SBA Certified SDVOSB | FL Certified Business Enterprise | SAM.gov Registered | MFMP Vendor
Now Accepting Clients

Compliance That
Protects Your Mission

Cybersecurity compliance advisory for federal agencies, state government, and commercial organizations operating in controlled environments. Veteran-owned. Results-driven.

21+
Years Security
Experience
10
Years U.S. Navy
Service
6
Regulated Markets
Served
SDVOSB
SBA Certified
Veteran-Owned
CISSP Certified
CEH Certified
MS Cybersecurity & IA
HHS OIG & USCIS Experience
MBA

Tailored for Your Mission

We speak your language, understand your regulations, and deliver compliance solutions built for your environment.

Federal Agency Cybersecurity Compliance

Mission-critical compliance for civilian agencies and cloud service providers. FedRAMP is in the middle of the largest change in its history, and the transition deadlines are now inside every CSP's planning horizon. We help you meet the mandates while keeping operations running.

  • FedRAMP 20x authorization under the CR26 rulesets
  • Rev 5 machine-readable package conversion ahead of the September 30, 2026 deadline
  • NIST 800-53 Rev 5 control assessments for civilian agency compliance
  • FISMA compliance and authorization packages (ATO)
  • Fractional vCISO for security leadership without the overhead
  • Direct experience with HHS OIG and USCIS environments

FedRAMP 20x Readiness

Authorization under the 20x model and the CR26 rulesets, including Key Security Indicators, continuous validation, and machine-readable evidence.

Largest Change in Years

Rev 5 Transition & Package Conversion

Machine-readable authorization packages for existing Rev 5 CSPs, plus transition planning before Rev 5 applications close in June 2027.

FedRAMP Rev 5

NIST 800-53 Rev 5 Assessments

Full control assessments against NIST 800-53 Rev 5, including Release 5.2.0 updates, for civilian agencies and their contractors.

NIST 800-53 Rev 5

FISMA Compliance

Authorization packages, system security plans, and ongoing compliance for federal information systems.

FISMA

Fractional vCISO

Executive-level security leadership, compliance oversight, and strategic planning on a fractional basis.

Core Offering

Defense Industrial Base Compliance

DFARS 252.204-7012 still applies to every contract that touches CUI, and it always has, with or without a certification program. We help DIB contractors post a defensible SPRS score, protect CUI, and satisfy the obligations they are actually being held to today.

  • NIST 800-171 self-assessments and defensible SPRS score submission
  • DFARS 252.204-7012 safeguarding, contractually binding regardless of certification status
  • CUI identification, scoping, and protection planning
  • Supply chain risk management and subcontractor flow-down
  • 72-hour cyber incident reporting and False Claims Act exposure reduction
Where CMMC stands: DoD suspended the CMMC Phase 2 third-party certification requirement in July 2026, and a reform task force is reviewing the program. Nothing about your underlying NIST 800-171 and DFARS obligations changed. We build the security program and evidence that satisfies today's requirements, and that carries straight into certification if and when Phase 2 resumes.

NIST 800-171 Self-Assessment & SPRS Scoring

Full 110-control assessment, scored to the DoD methodology, with the evidence trail to defend the number you post to SPRS.

Required Now

SSP & POA&M Development

System security plans and remediation roadmaps that hold up under government review. This is the documentation DFARS assumes you already have.

NIST 800-171

Supply Chain Security

Risk assessments for your subcontractor network, flow-down requirement management, and CUI scoping.

DFARS

Incident Response & DFARS Reporting

IR plans, tabletop exercises, and 72-hour cyber incident reporting procedures for defense contractors.

Critical

Aerospace & Space Systems Compliance

Aerospace suppliers answer to two rule sets that ask different questions about the same file. NIST 800-171 asks whether the data is protected. ITAR asks who can see it and whether they are a U.S. person. You can satisfy one and violate the other.

  • CUI and ITAR technical data mapped in one inventory, not two programs
  • U.S. person access review across employees, MSPs, and cloud support paths
  • Deemed export risk, including offshore MSP night shifts with domain access
  • CNSSI 1253 categorization and overlays for national security space programs
  • Shop floor OT scoping for CNC controllers, PLCs, and test equipment
Why this is different: Export control was never part of CMMC and is unaffected by the Phase 2 suspension. It carries its own enforcement path through the State Department's Directorate of Defense Trade Controls, with penalties that make most cybersecurity findings look modest. A compliance program that treats cybersecurity and export control as separate efforts will keep passing one while quietly failing the other.

