Meet Our Sponsors: Who Solves What
Grouped by the problem they solve, not by logo size. Find where you are on the road to NIST 800-171 and CMMC, and start there.
How To Use This Page
Most companies in the defense industrial base do not have a CISO or anyone whose job is to decode CMMC. When a vendor says they sell a “GRC platform,” that means nothing to a 15-person machine shop with a Navy subcontract. So the sponsors below are grouped by the problem they solve, roughly in the order those problems appear. Find where you are, and start there.
If you are not sure which of these companies is a good fit for your situation, that is exactly who this page is for. Use it before the event to understand who will be in the room and what each one actually does, then arrive with a short list. Two days and twenty booths goes quickly, and the attendees who get the most out of it are the ones who show up already knowing which three or four conversations matter to their business. Everyone else spends the event collecting brochures.
CMMC does not require you to certify your whole company. It requires you to certify everywhere Controlled Unclassified Information (CUI) lives and travels. That boundary is your scope, and you get to draw it. There are two honest answers, and Sections 3 and 4 below are organised around them. A cloud enclave means standing up one small controlled environment, usually Microsoft GCC High, keeping every piece of CUI inside it, and leaving the rest of your business out of scope. That suits companies where a handful of people touch CUI. On-premise means CUI lives on equipment you own, because drawings have to reach a CNC machine or a spec has to come off a plotter, so those machines and networks are inside the boundary. That is the reality for a lot of manufacturers, and it costs more to build and to assess.
- Know your level first. Only Federal Contract Information (FCI)? You are Level 1 and you self-attest. Handling CUI? Almost certainly Level 2 with a third-party assessment coming. Half the products here are irrelevant to a Level 1 company.
- Ask what stays on your plate. Every provider covers some controls, shares some, and leaves the rest to you. The item for understanding this is the shared responsibility matrix.
- Know the difference between a firm that can prepare you and a firm that can certify you. Only a C3PAO issues your certificate, and a firm that says it is “CMMC Level 2 certified” usually means it passed an assessment as a customer. Section 8 lists the two sponsors that can actually assess you.
- Ask the best question on the floor: “For a company my size, what would you tell me not to buy yet?” The honest answers are the ones worth following up on.
Level 1 Is a Smaller Problem Than This Page Makes It Look
If your contracts reference FAR 52.204-21 and you handle Federal Contract Information but not CUI, you are Level 1. That means 15 practices, 17 assessment objectives, and a self-assessment you submit yourself. No C3PAO, no third-party audit, no enclave required. Most of the enclaves, security operations centers, and GRC platforms further down this page are built for Level 2 companies. What a Level 1 company actually needs is guidance, documentation, and someone to check the work.
Compliance Cavalry L1 Clinic
Event HostA guided cohort that takes you from gap to submitted affirmation, led by a CMMC Certified Assessor. Both tracks cover all 15 practices, include the Cavalry GRC Tool and documentation templates, and end with live SPRS entry alongside your CCA. Two paces: a 4-week accelerated track at $1,500 per company if your IT documentation is already organized, or an 8-week track at $2,500 built for first-timers. Price is per company, not per seat.
A Registered Provider Organization with decades of assessment experience, offering a guided self-assessment portal plus gap analysis and mock assessments. Useful precisely because a Level 1 self-attestation is still a federal representation, and having someone experienced check your answers before you sign is cheap insurance. Their VP of Assessments has run well over 100 assessments and is speaking at this event.
Start here if you are not yet certain whether you are Level 1 or Level 2, because that single question changes everything you should spend money on. Washington's official NIST Manufacturing Extension Partnership affiliate is a nonprofit rather than a vendor, so while engagements do carry a cost, the guidance comes without a platform or license attached to it.
Washington APEX Accelerator
Regional ResourceFree contracting counseling funded in part by the Department of Defense, with a Region 1 office covering Kitsap and North Mason. For Level 1 specifically they run periodic low-cost readiness workshops that walk you through the 15 practices and the SPRS self-assessment, and they point contractors to Project Spectrum, a free DoD-sponsored self-guided option. A sensible stop if the paid routes are out of reach this year.
Strike Graph
Solutions Sponsor, GRCA Seattle-based compliance platform that covers Level 1 as well as Levels 2 and 3, useful if you want software to organize your 15 practices, evidence, and self-assessment rather than running it from a spreadsheet. Because it also handles SOC 2 and ISO 27001, the same evidence can serve your commercial customers' requirements too, which is a real saving for companies that are only partly defense businesses.
