An owner's representative for your security program. We design the target state and write the specification your team builds to, then we review the work they deliver against it. We are not your integrator and we are not your assessor, which is what lets us tell you the truth about both.
CMMC, DFARS, ITAR. The contract sets the date and the assessor sets the bar. Most of the cost lands on CUI that spread further than anyone scoped for.
Plant, OT, MES and ERP. The plant is in scope whether or not anyone planned for it. Unmanaged switches, devices that cannot take an agent, and ERP quietly moving controlled data.
HIPAA, NIST CSF 2.0. The policies usually exist. What is missing is the record that anyone followed them, which is the first thing a regulator asks to see.
SOX ITGC, SOC 2, vendor risk. Access reviews and change control get done, then have to be evidenced twice. Once for the auditor, again for every enterprise customer that sends a questionnaire.
NIST SP 800-171 controls met at CMMC Level 2 assessment
PoA&Ms carried at certification
Security questionnaires and third-party risk assessments completed
The people identifying your risks should not be the people profiting from fixing them. That principle decides how every engagement is structured, and it is the reason a finding from us is worth something to whoever reads it next.
We design the target state, write control specifications in the language the assessment objectives use, and then review the work your team or your provider delivers against them until it operates as specified.
The building. Your IT staff, your managed service provider, or an implementation partner we help you select holds the keys, makes the changes, and owns the configuration. We write the shared responsibility matrix that records exactly who owns which assessment objective.
A firm that builds a control and then attests that the control works has graded its own homework. CMMC's accreditation rules prohibit the equivalent arrangement for assessors, and the reasoning does not stop there. Keeping the line clean costs you nothing.
Getting a DoD supplier through CMMC Level 2 without carrying findings into the next contract cycle. CUI and FCI boundary definition, SSP authorship and SPRS scoring, PoA&M closure, GCC High enclave design and migration, DFARS readiness. We also build the identity, endpoint and data-protection configuration the SSP claims, including the plant and OT side.
Standing up or repairing a control environment that has to satisfy an auditor, a regulator, or an enterprise customer. HIPAA policy suites, SOX ITGC control design and evidence, ISO 27001 and SOC 2 readiness, NIST crosswalks, questionnaires and vendor reviews. We also build the access controls, DLP and evidence automation behind the policy set.
Ongoing security leadership for organizations that need the function but not a full-time executive. Governance committee, risk register ownership, third-party risk, access reviews, incident response planning and tabletops, board reporting. Hands-on remediation sits inside the retainer, not in a change order to a second vendor.
Produced on a cadence, tied to a control, with a named owner. Most programs fail on the second half of that sentence.
Myka Hauser, CISSP
Thirty minutes is usually enough for us to tell you whether your date is realistic, and what the first two weeks would need to cover.
We work in CMMC Level 1 and 2, NIST SP 800-171, NIST SP 800-53, NIST CSF 2.0, ISO 27001, SOC 2, HIPAA and SOX ITGC.
© 2026 CARMhaus Consulting LLC. All rights reserved. Cybersecurity · Assurance · Risk Management
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.