Home/Services/Running the Program

Running the Program

Compliance decays the day you stop maintaining it. Configurations drift, staff turn over, evidence goes stale. This is the part that keeps a position defensible between assessments — and the part most providers do not do.

Compliance Is a State, Not an Event

Why an assessment is not the finish line

A compliance position is a claim about how your environment behaves, made continuously. An assessor examines a slice of it. What they are really testing is whether the program that produced that slice is real — whether change is controlled, whether evidence has a history, whether the plan describes the environment as it exists today rather than as it existed the week before the audit.

Twelve months of demonstrated operation is not paperwork. It is the difference between a defensible position and a well-formatted document.

What we run

  • System Security Plan kept current — updated as the environment changes, not annually
  • POA&M actively managed — items worked and closed on schedule, with the 180-day closeout window tracked
  • Continuous evidence collection — artifacts captured as they occur, into a repository you own
  • Monthly Change Advisory Board — change control with a record, plus metrics reporting
  • Continuous monitoring — SIEM alerting with 24/7 escalation to TRANUSA on-call engineering
  • Endpoint and vulnerability management — EDR, application control, patching to defined targets, continuous scanning
  • Security awareness training and phishing simulation — because the practices require it and people are the control that lapses first
  • C3PAO audit support — evidence packages assembled and defended

We do not claim a staffed watch floor, because we do not run one. What you get is continuous SIEM alerting with 24/7 escalation to our on-call engineering team, staffed by U.S. Persons. Some providers describe that as a 24/7 SOC. We would rather you know exactly what you are buying, because it is the kind of thing that gets discovered during an incident.

Where we sit in your support model

TRANUSA is not your IT department and does not replace it. Your frontline support stays yours; we sit behind it as Tier 2 and Tier 3 escalation for the compliance environment. That boundary keeps accountability clear and keeps us focused on the thing you are actually paying for.

What you own, always

The SSP, the POA&M, the policies, the evidence repository, the assessment result and the posted score. Yours outright, unaffected by the engagement ending.

Book a CMMC Readiness Call

Thirty minutes. We review your contract requirements, identify your top compliance gaps, and give you a realistic timeline to audit readiness. No pitch decks, no obligation.

Book Your Call →
or email CMMC@tranusa.com