Summit 7
Breakfast SponsorA dedicated Level 1 solution for contractors handling FCI, built on the Microsoft licensing most companies already own. If you expect to grow into CUI work later, starting Level 1 with a firm whose main business is Level 2 means the foundation is already pointed the right way.
Aprio
Solutions SponsorSupport for the required Level 1 self-assessment, evaluating your program against the 15 controls and producing a report for SPRS submission. Comes with the reassurance of a firm that also performs formal assessments at Level 2, so they know what defensible looks like.
RADICL
Solutions SponsorA Level 1 templates and toolkit offering with guided self-assessment and SPRS score calculation inside their Comply platform. A lighter entry point with the same firm whose 24/7 security service you may want when CUI arrives.
FutureFeed
Solutions Sponsor, GRCTheir core subscription tier covers Level 1 with a guided self-assessment, so the 15 practices, your evidence, and your SPRS result live in one organized place instead of a folder of screenshots. The same platform then carries you into Level 2 if CUI shows up in your contracts.
ControlMap (a ScalePad product)
Solutions Sponsor, GRCStructured Level 1 or Level 2 readiness with SPRS scoring, SSPs, and POA&Ms, usually delivered through your MSP. If your IT provider manages your compliance, this is likely the tool they would run your Level 1 in, so ask them.
Riveron
Lunch SponsorTheir CMMC practice covers Level 1 as well as Level 2, folded into the same program-building approach: scope it honestly, document it properly, and keep the evidence current so next year's affirmation is routine rather than a fire drill.
Start Here: Neutral Guidance and Low-Cost Help
Washington's official NIST Manufacturing Extension Partnership affiliate and a nonprofit, not a vendor. They help small and mid-sized manufacturers understand what NIST 800-171 actually requires and steer toward right-sized practices instead of over-built ones. Engagements are consulting and training rather than free advice, though pricing is well below commercial rates and federal grant funding sometimes offsets it further. The real value is that they have no platform, enclave, or license to sell you.
Washington APEX Accelerator
Regional ResourceFunded in part through a cooperative agreement with the Department of Defense to help Washington businesses win and keep government contracts. Their advisors work the contracting side of the problem, which is the part most vendors cannot help with: reading the clauses in your contract, working out what is genuinely being required of you, and finding the work in the first place. Counseling is free to registered clients. Conveniently for this crowd, their Region 1 office covering Kitsap and North Mason is hosted by the Kitsap Economic Development Alliance. They also run periodic low-cost CMMC Level 1 readiness workshops, and point contractors toward Project Spectrum, a free DoD-sponsored self-guided option.
U.S. Small Business Administration
Federal ResourceTwo things the SBA offers that matter here. First, free counseling through Small Business Development Centers and SCORE, useful for building the business case and budget around a compliance investment. Second, the federal contracting certifications that shape what work you can pursue at all, including 8(a), HUBZone, women-owned, and service-disabled veteran-owned status. SBA-backed lending is also a legitimate way to finance the compliance spend, which is worth knowing before you decide the cost is impossible.
Washington APEX Accelerator and the SBA are listed here as regional and federal resources for attendees. They are not CMMC-PNW sponsors and are not exhibiting at the event.
Find Your CUI and Set Your Scope
Teramis
Premier SponsorSoftware that finds where your CUI actually lives, including the CAD drawings and scanned documents that keyword searches miss. Two things make it unusually relevant to a manufacturer: it runs entirely inside your own environment rather than uploading your data somewhere, and it covers legacy on-premise file shares on separate, non-connected networks alongside Microsoft 365 and endpoints. Guessing your scope is expensive both ways. Too wide and you pay to protect the whole company; too narrow and you attest to a boundary that was never true. The company reports up to 99.95 percent accuracy.
Cloud Enclaves: A Walled-Off Home for CUI
Security Cavalry
Event Host, Team Cavalry Robert Panek (CISSP, CEH), Security Manager, is also speakingA pre-engineered Microsoft GCC or GCC High cloud enclave with white glove service included, providing all aspects needed to get your company to Level 2 compliance and keep it there. Cavalry Enclave is where CUI lives; Cavalry Scout is a locked-down virtual desktop browser that governs how people reach it, from a computer or an iPad. Their argument is worth absorbing: written policies do not stop data spillage, controlled access paths do. A tightly scoped enclave also tends to mean a C3PAO assessment that can be done remotely, faster and cheaper. Bremerton-based and service-disabled veteran-owned.
One of the most established firms working exclusively with the defense industrial base, and a top Microsoft partner. Their Managed CUI Enclave is a GCC High environment they build and operate for you, with scaling for new users, contracts, printers, engineering systems, and manufacturing connections, supported by U.S. persons only. Notably they will pull awkward customer-owned equipment into enclave scope rather than pretending it does not exist, including legacy shop-floor systems that need isolating and monitoring. If you are standardizing on Microsoft and want depth of bench, this is the name you will hear most.
PreVeil
Solutions SponsorA different shape of enclave. Rather than moving your company into a government cloud, PreVeil adds end-to-end encrypted email and file sharing on top of the systems you already have, with encrypted data stored in AWS GovCloud. It is FedRAMP Moderate Equivalent and FIPS validated, and is widely used as a lower-cost alternative to a full GCC High migration, with pre-filled SSP documentation and free subcontractor accounts. Worth understanding before you buy: files are decrypted on the user's own device, so your workstations remain inside the assessment boundary. PreVeil puts its coverage at 102 of the 110 Level 2 requirements.
ISI designs and deploys CUI enclaves in Microsoft 365 GCC High and Azure Government, and was among the first MSPs in the country to pass a CMMC Level 2 assessment. ISI provides an integrated managed service offering so your business can focus solely on what matters most: innovation and outcomes. Their Managed IT, Cybersecurity, and Compliance services ensure you meet your contractual cybersecurity and compliance obligations, backed by a 24/7, in-house SOC team that monitors your environment for known threats and actively hunts for emerging ones. If your business currently holds or is pursuing classified contracts, their team can also help you obtain your facility security clearance (FCL), manage personnel security clearances (PCLs), and pass DCSA Security Reviews.
As a Microsoft partner, Aethon designs and builds the environment that fits your operation, whether that is Microsoft 365 Commercial, GCC, or GCC High, and Azure Commercial or Azure Government. They will also deploy PreVeil where that is the better-scoped answer, which is a good sign in a market full of one-answer vendors. Alongside the build they run it: Aethon Guard combines day-to-day IT with 24/7 monitoring, and Aethon Guide produces SSP and evidence documentation written to the NIST 800-171A objectives your assessor actually grades against. The firm has completed the Level 2 journey itself.
Aprio builds enclaves too, delivered through their Securitybricks brand: a turnkey GCC High enclave designed and built inside your own Microsoft tenant, rather than an environment they host for you. Their own framing is a useful corrective to vendor hype, that a GCC High enclave is not a product you buy but a boundary you draw. Important scoping caveat: Aprio is also an authorized C3PAO, and conflict-of-interest rules mean the same firm cannot both build your environment and then certify it. Decide which role you want them in first.
On-Premise and Hybrid: When CUI Touches Equipment You Own
Help Desk Cavalry
Event Host, Team Cavalry Steve Treanor, Founder & CEO, hosts both days as Master of CeremoniesA Kitsap County MSP since 2013, running the everyday IT that sits underneath any compliance program: help desk, networks, servers, endpoints, patching, and backup, on the equipment you actually own. They support both hybrid and fully on-premise Level 2 approaches, so if your CUI cannot all move to a cloud enclave, this is a provider built for that reality. Before you can prove a control, something has to be running it, and plenty of small contractors discover their compliance project is really an IT maturity project wearing a costume. The firm reached CMMC Level 2 internally, which is a fair question to put to any provider you are considering.
Untethered Labs (GateKeeper)
Solutions SponsorThe most on-premise product at the event, and the answer to a problem enclaves cannot touch. CMMC wants multi-factor authentication, per-user traceability, and automatic session lock, but a production floor runs on shared workstations and MES terminals where typing a long password in gloves twenty times a shift is not going to happen, so people share one login and traceability dies. GateKeeper logs users in by proximity with a token, badge tap, or phone, and locks the machine when they walk away. The management hub can run on your own Windows server, accessible only on your internal network, and it works on non-domain machines.
