cloudwaypoint ← Back to the overview

How the position is reached

The road is prevetted. The engagement finds where you stand on it.

The logic is fixed before the engagement begins. Only the evidence changes.

Tap any pipeline stage below for the detail behind it. Who applies the logic is not the interesting question — the same inputs produce the same position either way.

The pipeline

Five stages. One band above is fixed; one band below is yours.

Prevetted — fixed before the engagement

10 core domains — governance, platform, operations, ITIL practices, DevSecOps, RMF evidence, control inheritance, app visibility, migration, FinOps  ·  15 capability families, A2 to H1
01 · Current state. Observed practice rather than stated intent. Captured as evidence positions, each traceable back to the artifact, record or conversation it came from.
02 · Applicable standards. Six public, selectable industry lenses are supplemented by one governed fallback lens for offline use. The broader research corpus contains 36 declared anchors; the public lens set currently resolves to 34 distinct standards and 57 pairings. A pharma client is read against 21 CFR Part 11 and GxP expectations; a state agency against FedRAMP, GovRAMP, CJIS and IRS Pub 1075. The DoD Cloud Computing SRG means nothing to either, so neither sees it.
03 · Capability families. Fifteen families, organized as ITIL practices — configuration and architecture management, monitoring, incident, problem, change enablement, service level, capacity, continuity, platform and release engineering, service initiation, knowledge, workforce, compliance demonstration, cloud financial management, and hybrid operating governance.
04 · Current posture. Current posture (0 to 4) and confidence are held apart and never collapsed into one number. Collapsing them would report a practice as absent when the truth is only that it was not instrumented. Missing evidence is a gap, not proof the practice is missing.
05 · Position on the road. Where the organization stands, and what has to happen next — preparation and execution in sequence, with decision gates and a named owner on each. Horizons are planning scaffolds, not promised dates.

Per client — the only thing that varies

Observed practice and records, each carrying its own confidence  ·  peer-set evidence burden (light · standard · formal)  ·  regulatory overlays

Evidence informs. Named individuals with authority decide. The same inputs follow the same declared method; differences in evidence or judgment remain visible, and the position can be re-derived a year later.

Current posture

Named for how you operate, not for what you sent the assessor.

The point is not a grade. The upper rungs are leverageable strengths — practices already working that the next phase can lean on instead of rebuilding, and they are usually the cheapest thing in the plan.

The posture ladder, Reactive through Automated Five ascending rungs labeled Reactive, Inconsistent, Defined, Consistent and Automated, numbered zero to four. Level three is marked ITIL-shaped. A panel to the right explains the separate confidence dimension. Reactive — the practice happens when something forces it to. No defined trigger, no owner, no record. 0 Reactive Inconsistent — the practice exists somewhere and not elsewhere. The honesty rule applies here: earnest intent with nothing recorded anywhere is not level 1, it is level 0 wearing optimism. A practice genuinely in the future appears in a backlog, a roadmap or a project record. 1 Inconsistent Defined — the practice is written down and owned, but not yet reliably followed everywhere it applies. 2 Defined Consistent — the practice done properly, and ITIL-shaped by design. Across the model, level 3 is what ITIL describes. This is the rung most organizations are actually aiming at, whether or not they say so. 3 Consistent ITIL-shaped Automated — the practice is enforced by the platform rather than by discipline, and evidence of it is produced as a by-product rather than assembled for an audit. 4 Automated The second dimension Confidence is held separately and published beside every posture. Missing evidence is a gap, not proof the practice is absent. Level 1 honesty rule: earnest intent with nothing recorded anywhere is level 0 wearing optimism. The posture carries the skepticism so nobody has to voice it.

What the evidence is read against

Fifty-one artifacts, and the weight sits where the practice was built.

Basis of every artifact Cloud Waypoint assesses. Counted, not asserted.

Basis distribution across the 51 assessed artifacts DoD 6R disposition accounts for 15 artifacts, NIST 10, FinOps and investment governance 6, DoD Zero Trust and cATO pillars 5, Cloud Waypoint governance 5, ITIL 4 service management 5, workforce and adoption 2, and DISA FedRAMP acquisition, SRE, and migration wave methodology one each. DoD 6R disposition — 15 of 51. Rehost, replatform, refactor, repurchase, retain and retire, as the department states them. This is the disposition spine the assessment walks an application portfolio through. DoD 6R disposition 15 NIST — 10 of 51, split between RMF and cATO evidence and integration architecture. The federal risk spine, and the part of the basis that travels furthest outside government. NIST RMF, cATO, architecture 10 FinOps and investment governance — 6 of 51. Cost visibility, chargeback, showback and the funding conversation that decides whether a modernization sequence is affordable. FinOps / investment governance 6 DoD Zero Trust and cATO pillars — 5 of 51. The Zero Trust reference architecture, active defense, DevSecOps, supply chain and infrastructure-as-code pillars. DoD Zero Trust / cATO pillars 5 Cloud Waypoint governance 5 ITIL 4 service management 5 Workforce / adoption readiness 2 DISA / FedRAMP acquisition 1 SRE · migration wave method 1 each
Twenty-one of fifty-one are DoD-derived; thirty-one counting NIST. The practice was built where the authorization burden is heaviest, and the basis still shows it. Nothing on this chart is an estimate — it is a count of the artifact set the engagement actually walks.

Where the logic stops

Three things this method declines to claim.

Three stated limits of the method Workforce is read as a dimension rather than a domain; migration rollback readiness has no capability family behind it; and vulnerability management is a named limb with nothing behind it. Target-state workforce and skills has no domain of its own, because People is carried as one of three dimensions read on every artifact. Mapping it to a domain would flatten a dimension into a topic and double-count it. Workforce is a dimension Not a domain — read on every artifact instead of once. Migration execution and rollback readiness has no capability family behind it. The tempting wrong answer is the change-enablement test-and-back-out artifact, which is change remediation rather than migration rollback. Taking it would let the method claim calibration support for a domain nothing calibrated. Migration rollback A domain with no family behind it. Borrowing one was refused. Vulnerability management is a named limb of the operations domain with nothing calibrated behind it. It is recorded as an open gap rather than quietly filled, and it is the most likely place a future anchor lands. Vulnerability management A named limb with nothing behind it. Recorded, not hidden. Recorded in the model rather than left for a client to discover.

Why this page exists. “We have done the prework and we know the road” is a claim, and a claim of that shape is worth very little unstated. This is the stated form: the fixed part, the variable part, the posture ladder, and the places the logic declines to answer.

Representative of the governed logic, not an engagement output. Domain, family and distribution counts are the model's own; illustrative figures elsewhere on this site are illustrative. Evidence informs; named individuals with authority decide.