Compliance Hardening

Hardening your systems to a named baseline and proving it: for a customer security questionnaire, an enterprise review, or the technical half of CMMC. ZuluSec does not write policy or sell certification.

AWSAzureGCPOn-premHybrid

Every baseline splits the same way

This work almost never starts because someone wanted it. It starts with a deadline someone else set: a questionnaire citing CIS Benchmarks, an enterprise buyer making hardening evidence a condition of the deal, a prime flowing down a clause that names CMMC Level 2. Different requests, different baselines, the same shape of work. Every one of those baselines has a half that is a system setting and a half that is a management decision. The line between them is drawn below, and the assessment puts your version of it in writing so nothing falls in the gap.

ZuluSec does this

The technical half, assessed control by control and backed with evidence

  • ✓Access control and least privilege
  • ✓Identification, authentication, and multi-factor
  • ✓Audit logging, retention, and what can be traced to a person
  • ✓Configuration and hardening to a STIG or CIS Benchmark
  • ✓Encryption in transit and at rest
  • ✓System and communications protection

This stays with you

The organizational half, which no server setting produces

  • •Written policies and the security policy set
  • •Security awareness training and completion records
  • •Personnel screening and background checks
  • •Physical security
  • •Incident response and continuity plans, and evidence of exercising them
  • •Risk assessments, change approval, and subcontractor management

That half needs someone who can commit the organization: a named owner inside your business, or a governance consultant engaged for it. ZuluSec does not write, own, or operate any of it, and you will hear on the first call if the larger share of your obligation sits on that side rather than this one.

Your systems are assessed control by control against the technical requirements of your baseline, hardened to a DISA STIG or CIS Benchmark, and given the technical controls they are missing, with evidence drawn from how the systems actually run rather than from a screenshot taken on a good day. ZuluSec is equally direct about the organizational half, because this market fails in both directions: policy consultants who cannot harden a server, and technical shops that overclaim the paperwork.

Where teams get stuck

Buying tools instead of producing evidence. A compliance platform tracks the status of a control. It does not harden the server behind it, and it does not judge whether the evidence under the status holds. Without that, the dashboard goes green while the systems stay unchanged.

Guessing at the boundary. Too wide and you harden systems that never held the data anyone cares about. Too narrow and the review fails on something you excluded. On CMMC that boundary is the CUI enclave; on a questionnaire it is whichever systems touch the customer's data.

Splitting the work badly. Both halves get assigned to people who each assume the other side has it covered, and the controls in the gap between them are the ones that fail. That is why every assessment ends with a written list of what was not covered.

How the evidence is collected

Evidence collection is the tedious part of this work and the part that goes stale fastest, so it is automated. The checks are code, they live in your repository, and you keep them. When the same control has to be evidenced again six months later your team re-runs the check instead of repeating the scramble, and an assessor can read what the check does rather than taking anyone's word for what it found.

Proof you can read before you book

posture-reference is a public implementation of exactly this kind of check, with its tests, pull requests, and review rounds readable. The sample findings report is a complete 14-page deliverable; it is a Security Audit report rather than a control-by-control one, so read it for the standard of write-up. The two slices below are the control-by-control version, and how an engagement works covers NDA, authorization, and access.

What a questionnaire assessment looks like

A slice from a Windows and Azure environment assessed against the CIS Benchmarks a customer questionnaire named. Synthetic environment, no client data. These are the two questions such questionnaires ask most: is multi-factor on everywhere, and can you produce the logs to prove what happened.

HIGH

Multi-factor covers cloud sign-in and not the rest of the estate

Multi-factor is enforced through conditional access in Microsoft Entra ID for Microsoft 365 sign-in. The VPN concentrator and the RDP jump host still accept a username and password, and the conditional access policy carries a standing exclusion group holding several service accounts and two administrator accounts. That exclusion group is a gap against the CIS Microsoft Azure Foundations Benchmark on its own. The VPN and RDP gaps sit outside that benchmark, but the questionnaire asks about all remote access, so the honest answer is one the configuration does not support.

Fix: extend multi-factor to VPN and RDP access, empty the standing exclusion group or turn each entry into a documented, time-bound exception with a named owner, and keep the conditional access policy export and the sign-in report as the evidence behind the answer. Effort: ~half a week.

HIGH

Nothing retains ninety days of authentication records

The Windows Server systems run the Security event log at its default size with no forwarding, so authentication events roll off in days on the busiest of them. On the Azure side no diagnostic setting exports the activity or sign-in logs, so they age out on the platform's schedule. Both CIS Benchmarks address exactly this. When the questionnaire asks for ninety days of authentication records, there is nothing to produce.

Fix: raise the Security event log size and forward Windows security events to a central collector, add diagnostic settings exporting the activity and sign-in logs with a retention period that supports the answer you intend to give, and keep the retention configuration itself as the evidence rather than a screenshot of a search result. Effort: ~1 week.

Those are the answers a questionnaire actually tests, evidenced rather than asserted.

What a CMMC gap assessment looks like

The same method against a different baseline, in the CMMC Level 2 format. Synthetic environment, no client data. Every gap names the requirement, the setting at fault, and what closing it takes.

