BlueSteel Cybersecurity

DEFENSE AND GOVERNMENT

Cybersecurity compliance for mission systems, from a cleared facility on a GSA Schedule.

Ten years executing cybersecurity compliance inside the intelligence community, with ATOs achieved across unclassified, Secret and Top Secret networks.

GSA Schedule
47QTCA23D000B
CAGE Code
8WXY6
NAICS
541330, 541519
Facility clearance
Secret

Two ways we are engaged

Government program offices and defense contractors have different problems. Pick the one that describes you.

GOVERNMENT PROGRAM OFFICES

You need an ATO, and then you need to keep it.

RMF support across Impact Levels 1 through 6, evidence capture for the authorising official, and continuous compliance so the next cycle is a review rather than a rebuild. Buyable directly through our GSA Schedule.

What we deliver

DEFENSE CONTRACTORS

A clause appeared in a solicitation and the award depends on it.

CMMC Level 2 readiness, NIST SP 800-171 self assessment and SPRS scoring, STIG conduct, and the System Security Plan that carries a C3PAO assessment.

What we deliver

FOR GOVERNMENT PROGRAM OFFICES

Information assurance and authorisation

Information assurance, RMF and ATO support

We work with internal government teams and outside agencies to identify control requirements, produce the documentation, and capture the evidence an authorising official needs to sign.

  • Control requirement identification across Impact Levels 1 through 6
  • System Security Plan, POA&M and the supporting body of evidence
  • Evidence capture packaged for eMASS submission
  • Independent assessment support through to the authorisation decision

Application security and STIG

Testing and remediation against the standards an assessor will actually use, delivered as checklists rather than narrative.

  • Application Security and Development STIG conduct and remediation
  • SCAP and ACAS scan results, triaged for false positives before delivery
  • Application penetration testing across web, API and mobile
  • System security architecture review, cloud and on premise

Continuous compliance and ATO sustainment

An ATO is a start date, not a finish line. Our support services help mission owners hold authorisation on an ongoing basis rather than rebuilding the package each cycle.

  • Control implementation support and ongoing evidence production
  • Continuous monitoring against the authorised baseline
  • Change and configuration review as the system evolves
  • Reauthorisation preparation

Past performance

Ten years inside the intelligence community, with applications safeguarded across traditional server, virtual and cloud environments.

Customer Scope
NAVSEA STR Application security support, RMF, and ATO support
Navy SSP Application security support, RMF, and ATO support

ATOs achieved on unclassified, Secret and Top Secret networks. Detailed past performance available on request.

FOR DEFENSE CONTRACTORS

Compliance that unblocks the award

CMMC readiness and assessment support

No assessment, no award. We scope the enclave, close the practices that reliably fail, and author the System Security Plan that carries the C3PAO assessment.

  • Scoping and enclave strategy, which is the cheapest control available
  • Gap assessment against CMMC Level 2 and its 110 practices
  • Remediation of the practices that most often fail: MFA, audit logging, FIPS validated encryption, media protection
  • Evidence package and pre-assessment before the C3PAO arrives

NIST SP 800-171 and SPRS

The obligation exists whether or not a CMMC assessment has been scheduled. If a DFARS clause applies, you owe a current self assessment score in SPRS.

  • CUI identification and scoping
  • Self assessment scored to the DoD methodology
  • SPRS score calculation and posting
  • POA&M development and closure

Hosting on DoD systems

Where the goal is to host on a DoD system, the penetration test is one artifact in a much larger package. We prepare the whole thing at the impact level you actually need.

  • Impact level scoping under the DISA Cloud Computing SRG
  • IL2, IL4 and IL5 hosting paths, with the boundary drawn before implementation
  • System Security Plan against the applicable NIST SP 800-53 baseline
  • RMF steps through to the authorising official's decision

CMMC engagements · NIST SP 800-171 · Application security and STIG

How to buy

Assessments are scoped as a single fixed price deliverable with a two to four week period of performance, no option years and no follow on obligation. That shape fits inside simplified acquisition procedures, and at the low end within the government purchase card threshold.

We hold a GSA Schedule contract, so agencies can buy directly without running a new competition.

  • GSA Schedule 47QTCA23D000B
  • CAGE Code 8WXY6
  • NAICS 541330 and 541519
  • Cleared facility, Secret level

govcon@bluesteelcyber.com
(301) 531-4254

5.0 out of 5

Across 17 verified client reviews on Clutch.

  • Quality 4.9
  • Schedule 5.0
  • Cost 4.9
  • Willing to refer 5.0

Talk to us

For contracting and sources sought enquiries, email govcon@bluesteelcyber.com directly. For a scoping conversation, the calendar is below.