Compliance That
Protects Your Mission
Cybersecurity compliance advisory for federal agencies, state government, and commercial organizations operating in controlled environments. Veteran-owned. Results-driven.
Experience
Service
Served
Veteran-Owned
Tailored for Your Mission
We speak your language, understand your regulations, and deliver compliance solutions built for your environment.
Federal Agency Cybersecurity Compliance
Mission-critical compliance for civilian agencies and cloud service providers. FedRAMP is in the middle of the largest change in its history, and the transition deadlines are now inside every CSP's planning horizon. We help you meet the mandates while keeping operations running.
- FedRAMP 20x authorization under the CR26 rulesets
- Rev 5 machine-readable package conversion ahead of the September 30, 2026 deadline
- NIST 800-53 Rev 5 control assessments for civilian agency compliance
- FISMA compliance and authorization packages (ATO)
- Fractional vCISO for security leadership without the overhead
- Direct experience with HHS OIG and USCIS environments
FedRAMP 20x Readiness
Authorization under the 20x model and the CR26 rulesets, including Key Security Indicators, continuous validation, and machine-readable evidence.
Largest Change in YearsRev 5 Transition & Package Conversion
Machine-readable authorization packages for existing Rev 5 CSPs, plus transition planning before Rev 5 applications close in June 2027.
FedRAMP Rev 5NIST 800-53 Rev 5 Assessments
Full control assessments against NIST 800-53 Rev 5, including Release 5.2.0 updates, for civilian agencies and their contractors.
NIST 800-53 Rev 5FISMA Compliance
Authorization packages, system security plans, and ongoing compliance for federal information systems.
FISMAFractional vCISO
Executive-level security leadership, compliance oversight, and strategic planning on a fractional basis.
Core OfferingDefense Industrial Base Compliance
DFARS 252.204-7012 still applies to every contract that touches CUI, and it always has, with or without a certification program. We help DIB contractors post a defensible SPRS score, protect CUI, and satisfy the obligations they are actually being held to today.
- NIST 800-171 self-assessments and defensible SPRS score submission
- DFARS 252.204-7012 safeguarding, contractually binding regardless of certification status
- CUI identification, scoping, and protection planning
- Supply chain risk management and subcontractor flow-down
- 72-hour cyber incident reporting and False Claims Act exposure reduction
NIST 800-171 Self-Assessment & SPRS Scoring
Full 110-control assessment, scored to the DoD methodology, with the evidence trail to defend the number you post to SPRS.
Required NowSSP & POA&M Development
System security plans and remediation roadmaps that hold up under government review. This is the documentation DFARS assumes you already have.
NIST 800-171Supply Chain Security
Risk assessments for your subcontractor network, flow-down requirement management, and CUI scoping.
DFARSIncident Response & DFARS Reporting
IR plans, tabletop exercises, and 72-hour cyber incident reporting procedures for defense contractors.
CriticalAerospace & Space Systems Compliance
Aerospace suppliers answer to two rule sets that ask different questions about the same file. NIST 800-171 asks whether the data is protected. ITAR asks who can see it and whether they are a U.S. person. You can satisfy one and violate the other.
- CUI and ITAR technical data mapped in one inventory, not two programs
- U.S. person access review across employees, MSPs, and cloud support paths
- Deemed export risk, including offshore MSP night shifts with domain access
- CNSSI 1253 categorization and overlays for national security space programs
- Shop floor OT scoping for CNC controllers, PLCs, and test equipment
CUI & Export Control Alignment
One access model answering both regimes. Data inventory tagged by regime, U.S. person access review, and deemed export risk assessment.
Aerospace SpecificCNSSI 1253 & National Security Space
Categorization and overlay support under CNSSP 12 and CNSSI 1200, where civilian NIST 800-53 baselines and FedRAMP experience do not transfer cleanly.
CNSSI 1253NIST 800-171 & SPRS Scoring
Full 110-control self-assessment with SSP, POA&M, and the evidence trail to defend your posted score.