HIGH

CUI stored without FIPS-validated encryption

CUI sits in a file share and a cloud bucket. The file share encrypts with a module carrying no FIPS validation, and the bucket is reached over the provider standard endpoint rather than its FIPS-validated one. SC.L2-3.13.11 asks for FIPS-validated cryptography where it protects CUI, and validation is a property of the specific module in use rather than of the provider in general.

Fix: move CUI into a FIPS-validated configuration, record the module and its certificate number as evidence, and define where CUI is allowed to live so it stops spreading. Effort: ~1 week, longer if CUI has already spread into email and personal drives.

HIGH

Multi-factor covers email but not the systems holding CUI

MFA is enforced at the identity provider for email and chat, but the VPN and the on-prem file server still accept a password alone. IA.L2-3.5.3 requires multifactor for network access to any account and for local access to privileged ones. The VPN is network access for everyone who uses it, and the file server carries local administrative accounts, so both sit inside the requirement.

Fix: extend MFA to the VPN for every account and to privileged local access on the file server, and make any exception a documented, time-bound decision rather than a default. Effort: ~half a week.

MEDIUM

Audit logging does not cover the systems in boundary

Logging is on for the cloud environment but not for the on-prem systems that hold CUI, and retention is 30 days. AU.L2-3.3.1 requires audit records retained to the extent needed to investigate unauthorized activity, and right now half the boundary produces nothing to investigate from.

Fix: extend logging to every in-scope system, centralize it, and set a retention period long enough to support investigation, defined in writing so the assessor can see what you committed to and confirm the systems match it. Effort: ~1 week.

Closing these is the hardening engagement. The same assessment lists the requirements that are not technical, so you know what is left and who needs to own it.

Engagement options

Technical Gap Assessment

Where your systems stand against the technical requirements of your target baseline, and what it takes to close them.

  • ✓Assessment of the technical control families, control by control
  • ✓Findings with the specific setting or configuration at fault
  • ✓Prioritized remediation plan with effort and sequence
  • ✓Written handoff list of the non-technical controls you still need to own

Hardening Engagement

The technical work: harden to the baseline, implement the missing technical controls, and assemble the supporting evidence. Quoted from the assessment, once the size of the gap is measured rather than estimated.

  • ✓Everything in the Technical Gap Assessment
  • ✓STIG or CIS baseline hardening across the in-scope systems
  • ✓Implementation of the missing technical controls
  • ✓Evidence package mapped to each technical control
  • ✓Reassessment of the technical controls at completion

This work is quoted as one fixed price after a scoping call, agreed in writing before work starts. Scope is what sets that price, and the systems involved can be established on the call itself, which is why a firm figure can come out of it. There is no hourly meter: the number agreed is the number you pay, and you have it in front of you before you commit to anything.

Book a scoping call

FAQ

A customer sent us a security questionnaire. Is that this page?
Yes, for the technical questions, which is most of what a questionnaire actually tests. The approach maps the questionnaire to a concrete baseline, closes the gaps, and gives you answers with configuration behind them rather than intent. The split above shows which questions fall on the other side, and the assessment puts your version of that split in writing.
A customer is asking for SOC 2. Can ZuluSec help?
Only with the technical part. A SOC 2 report is an attestation issued by a licensed CPA firm under AICPA standards. ZuluSec is not a CPA firm, does not perform the examination, does not issue the report, and does not sell a readiness program. What it does is the technical control work a readiness effort runs on: assessing systems against the technical criteria, hardening them to a named baseline, and producing evidence off the running systems. Bring the criteria to the scoping call and you get a plain answer on how much of your work is technical.
How is this different from the Security Audit?
The Security Audit asks what an attacker would find. This asks what a named baseline requires, control by control, and produces evidence mapped to those controls. A customer questionnaire or a CMMC flowdown is this page. With no compliance obligation, the audit is the better first purchase. You rarely need both.
How long does it take, and how is it priced?
The Technical Gap Assessment is typically two to three weeks from access, quoted as a fixed price after the scoping call. The Hardening Engagement is quoted from the assessment, once the size of the gap is measured rather than estimated, so you commit the smaller amount first and see the full picture before the larger one. If you stop after the assessment, that is a complete piece of work and the remediation plan is yours.
Which CMMC level applies?
It depends on the data, not your size. Federal Contract Information (FCI) only means Level 1, the basic safeguarding requirements in FAR clause 52.204-21, self-assessed annually. Controlled Unclassified Information (CUI) means Level 2, the 110 requirements of NIST SP 800-171 Revision 2. Your contract and your prime's flowdown clauses are the authority, and reading that language together is part of the scoping call.
Can ZuluSec write my System Security Plan, certify me, or produce an SPRS score?
No to all three, each for its own reason. An SSP describes your whole organization and belongs to someone accountable inside it; ZuluSec supplies the technical content that goes into one, which is the part assessors probe hardest. Certification comes from an accredited C3PAO, and the firm that prepares you generally should not be the firm that assesses you. The SPRS score is your submission, affirmed by a named senior official and carrying real legal weight. For CMMC Level 2 most teams pair a compliance lead who owns all three with ZuluSec doing the technical work alongside them, which is usually cheaper than one firm charging for both when they are strong at one.