Rook

Federal Capabilities Statement

Rook Strategies LLC — Federal & Defense Industrial Base Capabilities

Integrated technology, cybersecurity, and compliance for organizations that cannot separate operational reliability from federal obligations. Rook combines managed technology, cybersecurity operations, CMMC / NIST SP 800-171 readiness, architecture, transition, and executive technology leadership under one accountable relationship.

Federal Capability Snapshot

Legal Entity
Rook Strategies LLC
Service Area
Nationwide
Years in Business
9
Primary Capabilities
Managed IT · Cybersecurity · CMMC Level 2 Readiness · NIST SP 800-171 · CUI Enclave Architecture · M&A Technology Integration · Executive Technology Advisory
SAM.gov
Registered
CAGE
In Progress
Delivery Model
Integrated technology team / white-glove managed services
Compliance Experience
Defense Industrial Base · CMMC · NIST SP 800-171 · DFARS · HIPAA

Core Capabilities

01Managed Technology

Service desk and end-user support · Endpoint and infrastructure management · Microsoft 365 and identity administration · Network and cloud operations · Asset, configuration, and change management · Vendor coordination · Backup and continuity

02Cybersecurity Operations

Endpoint detection and response · 24x7 automated monitoring and critical-event escalation · Vulnerability management · Identity and access controls · Email security · Security awareness · Incident response · Risk reporting

03CMMC & NIST SP 800-171

CMMC Level 2 readiness · Assessment-boundary design · CUI / FCI data-flow mapping · NIST SP 800-171 implementation · SSP and POA&M development · SPRS validation support · Control-to-evidence mapping · Mock-assessment preparation · C3PAO coordination support · Continuous compliance operations

04CUI Enclave Architecture

Deliberately bounded CUI environments · Enclave as a Service · Customer-owned enclave design · Microsoft government-cloud architecture · Identity segmentation · Secure virtual desktops · Security Protection Asset evaluation · External Service Provider qualification · Shared-responsibility documentation

05Integration & M&A

Multi-entity technology integration · Post-acquisition transition · Tenant and identity rationalization · Standardization planning · Incumbent provider transition · Multi-site deployment · Interim technology leadership · Private-equity portfolio support

06Executive Technology Advisory

vCIO / vCISO leadership · Technology roadmaps · Risk and investment decisions · Executive and board reporting · Architecture decisions · Vendor strategy · Federal technology strategy · Continuous improvement

CMMC Approach

Rook does not assume that CMMC Level 2 requires placing an entire enterprise into a government-cloud environment. Where permitted by contractual requirements and CMMC scoping rules, Rook favors deliberately bounded architectures: commercial enterprise → controlled access → CUI enclave → authorized users and systems → evidence and continuous governance. Architecture paths include Rook Enclave as a Service, customer-owned enclave, and broader government-cloud implementations (GCC, GCC High, Azure Government, Intune Government) where requirements make them appropriate.

No technology product should be represented as “CMMC certified.” Rook readiness support is distinct from an independent C3PAO certification assessment.

Control-to-Evidence Methodology

  1. 1. DefineIdentify contractual requirement, assessment objective, service, asset, and data flow.
  2. 2. AssignEstablish control owner and operating responsibility.
  3. 3. DocumentApprove policy, procedure, implementation statement, and responsibility allocation.
  4. 4. ImplementConfigure the technical, administrative, or physical control.
  5. 5. EvidenceCollect contemporaneous operating evidence.
  6. 6. TestExamine artifacts, interview owners, and validate operation.
  7. 7. MaintainClose findings or place eligible residual items into disciplined POA&M management; update SSP, diagrams, inventories, and evidence indexes.

Relevant Experience

  • Defense Industrial Base

    ~150 office staff · Five locations

    Managed IT, cybersecurity, infrastructure, service delivery, and CMMC readiness support.

  • Defense Contractor

    ~25 office staff

    Managed technology, cybersecurity, infrastructure, and CMMC-related support.

  • Regulated National Workforce

    Peak ~250 remote users

    Managed technology, cybersecurity, inventory logistics, endpoint deployment, hosted environments, and regulated operations.

  • Construction / Critical Operations

    ~100 office users

    Cybersecurity modernization, managed technology, security exercises, and independent third-party security assessment.

Why Rook

  • Integrated AccountabilityManaged technology, cybersecurity, architecture, and compliance coordination under one relationship.
  • Right-Sized CMMCBoundary decisions begin with CUI and contractual obligations rather than an assumption that the entire enterprise belongs in GCC High.
  • Operating ExperienceRook does not stop at assessment preparation. It operates the technology environment in which the controls must function.
  • Integration ExperienceM&A, multi-entity, multi-site, private-equity, and incumbent-provider transitions are part of the firm's operating experience.
  • Executive AccessSenior technical and executive personnel remain directly involved in architecture, risk, escalation, and strategic decisions.

Corporate

  • 9 years in business
  • Nationwide delivery
  • 8 technical personnel and expanding
  • SAM.gov Registered
  • CAGE Code: In Progress
  • $1,000,000 Cyber Liability Insurance
  • $1,000,000 Professional / E&O Insurance
  • More than eight years supporting regulated and security-sensitive environments, including HIPAA, NIST SP 800-171, DFARS, and CMMC readiness

Partnerships & Governance

Microsoft · Fortinet · HPE / Aruba / Juniper · Check Point · Huntress · 1Password

Weekly during transition / CMMC readiness · Monthly operational review · Quarterly executive review · Annual continuity and security review