# Rook CMMC Capability

Rook supports organizations pursuing CMMC Level 2 readiness and NIST SP 800-171 alignment.

## Rook Method

Rook uses a control-to-evidence operating methodology:

1. Define the contractual requirement and assessment objective.
2. Assign accountable control ownership.
3. Document policies, procedures, implementation, and responsibility.
4. Implement authorized technical, administrative, and physical controls.
5. Collect contemporaneous evidence.
6. Examine, interview, and test operation.
7. Remediate findings and maintain the SSP, POA&M, inventories, diagrams, and evidence index.

## Boundary Strategy

Rook begins with:

- contracts
- CUI and FCI
- data flows
- users
- assets
- applications
- service providers
- administrative access
- interconnections

The CMMC assessment boundary is then designed from those facts.

Rook does not assume that CMMC Level 2 automatically requires migration of an entire enterprise into GCC High.

Where permitted, Rook recommends deliberately bounded CUI architectures to reduce unnecessary cost, complexity, and assessment scope.

## Architecture Options

### Rook Enclave as a Service

A Rook-managed enclave providing the CMMC-aligned technology, security controls, management, and compliance infrastructure necessary to operate the defined environment.

### Customer-Owned Enclave

A customer-owned CUI environment designed and implemented by Rook, with control ownership, licensing, evidence, and operating responsibilities explicitly documented.

### Government Cloud

Microsoft GCC, GCC High, Azure Government, Intune Government, AVD, and related services may be selected where contractual, data, export-control, authorization, or architectural requirements make them appropriate.

Exact service editions and authorization boundaries must be validated before use.

## Assessment Readiness

Rook can support:

- scope validation
- gap analysis
- implementation planning
- SSP
- POA&M
- policies and procedures
- evidence management
- remediation tracking
- readiness reviews
- mock assessments
- C3PAO coordination support
- continuous compliance

Rook readiness consulting is distinct from an independent C3PAO certification assessment.
