Gesso Federal Book a call
Controlled Work

Your CUI stays within the systems your security team approves. We still do the work.

We handle controlled portions of federal responses, recurring reports, and past-performance records through the systems and access rules your security team approves. Your team does not have to take the paperwork back.

Start with the work that contains CUI. We will identify the exact questions and involve your security lead before we handle controlled data.

What we handle in Controlled Work

We deliver your approved response and reporting workflows inside the controlled boundary.

We still handle coordination, drafting, follow-up, checks, and the finished files.

01

Responses and proposals

We build the controlled response sections or, when your scope includes it, the complete package from the contract, solicitation, approved evidence, and your working rules.

02

Recurring contract reports

We collect approved updates, ask for missing facts and metrics, check the report, and deliver it for review.

03

Past-performance records

We preserve approved evidence while it is fresh so it is ready for the next RFI, RFQ, proposal, or recompete.

Controlled Work setup

Your security team approves the boundary before live work begins.

Controlled Work remains a done-for-you service. We document the scope, data flow, responsibilities, access, tests, and approved way of working.

01
Name the work and decision owners.

Tell us the first controlled workflow, governing contract or flowdown, data involved, and who owns the contract and security decisions. Do not send controlled files yet.

02
Agree on the scope and security responsibilities.

We prepare the scope, preliminary data flow, responsibility split, and intended processing route. Both sides sign the Controlled Work Schedule before we receive access.

03
Approve the test setup.

Your security owner approves invented-data testing in writing, and your team provisions named access to the blank approved environment.

04
We inspect, configure, and test it.

We inventory the actual environment, report any gaps, and configure your service. Using invented files, we prove the setup can read the sources, create and inspect every required file, keep the required records, and return finished work through the approved channel. Controlled work does not begin until every required file meets the agreed standard.

05
Your security owner approves live work.

After setup and testing pass, your security owner gives written approval. Then we begin handling controlled data through the systems and process your company approved.

Clear ownership

Your company governs the environment. We run the paperwork.

The signed responsibility matrix names every owner. Nothing depends on an informal assumption.

Your company governs

  • The contract's required CMMC status and flowdowns
  • The working environment, approved services, identities, access, and retention settings
  • Security and export-control approval
  • The incident plan, external contacts, and reporting duties assigned to your company

We perform

  • Service configuration inside the approved boundary
  • Drafting, contributor follow-up, checks, and file preparation
  • Work logs and records of approved changes
  • Immediate notice and any incident duties assigned to us in the signed responsibility matrix
Straight answers

What to tell your security team.

Your security owner approves Controlled Work for the named contract, data, people, systems, and workflow. That approval is specific to this scope and does not create a blanket Gesso certification.

Is Gesso Federal CMMC Level 2 certified?

We can handle CUI through Controlled Work for a named contract and approved scope. We do not claim a blanket CMMC Level 2 certification. We use client-issued access and only the systems and processing routes your security team approves. If the contract requires Gesso Federal to hold its own CMMC status, or the required processing route cannot pass approval, work does not begin.

Can you work with export-controlled technical data?

Only after your export-control owner confirms in writing the classification, U.S.-person and location restrictions, any required registration or authorization, and the approved systems and access path. Controlled Work does not itself authorize export-controlled work.

Can you handle classified information?

No. We do not handle classified information.

Will controlled data enter your ordinary systems?

No. Controlled Work uses the client-approved boundary and processing route. Standard Gesso email, storage, and commercial workspaces remain outside that boundary.

Tell us which work contains controlled information and what the contract requires.

We will identify the setup, processing route, approvals, and security owner needed. Do not send controlled files before the approved workflow is live.

Book a 20-minute fit call