CUI & Export Control Alignment

One access model answering both regimes. Data inventory tagged by regime, U.S. person access review, and deemed export risk assessment.

Aerospace Specific

CNSSI 1253 & National Security Space

Categorization and overlay support under CNSSP 12 and CNSSI 1200, where civilian NIST 800-53 baselines and FedRAMP experience do not transfer cleanly.

CNSSI 1253

NIST 800-171 & SPRS Scoring

Full 110-control self-assessment with SSP, POA&M, and the evidence trail to defend your posted score.

NIST 800-171

Shop Floor OT Security

CNC controllers, PLCs, CMMs, and test stands scoped as Specialized Assets, with safeguards for equipment that cannot run modern endpoint tooling.

OT / ICS

Healthcare Cybersecurity Compliance

Protect patient data, satisfy HHS requirements, and prepare for OCR audits. We help covered entities and business associates build sustainable HIPAA compliance programs.

  • HIPAA Security Risk Assessments, federally required annually
  • Covered entity and business associate compliance programs
  • Health IT security architecture and ePHI protection
  • Readiness for the proposed Security Rule overhaul, with final action now expected in 2027
  • Breach notification planning and OCR audit preparation
  • Direct experience with HHS OIG healthcare security environments

HIPAA Security Risk Assessments

Comprehensive SRA aligned with 45 CFR 164.308. Gap identification, remediation plans, and audit-ready evidence.

HIPAA

Policy & Procedure Development

HIPAA-compliant security policies, workforce training programs, and administrative safeguard documentation.

45 CFR 164

Breach Notification & IR Planning

HIPAA breach notification procedures, incident response plans, and tabletop exercises for healthcare scenarios.

High Priority

Fractional vCISO for Healthcare

Ongoing security leadership for practices, hospitals, and health IT companies without a full-time hire.

Core Offering

State Government Compliance

Florida agencies and state-level organizations face growing cybersecurity mandates. We're a registered MFMP vendor and Florida CBE ready for state procurement.

  • NIST CSF 2.0 alignment, including the new Govern function, and maturity assessments
  • Florida MFMP registered vendor, ready for state procurement
  • VBE/CBE set-aside eligible, Veteran Business Enterprise certified
  • HIPAA compliance for state health agencies and Medicaid programs
  • HB 1085 grant readiness — the new Local Government Cybersecurity Protection Program
  • Incident response planning for public sector environments

NIST CSF 2.0 Assessments

Baseline cybersecurity maturity against NIST CSF 2.0, including the Govern function added in the 2.0 release, with a prioritized remediation roadmap.

NIST CSF 2.0

HIPAA for State Health Programs

Security risk assessments for Medicaid, public health, and state-run healthcare programs.

HIPAA

HB 1085 Grant Readiness

Chapter 2026-115 created the Local Government Cybersecurity Protection Program inside the Florida Digital Service, effective July 1, 2026. FLDS procures solutions against a defined need, so a documented gap list is what makes a jurisdiction fundable.

New July 2026

Security Program Development

Build or mature your agency's security program from policies and procedures to technical controls.

Program Build

Fractional vCISO

Security leadership for agencies that need strategic direction without a full-time CISO hire.

Core Offering

Commercial Cybersecurity Advisory

For businesses over $1M annual revenue operating in regulated environments. Compliance isn't overhead. It's competitive advantage. We make it efficient and sustainable.

  • Fractional vCISO retainers, executive security leadership on demand
  • SOC 2 readiness for SaaS and service organizations
  • PCI DSS v4.0.1 gap analysis, including the 51 requirements that became mandatory in March 2025
  • AI security governance for organizations adopting AI in controlled environments
  • Compliance as competitive advantage: win contracts, reduce liability, build trust

Fractional vCISO Retainers

Ongoing security leadership, compliance management, board reporting, and strategic oversight for growing businesses.

Core Offering

SOC 2 Readiness

Gap analysis, control implementation guidance, and evidence preparation for SOC 2 Type I/II audits.

SOC 2

PCI DSS v4.0.1 Compliance

Gap analysis and remediation planning for payment card industry data security standards.

PCI DSS v4.0.1

AI Security & Governance

Risk assessments aligned to NIST AI RMF and ISO/IEC 42001, governance frameworks, LLM red teaming, and secure implementation for AI adoption in regulated industries.

AI Governance

Our Services

End-to-end compliance solutions from assessment through remediation and ongoing management.

NIST 800-171 & DFARS Compliance

Self-assessment, SPRS scoring, and CUI protection for defense contractors. No certification required. These obligations are already in your contract.

