CMMC L2 Certified MSSP · CMMC C3PAO · FedRAMP 3PAO · PCI QSA

SALES: +1 804-596-0596 | CALL US: +1 804-596-0596

Continu-US · Continuous compliance evidence

Continu-US: Live, Objective-by-Objective Compliance Evidence on Your Schedule

Know where every control stands today, not the week before your assessment. Evidence refreshes on the schedule you set: daily by default, weekly, or more often where it matters.

Continu-US is the continuous compliance platform from Anthony Timbers LLC. It checks your environment, maps every result to the objectives you’re assessed on and keeps assessor-ready evidence on hand. It’s included in our CMMC managed security service, and it’s also available on its own under license, deployed in your own cloud environment.

320

NIST SP 800-171A objectives mapped

284

Objectives with automated or document evidence

Daily

Refresh by default, or on your schedule

Any

Framework, mapped during onboarding

Independence

Evidence for your assessment, not a substitute for it

Continu-US supports, but does not replace, an assessor’s determination, and it doesn’t guarantee an assessment result. It shows you where you stand and keeps evidence current, so you can fix gaps early.

We never assess an organization we manage, advise, or license Continu-US to, in line with CMMC conflict-of-interest requirements.

The problem

Most security programs are built and run blind

Controls get configured once and checked once a year. In between, the admin console says a policy is assigned while the device says otherwise, an access review slips, a policy passes its review date, and nobody knows until an assessor or an incident finds it.

example fictional data · not client data

Example finding: time synchronization on a workstation

CheckAdmin consoleOn the device800-171A objective
Time sync policyAssignedApplied3.3.7[b]
Time serviceConfigured by policyManual start, not running3.3.7[c]
Last sync with time sourceNo data9 days ago3.3.7[c]

Status on EXAMPLE-WS-014: Not met. The admin console shows the policy as assigned; the device shows time sync isn’t running.

Continu-US closes that gap with evidence that’s only as old as the schedule you set.

How it works

Build it. Run it. Prove it.

Continu-US works across the whole compliance lifecycle, not just the weeks before an assessment.

01

Build

Stand up your environment against a live scoreboard. Every objective shows its status as you configure, document and connect, so progress is visible objective by objective.

02

Run

Keep it that way. Drift shows up as a finding on the next check, recurring reviews and exercises are scheduled and evidenced, and a Monday digest lists what’s due, overdue or newly failing.

03

Prove

Show it any day. Build an assessor-ready evidence package on demand: a page per objective, the source files, your current policies and a SHA-256 manifest.

How it decides

Objective by objective, with the reasoning on the record

Four results. The worst one wins.

Every one of the 320 NIST SP 800-171A objectives (59 Define, 59 Identified, 202 Implemented) shows Met, Needs review, Not met or Manual evidence. When several sources speak to one objective, the worst result wins.

Documents decide only what documents can

A policy or procedure only decides the objectives that require something to be defined or written down. A document can’t make a technical setting pass.

Exceptions stay on the record

Accepted alternatives and exceptions are recorded with a reason and who decided, right next to the automated result.

Honest about what can’t be automated

284 of the 320 objectives (89%) have an automated or document evidence source, and 162 of the 202 Implemented objectives have technical evidence. The rest, mostly physical and personnel controls, show as Manual evidence rather than a false pass.

Evidence sources

Where the evidence comes from

Every source runs on a cadence you can change.

Daily by default

Endpoints and servers

A signed agent checks hardening, encryption, accounts, audit policy, malware protection and patching on each system.

On your schedule

Cloud tenant

Access policies, MFA, device compliance, admin roles, logging and data protection in your cloud identity and productivity tenant.

On your schedule

Firewalls, routers and switches

Configurations checked against your baseline, with secrets redacted before anything is stored.

On your schedule

Ticketing system

Remediation, change and incident tickets with their deadlines, so missed due dates and unapproved changes show up.

On your schedule

SIEM

Cases and alerts, which also fill in the recurring alert review automatically.

On every upload and review

Document register

Every policy version hashed, with review dates and revision history.

