Authorized C3PAO · CMMC Level 2 Certification Assessments
Your CMMC Level 2 certification, assessed by a Lead Certified CMMC Assessor.
ManageIT Security is an authorized CMMC Third-Party Assessment Organization, conducting Level 2 certification assessments for defense contractors, cloud service providers, and the organizations that supply them. Every engagement is led personally by Rosalyn Foltz, CISSP and Lead Certified CMMC Assessor, with 40 Level 2 assessments led.
Level 2 certification assessments are for organizations that have implemented the NIST 800-171 requirements. If you are still working toward that, start with our readiness checklist.
Authorized CMMC Third-Party Assessment Organization
18
Years in cybersecurity compliance
40
CMMC Level 2 assessments led
CISSP
Certified Information Systems Security Professional
LCCA
Lead Certified CMMC Assessor
Who we work with
We assess. We do not consult.
A certification assessment is only worth what the assessor's independence is worth. As an authorized C3PAO, that independence is not a preference, it is the basis on which we are allowed to do this work.
So we removed the conflict entirely. ManageIT Security does not sell advisory or readiness services to anyone. We never prepare an organization and then grade our own work, and we never compete with the consultants and managed service providers who get you ready.
Keep your readiness partner. We will assess what they helped you build.
Services
What we do, and what we don't
CMMC Level 2 Certification Assessment
If your contract requires a CMMC Level 2 certification assessment, this is the engagement that gets you there. As an authorized C3PAO, we assess against the NIST 800-171 control set and issue the certification decision.
We do not provide advisory or readiness services. Not in CMMC, not in anything else. It is the whole reason our assessments mean something.
Learn more →Process
A five-week path to a certification decision.
- Week 0Intro call and scoping
- Week 1Kickoff meeting
- Weeks 2–3Evidence collection
- Week 4Assessment week
- Week 5Final certification decision, issued as an authorized C3PAO, with the documentation package that supports it.
About
Led by a Lead Certified CMMC Assessor
Rosalyn Foltz has spent 18 years in cybersecurity compliance — at the GAO, KPMG, the U.S. Department of State, and E*TRADE — and has led more than 40 CMMC Level 2 assessments.
She works with clients directly. Assessments are not delegated.
More about ManageIT Security →CMMC Level 2 Readiness Checklist
The evidence and scoping items we look for first. Sent as a single PDF.
Ready to talk about your assessment?
Book an intro call and we will walk through your environment, your timeline, and what certification will require.
Level 2 certification assessments are for organizations that have implemented the NIST 800-171 requirements. If you are still working toward that, start with our readiness checklist.
Book an Intro Call