You decide
- Whether the evidence meets your obligations
- Which open gaps to close first
- When you're ready for assessment (your assessor decides certification)
For defense contractors with a CMMC requirement
CMMC is how the Department of Defense verifies that contractors protect the information in their contracts. Whatever form it takes, the controls underneath are NIST SP 800-171, so Compliance: CMMC builds on that evidence and keeps your company ready for assessment. s90 doesn't certify you. Where a contract calls for an outside assessment, an authorized assessor does.

It likely applies if your company's contract includes:
Meet the requirements your contract calls for
The controls your contract requires, kept running
Evidence organized the way assessors review it
Document how you meet them
Support for your System Security Plan
Plan records
Pass the required assessment
Assessment readiness, and coordination with your assessor
Assessment readiness evidence
Affirm that you still meet them when your contract requires it
Evidence for each affirmation you make
Support for your affirmations
Scoped to CMMC, delivered every quarter without asking. The proof in your hands is never more than three months old.
Sample · Compliance Posture Report
ACME Corp · Quarter 3 · CMMC
Sample report for a fictional business. Example figures.
Bundle discounts available.

One question to ask yourself
In 30 minutes, we talk through your setup and you leave knowing which plan fits.
Book a callSee exactly what you'd receive each quarter, by email.
Get the sample Posture Report by email