On each activity’s schedule

Recurring activities

Access and log reviews, training and exercises, scheduled and evidenced.

With every refresh

Implementation statements

Stated vs. verified: what your implementation statements say, compared with what the evidence shows, with disagreements flagged.

What you get

Outputs you can act on and hand to an assessor

Live dashboard

Posture by objective and family, with a trend line so you can see whether things are getting better or worse.

Monday digest

A weekly summary of what’s due, what’s overdue and what’s newly failing.

Quarterly control assessment report

A technical report for the families assessed that quarter: each objective’s result and evidence, deficiencies, accepted exceptions and evidence freshness.

Evidence package on demand

A page per objective, the source files, your current policies and a SHA-256 manifest, whenever you need it.

Live dashboard

Posture, drift and open findings, with the trend over time.

Continu-US overview showing compliance posture, objectives with evidence, devices, open findings and a 57-day compliance trend line for a fictional organization
Demo mode, fictional organization. Four objectives are marked not applicable for this organization.

Every objective, every family

Coverage across Define, Identified and Implemented objectives, family by family.

Continu-US objective coverage summary by type and by family, from Access Control to System and Information Integrity, for a fictional organization
Demo mode, fictional organization. Four objectives are marked not applicable for this organization.

Stated vs. verified

Where your implementation statements and the evidence disagree, before an assessor finds it.

Continu-US stated vs. verified view flagging a contradiction between an implementation statement and the verified evidence, for a fictional organization
Demo mode, fictional organization.

Recurring activities

Reviews and exercises tracked against their schedule, with evidence attached.

Continu-US recurring activities list showing overdue reviews with start and target dates, for a fictional organization
Demo mode, fictional organization.

Quarterly reports

Pick the quarter and families; every download is recorded in the audit log with its hash.

Continu-US report builder for a quarterly control assessment, choosing year, quarter and control families
Demo mode, fictional organization.

Documents

Policies and procedures, kept current without the busywork

Bulk upload

Upload a whole folder; documents are matched to the register automatically.

Start from templates

New organizations start from templates with the company name, revision 001 and change history filled in.

Mark reviewed

Stamps the document itself with the next revision, the date and a Change History row, and keeps every prior version.

Bulk download

Download selected documents together with a hash manifest.

Document register

Every policy with its revision, owner, review status and the objectives it supports.

Continu-US document register listing policies with revision, owner, last reviewed date and review status, for a fictional organization
Demo mode, fictional organization.

Flexibility

Any framework. Your baseline. Your tools.

Maps to any framework

All 320 NIST SP 800-171A objectives are mapped today. Other frameworks, such as NIST SP 800-53 and FedRAMP baselines, PCI DSS, SOC 2, ISO 27001, the NIST Cybersecurity Framework or your internal standards, are added as mappings during onboarding.

Bring your own baseline

Measure against STIGs, benchmarks or your own hardening standard, or start from ours, built from real CMMC assessment experience.

Bring your own tools

Continu-US works with categories of tools, not one vendor. If a source you use isn’t connected yet, it becomes a new connector.

Security

Built for environments that handle sensitive data

Stays in your boundary

Licensed deployments run in your own cloud environment, so evidence stays inside your boundary.

Your sign-in, your roles

Organization sign-in with role-based access.

Keys protected

No stored account keys. Keys are kept in a protected vault, and agent submissions are encrypted and signed.

Evidence you can trust

Evidence is hashed, and every action is written to a full audit log.

Backed up

Nightly immutable backups.

Maintained

Dependencies are pinned and vulnerability-scanned with every release.

Built by Certified CMMC Assessors (CCAs) and Lead CCAs at a CMMC Level 2 certified MSSP, authorized CMMC C3PAO, FedRAMP 3PAO and PCI QSA.

Who it’s for

From defense suppliers to federal programs

Defense suppliers

Organizations working toward or maintaining CMMC Level 2 and NIST SP 800-171: keep self-assessments, SPRS scores and annual affirmations backed by current evidence, and be ready if or when your contracts call for certification.

