# Rook Federal & Defense Industrial Base Capabilities

## Organization

Legal entity: Rook Strategies LLC
Brand: Rook
Years in business: 9
Delivery footprint: Nationwide
Technical personnel: 8 and expanding
SAM.gov: Registered
CAGE Code: In progress

## Mission for Federal Clients

Rook provides an integrated technology team for organizations whose managed IT, cybersecurity, federal-contracting obligations, and compliance requirements cannot be effectively separated.

## Core Services

### Managed Technology

Service desk, end-user support, endpoint management, Microsoft 365, identity, cloud, network, asset, configuration, change, backup, recovery, vendor coordination, and executive reporting.

### Cybersecurity

Endpoint detection and response, monitoring, vulnerability management, identity security, email security, security awareness, incident response, risk management, and continuity.

### CMMC and NIST SP 800-171

CMMC Level 2 readiness, scope validation, CUI/FCI flow mapping, NIST SP 800-171 implementation, SSP/POA&M support, evidence governance, SPRS support, mock assessment preparation, and C3PAO coordination support.

### CUI Enclave Architecture

Rook-managed Enclave as a Service, customer-owned enclave design, secure hosted desktops, Microsoft government-cloud architecture, access segregation, asset classification, service-provider evaluation, and shared-responsibility documentation.

### Integration

M&A, multi-entity integration, private-equity portfolio support, incumbent-provider transition, tenant and identity consolidation, infrastructure standardization, multi-site deployment, and technology governance.

## Operating Philosophy

Rook treats compliance as an attribute of the operating environment rather than a parallel documentation exercise.

When permitted by contracts and CMMC scoping requirements, Rook seeks to constrain CUI and the assessment boundary to only the systems, users, applications, services, and workflows that require inclusion.

Rook does not represent any technology product as inherently "CMMC certified."

## Engagement Model

1. Discovery and assessment
2. Target-state architecture and standardization
3. Transition and migration
4. Steady-state operations and continuous compliance

## Typical Governance

- Weekly transition and readiness coordination
- Monthly operational reporting
- Quarterly executive reviews
- Incident reporting
- SLA/KPI reporting
- Risk and remediation tracking
- CMMC readiness tracking
- Continuous-improvement roadmap

## Relevant Industries

- Defense Industrial Base
- Federal contractors
- Healthcare
- Construction
- Middle-market private equity
- Professional services
- Other regulated and security-sensitive environments
