CARMhaus Consulting
Home
Services
  • Security Architecture
  • Readiness Assessment
  • Security Leadership
  • Third-Party Risk
Industries
  • Defense and Aerospace
  • Manufacturing and OT
  • Healthcare
  • Financial Services
Frameworks
  • CMMC Level 2
  • NIST SP 800-171
  • SOC 2
  • ISO 27001
  • HIPAA
  • SOX ITGC
Approach
About
Contact
CARMhaus Consulting
Home
Services
  • Security Architecture
  • Readiness Assessment
  • Security Leadership
  • Third-Party Risk
Industries
  • Defense and Aerospace
  • Manufacturing and OT
  • Healthcare
  • Financial Services
Frameworks
  • CMMC Level 2
  • NIST SP 800-171
  • SOC 2
  • ISO 27001
  • HIPAA
  • SOX ITGC
Approach
About
Contact
More
  • Home
  • Services
    • Security Architecture
    • Readiness Assessment
    • Security Leadership
    • Third-Party Risk
  • Industries
    • Defense and Aerospace
    • Manufacturing and OT
    • Healthcare
    • Financial Services
  • Frameworks
    • CMMC Level 2
    • NIST SP 800-171
    • SOC 2
    • ISO 27001
    • HIPAA
    • SOX ITGC
  • Approach
  • About
  • Contact
  • Home
  • Services
    • Security Architecture
    • Readiness Assessment
    • Security Leadership
    • Third-Party Risk
  • Industries
    • Defense and Aerospace
    • Manufacturing and OT
    • Healthcare
    • Financial Services
  • Frameworks
    • CMMC Level 2
    • NIST SP 800-171
    • SOC 2
    • ISO 27001
    • HIPAA
    • SOX ITGC
  • Approach
  • About
  • Contact
An engineer walking a data centre aisle, reviewing a running system rather than a document
Currently accepting engagements for Q4 2026

Your side of the table.

An owner's representative for your security program. We design the target state and write the specification your team builds to, then we review the work they deliver against it. We are not your integrator and we are not your assessor, which is what lets us tell you the truth about both.

Book a scoping call

Where we work

Defense and aerospace

Defense and aerospace

Defense and aerospace

CMMC, DFARS, ITAR. The contract sets the date and the assessor sets the bar. Most of the cost lands on CUI that spread further than anyone scoped for.

See the detail

Manufacturing

Defense and aerospace

Defense and aerospace

Plant, OT, MES and ERP. The plant is in scope whether or not anyone planned for it. Unmanaged switches, devices that cannot take an agent, and ERP quietly moving controlled data.

See the detail

Healthcare

Financial services

Financial services

HIPAA, NIST CSF 2.0. The policies usually exist. What is missing is the record that anyone followed them, which is the first thing a regulator asks to see.

See the detail

Financial services

Financial services

Financial services

SOX ITGC, SOC 2, vendor risk. Access reviews and change control get done, then have to be evidenced twice. Once for the auditor, again for every enterprise customer that sends a questionnaire.

See the detail

110 / 110

110 / 110

110 / 110

NIST SP 800-171 controls met at CMMC Level 2 assessment

Zero

110 / 110

110 / 110

PoA&Ms carried at certification

200+

110 / 110

200+

Security questionnaires and third-party risk assessments completed

Why we do not build what we assess

The people identifying your risks should not be the people profiting from fixing them. That principle decides how every engagement is structured, and it is the reason a finding from us is worth something to whoever reads it next.

What we do

What stays with your team

What stays with your team

We design the target state, write control specifications in the language the assessment objectives use, and then review the work your team or your provider delivers against them until it operates as specified.

What stays with your team

What stays with your team

What stays with your team

The building. Your IT staff, your managed service provider, or an implementation partner we help you select holds the keys, makes the changes, and owns the configuration. We write the shared responsibility matrix that records exactly who owns which assessment objective.

Why the line matters

What stays with your team

Why the line matters

A firm that builds a control and then attests that the control works has graded its own homework. CMMC's accreditation rules prohibit the equivalent arrangement for assessors, and the reasoning does not stop there. Keeping the line clean costs you nothing.

Three ways engagements usually start

CMMC and the Defense Industrial Base

CMMC and the Defense Industrial Base

CMMC and the Defense Industrial Base

Getting a DoD supplier through CMMC Level 2 without carrying findings into the next contract cycle. CUI and FCI boundary definition, SSP authorship and SPRS scoring, PoA&M closure, GCC High enclave design and migration, DFARS readiness. We also build the identity, endpoint and data-protection configuration the SSP claims, including the plant and OT side.

See the detail

Regulated industry compliance

CMMC and the Defense Industrial Base

CMMC and the Defense Industrial Base

Standing up or repairing a control environment that has to satisfy an auditor, a regulator, or an enterprise customer. HIPAA policy suites, SOX ITGC control design and evidence, ISO 27001 and SOC 2 readiness, NIST crosswalks, questionnaires and vendor reviews. We also build the access controls, DLP and evidence automation behind the policy set.

See the detail

Fractional CISO

CMMC and the Defense Industrial Base

Fractional CISO

Ongoing security leadership for organizations that need the function but not a full-time executive. Governance committee, risk register ownership, third-party risk, access reviews, incident response planning and tabletops, board reporting. Hands-on remediation sits inside the retainer, not in a change order to a second vendor.

See the detail

Assessors do not accept documents. They accept records

Produced on a cadence, tied to a control, with a named owner. Most programs fail on the second half of that sentence.

Myka Hauser, CISSP

Tell us the deadline and what it is attached to

Thirty minutes is usually enough for us to tell you whether your date is realistic, and what the first two weeks would need to cover.

We work in CMMC Level 1 and 2, NIST SP 800-171, NIST SP 800-53, NIST CSF 2.0, ISO 27001, SOC 2, HIPAA and SOX ITGC.

Book a scoping call

© 2026 CARMhaus Consulting LLC. All rights reserved. Cybersecurity · Assurance · Risk Management

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept