Cybersecurity Compliance Consultancy · Morgan County, WV

Information Assurance From Constraint to Capability

We're a cybersecurity compliance firm serving federal, DoD, contractor, and commercial organizations. We deliver precision, speed, security by starting with a high-resolution understanding of an organization: its mission-critical workflows, where the operational challenges live. We turn that understanding into reliable, repeatable processes, plus aligned tool configurations that strengthen operations. Independent assessments become a confirmation of your cybersecurity maturity, not a scramble — a sound foundation opens the path to automation that earns its place.

Who We Are

A West Virginia cybersecurity compliance firm serving federal, DoD, and commercial clients.

We deliver advisory, assessment, audit-readiness work grounded in the NIST Risk Management Framework. We're building toward authorized CMMC services for the Defense Industrial Base, plus scalable training to help close the national shortage of qualified CMMC professionals.

18+Years of assurance experience
50+Federal systems supported
RMFAuthorization & assessment support
Our Philosophy
“We stand on the shoulders of giants.
We honor their work by carrying it forward.”

A generation of information-assurance pioneers is retiring, and the understanding of why these processes exist is becoming scarce. We carry forward the discipline behind the foundational certification-and-accreditation lineage, so that as a new generation steps in, the reasoning isn't lost. In an era where AI can produce the documentation instantly, knowing why it exists is what separates an artifact from assurance. We evaluate the cross-functional process that produces a result, not just the field in a GRC tool.

TCSECDITSCAPDIACAPFISMA / RMFCMMCFedRAMPAI RMF
Current Services

What We Do Today

Senior-led engagements available now, grounded in years of hands-on operations experience.

01

NIST 800-171 / 800-53 / 800-53A

Implementation and assessment against the NIST control families, applied with audit-grade rigor.

02

RMF & cATO Enablement

Security categorization (FIPS 199 / SP 800-60), control assessment, continuous ATO enablement, FedRAMP advisory.

03

SSPs, POA&Ms & Policy

System Security Plans, Plans of Action & Milestones, policies and procedures built to withstand independent scrutiny.

04

Independent Control Assessment

Security control assessment with analyst support under NIST SP 800-53A, delivered directly or as a subcontractor to assessment teams or primes.

05

vCISO & GRC Advisory

Fractional virtual-CISO retainers plus governance, risk & compliance advisory, suited to small- to mid-size federal or commercial clients.

06

CMMC Readiness & Assessment Prep Following Credentialing

Levels 1–2 readiness, plus assessment preparation, offered once our ISACA / Cyber AB credentials are in place. Get in touch to be notified when these services launch.

Differentiators

Why It's Different

Audit-grade Evidence
We apply AICPA attestation discipline to CMMC and NIST work: control design versus operating effectiveness, sufficiency of evidence, burden of proof. The standard is whether it holds up to an independent assessor, not whether a box is filled.
The Process Behind the Result
Grounded in legacy C&A lineage, we evaluate the cross-functional process that produces a result, with disciplined categorization rather than approximate impact levels. We work the reasoning, not just the artifact.
Automation that Earns its Place
Firmly pro-automation and cATO, but never zero-to-autonomous overnight. We target real bottlenecks, delivering near-term efficiency without hollowing out the rigor beneath it.
Operations-Grounded Delivery
Led by senior practitioners who've spent years inside security operations, remediating real threats and vulnerabilities alongside IT teams. We translate between operations, IT, compliance, aligning cross-functional priorities around improvements that reduce actual risk. High compliance scores come as a result.
Where We're Going

Training Roadmap

A deliberate credential ladder building toward authorized CMMC certification instruction: CCP and CCA training courses delivered as, or under, an ISACA Approved Training Provider.

Available Now

RMF, FISMA, GRC & IA TrainingLive

Instructor-led training on the NIST Risk Management Framework, FISMA, GRC, Information Assurance within the federal context, alongside workshops, executive briefings, CUI-handling courses. Offered on expertise alone, outside the CMMC ecosystem.

Phase 1: Planned

Assessment & Advanced Courses

Expanded assessment support, plus RMF training, as the Certified Assessor credential comes online, with an ATP / C3PAO relationship in place.

CCP earnedCCA earned
Phase 2: The Destination

Authorized CCP / CCA Certification Training

Official, instructor-led CMMC certification training delivered as, or under, an ISACA Approved Training Provider, taught by a CMMC Certified Instructor.

CCI earnedATP authorized
Community & Workforce

Building West Virginia's Cyber Workforce

We're invested in our community. Plumbline Works promotes cybersecurity awareness across our community, local government, the state, working to turn national compliance standards into local opportunity — helping West Virginians reskill into meaningful IT and cybersecurity careers close to home.

Awareness

Cybersecurity Awareness

Promoting practical cybersecurity awareness across our community, local government, the state, from everyday cyber hygiene to the federal standards that shape the field.

Reskilling

Workforce Reskilling

Helping West Virginians affected by layoffs transition into cybersecurity and IT, mapping the skills they already have to in-demand compliance and security roles.

Education

Community Colleges

Engaging local community colleges and their students to connect coursework with real pathways into the cybersecurity and compliance workforce.

Local Jobs

Opportunity at Home

Working to bring IT and cybersecurity job opportunities to Morgan County, so local talent can build a career without having to leave the state.

CommunityLocal GovernmentState of West VirginiaCommunity CollegesStudents & Job Seekers
N Founder & Managing Member

Noah Walley

Morgan County, West Virginia
CISM, ISACA IBM Generative & Agentic AI Architect CMMC CCP / CCA / CCI (in progress)
The Person Behind the Work

Eighteen years of Federal Cybersecurity and Information Assurance.

Noah leads Plumbline Works after delivery leadership at IBM Consulting, where he supported federal cybersecurity across 50+ systems in AWS GovCloud, Azure Government, IBM Cloud, including audit readiness for FedRAMP High, DISA IL4/5, HIPAA, NIST RMF — most recently leading federal cyber threat management.

Earlier work spans GRC, audit support for federal financial systems under FISCAM / FFMIA, independent NIST SP 800-53 assessment, plus system authorization with control testing under DIACAP, FISMA, early RMF: the full arc of modern federal assurance practice.

Get in Touch

Let's talk about your compliance goals.

Emailcontact@plumblineworks.com
Location

Morgan County, WV

NAICS

541512 · 541519 · 541611 · 541690