# Essendis > Essendis is a U.S. cybersecurity advisory and cloud engineering firm that helps defense contractors and regulated businesses meet CMMC 2.0, NIST SP 800-171, HIPAA, and SOC 2 requirements — pairing former Big Four security auditors with cloud engineers under one roof so assessments, remediation, and implementation happen with a single team. Key facts: - Core services: CMMC 2.0 compliance (readiness assessments, secure enclaves, Microsoft GCC High, Level 1 and Level 2 certification support), network and application penetration testing, vulnerability management, managed cybersecurity, vendor risk management, vCISO, cloud assessments and migrations, managed cloud services, desktop virtualization, custom software and AI development, and vCTO. - Registered federal small business: Small Business Concern Control ID 002263271, Federal Unique Entity ID GZEHUQR13DE7, DoD CAGE Code 9DX02. - Microsoft Government Cloud reseller and AOS-G partner for GCC High licensing and migrations. - Track record: guided client RPS Defense to a perfect 110/110 score on its CMMC Level 2 assessment with C3PAO A-LIGN, with no POA&M required. - Founded by Jim Schraepfer (CISO; Deloitte alumnus; CISA, CISM, CDPSE, CISSP, CCSP, HCISPP) and Michael Schraepfer (CTO; former Sogeti USA solution architect; CISSP, ITIL, AWS-SAA, MCITP, MCSE, MCSA). Serves clients across the United States and Europe. - Standards expertise: CMMC 2.0, NIST SP 800-171, NIST SP 800-53, NIST CSF, DFARS, HIPAA/HITECH, HITRUST, ISO/IEC 27001, SOC 1, SOC 2, PCI-DSS, FedRAMP, FISMA, CJIS, GDPR, CCPA, PIPEDA. - To engage: https://www.essendis.com/contact-us ## CMMC 2.0 Compliance - [CMMC Services Hub](https://www.essendis.com/cmmc): Entry point to all Essendis CMMC 2.0 offerings for defense contractors. - [CMMC 2.0 Overview](https://www.essendis.com/cmmc/cmmc-2-0): What CMMC 2.0 requires, who must comply, and how the certification levels work now that assessment requirements appear in new DoD contracts. - [CMMC Readiness Assessments](https://www.essendis.com/cmmc/cmmc-readiness-assessment): Gap analysis against all 110 NIST SP 800-171 controls so an organization knows exactly where it stands before a formal assessment. - [CMMC Secure Enclave](https://www.essendis.com/cmmc/secure-enclave): Isolating Controlled Unclassified Information (CUI) in a purpose-built enclave to shrink assessment scope, cost, and business disruption. - [Microsoft GCC High](https://www.essendis.com/cmmc/microsoft-gcc-high): GCC High licensing and migration services delivered through Essendis' Microsoft AOS-G partnership. - [CMMC Level 1 Compliance Services](https://www.essendis.com/cmmc/cmmc-2-0-level-1-compliance-services): Support for the 17 Level 1 practices and the required annual self-assessment for contractors handling Federal Contract Information (FCI). - [CMMC Level 2 Compliance Services](https://www.essendis.com/cmmc/cmmc-2-0-level-2-compliance-services): End-to-end preparation for a C3PAO assessment, covering everything Level 2 certification requires. ## Penetration Testing - [Penetration Testing Services](https://www.essendis.com/penetration-testing-services): Overview of network and application penetration testing with actionable findings and auditor-ready reports. - [Network Penetration Testing](https://www.essendis.com/penetration-testing/network-penetration-testing-services): External and internal network testing for regulated environments. - [Application Penetration Testing](https://www.essendis.com/penetration-testing/application-penetration-testing-services): Security testing for web and business applications. ## Cybersecurity Advisory - [Cybersecurity Advisory Services](https://www.essendis.com/cybersecurity-advisory/cybersecurity-advisory-services): Hub for advisory offerings, from security program design to compliance guidance, led by former Big Four auditors. - [Vulnerability Management Services](https://www.essendis.com/cybersecurity-advisory/vulnerability-management-services): Continuous network security scanning, prioritization, and remediation support. - [Managed Cybersecurity Services](https://www.essendis.com/cybersecurity-advisory/managed-cybersecurity-services): Ongoing outsourced security operations for organizations