
Continu-US · Continuous compliance evidence
Continu-US: Live, Objective-by-Objective Compliance Evidence on Your Schedule
Know where every control stands today, not the week before your assessment. Evidence refreshes on the schedule you set: daily by default, weekly, or more often where it matters.
Continu-US is the continuous compliance platform from Anthony Timbers LLC. It checks your environment, maps every result to the objectives you’re assessed on and keeps assessor-ready evidence on hand. It’s included in our CMMC managed security service, and it’s also available on its own under license, deployed in your own cloud environment.
320
NIST SP 800-171A objectives mapped
284
Objectives with automated or document evidence
Daily
Refresh by default, or on your schedule
Any
Framework, mapped during onboarding
Independence
Evidence for your assessment, not a substitute for it
Continu-US supports, but does not replace, an assessor’s determination, and it doesn’t guarantee an assessment result. It shows you where you stand and keeps evidence current, so you can fix gaps early.
We never assess an organization we manage, advise, or license Continu-US to, in line with CMMC conflict-of-interest requirements.
The problem
Most security programs are built and run blind
Controls get configured once and checked once a year. In between, the admin console says a policy is assigned while the device says otherwise, an access review slips, a policy passes its review date, and nobody knows until an assessor or an incident finds it.
Example finding: time synchronization on a workstation
| Check | Admin console | On the device | 800-171A objective |
|---|---|---|---|
| Time sync policy | Assigned | Applied | 3.3.7[b] |
| Time service | Configured by policy | Manual start, not running | 3.3.7[c] |
| Last sync with time source | No data | 9 days ago | 3.3.7[c] |
Status on EXAMPLE-WS-014: Not met. The admin console shows the policy as assigned; the device shows time sync isn’t running.
Continu-US closes that gap with evidence that’s only as old as the schedule you set.
How it works
Build it. Run it. Prove it.
Continu-US works across the whole compliance lifecycle, not just the weeks before an assessment.
01
Build
Stand up your environment against a live scoreboard. Every objective shows its status as you configure, document and connect, so progress is visible objective by objective.
02
Run
Keep it that way. Drift shows up as a finding on the next check, recurring reviews and exercises are scheduled and evidenced, and a Monday digest lists what’s due, overdue or newly failing.
03
Prove
Show it any day. Build an assessor-ready evidence package on demand: a page per objective, the source files, your current policies and a SHA-256 manifest.
How it decides
Objective by objective, with the reasoning on the record
Four results. The worst one wins.
Every one of the 320 NIST SP 800-171A objectives (59 Define, 59 Identified, 202 Implemented) shows Met, Needs review, Not met or Manual evidence. When several sources speak to one objective, the worst result wins.
Documents decide only what documents can
A policy or procedure only decides the objectives that require something to be defined or written down. A document can’t make a technical setting pass.
Exceptions stay on the record
Accepted alternatives and exceptions are recorded with a reason and who decided, right next to the automated result.
Honest about what can’t be automated
284 of the 320 objectives (89%) have an automated or document evidence source, and 162 of the 202 Implemented objectives have technical evidence. The rest, mostly physical and personnel controls, show as Manual evidence rather than a false pass.
Evidence sources
Where the evidence comes from
Every source runs on a cadence you can change.
Daily by default
Endpoints and servers
A signed agent checks hardening, encryption, accounts, audit policy, malware protection and patching on each system.
On your schedule
Cloud tenant
Access policies, MFA, device compliance, admin roles, logging and data protection in your cloud identity and productivity tenant.
On your schedule
Firewalls, routers and switches
Configurations checked against your baseline, with secrets redacted before anything is stored.
On your schedule
Ticketing system
Remediation, change and incident tickets with their deadlines, so missed due dates and unapproved changes show up.
On your schedule
SIEM
Cases and alerts, which also fill in the recurring alert review automatically.
On every upload and review
Document register
Every policy version hashed, with review dates and revision history.
On each activity’s schedule
Recurring activities
Access and log reviews, training and exercises, scheduled and evidenced.
With every refresh
Implementation statements
Stated vs. verified: what your implementation statements say, compared with what the evidence shows, with disagreements flagged.
What you get
Outputs you can act on and hand to an assessor
Live dashboard
Posture by objective and family, with a trend line so you can see whether things are getting better or worse.
Monday digest
A weekly summary of what’s due, what’s overdue and what’s newly failing.
Quarterly control assessment report
A technical report for the families assessed that quarter: each objective’s result and evidence, deficiencies, accepted exceptions and evidence freshness.
Evidence package on demand
A page per objective, the source files, your current policies and a SHA-256 manifest, whenever you need it.
Live dashboard
Posture, drift and open findings, with the trend over time.

Every objective, every family
Coverage across Define, Identified and Implemented objectives, family by family.

Stated vs. verified
Where your implementation statements and the evidence disagree, before an assessor finds it.

Recurring activities
Reviews and exercises tracked against their schedule, with evidence attached.

Quarterly reports
Pick the quarter and families; every download is recorded in the audit log with its hash.

Documents
Policies and procedures, kept current without the busywork
Bulk upload
Upload a whole folder; documents are matched to the register automatically.
Start from templates
New organizations start from templates with the company name, revision 001 and change history filled in.
Mark reviewed
Stamps the document itself with the next revision, the date and a Change History row, and keeps every prior version.
Bulk download
Download selected documents together with a hash manifest.
Document register
Every policy with its revision, owner, review status and the objectives it supports.

