DRAFT: pending approval. This site is not published and nothing here is final.

Product

How NexusIQ works

NexusIQ is built only for CMMC Level 1. It helps you scope your FCI, work through all 17 practices, and hand a complete packet to the Affirming Official, without moving your FCI files into yet another tool. [product details to be confirmed by Seth]

Five steps

Five steps

  1. Step 1: Scope your FCI

    A guided wizard helps you decide what counts as Federal Contract Information and where it lives.

    [Wizard details and screenshots: pending Seth]

  2. Step 2: Work the 17 practices

    Walk through all 17 practices and 59 assessment objectives in plain English.

    [Feature details: pending Seth]

  3. Step 3: Lock the assessment

    Lock your answers before affirmation so everyone is looking at the same record.

    [Feature details: pending Seth]

  4. Step 4: Hand off to your Affirming Official

    NexusIQ prepares a packet and hands it off to the Affirming Official, who uploads it to SPRS and makes the annual affirmation. The Affirming Official remains accountable for the affirmation.

    [Packet contents and screenshots: pending Seth. Compliance to review wording.]

  5. Step 5: Stay current

    See what changed and what’s due before the next annual affirmation.

    [Feature details: pending Seth]

NexusIQ organizes the work. It does not certify or guarantee anything. Your company and its Affirming Official remain responsible for the accuracy of your assessment and affirmation.

Level 1 topics

Level 1 topics, in plain words

DRAFT plain-name list. It is not the official practice list and Compliance has not verified it. [Compliance to check against the official list and fix wording]

  • Limit who can get inOnly authorized people and devices reach company systems.
  • Limit what they can doPeople only run the functions their job needs.
  • Control outside connectionsKnow what connects to your network from outside.
  • Control what goes publicReview what gets posted on public sites.
  • Identify and verify usersEveryone has their own login, and it’s checked.
  • Wipe media before disposalDrives, USB sticks, and paper get cleaned or shredded.
  • Limit physical accessDoors, locks, and who has keys.
  • Escort and log visitorsVisitor sign-in and escorts.
  • Boundary protectionA firewall between your network and the internet.
  • Separate public systemsYour public website or guest wifi isn’t on the same network as the internal one.
  • Patch flawsInstall updates on a regular schedule.
  • Malware protectionAntivirus on, and kept current.
  • Scan files and systemsRegular scans.

Product screenshots will appear here once Seth approves them. [awaiting real screenshots]

See it for yourself

Book a 20-minute demo.

Book a 20-minute demo