We're a cybersecurity compliance firm serving federal, DoD, contractor, and commercial organizations. We deliver precision, speed, security by starting with a high-resolution understanding of an organization: its mission-critical workflows, where the operational challenges live. We turn that understanding into reliable, repeatable processes, plus aligned tool configurations that strengthen operations. Independent assessments become a confirmation of your cybersecurity maturity, not a scramble — a sound foundation opens the path to automation that earns its place.
We deliver advisory, assessment, audit-readiness work grounded in the NIST Risk Management Framework. We're building toward authorized CMMC services for the Defense Industrial Base, plus scalable training to help close the national shortage of qualified CMMC professionals.
“We stand on the shoulders of giants.
We honor their work by carrying it forward.”
A generation of information-assurance pioneers is retiring, and the understanding of why these processes exist is becoming scarce. We carry forward the discipline behind the foundational certification-and-accreditation lineage, so that as a new generation steps in, the reasoning isn't lost. In an era where AI can produce the documentation instantly, knowing why it exists is what separates an artifact from assurance. We evaluate the cross-functional process that produces a result, not just the field in a GRC tool.
Senior-led engagements available now, grounded in years of hands-on operations experience.
Implementation and assessment against the NIST control families, applied with audit-grade rigor.
Security categorization (FIPS 199 / SP 800-60), control assessment, continuous ATO enablement, FedRAMP advisory.
System Security Plans, Plans of Action & Milestones, policies and procedures built to withstand independent scrutiny.
Security control assessment with analyst support under NIST SP 800-53A, delivered directly or as a subcontractor to assessment teams or primes.
Fractional virtual-CISO retainers plus governance, risk & compliance advisory, suited to small- to mid-size federal or commercial clients.
Levels 1–2 readiness, plus assessment preparation, offered once our ISACA / Cyber AB credentials are in place. Get in touch to be notified when these services launch.
A deliberate credential ladder building toward authorized CMMC certification instruction: CCP and CCA training courses delivered as, or under, an ISACA Approved Training Provider.
Instructor-led training on the NIST Risk Management Framework, FISMA, GRC, Information Assurance within the federal context, alongside workshops, executive briefings, CUI-handling courses. Offered on expertise alone, outside the CMMC ecosystem.
Expanded assessment support, plus RMF training, as the Certified Assessor credential comes online, with an ATP / C3PAO relationship in place.
Official, instructor-led CMMC certification training delivered as, or under, an ISACA Approved Training Provider, taught by a CMMC Certified Instructor.
We're invested in our community. Plumbline Works promotes cybersecurity awareness across our community, local government, the state, working to turn national compliance standards into local opportunity — helping West Virginians reskill into meaningful IT and cybersecurity careers close to home.
Promoting practical cybersecurity awareness across our community, local government, the state, from everyday cyber hygiene to the federal standards that shape the field.
Helping West Virginians affected by layoffs transition into cybersecurity and IT, mapping the skills they already have to in-demand compliance and security roles.
Engaging local community colleges and their students to connect coursework with real pathways into the cybersecurity and compliance workforce.
Working to bring IT and cybersecurity job opportunities to Morgan County, so local talent can build a career without having to leave the state.
Noah leads Plumbline Works after delivery leadership at IBM Consulting, where he supported federal cybersecurity across 50+ systems in AWS GovCloud, Azure Government, IBM Cloud, including audit readiness for FedRAMP High, DISA IL4/5, HIPAA, NIST RMF — most recently leading federal cyber threat management.
Earlier work spans GRC, audit support for federal financial systems under FISCAM / FFMIA, independent NIST SP 800-53 assessment, plus system authorization with control testing under DIACAP, FISMA, early RMF: the full arc of modern federal assurance practice.