FAQ
Questions people actually ask.
Including the awkward ones. If yours is not here, ask it directly and we will answer it the same way.
Working with us
- How big is APT Security Management?
- Two people. We say so on the about page rather than implying a bench that does not exist. For this kind of work small and senior beats large and junior, and you deal directly with the practitioner who does the testing.
- Who actually does the work?
- The practitioner you speak to. There is no handoff from a salesperson to a delivery team, because there is no salesperson.
- Do you work outside the Carolinas?
- Yes. We are remote-first and headquartered in South Carolina, with staff across the Carolinas, and we work with clients across the United States. Testing is remote by nature.
- Will you tell us if we do not need what we are asking for?
- Yes, and it happens regularly. A company with no asset inventory and no patching process does not need a penetration test first, it needs those. We would rather lose an engagement than sell a document you cannot act on.
The agentic platforms
- Does an AI write my penetration test report?
- No. Agents gather evidence and draft findings. A practitioner reproduces each issue, confirms it is exploitable in your environment rather than in theory, and judges the real impact before anything enters a report.
- Can we buy your platform?
- No. It is internal tooling we use to deliver services, not a product. You are buying an engagement, and the platform is how we deliver it.
- Does the platform make testing faster?
- No, and that is deliberate. It makes a test more thorough and more consistent in the same amount of time. Speed would mean less coverage, which is the opposite of the point.
CMMC and compliance
- Is CMMC cancelled?
- No. On 13 July 2026 the Department of War suspended CMMC Phase 2 and froze later phases pending a reform review. The program rule and the DFARS clauses remain in force. Level 2 third-party assessment paused; NIST SP 800-171 self-assessment, your SSP, your POA&M, SPRS scoring and the annual affirmation did not.
- Do we still need to do anything for CMMC right now?
- If your contract carries DFARS 252.204-7012 or 7021, yes. You still self-assess against NIST SP 800-171, maintain a System Security Plan and POA&M, post a score in SPRS, and affirm compliance annually. A contractor who stopped in July is out of compliance today.
- Are you a C3PAO? Can you certify us?
- No, and that separation is correct. We hold CMMC Registered Practitioner status and prepare organizations for assessment. The people who prepare you should not be the people who assess you.
- What is the difference between FCI and CUI?
- Federal Contract Information is information generated for or provided by the government under a contract and not intended for public release. Controlled Unclassified Information is a broader category that a law or policy requires you to safeguard. FCI points to Level 1, CUI points to Level 2.
Penetration testing
- How often should we run a penetration test?
- Annually is the common answer and it is usually driven by an audit cycle. The more useful trigger is change: a significant release, a new environment, an acquisition, or a shift in what data the application handles.
- Do you retest after we fix things?
- Yes, and it is included. A finding is not closed because a ticket says so. Retesting is what makes the report defensible to an auditor or a customer.
- Will a test satisfy our SOC 2 auditor?
- Generally yes, and the deciding factors are scope and evidence rather than the word penetration test. Tell us who is asking and what they said, and we will scope it so the report answers their question directly.
- Can we see a sample report before deciding?
- Yes. A redacted sample report is available, and it is the fastest way to judge whether our work is worth buying.
Question not answered here?
Ask it directly. You will get the same kind of answer, from the person who would do the work.
