Get ready for certification. Then get certified.
CMMC, ITAR, CJIS, and CIS 18 readiness for organizations that cannot afford to guess.
Compliance frameworks are demanding and the rules keep moving. Most organizations we talk to are not confused about whether they need to comply. They are stuck on what to do first, who owns the work, and how much of the environment is actually in scope.
Our Compliance Readiness Program is a sequenced process that takes you from an unknown starting position to an environment, control set, and evidence trail built to withstand scrutiny.
What readiness has to prove
The question is not whether you have a policy document. The question is whether the environment, controls, and evidence all tell the same story.
CMMC is evolving, but readiness work is still the constraint. On July 13, 2026, the Department suspended CMMC Phase II requirements for a 60-day review. Phase I self-assessment requirements remain in place, and organizations still need to protect covered defense information under the underlying DFARS and NIST 800-171 obligations.
That makes the practical work even more important: know your scope, implement the controls, organize the evidence, and avoid representing a posture you cannot prove.
Source: DoD CMMC program update.
Where our work ends and the assessor’s begins
For CMMC, independence matters. Covenant prepares the environment and evidence. Certification or assessment is handled by the appropriate authorized body when required.
We work with authorized C3PAO assessment partners, including ControlCase, when a third-party CMMC assessment is part of the path. They conduct the assessment work. Covenant builds and secures the environment the assessment is meant to evaluate.
For ITAR, CJIS, and CIS 18, there is no single third-party certificate to earn. The obligation stays with your organization continuously, which puts the weight on implemented controls and defensible evidence.
Covenant readiness work
Scope, roadmap, Microsoft licensing alignment, Fortify hardening, GCC High planning, control implementation, and evidence organization.
Independent assessment
When a third-party CMMC assessment is required, it must be performed independently by an authorized assessor.
Your ongoing obligation
Controls drift, people change, systems move, and evidence ages. Readiness has to be maintained after the initial push.
How we get you ready
Compliance readiness works best when the steps happen in the right order. We start with what applies, then build the technical and documentation path around it.
Gap analysis and roadmap
We assess your current environment against the framework that applies, identify where you fall short, and sequence the work by what matters and what blocks what.
License alignment
We review Microsoft 365, Azure, and security licensing against what the controls require so you are not missing capability you assumed you had.
Fortify hardening
Our Microsoft cyber-hardening program strengthens identity, access, email, devices, data protection, and cloud controls mapped to your readiness path.
Data isolation and GCC High
Regulated data may need stronger boundaries than your general environment provides. We build and operate Microsoft 365 GCC High environments where the scope requires it.
Controls and evidence
We organize documentation that matches the actual environment, because that is the only kind that survives scrutiny.
Ongoing maintenance
After the first readiness push, we help keep controls and documentation current so drift does not become the next finding.
The frameworks we work in
Different frameworks create different obligations. The common thread is that your controls have to be real, documented, and maintainable.
Defense contract readiness
Applies when you handle controlled unclassified information under a Department of Defense contract. Our work focuses on scoping, hardening, GCC High where needed, control implementation, and evidence.
Export-controlled data
Applies when you manufacture, export, or handle defense articles or export-controlled technical data. The technical core is access control, environment separation, and identity governance.
Criminal justice information
Applies when you handle criminal justice information. Personnel screening, advanced authentication, validated encryption, physical security, and audit logging all matter.
Control framework baseline
CIS 18 is not a certification regime. It is a practical control framework and a strong baseline for insurers, prime contractors, and broader security readiness.
Certification is not the finish line
Passing once does not mean the environment stays ready.
Controls drift. Someone gets standing admin rights, a new SaaS tool starts touching regulated data, a setting gets loosened to fix an urgent problem and never gets tightened. An environment that passed review months ago is not necessarily an environment that would pass today.
What staying ready requires
- Controls kept in place after the project.
- Documentation updated when the environment changes.
- Evidence maintained before someone asks for it.
Monitor drift
Find configuration, identity, and process drift before it becomes a finding.
Maintain evidence
Keep evidence organized and current rather than rebuilding it in a panic.
Keep ownership clear
Controls need owners. If nobody owns a control, it will eventually stop being true.
When this is the right fit
This program is built for organizations that need a clear path from compliance uncertainty to implemented, defensible controls.
- You have a contract requirement, or expect one, and no clear path to meeting it.
- You have been told you need CMMC Level 2 and do not know your current position.
- You handle controlled unclassified information, export-controlled technical data, or criminal justice information.
- A prime contractor, insurer, auditor, or agency has started asking questions you cannot answer with documents.
- You attempted readiness internally and stalled.
- You passed previously and are not confident the environment would still hold up.
What we do not control
We do not issue certifications. No MSP, consultant, or advisor does. We also cannot guarantee an assessment outcome.
