About

Assessment expertise informed by decades of federal cybersecurity oversight.

ManageIT Security is an Authorized CMMC Third-Party Assessment Organization (C3PAO) specializing in Level 2 certification assessments, founded and led by Rosalyn Foltz.

Rosalyn Foltz, CISSP and Lead Certified CMMC Assessor at ManageIT Security

Rosalyn Foltz
CISSP, Lead Certified CMMC Assessor

Rosalyn Foltz founded ManageIT Security to bring complete objectivity and clarity to the CMMC process, giving defense contractors an assessment partner focused solely on fair, rigorous evaluation. The firm is an authorized C3PAO, one of roughly a hundred organizations cleared to conduct CMMC Level 2 certification assessments.

Rosalyn Foltz has spent 18 years in cybersecurity compliance — first inside the federal government, then advising the organizations regulated by it. She has led more than 40 CMMC Level 2 assessments.

Her career spans audit work at the Government Accountability Office, advisory engagements at KPMG, security program work at the U.S. Department of State, and enterprise compliance at E*TRADE. That combination — regulator, auditor, and practitioner — shapes how every ManageIT Security assessment is run.

She works with clients directly and leads a team of highly skilled CMMC assessors.

Depth beyond CMMC

CMMC assessments are the entire practice today, but the judgment behind them was built across a wider field. Rosalyn has worked through NIST 800-53, FedRAMP and FISMA environments, in defense, healthcare, finance and federal agencies, and spent years inside E*TRADE Financial, the U.S. Department of State, KPMG and the Government Accountability Office.

Credentials

  • Authorized CMMC Third-Party Assessment Organization (C3PAO)Authorized CMMC Third-Party Assessment Organization (C3PAO)
  • Lead Certified CMMC Assessor (LCCA)
  • Certified Information Systems Security Professional (CISSP)
  • B.S. Management Information Systems, George Mason University
  • M.A. Global Affairs, IT Policy concentration, George Mason University

Background

  • GAO

    Federal audits of agency information security programs.

  • KPMG

    Advisory engagements across regulated industries.

  • U.S. Department of State

    Security program and control assessment work.

  • E*TRADE

    Enterprise security compliance in financial services.

We assess. We do not consult.

A certification assessment is only worth what the assessor's independence is worth. As an authorized C3PAO, that independence is not a preference, it is the basis on which we are allowed to do this work.

Ready to talk about your assessment?

Book an Intro Call