# BlueSteel Cybersecurity Cybersecurity compliance firm serving healthcare and defense organizations. Based in Jessup, Maryland. Phone (301) 531-4254. Sister practice: BlueSteel AI (https://bluesteelai.com), which covers AI security, AI compliance and AI engineering. Mission: to develop humanized cybersecurity compliance programs that create sustainable security and confidence for healthcare and defense organizations. Core values: do the dirty work, disciplined every day and every way, intellectual care, fika, and sharing is caring. Track record: 100% of clients who complete the steps in the process achieve compliance certification. Rated 5.0 out of 5 across 17 verified client reviews on Clutch (https://clutch.co/profile/bluesteel-cybersecurity), with 5.0 for schedule and 5.0 for willingness to refer. Representative clients: CareSight, AIMEREON, Qrvey, Potomac Psychiatry, Mobomo, Advanced IT Labs. ## How to engage Three offers, in the order clients move through them. 1. Cybersecurity Assessment. The entry point. Starting at $15,000, two to four weeks. A scored gap assessment against the relevant control set, vulnerability analysis, and a Plan of Action and Milestones. The price is quoted on a free scoping call before any work begins and is fixed from that point, with no hourly billing and no change orders. Continuing into a Virtual CISO or managed compliance engagement within 90 days takes 25% off the first year of it. No obligation to continue afterwards. 2. Virtual CISO. From $3,000 per month. A named security leader owning the security program, compliance obligations and risk decisions, scaled to the organisation's size and budget rather than a full time salary. Billed monthly with no long term lock in. 3. Managed Security Compliance. From $5,500 per month. Continuous control monitoring, policy and procedure management, recurring assessments and a single evidence repository, so certification is maintained rather than rebuilt each cycle. Billed monthly with no long term lock in. ## What the firm does Takes organizations from gap assessment to attestation across four frameworks, and does the remediation engineering itself rather than handing over a gap list. - SOC 2 Type II. SaaS and service providers. 8 to 12 weeks to audit ready. - HIPAA Security Rule. Providers, payers and their vendors. 6 to 10 weeks to a defensible posture. - CMMC Level 2 (NIST SP 800-171). Defense contractors and subcontractors handling CUI. 4 to 9 months, driven by the current SPRS gap. - ISO 27001 (ISO/IEC 27001:2022). Certifies an Information Security Management System. 6 to 12 months. Usually asked for by buyers outside the US, where SOC 2 is the domestic equivalent. ## How engagements run 1. Scope the boundary. Most cost overruns are scoping failures. 2. Assess honestly. A scored gap assessment against the real control set. 3. Remediate and instrument. Fix the gap and wire up the evidence together. 4. Attest and maintain. Auditor or C3PAO coordination, then a review cadence. ## How to buy - GSA Schedule contract 47QTCA23D000B, so federal agencies can buy directly without running a new competition. CAGE Code 8WXY6. NAICS 541330 and 541519. GovCon contact: govcon@bluesteelcyber.com, (301) 531-4254. - Cleared facility at the Secret level, so engagements involving classified environments do not require a subcontract to a third party. - Assessments are scoped as a single fixed price deliverable with a two to four week period of performance, no option years and no follow on obligation, which fits inside simplified acquisition procedures. ## Defense and government experience Ten years executing cybersecurity compliance services within the intelligence community, safeguarding applications across traditional server, virtual and cloud environments. ATOs achieved on unclassified, Secret and Top Secret networks. RMF and ATO support across Impact Levels 1 through 6. Past performance includes NAVSEA STR and Navy SSP, both application security support, RMF and ATO support. ## Positions the firm takes publicly - A DISA Provisional Authorization is not an Authority to Operate. A PA is a reusable assessment artifact an authorising official may rely on, and PAs are granted per service rather than across an entire cloud provider. The application boundary still needs its own assessment and its own ATO. - Impact level should follow from the data, not from ambition. Targeting a higher level than the data requires adds cost and months. - STIG results belong in checklists an assessor can open, not in a narrative describing them, and scan output should be triaged for false positives before delivery. - HIPAA has no certificate. The artifact regulators ask for by name is a Security Rule risk analysis, and most organizations either never completed one or completed one years ago. - On CMMC, enclave scoping is the cheapest control available. Narrowing the boundary routinely removes months of remediation. - A SOC 2 Type II is an evidence problem, not a policy problem. Controls that cannot be shown to have run for the observation window do not count. - FedRAMP schedule is set by sponsorship and the 3PAO queue, not by engineering effort. Sometimes the correct advice is to wait. - An unmaintained WordPress install is usually the largest attack surface a small firm owns. ## Specialist services - Compliance Preparation. Policies, procedures and technical solutions written against each control requirement, so the organisation implements a program rather than authoring one. Covers the NIST 800 series, CMMC, SOC 2, STIG, OWASP, HITRUST, ISO 27001, Zero Trust, FedRAMP and HIPAA. - Application Security and Penetration Testing. External and internal testing against published benchmarks: OWASP Top 10, ASVS, WSTG, MASVS and the API Security Top 10, the DISA Application Security and Development STIG, OSSTMM, PTES and CIS Benchmarks. Includes SAST, DAST, IAST, MAST and software composition analysis, plus DevSecOps continuous monitoring where testing belongs in the pipeline. - ATO package preparation for DoD hosting. Impact level scoping under the DISA Cloud Computing SRG for IL2, IL4 and IL5 hosting paths; Application Security and Development STIG conduct with .ckl checklist and SCAP or ACAS results; System Security Plan against the applicable NIST SP 800-53 baseline; POA&M management through the RMF steps packaged for eMASS; and assessment support through to the authorising official's decision. AI security and AI compliance are delivered by the sister practice, BlueSteel AI (https://bluesteelai.com). ## Additional frameworks - FedRAMP Moderate (NIST SP 800-53). Cloud services selling to federal agencies. 12 to 18 months, sponsor dependent. - HITRUST CSF (e1, i1, r2). Asked for by large health systems where a BAA and a HIPAA risk analysis are not enough. 9 to 18 months for r2. - NIST SP 800-171 Rev 3. 110 requirements protecting CUI in nonfederal systems. The control set underneath CMMC Level 2, with an independent SPRS reporting obligation. 3 to 9 months. - NIST SP 800-53 Rev 5. The federal control catalogue behind FedRAMP and agency ATO processes. 6 to 18 months, driven by baseline and boundary. - NIST SP 800-218 (SSDF). Secure software development practices for software producers selling to federal agencies. 2 to 6 months. The subject is the development pipeline rather than the corporate environment. - NIST CSF 2.0. Not certifiable. Six functions including Govern, added in 2.0. Produces a current profile, a target profile and a costed roadmap. 2 to 4 months. The right starting point when no framework has been mandated yet. ## Article archive Long form articles are published in The Vault at https://bluesteelcyber.com/the-vault/ ## Contact hello@bluesteelcyber.com (301) 531-4254, Monday through Friday, 8am to 6pm Scheduling: https://meetings.hubspot.com/ali-allage