Flexibility
Any framework. Your baseline. Your tools.
Maps to any framework
All 320 NIST SP 800-171A objectives are mapped today. Other frameworks, such as NIST SP 800-53 and FedRAMP baselines, PCI DSS, SOC 2, ISO 27001, the NIST Cybersecurity Framework or your internal standards, are added as mappings during onboarding.
Bring your own baseline
Measure against STIGs, benchmarks or your own hardening standard, or start from ours, built from real CMMC assessment experience.
Bring your own tools
Continu-US works with categories of tools, not one vendor. If a source you use isn’t connected yet, it becomes a new connector.
Security
Built for environments that handle sensitive data
Stays in your boundary
Licensed deployments run in your own cloud environment, so evidence stays inside your boundary.
Your sign-in, your roles
Organization sign-in with role-based access.
Keys protected
No stored account keys. Keys are kept in a protected vault, and agent submissions are encrypted and signed.
Evidence you can trust
Evidence is hashed, and every action is written to a full audit log.
Backed up
Nightly immutable backups.
Maintained
Dependencies are pinned and vulnerability-scanned with every release.
Built by Certified CMMC Assessors (CCAs) and Lead CCAs at a CMMC Level 2 certified MSSP, authorized CMMC C3PAO, FedRAMP 3PAO and PCI QSA.
Who it’s for
From defense suppliers to federal programs
Defense suppliers
Organizations working toward or maintaining CMMC Level 2 and NIST SP 800-171: keep self-assessments, SPRS scores and annual affirmations backed by current evidence, and be ready if or when your contracts call for certification.
Military and federal programs
Programs working under RMF and NIST SP 800-53. The Department of War’s September 2025 Cybersecurity Risk Management Construct calls for continuous monitoring and near real-time visibility.
PCI and beyond
PCI DSS, SOC 2, ISO 27001 and any organization that wants live insight into its security program.
Onboarding
From scoping to live evidence
Onboarding takes about 4–6 weeks for a defense supplier and 3–6 months for a government deployment.
01
Scope
Agree the boundary, systems and frameworks in scope.
02
Map
Map objectives to your environment, your baseline and your implementation statements.
03
Connect
Connect endpoints, your cloud tenant, network devices, ticketing, SIEM and documents.
04
Test
Check results against what’s actually on your systems and tune them.
05
Pilot
Run alongside your team through a cycle of reviews and reports.
06
Operate
Go live with the dashboard, Monday digest, quarterly reports and on-demand evidence.
FAQ
Continu-US FAQ
Is CMMC certification still required?
Not as a default contract requirement right now. On July 13, 2026, the Department of War suspended CMMC Phase 2, the phase that would have made third-party (C3PAO) certification a default contract requirement, pending a reform review. Self-assessments, SPRS scores, annual affirmations and DFARS 252.204-7012 still apply, and C3PAOs are still conducting Level 2 certification assessments. Continu-US keeps your evidence current either way.
Does it replace my assessor?
No. Continu-US supports, but does not replace, an assessor’s determination, and it doesn’t guarantee an assessment result. It shows you where you stand and keeps evidence ready. We never assess an organization we manage, advise, or license Continu-US to, in line with CMMC conflict-of-interest requirements.
Where does our data live?
Licensed deployments run in your own cloud environment, so evidence stays inside your boundary, with your organization’s sign-in and role-based access. For managed security clients, Continu-US is delivered as part of our CMMC Level 2 certified managed service.
How often is evidence refreshed?
On the schedule you set. Endpoints check in daily by default, and you can move a source to weekly or check more often where it matters.
Which frameworks does it cover?
All 320 NIST SP 800-171A objectives are mapped today. Continu-US maps to any framework: NIST SP 800-53 and FedRAMP baselines, PCI DSS, SOC 2, ISO 27001, the NIST Cybersecurity Framework or your internal standards are added as mappings during onboarding.
We use different tools. Does it work?
Yes. Continu-US works with categories of tools: your cloud identity and productivity tenant, firewalls, routers and switches, your ticketing system and your SIEM. If a source you use isn’t connected yet, it becomes a new connector.
Is it only for managed security clients?
No. It’s included in our CMMC managed security service, and it’s also available on its own under license, deployed in your own cloud environment.
How long does onboarding take?
About 4–6 weeks for a defense supplier and 3–6 months for a government deployment, through Scope, Map, Connect, Test, Pilot and Operate.

Talk to us about Continu-US
Call us at +1 804-596-0596 or fill out the form. We’ll walk through your environment, your frameworks and whether Continu-US fits best inside our managed security service or licensed in your own environment.
How can we help?
Want to see Continu-US on your own environment? We’ll talk through your frameworks, your tools and whether it fits best inside our managed security service or licensed in your own environment.
Call us at +1 804-596-0596 or complete the form below and we'll help in any way we can.
One firm. Four authorizations.
MSSP
CMMC Level 2 Certified MSSP
24/7 security monitoring and incident response for small to mid-sized businesses and DoD contractors.
C3PAO
Authorized CMMC C3PAO
Official CMMC Level 2 certification assessments, authorized by the Cyber AB.
3PAO
FedRAMP 3PAO
FedRAMP Rev5 and 20x assessments as a FedRAMP Recognized independent assessor, accredited to ISO/IEC 17020.
QSA
PCI Qualified Security Assessors
PCI DSS assessments and consulting, listed as QSAs on the PCI SSC website.
Team credentials




ISO/IEC 17020 accredited
