Security assessments, by an engineer who builds.

MercIT Labs is a one-person practice: security assessments and compliance engineering for NIST-framework environments, backed by two decades of building and operating the same kinds of systems being assessed.

Services

Security assessment

A structured assessment against NIST SP 800-53 Rev. 5, run on IDAC — the assessment platform the practice built for its own engagements. Scored controls, the evidence behind every score, and a report that's a view of the data rather than a document rebuilt by hand. Fixed scope, defined deliverable.

CMMC and STIG readiness

A gap review before the formal assessment: which controls are met, which aren't, and what to fix first, in priority order. CMMC Level 2 and DISA STIG workflows are being added to IDAC now — readiness engagements are how they're being built.

Remediation and hardening

The findings, fixed by the person who found them: virtualization, Windows and Linux server infrastructure, Active Directory, network configuration. An assessment that ends with working systems, not a PDF.

Built, not just described.

The practice builds its own tooling. IT Discovery & Assessment Checklist (IDAC) is the assessment platform used for its own engagements: control catalogs, evidence, and reporting in one system instead of six spreadsheets. SafeShare is self-hosted secure file sharing, open source and auditable by anyone who wants to read it.

IDAC isn't hypothetical: it's the system every engagement listed above runs on. Two of the three products on this site exist because the work needed them.

See what's built →

Contact

Questions about the software, or about working together? Email goes straight to the engineer — no forms, no funnel.

Get in touch →

Not ready for a conversation? Start with the credentials and experience →