Independent, evidence-based NIST assessments that quantify your real risk, satisfy auditors, and give you a clear roadmap โ not a 200-page PDF that sits on a shelf. Serving federal contractors, healthcare organizations, and regulated businesses across Washington, DC.
Every engagement is tailored to DC market realities โ regulatory complexity, competitive density, and client expectations.
A structured evaluation of your security posture across all six CSF 2.0 functions, producing a current-state profile, target-state profile, and a prioritized gap list with effort and risk-reduction estimates for every finding.
A deep-dive evaluation of your security and privacy controls against the NIST SP 800-53 Rev 5 catalog โ required for federal systems and increasingly expected by enterprise customers and cyber insurers.
Purpose-built assessment for defense contractors and organizations handling Controlled Unclassified Information (CUI) โ covering all 110 SP 800-171 practices required for CMMC 2.0 Level 2 certification.
Full RMF lifecycle support for federal agencies and contractors seeking an Authority to Operate (ATO) โ from categorization and control selection through assessment, authorization, and continuous monitoring.
Quantitative and qualitative risk assessments aligned with NIST SP 800-30 and SP 800-39 โ giving leadership a defensible, prioritized view of organizational risk that informs budget and strategy decisions.
A structured evaluation of your ICT supply chain risks aligned with NIST SP 800-161 Rev 1 โ the gold standard for identifying, assessing, and responding to cybersecurity risks introduced through vendors, suppliers, and technology providers.
We're based at 1717 N Street NW in DC. We understand local compliance, federal contracting nuance, and what DC clients expect โ and we've built our process around it.
Our assessors are trained practitioners who work from primary NIST source documents โ not commercial tools that auto-generate reports without human judgment.
Every gap finding includes a specific remediation recommendation, effort estimate, and a risk-reduction score. You leave with a prioritized roadmap, not just a list of problems.
Deep experience with DoD contractors, civilian agencies, healthcare organizations, and financial firms โ where NIST compliance is mandatory, not aspirational.
We don't sell the tools we recommend. Our assessments are vendor-neutral so findings reflect your actual risk, not a path to a product sale.
Every assessment produces evidence packages, control narratives, and artifacts formatted to satisfy C3PAO assessors, FedRAMP 3PAOs, and SOC 2 auditors โ not just internal stakeholders.
We translate NIST control language into business risk. Board-level summary decks, CISO-level technical findings, and engineering-level remediation tickets โ all from one engagement.
Numbers that reflect real business impact โ not vanity metrics.
A transparent, milestone-driven engagement from first call to launch.
We define the assessment boundary โ which systems, data types, and organizational units are in scope. We align on the specific NIST framework(s) being assessed, collect existing documentation (SSPs, policies, network diagrams), and schedule stakeholder interviews. No surprises mid-engagement.
Our assessors conduct structured interviews with system owners, administrators, and leadership; review technical artifacts and policy documentation; and perform hands-on technical testing (configuration review, vulnerability scanning, log analysis). Every finding is tied to specific evidence.
We map findings to specific NIST controls or CSF subcategories, assign maturity scores or control determinations, and calculate risk using likelihood/impact scoring per NIST SP 800-30. Gaps are categorized by severity and sequenced for remediation based on risk reduction per dollar spent.
Final deliverables include an executive summary (board-ready), full technical findings report, current-state and target-state profiles, prioritized POA&M, and a remediation roadmap with timelines and effort estimates. We present findings directly to your leadership and answer every question.
Common questions from DC businesses considering NIST CSF 2.0 Assessment.
Schedule a free 30-minute scoping call. We'll tell you exactly which NIST assessment applies to your situation, what the engagement looks like, and what it costs โ before you commit to anything.
Based at 1717 N Street NW, Washington, DC ยท hello@thoriumdc.com ยท (301) 337-7268