An assessment tells you where you stood on the day it ended. Assurance keeps you defensible every day after. Merek delivers ongoing visibility, evidence, and executive clarity — one accountable partner who owns your security posture continuously.
CMMC Phase II is suspended — but NIST SP 800-171, DFARS 252.204-7012, annual affirmations, and SPRS scoring all remain in effect. Whatever assessment model emerges, contractors still need current, defensible evidence. Continuous assurance is the hedge.
Security is reactive, evidence goes stale, ownership is unclear, and audit readiness becomes a scramble. Posture drifts undetected between reviews — and leadership finds out when it costs a contract.
Over 200,000 defense industrial base organizations had not yet begun a formal compliance program as of early 2026. The ones that win contracts are the ones that can produce current evidence on demand.
Talk to us about where you stand →Not a vendor. Not a tool. A partner who owns your posture continuously — across four functions, every month.
Continuous visibility into your security environment. We surface threats, misconfigurations, and control gaps before they become incidents or audit findings.
Schedule a Consultation →Your SSP, POA&M, and SPRS score stay current and defensible. Your compliance documentation is always ready — never scrambled together before an assessment.
Schedule a Consultation →A clear, structured briefing so leadership always knows where the organization stands — no surprises, no guesswork, full accountability.
A current snapshot scored against NIST SP 800-171 Rev. 2 controls and benchmarked against your prior-month baseline — with your highest-priority risks ranked by likelihood and impact, in plain language suitable for non-technical leadership review.
Every engagement begins with onboarding ($3,500–$5,000): baseline posture, evidence inventory, and SPRS score. Monthly assurance then continues at the level that fits your program maturity. Industry vCISO retainers run $1,500–$8,000/month in 2026 — every Merek tier sits inside the established band, priced on accountability level, not hours.
Continuous posture monitoring, monthly risk summary, SPRS tracking, and evidence maintenance. For organizations establishing foundational cybersecurity accountability.
Start with Core →All Core services plus expanded POA&M management, remediation guidance, control-owner tracking, and enhanced executive reporting for maturing compliance programs.
Ask about Program →A 30-minute discovery session delivers five identified risks, a preliminary SPRS-aligned score, and an initial posture summary — at no cost. This is not a sales call. It is a structured intake that gives your leadership a concrete starting point. You leave with clarity, not a proposal.