Services and prices

What we do

We offer two engagements. Both are paperwork. We write the documents; your IT provider does the technical work.

Who does what

You

Decide and sign

  • Decide whether to go further after the scope map
  • Sign your self-assessment
Documents, and a walkthrough of the binder

Nexxus

Write the documents

A second person checks each one before you get it.

The plan of action: their list of what’s left to do

Your IT provider

Do the technical work

  • Install, set up, and run your systems
  • Work through the plan of action’s list

The two engagements

Start here

Scope map

We visit your shop and map where controlled information comes in, where it goes, and where it’s kept.

What you get

A written scoping document you keep. It names the people, computers, and places inside your boundary, and the places where scope quietly grows. See six common ones on the example map.

Price
$2,000 to $3,500. A fixed fee, agreed before we start. No hourly billing.
Time
The site visit takes two to four hours. We give you a date for the written document when we schedule.

Then, if it makes sense

Full write-up

The documents your self-assessment rests on, written from what we found at your shop.

What you get

  • Your System Security Plan (SSP), written by us
  • A score worksheet
  • A plan of action and milestones (POA&M) for the gaps that remain
  • Supporting policies
  • An evidence binder, organized so you can find things when asked
Price
$7,500 to $15,000. A fixed quote after the scope map, based on what we found. No hourly billing.
Time
We agree on a schedule with you before we start.

What moves the price

The scope map sets the boundary. After it, you get a fixed quote for the full write-up based on what we found.

It goes up with

  • how many computers and systems touch controlled information: CAM stations, file servers, cloud accounts
  • how many people handle drawings
  • how many buildings or locations are involved
  • how many ways drawings come in and go out, including outside processors
  • older equipment that has to be documented as an exception
  • how many outside services hold your files: your IT provider, cloud email, your ERP

It comes down with

  • documentation you already have to build on
  • defense work kept on separate computers

It doesn’t depend on

  • your revenue
  • your score
  • people who never handle drawings

What you’re paying for

  • Documents only. We don’t sell IT services, software, hardware, or licenses.
  • Keep your IT provider. You don’t need to switch providers or cloud systems to work with us.
  • Know before you commit. The scope map comes first, and you can stop there.
  • A smaller scope costs less to protect. Every computer and person kept out of scope is one less thing to secure and document.

We’re paid for the documents. Our fee never depends on your score or any result.

Our limits

What we don’t do

These limits are on purpose.

  • We don’t audit you.
  • We don’t certify you. We’re not a C3PAO.
  • We don’t install, set up, or run your systems.
  • We don’t give legal opinions.
  • We don’t log in to SPRS or the Procurement Integrated Enterprise Environment (PIEE) for you. You post your own score, on your own computer.
  • We don’t predict or promise a score, a result, or a certification.

Contact

Talk to us

Call or email Josh. He’ll book a free 15-minute call with Juan, who answers the technical questions.

We don’t record calls.

Please don’t send drawings, contracts, or controlled information by email or through this site.