What we can do is make sure your controls are genuinely implemented, your environment matches what is documented, and the hard questions are answered before they are asked in the room.
Why Covenant Technology Solutions
Covenant brings Microsoft-first engineering, security-first operations, and compliance-aware implementation into one practical readiness path.
20+ years in business
Since 2002, helping organizations in regulated industries secure and modernize IT across the Pacific Northwest and the nation.
GCC High experience
We build and operate Microsoft 365 GCC High environments for organizations that need stronger boundaries around CUI or export-controlled technical data.
Authorized C3PAO relationship
When a third-party CMMC assessment is required, we are not starting the assessor conversation from zero.
Fortify is framework-aligned
Our Microsoft cyber-hardening program maps to practical control frameworks rather than treating compliance as a bolt-on exercise.
We stay after readiness
Controls drift. We help maintain the controls, documentation, and operational habits that keep readiness from fading.
CJIS certified
Covenant is CJIS certified, which helps us support CJIS-aware implementation, evidence, and operational controls with practical context.
Related Covenant services
Compliance readiness usually touches Microsoft licensing, security hardening, monitoring, cloud configuration, and day-to-day operations.
Microsoft 365 Tenant Optimization Review
Align Microsoft 365 licensing, tenant health, security posture, and configuration before paying for tools twice.
Explore tenant optimizationFortify
Microsoft cyber hardening across identity, email, devices, data protection, governance, and monitoring readiness.
Explore FortifyMicrosoft 365 Secure Score Assessment
Benchmark Microsoft security posture and prioritize practical gaps before readiness turns into an assessment scramble.
Explore Secure ScoreAzure Cloud Security Hardening
Close cloud configuration, access, logging, and network boundary gaps that affect regulated workloads.
Explore cloud securityAlways On IT Operations
Keep controls, support, patching, documentation, and day-to-day technology operations from drifting after readiness.
Explore operationsCompliance Readiness Program questions
A few clear answers before you start a readiness effort.
Do you certify us?
No. For CMMC, certification or assessment comes from the appropriate authorized assessment process when required. For ITAR and CJIS, there is no single certificate to earn. Our work is making the controls real, documented, and maintainable.
Why can’t one company do both remediation and assessment?
For CMMC third-party assessments, independence matters. The organization assessing the environment cannot be the same organization that remediated it. Covenant prepares the environment and evidence; the assessment path remains independent.
Who performs the CMMC assessment?
When a third-party assessment is required, it is performed by an authorized C3PAO. Covenant works with assessment partners, including ControlCase, while Covenant handles readiness, implementation, and evidence support.
What is GCC High and do we need it?
Microsoft 365 GCC High is a US-sovereign environment with US-person access restrictions and US data residency. If you handle controlled unclassified information or export-controlled technical data, it may be required. We will tell you honestly if your scope does not justify it.
Why does licensing come so early?
Because it often changes the budget conversation. Organizations are frequently paying for capability they are not using and missing capability they assumed they had. Sorting that out early helps fund and focus the rest of the work.
What does data isolation do beyond security?
It can shrink assessment scope. Fewer systems handling regulated data means fewer systems that need to be assessed, maintained, and evidenced.
How long does readiness take?
It depends on your starting position, environment complexity, scope, and internal availability. We give you a realistic range after the gap analysis rather than guessing before we have seen the environment.
What happens after we are ready?
The work becomes maintenance: controls, evidence, policies, documentation, and operations need to stay aligned. Covenant can help maintain that posture so readiness does not fade.
Can you help if we already tried and stalled?
Yes. Stalled readiness efforts usually have a specific cause: scope that was never bounded, documentation describing an environment that no longer exists, or a control nobody owns. The gap analysis finds it.
Do you support ITAR and CJIS as well as CMMC?
Yes. The work looks different for each. CMMC has a formal assessment path. ITAR and CJIS place more weight on continuous controls and evidence. Covenant supports the implementation and documentation work behind both.
Stay connected with Covenant
Keep learning between conversations with practical technology guidance, short videos, and a simple way to introduce a business that could use a stronger IT partner.
Get the Covenant Technology Briefing
Timely guidance on cybersecurity, Microsoft 365, cloud, AI, and the decisions shaping secure, productive organizations.
Subscribe to the newsletterFollow Covenant on YouTube
Short, practical videos that explain risks, opportunities, and next steps in plain language leaders and teams can use.
Visit our YouTube channelShare Covenant with a business you respect
If you know an organization that deserves better IT, security, cloud, or Microsoft support, we will handle the introduction with care.
Explore the referral programStart with where you actually stand.
Most organizations are further along than they think in some areas and further behind in others. The gap analysis tells you which is which, in your environment, against the framework that applies to you.
From there, you will have a sequence, an effort estimate, and a realistic view of the readiness timeline.
