Home/FAQ

Questions our clients actually ask.

Straight answers on what we do, the frameworks we support, AI, remote work, and how engagements with AMA actually run.

What does AMA IT Consulting actually do?
We're a U.S.-based IT and security partner. We run day-to-day IT support for remote and hybrid teams, design and manage cloud infrastructure, help organizations adopt AI safely with governance and AI-assisted operations, and implement security compliance across whichever frameworks apply to you — NIST 800-171/CMMC, HIPAA, GLBA, or ISO. Government contractors, nonprofits, and startups are our core clients.
Which compliance frameworks do you support?
The ones our clients actually answer to: NIST 800-171 and CMMC for government contractors, HIPAA for organizations handling health information, GLBA for financial data, and ISO 27001 for companies that need an internationally recognized security standard. The discipline is the same across all of them — implement real controls, document them, and keep them alive — only the rulebook changes.
What is 'AI methodology' and why would my organization need it?
Two things. First, AI process management and policy development: your team is already using AI tools, and we help you adopt them deliberately — with policies, guardrails, and documentation so it's safe and compliant rather than a shadow-IT risk. Second, AI-assisted operations: we use AI to make your IT smarter, with better alerting, monitoring, and continuous process improvement across your environment.
How much does CMMC Level 2 readiness cost for a small contractor?
For a 15–75 person contractor, expect a one-time readiness engagement in the low-to-mid five figures plus a monthly retainer in the low four figures to maintain it. We quote fixed fees after the gap assessment, so you know the full number before committing — and the gap assessment itself is a small standalone project you can take and walk.
Can't we just buy compliance software instead?
No — compliance platforms track whether the work got done; they don't do the work. Someone still has to scope your CUI boundary, implement 110 controls, write the SSP, harden the tenant, and stand in front of the assessor. We use automation where it helps, and do the implementation work a dashboard can't.
Do we need Microsoft GCC High?
Not always. ITAR data and certain CUI categories effectively require it; other contractors can meet requirements in GCC or a properly configured commercial tenant with an enclave. We map your actual data flows first and recommend the least disruptive environment that passes — not the most expensive one.
Our team works from home. Does that make security and compliance harder?
It changes the approach, not the outcome — and it's what we specialize in. Remote work expands your security boundary to every home office, so we lean on zero-trust access, managed endpoints, and tightly scoped environments. A distributed team can meet the same standards — CMMC, HIPAA, ISO, or otherwise — that an office-based one does.
We already have an IT company. Can you just do the compliance part?
Yes. We regularly work alongside an incumbent IT provider, handling the compliance program while they run day-to-day support. Because most audit findings come from routine IT changes, many clients eventually consolidate with us for one accountable party — but it's not required.
How fast can we start?
Typically within one week of a signed agreement. The gap assessment takes two to three weeks, and you'll have your real SPRS score, remediation roadmap, and a fixed readiness quote at the end of it.
What is CMMC, in plain terms?
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's program for verifying that contractors protect sensitive information. Level 2 — the level most contractors handling Controlled Unclassified Information need — requires implementing the 110 security requirements of NIST SP 800-171. As of July 2026 the mandatory third-party certification step (Phase 2) is suspended pending a reform review, but Phase 1 self-assessment, SPRS scoring, and DFARS 252.204-7012 safeguarding obligations all remain in force — the requirement to actually be compliant hasn't moved.
What is an SPRS score?
Your SPRS (Supplier Performance Risk System) score is a number from -203 to 110 that summarizes how many NIST SP 800-171 requirements you've implemented, reported to the DoD's database. Primes check it. A defensible score backed by evidence matters more than an optimistic self-assessment — inflated scores create False Claims Act exposure.
Let's strengthen your IT together

Know your number before your prime asks for it.

Book a consultation or a fixed-fee gap assessment. In three weeks you'll have your real SPRS score, a prioritized roadmap, and a firm quote.

Book an Appointment
benjamin@aristidemanagement.com · (540) 742-7249 · 212 E Main St STE F, Front Royal, VA 22630