Skip to content
Third Rock Consulting Aerospace · Defence · Space

The Third Rock Group

Cyber compliance as a service for defence supply chains in Canada and allied markets.

Standards
CP-CSC, CMMC, NIST 800-171
Also covers
Controlled Goods, ITAR
Optional
Compliance platform
First step
30-minute call

Compliance is becoming a condition of the contract.

Nobody stops you bidding. The requirement lands after you’ve won, on a clock you didn’t set. Most suppliers have the capability but no compliance function, and that gap costs contracts.

Not a report. A route.

We take you from “what applies to us?” to evidence you can stand behind, and keep you there as the standards move. Work done now is built to count at the next level.

Optional: everything in one place.

Add the Third Rock Cyber compliance platform and your controls, evidence and reporting live in one system. It’s ready when an assessor or a prime asks. Take it on when you’re ready; the service stands on its own without it.

Led by our principal: Controlled Goods and Designated Organization Screening clearances achieved for a supplier entering Canadian defence work.

Part of the Third Rock group. When a cyber requirement is really a market-access problem, Third Rock Consulting works alongside. You get one conversation, not a hand-off.

Evidence

Where this has already held up.

Cyber Compliance Strategy & Readiness

Tier 2 supplier on a U.S. defence contract

103 "yes" answers. 56 survived the evidence.

All 110 CMMC Level 2 requirements validated in four weeks, 20 more than the scope asked for.

The problem
The supplier filed a self-assessment every six months and the contract obligation was live, yet nobody had ever asked the answers to prove themselves.
The approach
We tested every requirement against evidence, not a questionnaire. That surfaced controls the supplier had already paid for but never claimed. It also found a boundary fix that swapped a construction project for a door and a fob. Leadership left with three decisions, and two of them cost nothing.

Cyber Compliance Strategy & Readiness

Aerospace machining supplier to U.S. and Canadian defence programs

From breach to certification-ready, with one partner end to end.

The problem
Phishing incidents kept coming back after IT cleaned up, while the certification clock kept running. It was two problems on one network.
The approach
We investigated the breach independently. Then we tested the people, the systems and the building, and walked in uninvited to prove the point. From there we drew the controlled-information boundary, ran a mock audit and a second pre-assessment, and turned an incident into a compliance programme. Delivered with a specialist partner.

Cyber Compliance Strategy & Readiness

Supplier seeking work with the Canadian Armed Forces

Controlled Goods and DOS clearances achieved.

Opened negotiation of new defence business streams

The problem
Real capability, but no mapped route to the security clearances the work required, and no view of which clearances served the near term versus the long term.
The approach
Built a clearance roadmap with the C-suite against short-, mid- and long-term goals, then held single point of contact across Legal, Compliance and Operations to carry both the Controlled Goods and Designated Organization Screening applications through.

Start the conversation

Thirty minutes. If you do not have a problem, we will tell you.

Back to the Third Rock group