
Services, phase by phase.
Not every client fits a clean four-phase approach, and that is expected. These services plug in wherever you are in your build — come in at the beginning for full business modeling, or pick up the one piece you are missing. This page is the overview of the different areas where Input Trace can support you.
Business Modeling Current State
Discovery — learn how the business actually runs and where CUI lives. The foundation every later phase is built on.
Current-state data-flow discovery
Map how FCI and CUI enter, move, mutate, and leave the business — through client narratives, operator interviews, and a data lifecycle matrix.
→ CUI data-flow diagramExternal-organization scoping
Enumerate every external dependency and classify each as Prime, Subcontractor, ESP, CSP, or Out of Scope, with the information category it exchanges.
→ External Organization InventoryNetwork & asset inventory
Categorize every asset against the CMMC asset categories — CUI, Security Protection, Contractor Risk Managed, Specialized, and Out-of-Scope — and map the networks it lives on. The depth of the finished inventory depends on your architectural model, and it is delivered in your Technical Data Package.
→ Asset & network inventoryScope boundary definition
Fix the physical and logical boundary — exactly what is in scope, what is out, and why. Over-scope and cost inflates; under-scope and the assessment fails.
→ Scope boundary document
Enclave Proposal & TDP Target State
Propose the target-state architecture and package it as the Technical Data Package you sign off before anything is built.
Target-state architecture design
Select the deployment pattern that fits the workload — cloud, cloud + AVD, or hybrid — and design the enclave around how the business actually operates, not the other way around.
→ Target Design Package (TDP)Shared Responsibility Matrix
Trace every applicable practice to a responsible party — Input Trace, your MSP, your team, or shared — so nothing falls through a gap at assessment.
→ Shared Responsibility MatrixSSP foundation
Stand up the System Security Plan skeleton, control-to-config mapping, and license matrix so implementation has a precise spec to build to.
→ SSP skeleton + control mappingCost & timeline
Scope, phased delivery dates, and a tight cost range — locked at sign-off. No moving targets once you approve.
→ Engagement proposalMSP services
The proposal is where you decide who operates the enclave day to day, and we work with whichever answer fits. Hire internally and we work alongside your team. Already have an MSP — we work with them, with the split made explicit in the Shared Responsibility Matrix. Or Input Trace takes it on and runs a full secure client workspace that you own, as a Type 2 or Type 3 deployment we manage end to end. No lock-in either way.
→ Operating-model decision
Implementation Build
Build the target state as one of the three deployment types — the same three from our solution catalog. Which one you land on was decided in Phase 2; here is what each build looks like.
Greenfield enclave deployment
Stand up the reference architecture for your deployment type: hub-and-spoke networking, Azure Virtual Desktop host pools, FSLogix on Azure Files over private endpoints, GCC High data routing. CAD/CAM and on-prem compute stay inside the boundary.
→ Deployed enclave[ Request access ]The engineering assets behind our deployments are shared during a discovery conversation, not posted publicly. Pick your deployment type and we will take it from there.
Type 01 — SaaS
Request a quick quote and install. Fixed scope, static price — the fastest path to a compliant environment.
Type 02 — Cloud
Request the blueprint — the reference architecture for extending the boundary with IaaS/PaaS alongside your SaaS.
Type 03 — Cloud + On-Prem
Request a solution architect. The hybrid build is scoped with you directly, not from a template.
SaaS deployment
A boxed SaaS solution — M365, Google Workspace, or an out-of-the-box compliant overlay product. The scope is fixed, nothing structural changes build to build, and the price is static. Worth knowing: because the endpoint that reaches your CUI has to live somewhere, we deliver SaaS-centric builds under the Type 2 cloud model — the VDI environment deploys into Azure and the SaaS runs alongside it.
→ Fixed-price deploymentCloud deployment
Part of the work needs an application SaaS cannot host, so IaaS/PaaS extends the boundary to run it. This takes minor solution architecting before the build is priced — which firewall openings the workload needs, which external SaaS services have to be punched through the enclave, and how the pieces stay inside the boundary.
→ Cloud enclaveCloud + on-prem deployment
Part of the CUI workflow exists onsite, so the enclave extends to the room where the work happens. Dual domain controllers, Azure Arc projecting the cloud control plane onto the floor, on-prem logs shipping into the Log Analytics Workspace. This is the build where a solution architect is not optional — and the one we specialize in.
→ Hybrid enclaveEvidence & traceability
We do not leave you with just the technology. As the enclave goes up we help you generate the evidence and format your policies and procedures in a well-organized way that is ready for assessment — all indexed in the Document Traceability Matrix, which ties every control to its SSP statement, its policy and procedure, and the evidence that proves it. Nothing is assembled at the last minute.
→ Document Traceability Matrix (DTM)The System Security Plan is the overarching plan; policies, procedures, and evidence tie into the DTM, which traces every one back to its control in the SSP — the index the assessor follows.
Assessment Readiness & Audit Support
Assessment and readiness services — walk the mock assessment, sit with the C3PAO through the real thing, and keep the certification holding up afterward.
Mock assessment
A full dry run against the C3PAO methodology so there are no surprises on the day of the real assessment.
→ Mock assessment reportC3PAO audit support
We sit with you and the C3PAO through the actual assessment and advocate for the architecture we built.
→ Live audit supportContinuous compliance
Annual affirmation and change management so the certification keeps holding up as the business grows. Under 32 CFR 170.19, in-pattern growth is not a significant change.
→ Affirmation + change plan