NIST 800-171Shop Floor OT Security
CNC controllers, PLCs, CMMs, and test stands scoped as Specialized Assets, with safeguards for equipment that cannot run modern endpoint tooling.
OT / ICSHealthcare Cybersecurity Compliance
Protect patient data, satisfy HHS requirements, and prepare for OCR audits. We help covered entities and business associates build sustainable HIPAA compliance programs.
- HIPAA Security Risk Assessments, federally required annually
- Covered entity and business associate compliance programs
- Health IT security architecture and ePHI protection
- Readiness for the proposed Security Rule overhaul, with final action now expected in 2027
- Breach notification planning and OCR audit preparation
- Direct experience with HHS OIG healthcare security environments
HIPAA Security Risk Assessments
Comprehensive SRA aligned with 45 CFR 164.308. Gap identification, remediation plans, and audit-ready evidence.
HIPAAPolicy & Procedure Development
HIPAA-compliant security policies, workforce training programs, and administrative safeguard documentation.
45 CFR 164Breach Notification & IR Planning
HIPAA breach notification procedures, incident response plans, and tabletop exercises for healthcare scenarios.
High PriorityFractional vCISO for Healthcare
Ongoing security leadership for practices, hospitals, and health IT companies without a full-time hire.
Core OfferingState Government Compliance
Florida agencies and state-level organizations face growing cybersecurity mandates. We're a registered MFMP vendor and Florida CBE ready for state procurement.
- NIST CSF 2.0 alignment, including the new Govern function, and maturity assessments
- Florida MFMP registered vendor, ready for state procurement
- VBE/CBE set-aside eligible, Veteran Business Enterprise certified
- HIPAA compliance for state health agencies and Medicaid programs
- HB 1085 grant readiness — the new Local Government Cybersecurity Protection Program
- Incident response planning for public sector environments
NIST CSF 2.0 Assessments
Baseline cybersecurity maturity against NIST CSF 2.0, including the Govern function added in the 2.0 release, with a prioritized remediation roadmap.
NIST CSF 2.0HIPAA for State Health Programs
Security risk assessments for Medicaid, public health, and state-run healthcare programs.
HIPAAHB 1085 Grant Readiness
Chapter 2026-115 created the Local Government Cybersecurity Protection Program inside the Florida Digital Service, effective July 1, 2026. FLDS procures solutions against a defined need, so a documented gap list is what makes a jurisdiction fundable.
New July 2026Security Program Development
Build or mature your agency's security program from policies and procedures to technical controls.
Program BuildFractional vCISO
Security leadership for agencies that need strategic direction without a full-time CISO hire.
Core OfferingCommercial Cybersecurity Advisory
For businesses over $1M annual revenue operating in regulated environments. Compliance isn't overhead. It's competitive advantage. We make it efficient and sustainable.
- Fractional vCISO retainers, executive security leadership on demand
- SOC 2 readiness for SaaS and service organizations
- PCI DSS v4.0.1 gap analysis, including the 51 requirements that became mandatory in March 2025
- AI security governance for organizations adopting AI in controlled environments
- Compliance as competitive advantage: win contracts, reduce liability, build trust
Fractional vCISO Retainers
Ongoing security leadership, compliance management, board reporting, and strategic oversight for growing businesses.
Core OfferingSOC 2 Readiness
Gap analysis, control implementation guidance, and evidence preparation for SOC 2 Type I/II audits.
SOC 2PCI DSS v4.0.1 Compliance
Gap analysis and remediation planning for payment card industry data security standards.
PCI DSS v4.0.1AI Security & Governance
Risk assessments aligned to NIST AI RMF and ISO/IEC 42001, governance frameworks, LLM red teaming, and secure implementation for AI adoption in regulated industries.
AI GovernanceOur Services
End-to-end compliance solutions from assessment through remediation and ongoing management.
AI Security & Governance
Secure AI adoption for organizations in regulated environments. We assess AI risk, build the governance program, and ship the automation ourselves.
