An effective cybersecurity program requires not only a technical overhaul of information systems but also the creation of rigorous documentation, to include Policies/Procedures, Security Plans, and Incident Response Plans just to mention a few. For many contractors, the internal overhead of managing these complex, and oft times shifting regulations, while maintaining core operations creates a significant risk of non-compliance and potential loss of contract eligibility. The i2 "3-Phase | Multistage CMMC Assessment, Remediation, and Sustainment Model" shown below has been practiced and has survived the rigors of C3PAO Certification Assessments and has proven to be a repeatable, and more importantly... a budget-friendly solution for our customers.
Imprimis engages the client in a series of Initial Planning sequences that begins with an initial Readiness Report and Gap Analysis using our IC2E Fundamentals to ascertain an initial "Cybersecurity Situational Awareness" status for the client.
Read More
Following the initial planning, we move the client into an Assessment Phase that includes a detailed review of a client’s overall NIST|CMMC cybersecurity posture. We use our i2ACT Software Tool to assess the NIST|CMMC requirements and objectives and input the current compliance status… met, not met, or remediation needed. All associated reports are generated in the i2ACT tool.
Read More
After the initial assessment, the Remediation Phase begins where all required physical, procedural and logical security requirements are addressed to include networking infrastructure, hardware, software, documentation, and Government Community Cloud migrations. Sustaining security protocols are also established during the remediation phase.
Read More
In parallel, we use our ITSG (Information Technology Steering Group) model to provide a stakeholder governance and management authority, as well as encouraging our clients to utilize our built-in NIST and CMMC Cybersecurity Education Tools in the i2ACT Software tool.
Read More
During the remediation phase, our complete package of compliance documentation can be selected (i2ExpressDocs) for purchase and Imprimis will populate them with client-specific data. This documentation package contains all relevant Policies and Procedures, SSP, IRP, CUI Management Plan, Configuration Management Plan and CMMC related/required catalogs and matrices.
Read More
Many of the required sustainment activities will be selected and activated during the remediation phase but a few may not be implemented until remediation is complete. These services will include a disciplined Remote Monitoring and End-Point Protection Program (for Servers, Workstations, Laptops, IoT devices, etc.), as well as Vulnerability Scanning, Event Logging services and Training.
Read More

Every robust security program stands on four pillars – physical, procedural, logical, and transformational. Yet many organizations stop at door locks and firewalls, leaving the human and process layers fragmented, or have not addressed cybersecurity at all.
(IC2E™) transcends this piecemeal approach by uniting all four dimensions into a single, streamlined framework and is designed for companies just developing their cybersecurity program or for companies not in the defense sector.
The i2CyberStart program has been designed for commercial businesses not needing to be NIST 800-171 or CMMC compliant.
This program is targeted at small to medium sized businesses, however it dynamically scales up for use with larger commercial enterprises as well.
The program utilizes best practices accepted throughout the industry by selecting specific requirements contained in NIST 800-171 and adapting them to the commercial environment. This ensures that the basic requirements for a minimum level of security are met and allows companies to build on that security as time moves on and as their operational and security requirements change.
During the i2Assess phase, an initial assessment will be performed using the i2ACT Assessment and Compliance Software Tool to the desired baseline.
A Quick Start Phase I Package is available to start the assessment and compliance process that is affordable, repeatable and gets compliance moving quickly and most clients select this option.
The Package consists of:
Identification of the specific remediation actions and documents required for compliance occurs during this time.
Imprimis has deployed a secure customer-centric, online communication and collaboration space called "i2Portal".
It's a unique online support solution that allows Imprimis to tailor client communications as well as provide direct customer support. Clients will be able to directly access the status of their projects, retrieve files and submit detailed support tickets.
The client portal is secure and each Imprimis client will only see their data, documentation and support tickets. Each client will be required to have their own login credentials, and 2-factor authentication will be implemented.
During i2CyberBuild, Imprimis provides services to support the remediation process to include:
This process is typically directed by Imprimis staff at the client’s pace with the client participating as much or as little as they choose.
Several of the Sustainment requirements may be initiated during the remediation phase.
Based upon the mandated DoD CMMC | NIST 800-171 requirements, Imprimis has developed a Document Express Package specifically designed to meet compliance and stand up to a C3PAO assessment.
The documents provided can easily be edited to account for client differences and requirements. The documents can be purchased individually or as the Express Package at a 30% discount for all.
Documents Offered:
Once an organization achieves full compliance with a CMMC | NIST mandate, they need to commit to ongoing efforts to remain in compliance – or sustain compliance.
Imprimis provides a full suite of supporting services called i2Sustain and includes endpoint protection, vulnerability monitoring and scanning, multi-factor authentication, backups, SIEM, SASE and training.
Many of these services will be implemented during the remediation phase and are divided into two groups:
The client then decides on an approach to remediation implementation: use internal staff, Imprimis services, another third party, or any combination that fits their needs. Imprimis will provide as much or as little remediation support as the client wants and needs.
The compliance documentation would be completed during the remediation phase, again, either by selecting the i2ExpressDoc Package or by the client utilizing or preparing their own documents.
Once compliance is achieved, Imprimis is available to provide the sustainment support or a security stack specifically designed for the client, if desired. Sustainment activities typically include endpoint management, multi-factor authentication, vulnerability scanning, monitoring, training, backups, incident response exercises, and ongoing CISO advisory.