Aethon Security
Solutions Sponsor, GRCAethon Guard monitors and maintains networks, servers, endpoints, cloud backups, and user accounts, meaning the infrastructure you own as well as the cloud. Their remediation work includes integrating new systems into your existing environment and onboarding devices to your network, so a hybrid boundary where some CUI systems stay physical is squarely inside their model, run alongside whatever enclave they build you.
Summit 7
Breakfast SponsorTheir enclave is built to absorb hybrid reality rather than deny it: on-premise systems, printers, engineering tools, and manufacturing connections are supported inside the boundary, and legacy shop-floor machines running the operating systems nobody admits to are isolated, access-restricted, and monitored rather than ignored. If your CUI genuinely has to move through a plant, ask them how the boundary is drawn around it.
RADICL
Solutions SponsorRADICL does not build or host environments; they defend the one you have, and that coverage explicitly includes physical infrastructure. Their monitoring reaches end-user devices, physical servers in data centers, and physical and wireless network equipment, with the security activity tied back to specific NIST 800-171 requirements. If your Level 2 boundary includes on-premise systems, this is how those systems get the 24/7 monitoring and response the rule expects.
Teramis
Premier SponsorCUI discovery that runs entirely inside your own environment, with no data leaving your systems, and covers legacy on-premise file shares even on separate, non-connected networks. If you suspect twenty years of drawings are scattered across old servers, this is how you find out what is actually there before you draw a boundary around it.
Riveron
Lunch SponsorScoping and environment architecture are the front end of Riveron's CMMC work, and that is exactly where the enclave, on-premise, or hybrid decision gets made. They do not sell an environment of their own, which is precisely why they are a useful voice on this question: their advice on which boundary to build is not attached to a product they need you to buy.
FutureFeed
Solutions Sponsor, GRCFutureFeed does not host or secure CUI; it is the compliance layer that makes an on-premise or hybrid boundary provable. The platform inventories the information types your company holds and where each is stored, maps your technology inventory to controls, and ties evidence to the individual assessment objectives. An on-premise environment without that documentation layer is nearly impossible to defend in front of an assessor.
Someone To Operate It: Managed IT and Security
RADICL
Solutions SponsorA 24/7 virtual security operations centre built for small defense contractors, combining AI-driven detection with human threat hunting, incident response, and log management. Read this part carefully, because it is the thing most attendees get wrong: RADICL is deliberately not an MSP. In their own words, your MSP or IT team handles infrastructure, help desk, and day-to-day operations, and they are not trying to change that. They sit alongside your IT provider rather than replacing them, and hand remediation work back to them. They also sell their own compliance tracking product, Comply, and are a Cyber AB Registered Provider Organization.
ISI provides an integrated managed service offering so your business can focus solely on what matters most: innovation and outcomes. Their Managed IT, Cybersecurity, and Compliance services ensure you meet your contractual cybersecurity and compliance obligations, backed by a 24/7, in-house SOC team that monitors your environment for known threats and actively hunts for emerging ones. If your business currently holds or is pursuing classified contracts, their team can also help you obtain your facility security clearance (FCL), manage personnel security clearances (PCLs), and pass DCSA Security Reviews.
Track It and Prove It: GRC Platforms
FutureFeed
Solutions Sponsor, GRC Tiffiney Groce, Director of Education and Compliance, is also speakingA platform built specifically for NIST 800-171 and CMMC rather than adapted from a generic compliance tool. It walks you through building a program step by step: live SPRS scoring, tracking at both the control and individual objective level, SSP and POA&M management, evidence collection, and accountability assigned to named people, ending in a report your C3PAO can read. It also inventories where your information is stored, which is how you document an on-premise boundary. The guided path matters most when nobody at your company has compliance in their job title.
An MSP-native GRC platform running more than 700 active CMMC projects. Its real value is explicit responsibility tracking between you and your provider, because the most common documentation failure is not a missing tool, it is both sides assuming the other owned a control. It usually arrives through your MSP rather than being something you shop for directly, so the most useful thing you can do at this booth is learn what to ask your own provider.
Strike Graph
Solutions Sponsor, GRCA Seattle-based platform covering CMMC Levels 1 through 3 and NIST 800-171 alongside SOC 2 and ISO 27001, with cross-framework mapping so evidence gathered once counts in several places. Worth a look if CMMC is not your only obligation, which is common for companies that are only partly defense businesses. They have an evidence API for legacy and on-premise systems that cannot be integrated directly, and a published multi-site manufacturing case study where plant leaders attach evidence specific to their own location. If CMMC is your only framework, a DIB-specific platform may be a tighter fit.
