About
Assessment expertise informed by decades of federal cybersecurity oversight.
ManageIT Security is an Authorized CMMC Third-Party Assessment Organization (C3PAO) specializing in Level 2 certification assessments, founded and led by Rosalyn Foltz.

Rosalyn Foltz
CISSP, Lead Certified CMMC Assessor
Rosalyn Foltz founded ManageIT Security to bring complete objectivity and clarity to the CMMC process, giving defense contractors an assessment partner focused solely on fair, rigorous evaluation. The firm is an authorized C3PAO, one of roughly a hundred organizations cleared to conduct CMMC Level 2 certification assessments.
Rosalyn Foltz has spent 18 years in cybersecurity compliance — first inside the federal government, then advising the organizations regulated by it. She has led more than 40 CMMC Level 2 assessments.
Her career spans audit work at the Government Accountability Office, advisory engagements at KPMG, security program work at the U.S. Department of State, and enterprise compliance at E*TRADE. That combination — regulator, auditor, and practitioner — shapes how every ManageIT Security assessment is run.
She works with clients directly and leads a team of highly skilled CMMC assessors.
Depth beyond CMMC
CMMC assessments are the entire practice today, but the judgment behind them was built across a wider field. Rosalyn has worked through NIST 800-53, FedRAMP and FISMA environments, in defense, healthcare, finance and federal agencies, and spent years inside E*TRADE Financial, the U.S. Department of State, KPMG and the Government Accountability Office.
Credentials
Authorized CMMC Third-Party Assessment Organization (C3PAO)- Lead Certified CMMC Assessor (LCCA)
- Certified Information Systems Security Professional (CISSP)
- B.S. Management Information Systems, George Mason University
- M.A. Global Affairs, IT Policy concentration, George Mason University
Background
GAO
Federal audits of agency information security programs.
KPMG
Advisory engagements across regulated industries.
U.S. Department of State
Security program and control assessment work.
E*TRADE
Enterprise security compliance in financial services.
We assess. We do not consult.
A certification assessment is only worth what the assessor's independence is worth. As an authorized C3PAO, that independence is not a preference, it is the basis on which we are allowed to do this work.