

What it is

A CISO, a chief information security officer, is the person accountable for a company's security program. Most small defense suppliers cannot justify one full time, yet CMMC is not finished when a score is posted: controls drift, people leave, systems change, and the affirmation is signed again every year. A fractional CISO is that role, part-time: someone who keeps the plan current, runs the reviews where decisions get made and recorded, and can speak to the program when a prime or an assessor asks.

Is this the right service?

SCOPED, NOT PRICED

Who it is for

A contractor with a CMMC Level 2 requirement and nobody on staff whose job it is to own the security program. Usually a business that has started the work and needs it run, not restarted.

How it starts

A scoping call to agree the shape of the role: which reviews, how often, and what is already in place. If there is no recent gap assessment, the role starts with one.

How it differs

The gap assessment tells you where you stand, once. CMMC Level 2 program leadership gets you from there to your assessment. A fractional CISO owns the program after that, or alongside your own team. CMMC In A Container includes that ownership inside a managed program with its own environment.

What you receive

A security and compliance lead working from inside the business, part-time.Recorded reviews: what was decided, by whom, and what changed.The plan and the POA&M kept current between assessments.Someone to speak to the program when a prime or an assessor asks about it.

What this is not

We are not an Authorized C3PAO and we do not certify anyone. A fractional CISO is a part-time role we provide, not a full-time hire, and what we can commit to is our own accountability rather than what a third party will do.

Book a 30-minute call.

BOOK A CALL

Scoped per client, so the first step is a conversation. Pick a time.

What happens in 30 minutes

  1. We read your contract's CMMC and DFARS clauses with you.
  2. We confirm which level applies and how it will be assessed.
  3. We tell you the first step, whether or not it involves us. No slides.

Talk to us about it.

This is scoped per client, not priced on a page. Tell us what you have and we will tell you what it takes.

Book a 30-minute call

Defense supplier under 25 people? Start with the grant.

Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.

Apply for a CGA grant