Control implementation review across identity, device management, logging, configuration, incident response, media handling, supplier access, and cloud boundaries.
CPCSC and CMMC readinessfor assessments
For defence suppliers that need their controls, evidence, and assessment story to hold up before CPCSC or CMMC requirements land in a contract.
What does CPCSC readiness work include?
CPCSC readiness work maps a supplier's systems and evidence against the Canadian CPCSC path led by Public Services and Procurement Canada and National Defence. The work uses ITSP.10.171, Canada's version of NIST SP 800-171, and keeps U.S. DoD CMMC expectations in view for suppliers that may face both markets. Nelson holds the CMMC CCP credential; that supports readiness preparation, not legal advice, certification authority, C3PAO work, or final assessment decisions.
What I usually look at
Best fit when sales, procurement, or a defence customer is asking how the environment maps to CPCSC, CMMC, ITSP.10.171, or NIST SP 800-171 and the delivery team needs a grounded current-state view before a formal assessor or government authority is involved.
Evidence gathering that ties screenshots, exports, policies, procedures, diagrams, ticket records, and system settings back to CPCSC, CMMC, ITSP.10.171, and NIST SP 800-171 expectations.
Mock assessment prep using NIST SP 800-171A style methods so teams can practice explaining what is implemented, what evidence exists, and where the boundary of the assessed system sits.
Gap sequencing that separates contract-risk items from cleanup work, with owner, effort, dependency, and evidence notes for each gap.
Assessment-facing documentation, including system security plan material, control narratives, evidence indexes, supplier-flow notes, and plain-language explanations for non-technical reviewers.
If this matches what you are trying to make real, send a note. A few sentences is enough.