DRAFT: pending approval. This site is not published and nothing here is final.

For small defense contractors

Built only for CMMC Level 1.

NexusIQ helps small defense contractors scope their FCI, work through all 17 practices, and hand a complete packet to the Affirming Official. Your FCI files stay where they are.

  • Veteran-owned
  • CISSP-led

The problem

Most compliance platforms start with SOC 2 and add CMMC on later. They want your documents uploaded, ask you to wade through features you don’t need, and are priced for larger teams. [Seth/Compliance to confirm this general statement about other platforms] A Level 1 contractor has one job: understand what counts as FCI, work through the 17 practices, and have someone accountable affirm the result every year.

How it works

Five steps, in plain English.

  1. Step 1

    Scope your FCI

    A guided wizard helps you decide what counts as Federal Contract Information and where it lives.

  2. Step 2

    Work the 17 practices

    Walk through all 17 practices and 59 assessment objectives in plain English.

  3. Step 3

    Lock the assessment

    Lock your answers before affirmation so everyone is looking at the same record.

  4. Step 4

    Hand off to your Affirming Official

    NexusIQ prepares a packet and hands it off to the Affirming Official, who uploads it to SPRS and makes the annual affirmation. The Affirming Official remains accountable for the affirmation.

  5. Step 5

    Stay current

    See what changed and what’s due before the next annual affirmation.

More on how it works

Why NexusIQ

  • Your FCI stays where it is
    NexusIQ records where your evidence lives instead of collecting FCI files into another system.
  • Built only for CMMC Level 1
    No SOC 2 tangents, no feature sprawl.
  • Know what changed, know what’s due
    Built around the annual affirmation cycle.
  • Built by a veteran-owned cybersecurity firm
    Method Tech is a veteran-owned firm with CISSP-led expertise.

Roadmap

Planned Planned: CMMC Level 2, then additional frameworks such as HIPAA and SOC 2. Planned items are not available today and carry no dates.

Frequently asked questions

What is CMMC Level 1?

The entry level of the Department of Defense’s cybersecurity program, covering 17 basic practices for protecting Federal Contract Information. [Compliance to review wording]

CMMC Level 1 explainer (DRAFT)

Does NexusIQ make me compliant?

No. NexusIQ helps you organize and track your Level 1 work. Your company and its Affirming Official are responsible for the accuracy of your assessment and affirmation. [Compliance to review]

Does NexusIQ store my FCI?

NexusIQ records pointers to where your evidence lives and is designed to keep FCI files out of the platform. [Seth/Compliance to confirm exact wording]

Security & architecture (DRAFT)

Does NexusIQ submit to SPRS for me?

No. NexusIQ prepares your SPRS packet and hands it off to your Affirming Official, who uploads it themselves.

Does it support Level 2?

Not today. Level 2 is planned. No dates.

What does it cost?

[pending Seth]

Pricing

Level 1 doesn’t need to be complicated.

Book a 20-minute demo.

Book a 20-minute demo