Advisors and Readiness: Getting You Prepared
Compliance Cavalry
Event Host, Team CavalryFlat-fee CMMC consulting plus its own GRC tool, which exists to answer the question every contractor asks first: is this a ten thousand dollar problem or a hundred thousand dollar problem? A Level 1 self-assessment engagement is $5,000, a Level 2 gap assessment across all 110 controls is $15,000, and the Cavalry GRC Tool underneath both is $150 a month. Deliberately not a C3PAO, which removes any incentive to find billable problems in an environment it would later have to certify. Confirm current pricing at the booth.
Riveron
Lunch SponsorRiveron builds assessable, sustainable federal compliance programs rather than one-time assessment prep. For the defense industrial base that means end-to-end CMMC: scoping, environment architecture, readiness, remediation, documentation, evidence operations, and assessment readiness. They also cover FedRAMP, FedRAMP 20x, GovRAMP, and NIST more broadly, so the program can scale as the business takes on new federal obligations instead of being rebuilt each time. The phrase to take away from their booth is "evidence operations", meaning the ongoing job of proving controls still work between assessments, which is the part almost everyone underestimates.
A Registered Provider Organization with decades of assessment experience behind it, offering full organizational scoping, gap analysis, mock assessments, and a guided self-assessment portal. They also run a portal that lets a prime contractor track subcontractor flow-down in one place. Particularly useful if you are Level 1 and want someone experienced to check your answers before you sign, since a self-attestation is still a federal representation. They are explicit that they are an RPO and not a C3PAO, and will point you to an assessor when you need one.
C3PAOs: The Firms That Can Actually Certify You
A cybersecurity risk-management firm in Huntsville, Alabama, designated a C3PAO by The Cyber AB, with team members who worked with DoD on the development of CMMC itself. They began formal assessments in early 2025 and now field a team of assessors. They are also an advisory organization, and they publish a clear separation between certification and non-certification activities, so pick the role you need them in. Worth knowing what they are not: they do not run a help desk or a security operations centre, so they are your assessor or your advisor, not your provider.
Aprio
Solutions Sponsor Authorized C3PAO Ashley Lex, Senior Client Success Manager, is also speakingA national advisory and CPA firm whose cybersecurity practice is both an authorized CMMC C3PAO and an accredited FedRAMP 3PAO, a combination only a handful of US firms hold. Attractive if you would rather an existing accounting and advisory relationship handle this than add a fifth vendor, or if FedRAMP is on your horizon alongside CMMC. Their readiness and enclave-build work runs through their Securitybricks brand, which is exactly where the conflict rule bites: if Securitybricks builds your boundary, Aprio should not be the firm certifying it.
For clarity, because the marketing language genuinely is confusing: Summit 7, ISI, Aethon Security, SecurityMetrics, RADICL, and Compliance Cavalry are advisory or provider organizations, not C3PAOs. Several have passed a Level 2 assessment themselves or hold RPO status, which is worth knowing, but none of them can issue your certificate.
Buy Smart
RAMPxchange
Premier SponsorAn online marketplace for buying cybersecurity and risk-management services: a vetted provider network, standardized scopes, competitive bidding, and contract execution. In April 2026 The Cyber AB announced RAMPxchange as its partner to build and operate the next-generation official CMMC Marketplace, the directory where contractors find authorized assessors and practitioners. Every vendor at this event claims CMMC expertise, and procurement is a genuinely underrated risk: contractors regularly overpay, buy the wrong scope, or hire a firm that turns out not to hold the authorization it implied. This is where you compare like with like and verify a credential rather than taking it on faith.
Paying For It
Liberty Bank
Mission SupporterAn independently owned community bank in Poulsbo serving Kitsap County and Puget Sound. Not a CMMC service, and they will tell you so. But compliance costs land before the revenue does, and a local banker who understands the regional defense economy is a legitimate part of solving that problem.
Why Any Of This Matters
Port Madison Construction Company
Dinner Sponsor Randy Blank, Federal Construction Program Manager, is also speakingA regional federal construction contractor working across Puget Sound naval installations. They are not selling you anything. They are here from the prime contractor's side, which makes them the best answer to the question everyone is quietly asking: is anyone actually going to require this of me? Ask what they require of subs.