- AI risk assessments & NIST AI RMF alignment
- Governance frameworks & acceptable use policy
- LLM red teaming & prompt injection testing
- AI-powered security automation & evidence collection
NIST 800-171 & DFARS Compliance
Self-assessment, SPRS scoring, and CUI protection for defense contractors. No certification required. These obligations are already in your contract.
- 110-control self-assessment
- Defensible SPRS score submission
- SSP & POA&M development
- CUI scoping & flow-down
Fractional vCISO
Executive-level security leadership without a full-time hire. Strategy, oversight, and compliance management.
- Security strategy & oversight
- Board & executive reporting
- Compliance program management
- Team development & mentoring
HIPAA Security Risk Assessments
Federally required annual assessments for every healthcare covered entity. Audit-ready evidence documentation for HHS OCR.
- Annual SRA compliance (45 CFR 164.308)
- Gap identification & remediation
- Policy & procedure development
- OCR audit preparation
Security Assessments
Comprehensive evaluation across PCI DSS v4.0.1, NIST 800-53 Rev 5, NIST CSF 2.0, SOC 2, and FedRAMP.
- PCI DSS v4.0.1 gap analysis
- FedRAMP 20x readiness
- SOC 2 preparation
- Security architecture review
Incident Response Planning
Be prepared when security events occur. Meet HIPAA breach notification and DFARS reporting requirements.
- IR plan development
- Tabletop exercises
- Business continuity planning
- Breach notification compliance
Deep Expertise. Veteran Discipline. Audit-Ready Results.
Trusted advisory backed by decades of real-world security experience across federal and commercial environments.
Veteran-Owned
10 years U.S. Navy service. We understand the mission, speak the language, and bring military discipline to every engagement.
Federal Experience
Direct experience with HHS OIG, USCIS, and major defense contractors. We know what auditors look for because we've been there.
21+ Years Security
Deep expertise across HIPAA, NIST 800-171, NIST 800-53 Rev 5, NIST CSF 2.0, PCI DSS v4.0.1, SOC 2, FedRAMP 20x, FISMA, and risk management frameworks.
Builder, Not Just Auditor
We build tools, automations, and evidence systems that make compliance sustainable, not a one-time exercise.
From the Field
Practical guidance on compliance, security, and the tools we build to make both sustainable.
Your FedRAMP Package Has to Be Machine-Readable by September 30
The deadline applies to existing Rev 5 certifications, not just new applicants, and most providers have not started. What conversion actually involves, and what non-compliance costs once the grace period ends.
FedRAMP 20x Turns Compliance Into Code
20x replaces narrative control descriptions with automated Key Security Indicators, and refuses written descriptions altogether, from humans and language models alike.
Aerospace Suppliers Are Governed by Two Rule Sets That Do Not Agree
A NIST 800-171 environment can be fully compliant and still be an ITAR violation, because the two regimes ask different questions about the same data. Add national security space and there are three.
CMMC Phase 2 Is Suspended. Your Legal Exposure Went Up.
The certification deadline is gone. The obligations are not, and the one government mechanism that used to catch a bad SPRS score before a lawyer did is paused.
Florida Gave You the Mandate, Vetoed the Safe Harbor, and Just Funded the Fix
Florida mandates NIST CSF by statute, the alignment deadlines have passed, the liability safe harbor was vetoed, and as of July 1 there is finally state money on the table.
Florida Makers and CMMC: The OT Blind Spot on Your Shop Floor
Your CNC machines, PLCs, and IoT sensors are in scope. Most small manufacturers are not thinking about operational technology when they scope an assessment, and it is the gap that kills timelines.
Certifications & Business Information
Registered and ready for federal, state, and commercial contracting.
Professional Certifications
Business Information
Ready to Strengthen Your
Compliance Posture?
Schedule a free 30-minute consultation to discuss your compliance challenges, timeline, and how Waypoint can help.
Schedule a 30-minute Zoom call
Discuss your compliance challenges
Get a tailored action plan