without a full internal team. - [CMMC-Compliant MSSP](https://www.essendis.com/cybersecurity-advisory/cmmc-compliant-mssp): Managed security services structured to satisfy CMMC and DFARS requirements. - [Vendor Risk Management](https://www.essendis.com/cybersecurity-advisory/vendor-risk-management): Third-party risk assessment and monitoring programs. - [Virtual CISO (vCISO)](https://www.essendis.com/cybersecurity-advisory/virtual-chief-information-security-officer): Fractional chief information security officer leadership for security strategy, compliance, and stakeholder assurance. ## Cloud Engineering - [Cloud Engineering Services](https://www.essendis.com/cloud-engineering/cloud-engineering-services): Hub for cloud design, build, and operations services. - [Software Development & AI](https://www.essendis.com/cloud-engineering/custom-development-services): Custom application development and AI solution engineering. - [Cloud Assessments & Migrations](https://www.essendis.com/cloud-engineering/assessments-migrations/cloud-assessments-and-migrations): Evaluating current environments and planning secure moves to the cloud. - [Cloud Assessment Services](https://www.essendis.com/cloud-engineering/assessments-migrations/cloud-assessment-services): Detailed readiness and architecture assessments before migration. - [Cloud Migrations](https://www.essendis.com/cloud-engineering/assessments-migrations/cloud-migrations): Execution of migrations to secure, audit-ready cloud environments. - [Managed Cloud Services](https://www.essendis.com/cloud-engineering/managed-cloud-services): Ongoing management and optimization of cloud infrastructure. - [Desktop Virtualization](https://www.essendis.com/cloud-engineering/desktop-virtualization): Virtual desktop solutions for secure, distributed workforces. - [Virtual CTO (vCTO)](https://www.essendis.com/cloud-engineering/virtual-chief-technology-officer-services): Fractional chief technology officer leadership for technology strategy and delivery. ## Company - [About Essendis](https://www.essendis.com/about-us): Firm background, collaborative advisory-plus-engineering model, and founder bios. - [Case Studies](https://www.essendis.com/case-studies): Client success stories, including CortiCare and AgilityHealth. - [AgilityHealth Case Study](https://www.essendis.com/agility-health): How Essendis removed security barriers so AgilityHealth could close enterprise deals. - [Learning Center](https://www.essendis.com/learning): Library of roughly twenty short security-awareness training videos on topics like DDoS attacks, social engineering, incident response, data classification, cryptography, and remote work security. - [Blog](https://www.essendis.com/blog): Articles on CMMC, penetration testing, and vulnerability management. - [Contact / Talk to an Expert](https://www.essendis.com/contact-us): How to reach Essendis for questions, pricing, and engagements. ## CMMC & Compliance Guides - [CMMC is Enforceable from November 10, 2025](https://www.essendis.com/post/the-final-rule-has-cleared-its-last-hurdle-cmmc-is-enforceable-from-november-10-2025): What the final rule clearing its last hurdle means for defense contractors. - [The 48 CFR Final Rule](https://www.essendis.com/post/the-48-cfr-final-rule-cmmc-requirements-to-be-included-in-all-defense-contracts-by-q4-2025): CMMC requirements entering all defense contracts and the timeline contractors face. - [Navigating the Path to CMMC Level 2](https://www.essendis.com/post/navigating-the-path-to-cmmc-level-2): A roadmap from initial gap analysis to Level 2 certification. - [Is a Secure CMMC Enclave Right for Your Business?](https://www.essendis.com/post/is-a-secure-cmmc-enclave-right-for-your-business-2): When isolating CUI in an enclave lowers compliance cost and scope. - [Understanding "Significant Change" and Recertification](https://www.essendis.com/post/why-does-my-company-need-to-get-recertified-understanding-significant-change-on-the-path-to-cmmc-certification): Which changes trigger CMMC reassessment and how to prepare. - [The Cost, Burden, and Viability of CMMC for SMBs](https://www.essendis.com/post/the-cost-burden-and-viability-of-cmmc-compliance-for-smbs-and-lower-tier-subcontractors): What