SKIP TO CONTENT

PROGRAM-BUILD DOMAIN 04 OF 05

Program setup

Governance charter and roles; SSP and POA&M structure; policy framework; training program; incident-response plan; operating cadence and budget.

THE PHASE THREAD

How program setup moves through OORAH.

Ownership screened in ORIENT, charter, SSP, and POA&M architecture designed in ORGANIZE, policy, training, and incident response implemented in REMEDIATE, governance rehearsed in ASSESS, and an annual cadence sustained in HOLD.

PRIMARY PUBLIC REFERENCES

32 CFR Part 170 evidence expectations; DFARS 252.204-7012 and 252.204-7021; NIST SP 800-171 Rev.2.

STANDING BOUNDARY
No compliance-by-subscription. No assessment or certification outcome is promised.
CURRENT CMMC POSTURE
CMMC Phase II (Level 2 and Level 3 third-party assessments) has been suspended since 2026-07-13 pending the Department of War reform review, and contracting officers were directed on 2026-09-03 to remove Phase II requirements from solicitations and contracts. Level 1 and Level 2 self-assessments, baseline NIST SP 800-171 Revision 2 compliance, SPRS, and the DFARS 252.204-7012 safeguarding obligation remain in force. CMMC work is quoted only after the current-posture check.

SCOPE THE DOMAIN

Does this pursuit need program setup?

Domains fire only when the route, the target contract, or an evidence gap justifies the spend. We will tell you if it does not.

A 30-minute introductory call. Bring the target solicitation and what you already know about your gaps.

VOSB + SDVOSB CERTIFIED (SBA VETCERT) · UEI VU2HV8458J93 · CAGE 21BA0