Managed Services for Mission Assurance — August Schell
Authorized C3PAO + RPO Compliance-First Delivery MSP MSSP

One accountable team. Compliance, IT, and security.

“I don’t want to manage vendors — I want one team accountable for all of it.”

A single managed program across compliance, IT, and security operations — CUI enclave and SSP administration, vCIO/vCISO advisory, continuous monitoring, and incident response — so your compliance posture, your operations, and your security program are run by one accountable team instead of stitched together from three.

Sustaining your compliance, enabling your operations, protecting your mission.
01What we run

Three disciplines, one program.

Most organizations buy compliance from one vendor, IT from another, and security from a third — then spend their time refereeing between them. We deliver all three as a single managed program, built compliance-first, because in a regulated environment the compliance requirement is the design constraint, not an afterthought.

Compliance-First Managed Services

Risk & Compliance Foundation

Stay compliant. Stay contract eligible.
C3PAO CMMC Level 2 Certification Assessment
The formal assessment that goes on record in SPRS, performed by our in-house, all-W-2 Lead CCAs — not 1099 subcontractors.
Level 2 & 3 Mock Assessment
A full dress rehearsal against all 110 controls — the same line-by-line diagnostic an assessor applies, without the certification cost, and without establishing a consulting relationship under Cyber AB rules.
CMMC Secure Enclave — Documentation & Administration
SSP, policies, POA&M and the evidence behind them — written to survive an assessment, not to fill a binder.
Sustainment & Compliance Management
Compliance isn’t a project that ends. We keep the SSP current, the POA&M moving, and your annual SPRS affirmation defensible year over year.
FedRAMP & DoD Cloud Authorization
Advisory and support for product and software companies selling into federal clouds — the authorization path that begins where CMMC ends.
Managed Service Provider · MSP

CyberOps

Keep the lights on — securely.
vCIO — Technology Development & Advisement
Senior technology leadership without the headcount. Roadmap, budget, and architecture decisions made by people who have run federal environments.
ASE Secure Enclave — Managed Services & Documentation
We build the CUI enclave and then we run it — with documentation maintained as the environment changes, instead of reconstructed the week before an assessment.
Enterprise IT Support & Administration
Day-to-day IT for the whole organization, delivered by a team that already knows what your compliance program requires of it.
Continuous Monitoring & Audit Readiness
Controls checked continuously, so an audit becomes a report you pull rather than a project you launch.
Email Security & Spam Filtering
The most common initial access vector into the defense industrial base — closed.
Asset Visibility & Mobile Device Management
You cannot protect, or attest to, what you cannot see. Full inventory and managed endpoints.
Managed Security Service Provider · MSSP

SecOps

Detect. Respond. Recover.
vCISO — Security Advisory & Program Management
A security executive accountable for the program, the risk decisions, and the conversations with your primes and your auditors.
AI-Enabled Unified Security Posture Management
One view of posture across the environment, with AI surfacing what actually matters instead of another dashboard nobody reads.
AI-Enabled Mobile Threat Defense
Mobile is in scope, and it is usually the gap.
Incident Response & Threat Intelligence
DFARS 252.204-7012 gives you 72 hours to report a cyber incident. We’re the team that makes that deadline.
Vulnerability-as-a-Service (VULaaS)
Continuous identification, prioritization, and remediation tracking — with the evidence trail your assessment will ask for.
SOC-as-a-Service (SOCaaS)
24/7 monitoring and response, without standing up a SOC of your own.
02Why one team

Three vendors, three stories, one auditor.

When compliance, IT, and security are three separate contracts, the seams between them are where findings live — and every seam is a conversation about whose job it was.

Compliance-first, not compliance-after

We’re an authorized C3PAO. We know what an assessor asks for because we’re the ones who ask it. That standard is designed into the environment on day one rather than retrofitted the quarter before your assessment.

The documentation matches the environment

Your SSP is only true on the day it was written unless someone maintains it. When the team running your IT is the team writing your evidence, your paperwork and your reality don’t drift apart.

One number to call at 2am

An incident is not the moment to discover that your MSP, your MSSP, and your compliance consultant each believe someone else owns the 72-hour clock.

03Who we serve

Regulated environments, wherever they are.

Defense Industrial Base
Prime and sub-contractors carrying CUI and DFARS obligations.
Federal Civilian & DoD Agencies
Federal and Intelligence Community mission owners.
State, Local & Education
Government and academic institutions.
Regulated Commercial
Banking, healthcare, finance, and other organizations under a regulator.
04How it works

Structured to fit, not to lock you in.

Fixed-price or hourly bundlesDefined scope, defined number — or a block of hours you draw against.
Monthly managed subscriptionsPer-user, predictable, and budgetable.
End-to-end assessment & authorizationFrom first scoping call through certification or authorization.
Scale up or downYour needs change. The engagement changes with them.
05Pricing

Pricing at a glance.

Every environment is different, so final scope drives final price — but you shouldn’t have to sit through a discovery call to find out the order of magnitude. Here’s where engagements start.

C3PAO CMMC Assessments
Level 2 & 3 Mock Assessmentfrom $15,000
Level 2 Certification Assessmentfrom $35,000
Custom pricing available. Final scope depends on environment size and complexity.
Risk & Compliance Consulting
10 hoursfrom $3,500
20 hoursfrom $5,000
40 hoursfrom $8,000
RPO · FedRAMP · DoD Cloud · vCIO · vCISO — 3 / 6 / 9 / 12-month terms. Commitment discounts apply.
Managed Services · MSP
Per user, per monthfrom $250
Additional servicescustom quote
12-month terms. Commitment discounts apply.
Managed Security Services · MSSP
SecOps programcustom quote
12-month terms. Commitment discounts apply. Scoped to your environment, your regulator, and your risk.
Why we publish this. The Department of War suspended CMMC Phase II in part over the cost of compliance — and the figures in circulation describe the total cost of implementing security controls you already owe under DFARS 252.204-7012, not the price of an assessment. We think the honest answer to a pricing argument is a price list. If a number here doesn’t fit your situation, tell us and we’ll scope it.
06Independence

Conflict of interest, handled honestly.

Legal notice

Cyber AB rules keep advisory and certification independent. If August Schell has provided you RPO, advisory, remediation, or managed services in the last three years, we cannot perform your CMMC certification assessment — we will coordinate an independent C3PAO on your behalf instead. A non-certification mock assessment does not establish a consulting relationship under those rules. We will tell you which side of that line you are on before you engage, in writing, every time.

Contract vehicle
SEWP V
Category C
UEI
PPMBFPRXNAJ9
Unique Entity ID
CAGE
1W5J9
Commercial and Government Entity
Authorizations
C3PAO + RPO
Cyber AB authorized and registered
Talk to us

Tell us what you’re carrying.

Bring us your contracts, your environment, and your deadline. We’ll come back with a straight read on what you actually need — which of the three disciplines, at what scope, and what it costs. To determine pricing for your situation, schedule a meeting and request a quote.

Business POC
Alonzo “Cory” Booker
Director, Managed Services for Mission Assurance
alonzo.booker@augustschell.com · 858-774-4849
Technical POC
Timothy Judy
Chief Information Security Officer
timothy.judy@augustschell.com · 443-370-6604