Protect the environment. Meet the requirements.
ACC Inc. helps businesses strengthen network security, manage secure access, address technical risks, and prepare for compliance requirements including CMMC and SOC 2.
Two sides of the same environment.
Cybersecurity protects the systems, networks, users, and data your business relies on. Compliance focuses on meeting defined requirements and showing that the right controls are in place.
We handle both sides of the work, from network security and secure access to readiness assessments, documentation, remediation planning, and assessment preparation.
Network security and secure access
Practical security services focused on protecting the network, controlling access, and reducing unnecessary exposure.
Managed Network Security
Firewall deployment, configuration, remote administration, policy changes, firmware updates, monitoring, and ongoing maintenance.
VPN & Secure Remote Access
Secure remote access for employees and administrators, plus site-to-site VPN connectivity between business locations.
Get ready before the assessment begins
We help organizations understand what is required, identify gaps, document controls, and prepare the evidence needed for review.
Readiness Assessments
Review the current environment against the applicable framework and identify where additional work is needed.
Gap Analysis & Remediation Planning
Identify control gaps, set priorities, assign ownership, and build a practical plan for closing them.
Policies & Documentation
Develop and organize the policies, procedures, plans, and supporting documentation required for the program.
Technical Remediation
Implement technical changes needed to support compliance requirements across network, access, security, and infrastructure controls.
Evidence & Assessment Preparation
Organize evidence, review documentation, prepare internal teams, and coordinate with independent assessors or auditors.
Managed Compliance
Ongoing support for documentation, evidence tracking, control reviews, remediation follow-up, and maintaining the program over time.
CMMC Level 1, Level 2 and SOC 2
Our current compliance work is centered on CMMC Level 1 and Level 2 readiness and SOC 2 readiness.
CMMC
CMMC applies to organizations in the defense industrial base that handle Federal Contract Information or Controlled Unclassified Information. We help organizations understand what applies to their environment, determine where they stand today, and prepare for the level of assessment they need.
Support for organizations working with Federal Contract Information. We review the environment, identify gaps in basic safeguarding practices, help document how requirements are being met, and prepare the organization for self-assessment and ongoing maintenance.
Readiness and remediation support for organizations that handle Controlled Unclassified Information, including preparation for the applicable assessment path.
Environment scoping, readiness review, control gap analysis, policy and procedure development, remediation tracking, evidence organization, assessment preparation, and ongoing compliance support.
SOC 2
SOC 2 is commonly used by service organizations to demonstrate how they manage controls around security and other applicable Trust Services Criteria. We help organizations get the environment, documentation, and evidence ready before an independent examination begins.
Review current controls, policies, systems, and operating practices to identify what is already in place and where work is still needed before the audit period.
Help define and document the controls the organization relies on, including policies, procedures, ownership, and the way those controls operate in practice.
Organize supporting evidence, validate documentation, address open gaps, and prepare internal teams to work with the independent auditor during the examination.
Maintain documentation, track recurring evidence, review changes to the environment, and keep the compliance program from becoming a one-time exercise.