Security assessments, by an engineer who builds.
MercIT Labs is a one-person practice: security assessments and compliance engineering for NIST-framework environments, backed by two decades of building and operating the same kinds of systems being assessed.
Services
Security assessment
A structured assessment against NIST SP 800-53 Rev. 5, run on IDAC — the assessment platform the practice built for its own engagements. Scored controls, the evidence behind every score, and a report that's a view of the data rather than a document rebuilt by hand. Fixed scope, defined deliverable.
CMMC and STIG readiness
A gap review before the formal assessment: which controls are met, which aren't, and what to fix first, in priority order. CMMC Level 2 and DISA STIG workflows are being added to IDAC now — readiness engagements are how they're being built.
Remediation and hardening
The findings, fixed by the person who found them: virtualization, Windows and Linux server infrastructure, Active Directory, network configuration. An assessment that ends with working systems, not a PDF.
Built, not just described.
The practice builds its own tooling. IT Discovery & Assessment Checklist (IDAC) is the assessment platform used for its own engagements: control catalogs, evidence, and reporting in one system instead of six spreadsheets. SafeShare is self-hosted secure file sharing, open source and auditable by anyone who wants to read it.
IDAC isn't hypothetical: it's the system every engagement listed above runs on. Two of the three products on this site exist because the work needed them.
See what's built →Contact
Questions about the software, or about working together? Email goes straight to the engineer — no forms, no funnel.
Get in touch →Not ready for a conversation? Start with the credentials and experience →