compliance realistically costs smaller and lower-tier subcontractors. - [Third-Party Risk Management Through a CMMC Lens](https://www.essendis.com/post/third-party-risk-management-through-a-cmmc-lens): Managing subcontractor and vendor risk under CMMC. - [Does CMMC Have an Impact Outside the Defense Portfolio?](https://www.essendis.com/post/does-cmmc-have-an-impact-outside-the-defense-portfolio): How CMMC concepts spill over into other regulated industries. - [CMMC Assessor Capacity Constraints](https://www.essendis.com/post/capacity-constraints-bottlenecks-in-cmmc-assessor-availability-and-assessment-scalability): Bottlenecks in C3PAO availability and what they mean for scheduling. - [The DoD Prioritizes CMMC](https://www.essendis.com/post/the-dod-prioritizes-cmmc-what-defense-contractors-need-to-know): What contractors need to know about DoD enforcement priorities. - [Penetration Testing for CMMC 2.0](https://www.essendis.com/post/penetration-testing-for-cmmc-2-0-meeting-dod-compliance-requirements): How testing supports DoD compliance requirements. - [HIPAA Vulnerability Scanning Requirements](https://www.essendis.com/post/hipaa-vulnerability-scanning-requirements-2025-compliance-checklist): Compliance checklist for scanning under HIPAA. ## Penetration Testing & Vulnerability Management Guides - [What is Penetration Testing? A Plain-English Guide](https://www.essendis.com/post/what-is-penetration-testing-a-plain-english-guide-for-business-leaders): Non-technical introduction for business leaders. - [Vulnerability Assessment vs. Penetration Testing](https://www.essendis.com/post/vulnerability-assessment-vs-penetration-testing-why-regulated-industries-need-both): Why regulated industries need both, and how they differ. - [Black Box vs. White Box vs. Gray Box Testing](https://www.essendis.com/post/black-box-vs-white-box-vs-gray-box-testing-which-is-right-for-you): Choosing the right testing approach. - [Web Application Penetration Testing](https://www.essendis.com/post/web-application-penetration-testing-protecting-your-most-exposed-assets): Protecting an organization's most exposed assets. - [AI System Penetration Testing: The Next Frontier](https://www.essendis.com/post/ai-system-penetration-testing-the-next-frontier): Emerging threats and testing strategies for AI systems. - [Container and Kubernetes Penetration Testing](https://www.essendis.com/post/container-and-kubernetes-penetration-testing-a-devsecops-approach): A DevSecOps approach to securing containerized infrastructure. - [Maximizing ROI from Penetration Testing](https://www.essendis.com/post/maximizing-roi-from-penetration-testing-turning-findings-into-business-value): Turning findings into prioritized remediation and business value. - [The Vulnerability Management Lifecycle: A 5-Step Guide](https://www.essendis.com/post/what-is-the-vulnerability-management-lifecycle-a-5-step-guide): The core stages of an effective program. - [Building a Vulnerability Management Policy](https://www.essendis.com/post/building-a-vulnerability-management-policy-a-step-by-step-template): Step-by-step policy template. - [Vulnerability Management Metrics: Key KPIs for CISOs](https://www.essendis.com/post/vulnerability-management-metrics-key-kpis-for-cisos): MTTR, MTTD, risk scoring, and board reporting. - [Integrating Vulnerability Management into CI/CD Pipelines](https://www.essendis.com/post/integrating-vulnerability-management-into-ci-cd-pipelines-a-comprehensive-guide-for-modern-businesses): Shift-left security with SAST, DAST, and SCA tooling. ## Optional - [Why Cybersecurity Should Be Your Number One Priority](https://www.essendis.com/post/why-cybersecurity-should-be-your-number-one-priority): General-audience argument for prioritizing security. - [Vulnerability Management Services Overview](https://www.essendis.com/post/cybersecurity-vulnerability-management-services): Blog-format overview of the Essendis vulnerability management offering. - [Penetration Testing Services Overview](https://www.essendis.com/post/cybersecurity-penetration-testing-services): Blog-format overview of the Essendis penetration testing offering. - [Privacy Policy](https://www.essendis.com/privacy-policy): Site privacy practices.