Defense suppliers and subcontractors
Manufacturers, engineering firms and service companies that handle federal contract information or controlled unclassified information (CUI) and may need cybersecurity readiness for federal defense contracts.
Defense contracts, patient records, customer financial data and card payments all come with security rules. Chrysalis puts technical controls in place, documents them and helps you prepare evidence for the review your customer, regulator, insurer, payment processor or contract requires.
IT compliance services support your readiness for the security requirements in frameworks such as CMMC, HIPAA, the FTC Safeguards Rule and PCI. Chrysalis maps each requirement to your systems, works through technical gaps such as multi-factor authentication (MFA), encryption, logging and backup, and helps build the evidence customers, regulators, insurers, payment processors or government reviewers may ask for. We help with readiness. We are not an auditor or a certification assessor.
Businesses where a customer, regulator or insurer has started asking for proof.
Manufacturers, engineering firms and service companies that handle federal contract information or controlled unclassified information (CUI) and may need cybersecurity readiness for federal defense contracts.
Practices, labs and the companies that handle patient information for them, all of which have security duties under the HIPAA Security Rule.
Mortgage brokers, tax preparers, auto dealers that arrange financing and other businesses covered by the FTC Safeguards Rule.
Retailers, restaurants and service companies that must meet the PCI Data Security Standard their bank or payment processor requires.
The rules are written for lawyers and auditors. The work lands on whoever runs IT.
Frameworks describe outcomes such as access control and audit logging, not which settings to change in Microsoft 365 or on your firewall.
Policies get downloaded from a template, but nobody checks whether the systems work the way the policy says they do.
MFA gets switched off for one person, a new laptop skips encryption, an old account stays active. Small exceptions pile up between reviews.
Technical controls, documentation and upkeep for the frameworks that apply to you.
We compare your systems and practices against the framework that applies and list what is missing, ordered by risk and effort.
We work through the National Institute of Standards and Technology (NIST) 800-171 controls behind CMMC Level 2, help write your system security plan (SSP) and plan of action and milestones (POA&M), and prepare the evidence your contract currently requires for self-assessment, annual affirmation or government review.
Access controls, encryption, audit logging and backup for systems that hold patient information, plus help with the security risk analysis the HIPAA Security Rule calls for.
Multi-factor authentication, encryption of customer information, monitoring and the technical parts of the written information security program the rule requires.
Network segmentation that keeps card payments apart from guest Wi-Fi and office systems, plus firewall rules, patching and access controls that support your PCI self-assessment.
A complimentary risk assessment is a practical first look at your security gaps before a formal compliance review.
Request a risk assessmentImpact Church of The Woodlands, on the security updates and recommendations Chrysalis provides.
Read more client stories“Chrysalis has greatly enhanced our IT operations and overall security posture. Their team consistently provides updates on our security status and offers clear recommendations to strengthen our current practices. Their proactive communication and support have given us confidence that our systems are being properly maintained and protected”
The frameworks differ, but the work follows the same four steps.
We confirm which rules apply, which systems and data they cover, and what your customers or regulators expect.
We check your current controls against the requirements and rank the gaps.
We put the technical controls in place with your team and record how each one works.
We watch for drift as people, devices and systems change, and update the evidence before each review.
What businesses ask before they start compliance work.
No. No IT provider can make you compliant on its own, and Chrysalis is not an auditor or a CMMC certification assessor. We put technical controls in place, help with documentation and work with you on readiness. The result depends on your contract, your self-assessment and affirmation where CMMC currently requires them, and your policies and people as well as your systems. Your organization remains responsible for deciding which laws, regulations, contract terms and industry standards apply to it.
Your contracts decide. Companies that handle only federal contract information generally need Level 1. Companies that handle CUI generally need Level 2, which follows the NIST 800-171 controls. Check the clauses in your contracts or ask your prime contractor, and we can help you read them.
It can. Companies that handle patient information for a healthcare provider, such as billing, IT or transcription vendors, are business associates under HIPAA and have security obligations of their own.
Yes. Chrysalis signs business associate agreements with its healthcare clients. HIPAA calls for one between a healthcare provider and any IT provider that handles patient information on its behalf.
Non-bank financial businesses such as mortgage brokers, auto dealers that arrange financing, tax preparers and some accounting firms. It requires a written information security program supervised by a Qualified Individual, plus controls such as multi-factor authentication, encryption and regular monitoring or testing.
It depends on where you start and which framework applies. A gap assessment shows the size of the job, and we give you a plan and timeline after that, not before.
Tell us which framework you are working toward and what your customer, insurer or regulator has asked for. We will explain what a readiness project would involve before you commit. Call sales at 713.575.2608.