[Services]

Services, phase by phase.

Not every client fits a clean four-phase approach, and that is expected. These services plug in wherever you are in your build — come in at the beginning for full business modeling, or pick up the one piece you are missing. This page is the overview of the different areas where Input Trace can support you.

[Phase 01]

Business Modeling Current State

Discovery — learn how the business actually runs and where CUI lives. The foundation every later phase is built on.

  • Current-state data-flow discovery

    Map how FCI and CUI enter, move, mutate, and leave the business — through client narratives, operator interviews, and a data lifecycle matrix.

    → CUI data-flow diagram
  • External-organization scoping

    Enumerate every external dependency and classify each as Prime, Subcontractor, ESP, CSP, or Out of Scope, with the information category it exchanges.

    → External Organization Inventory
  • Network & asset inventory

    Categorize every asset against the CMMC asset categories — CUI, Security Protection, Contractor Risk Managed, Specialized, and Out-of-Scope — and map the networks it lives on. The depth of the finished inventory depends on your architectural model, and it is delivered in your Technical Data Package.

    → Asset & network inventory
  • Scope boundary definition

    Fix the physical and logical boundary — exactly what is in scope, what is out, and why. Over-scope and cost inflates; under-scope and the assessment fails.

    → Scope boundary document
[Phase 02]

Enclave Proposal & TDP Target State

Propose the target-state architecture and package it as the Technical Data Package you sign off before anything is built.

  • Target-state architecture design

    Select the deployment pattern that fits the workload — cloud, cloud + AVD, or hybrid — and design the enclave around how the business actually operates, not the other way around.

    → Target Design Package (TDP)
  • Shared Responsibility Matrix

    Trace every applicable practice to a responsible party — Input Trace, your MSP, your team, or shared — so nothing falls through a gap at assessment.

    → Shared Responsibility Matrix
  • SSP foundation

    Stand up the System Security Plan skeleton, control-to-config mapping, and license matrix so implementation has a precise spec to build to.

    → SSP skeleton + control mapping
  • Cost & timeline

    Scope, phased delivery dates, and a tight cost range — locked at sign-off. No moving targets once you approve.

    → Engagement proposal
  • MSP services

    The proposal is where you decide who operates the enclave day to day, and we work with whichever answer fits. Hire internally and we work alongside your team. Already have an MSP — we work with them, with the split made explicit in the Shared Responsibility Matrix. Or Input Trace takes it on and runs a full secure client workspace that you own, as a Type 2 or Type 3 deployment we manage end to end. No lock-in either way.

    → Operating-model decision
[Phase 03]

Implementation Build

Build the target state as one of the three deployment types — the same three from our solution catalog. Which one you land on was decided in Phase 2; here is what each build looks like.

  • Greenfield enclave deployment

    Stand up the reference architecture for your deployment type: hub-and-spoke networking, Azure Virtual Desktop host pools, FSLogix on Azure Files over private endpoints, GCC High data routing. CAD/CAM and on-prem compute stay inside the boundary.

    → Deployed enclave
    [ Request access ]

    The engineering assets behind our deployments are shared during a discovery conversation, not posted publicly. Pick your deployment type and we will take it from there.

    • Type 01 — SaaS

      Request a quick quote and install. Fixed scope, static price — the fastest path to a compliant environment.

    • Type 02 — Cloud

      Request the blueprint — the reference architecture for extending the boundary with IaaS/PaaS alongside your SaaS.

    • Type 03 — Cloud + On-Prem

      Request a solution architect. The hybrid build is scoped with you directly, not from a template.

    Request these
  • [ Type 01 ]Simplest

    SaaS deployment

    A boxed SaaS solution — M365, Google Workspace, or an out-of-the-box compliant overlay product. The scope is fixed, nothing structural changes build to build, and the price is static. Worth knowing: because the endpoint that reaches your CUI has to live somewhere, we deliver SaaS-centric builds under the Type 2 cloud model — the VDI environment deploys into Azure and the SaaS runs alongside it.

    → Fixed-price deployment
  • [ Type 02 ]More complicatedOur specialty

    Cloud deployment

    Part of the work needs an application SaaS cannot host, so IaaS/PaaS extends the boundary to run it. This takes minor solution architecting before the build is priced — which firewall openings the workload needs, which external SaaS services have to be punched through the enclave, and how the pieces stay inside the boundary.

    → Cloud enclave
  • [ Type 03 ]Most complicatedOur specialty

    Cloud + on-prem deployment

    Part of the CUI workflow exists onsite, so the enclave extends to the room where the work happens. Dual domain controllers, Azure Arc projecting the cloud control plane onto the floor, on-prem logs shipping into the Log Analytics Workspace. This is the build where a solution architect is not optional — and the one we specialize in.

    → Hybrid enclave
  • Evidence & traceability

    We do not leave you with just the technology. As the enclave goes up we help you generate the evidence and format your policies and procedures in a well-organized way that is ready for assessment — all indexed in the Document Traceability Matrix, which ties every control to its SSP statement, its policy and procedure, and the evidence that proves it. Nothing is assembled at the last minute.

    → Document Traceability Matrix (DTM)
    The System Security Plan is the overarching plan; policies, procedures, and evidence tie into the Document Traceability Matrix, which traces back to the controls documented in the SSP.
    The System Security Plan is the overarching plan; policies, procedures, and evidence tie into the DTM, which traces every one back to its control in the SSP — the index the assessor follows.
[Phase 04]

Assessment Readiness & Audit Support

Assessment and readiness services — walk the mock assessment, sit with the C3PAO through the real thing, and keep the certification holding up afterward.

  • Mock assessment

    A full dry run against the C3PAO methodology so there are no surprises on the day of the real assessment.

    → Mock assessment report
  • C3PAO audit support

    We sit with you and the C3PAO through the actual assessment and advocate for the architecture we built.

    → Live audit support
  • Continuous compliance

    Annual affirmation and change management so the certification keeps holding up as the business grows. Under 32 CFR 170.19, in-pattern growth is not a significant change.

    → Affirmation + change plan
[Start]

Wherever you are in the build, start the conversation.