Military and federal programs

Programs working under RMF and NIST SP 800-53. The Department of War’s September 2025 Cybersecurity Risk Management Construct calls for continuous monitoring and near real-time visibility.

PCI and beyond

PCI DSS, SOC 2, ISO 27001 and any organization that wants live insight into its security program.

Onboarding

From scoping to live evidence

Onboarding takes about 4–6 weeks for a defense supplier and 3–6 months for a government deployment.

01

Scope

Agree the boundary, systems and frameworks in scope.

02

Map

Map objectives to your environment, your baseline and your implementation statements.

03

Connect

Connect endpoints, your cloud tenant, network devices, ticketing, SIEM and documents.

04

Test

Check results against what’s actually on your systems and tune them.

05

Pilot

Run alongside your team through a cycle of reviews and reports.

06

Operate

Go live with the dashboard, Monday digest, quarterly reports and on-demand evidence.

FAQ

Continu-US FAQ

Is CMMC certification still required?

Not as a default contract requirement right now. On July 13, 2026, the Department of War suspended CMMC Phase 2, the phase that would have made third-party (C3PAO) certification a default contract requirement, pending a reform review. Self-assessments, SPRS scores, annual affirmations and DFARS 252.204-7012 still apply, and C3PAOs are still conducting Level 2 certification assessments. Continu-US keeps your evidence current either way.

Does it replace my assessor?

No. Continu-US supports, but does not replace, an assessor’s determination, and it doesn’t guarantee an assessment result. It shows you where you stand and keeps evidence ready. We never assess an organization we manage, advise, or license Continu-US to, in line with CMMC conflict-of-interest requirements.

Where does our data live?

Licensed deployments run in your own cloud environment, so evidence stays inside your boundary, with your organization’s sign-in and role-based access. For managed security clients, Continu-US is delivered as part of our CMMC Level 2 certified managed service.

How often is evidence refreshed?

On the schedule you set. Endpoints check in daily by default, and you can move a source to weekly or check more often where it matters.

Which frameworks does it cover?

All 320 NIST SP 800-171A objectives are mapped today. Continu-US maps to any framework: NIST SP 800-53 and FedRAMP baselines, PCI DSS, SOC 2, ISO 27001, the NIST Cybersecurity Framework or your internal standards are added as mappings during onboarding.

We use different tools. Does it work?

Yes. Continu-US works with categories of tools: your cloud identity and productivity tenant, firewalls, routers and switches, your ticketing system and your SIEM. If a source you use isn’t connected yet, it becomes a new connector.

Is it only for managed security clients?

No. It’s included in our CMMC managed security service, and it’s also available on its own under license, deployed in your own cloud environment.

How long does onboarding take?

About 4–6 weeks for a defense supplier and 3–6 months for a government deployment, through Scope, Map, Connect, Test, Pilot and Operate.

Talk to us about Continu-US

Call us at +1 804-596-0596 or fill out the form. We’ll walk through your environment, your frameworks and whether Continu-US fits best inside our managed security service or licensed in your own environment.

secure-intake 15-minute call

How can we help?

Want to see Continu-US on your own environment? We’ll talk through your frameworks, your tools and whether it fits best inside our managed security service or licensed in your own environment.

Call us at +1 804-596-0596 or complete the form below and we'll help in any way we can.

One firm. Four authorizations.

MSSP

CMMC Level 2 Certified MSSP

24/7 security monitoring and incident response for small to mid-sized businesses and DoD contractors.

C3PAO

Authorized CMMC C3PAO

Official CMMC Level 2 certification assessments, authorized by the Cyber AB.

3PAO

FedRAMP 3PAO

FedRAMP Rev5 and 20x assessments as a FedRAMP Recognized independent assessor, accredited to ISO/IEC 17020.

QSA

PCI Qualified Security Assessors

PCI DSS assessments and consulting, listed as QSAs on the PCI SSC website.

Team credentials

Cyber AB Authorized C3PAO
Certified CMMC Assessor (CCA)
Certified CMMC Professional (CCP)
Lead Certified CMMC Assessor (LCCA)

ISO/IEC 17020 accredited