CMMC Compliance

Manage Information Security Requirements

CMPRO is an invaluable tool for Organizations Seeking Assessments (OSAs) under the Department of Defense’s Cybersecurity Maturity Model Certification Program (CMMC). CMPRO can help your organization:

  • Manage your Information Security Program documents
  • Automate tasks to implement NIST SP 800-171 security requirements
  • Formalize and create an Operation Plan of Action using change forms and impact matrix
  • Inventory and track system assets and components
  • Establish and maintain baseline configurations for systems, assets, and components
  • Manage contracts and authorized vendor information
  • Automate self-assessment processes needed to evaluate and score the implementation of security requirements, documenting findings along the way.
  • Produce assessment objects and evidence on-demand during third-party assessments

CMPRO for Defense

  • Operates within U.S. Department of Defense (DOD), most notably the Department of the Navy (DON)
    • CMPRO has been in operation within the Department of the Navy for more than 25 years, is DADMS approved, and registered in DITPR DON
    • Multiple ATOs for CMPRO have been approved for NAVWAR, NAVSEA, and NAVAIR (references upon request); NIPRNET and SIPRNET (.mil)
  • Operates within the U.S. Department of Homeland Security (DHS), supporting U.S. Coast Guard and U.S. Customs and Border Protection (CBP).

CMPRO is developed and maintained by PSA Inc.

  • Professional Systems Associates Inc. (PSA) is an American-owned small business with a staff that consists entirely of U.S. Citizens.
  • PSA uses its own instances of CMPRO to maintain different aspects of its security program like managing program documents (policies, procedures, guidelines) and reviewing directives within Security Technical Implementation Guides (STIGs) to maintain secure configuration standards.
  • The security program at PSA, led by a Certified Information Systems Security Professional (CISSP), includes mandatory security training for all personnel and role-based security training for ITOPS and DEVOPS team members.