  • 110-control self-assessment
  • Defensible SPRS score submission
  • SSP & POA&M development
  • CUI scoping & flow-down

Fractional vCISO

Executive-level security leadership without a full-time hire. Strategy, oversight, and compliance management.

  • Security strategy & oversight
  • Board & executive reporting
  • Compliance program management
  • Team development & mentoring

HIPAA Security Risk Assessments

Federally required annual assessments for every healthcare covered entity. Audit-ready evidence documentation for HHS OCR.

  • Annual SRA compliance (45 CFR 164.308)
  • Gap identification & remediation
  • Policy & procedure development
  • OCR audit preparation

Security Assessments

Comprehensive evaluation across PCI DSS v4.0.1, NIST 800-53 Rev 5, NIST CSF 2.0, SOC 2, and FedRAMP.

  • PCI DSS v4.0.1 gap analysis
  • FedRAMP 20x readiness
  • SOC 2 preparation
  • Security architecture review

Incident Response Planning

Be prepared when security events occur. Meet HIPAA breach notification and DFARS reporting requirements.

  • IR plan development
  • Tabletop exercises
  • Business continuity planning
  • Breach notification compliance

Deep Expertise. Veteran Discipline. Audit-Ready Results.

Trusted advisory backed by decades of real-world security experience across federal and commercial environments.

Veteran-Owned

10 years U.S. Navy service. We understand the mission, speak the language, and bring military discipline to every engagement.

Federal Experience

Direct experience with HHS OIG, USCIS, and major defense contractors. We know what auditors look for because we've been there.

21+ Years Security

Deep expertise across HIPAA, NIST 800-171, NIST 800-53 Rev 5, NIST CSF 2.0, PCI DSS v4.0.1, SOC 2, FedRAMP 20x, FISMA, and risk management frameworks.

Builder, Not Just Auditor

We build tools, automations, and evidence systems that make compliance sustainable, not a one-time exercise.

From the Field

Practical guidance on compliance, security, and the tools we build to make both sustainable.

FedRAMP Aug 11, 2026

Your FedRAMP Package Has to Be Machine-Readable by September 30

The deadline applies to existing Rev 5 certifications, not just new applicants, and most providers have not started. What conversion actually involves, and what non-compliance costs once the grace period ends.

OSCAL Rev 5 Transition Sept 30 Deadline
FedRAMP Aug 11, 2026

FedRAMP 20x Turns Compliance Into Code

20x replaces narrative control descriptions with automated Key Security Indicators, and refuses written descriptions altogether, from humans and language models alike.

FedRAMP 20x OSCAL Cloud Security
Aerospace Aug 11, 2026

Aerospace Suppliers Are Governed by Two Rule Sets That Do Not Agree

A NIST 800-171 environment can be fully compliant and still be an ITAR violation, because the two regimes ask different questions about the same data. Add national security space and there are three.

ITAR CUI CNSSI 1253
Defense Aug 11, 2026

CMMC Phase 2 Is Suspended. Your Legal Exposure Went Up.

The certification deadline is gone. The obligations are not, and the one government mechanism that used to catch a bad SPRS score before a lawyer did is paused.

NIST 800-171 DFARS False Claims Act
Florida Aug 11, 2026

Florida Gave You the Mandate, Vetoed the Safe Harbor, and Just Funded the Fix

Florida mandates NIST CSF by statute, the alignment deadlines have passed, the liability safe harbor was vetoed, and as of July 1 there is finally state money on the table.

NIST CSF 2.0 Local Government HB 1085
Manufacturing Apr 14, 2026

Florida Makers and CMMC: The OT Blind Spot on Your Shop Floor

Your CNC machines, PLCs, and IoT sensors are in scope. Most small manufacturers are not thinking about operational technology when they scope an assessment, and it is the gap that kills timelines.

OT Security Manufacturing NIST 800-171

Certifications & Business Information

Registered and ready for federal, state, and commercial contracting.

Professional Certifications

CISSP CEH CHFI MS Cybersecurity & IA BS Software Engineering MBA

Business Information

UEI
K2NVWB4QXKN6
CAGE Code
14Z63
Status
SBA Certified SDVOSB
Florida
MFMP Vendor + CBE

Ready to Strengthen Your
Compliance Posture?

Schedule a free 30-minute consultation to discuss your compliance challenges, timeline, and how Waypoint can help.

or email directly at [email protected]
1

Schedule a 30-minute Zoom call

2

Discuss your compliance challenges

3

Get a tailored action plan