Security and compliance
10 CMMC consultants
These ten CMMC consultants help organizations prepare for CMMC compliance, working at consulting firms or through their own practices. A reader can learn how CMMC specialists scope controlled unclassified information, work through NIST 800-171 control gaps and get a company ready for its assessment.
Professionals to explore
01—10Brendan Kenney
LinkedInExperience: Lead Consultant · Forvis Mazars US
Lead Consultant at Forvis Mazars US since 2025. Former Senior Cybersecurity Advisor (2024–2025) and Information Security Analyst (2019–2024) at DataSure24. The profile lists CMMC Certified Assessor and describes leading CMMC 2.0 Level 2 readiness engagements for Defense Industrial Base clients, including data flow mapping, assessment boundary definition and network design reviews.
Damien Lawless
LinkedInExperience: Managing Consultant · 112Cyber
Managing Consultant at 112Cyber since 2026. Former Manager (2024–2026), Supervisor (2022–2024) and Senior Associate, Security & Privacy Risk Consulting (2020–2022) at RSM US LLP. The profile describes specializing in CMMC and NIST SP 800-171 in the Defense Industrial Base as a Lead CMMC Certified Assessor (Lead CCA), focused on assessment, control interpretation and evidence evaluation.
Daniel Hooper
LinkedInExperience: Vice President of Cyber Compliance · Gensura Strategies
Vice President of Cyber Compliance at Gensura Strategies since 2025. The profile lists the firm as a CMMC RPO and says the role helps small and midsized DoD contractors prepare for CMMC Level 2 and NIST 800-171; it also lists CCA certification and TS clearance. The profile also lists Oracle E-Business Suite DBA work as an independent consultant since 2015.
Drew Griffin
LinkedInExperience: Founder & Principal Consultant · Cohort Shield | CMMC Compliance Solutions
Founder & Principal Consultant at Cohort Shield | CMMC Compliance Solutions since 2024, and Director IT at National Parcel Logistics Inc. since 2010. The profile describes helping defense contractors and supply chain partners with cybersecurity governance, risk and compliance for the Defense Industrial Base. Former Chief Executive Officer at Red Rover Computing Inc. (2003–2010).
Evan Fricker
LinkedInExperience: CMMC Senior Consultant · A-LIGN
CMMC Senior Consultant at A-LIGN since 2025. Former Certified CMMC Assessor at RPM Technologies, LLC (2024–2025), a role the profile describes as preparing DoD Defense Industrial Base contractors to meet NIST SP 800-171 requirements and become CMMC L2 certified, and contracting with C3PAOs to assess contractors against CMMC L2 standards.
James Paul
LinkedInExperience: CMMC, Cybersecurity Strategy and Compliance · Tevora
CMMC, Cybersecurity Strategy and Compliance at Tevora, a role listed from 2012. The profile describes CMMC and NIST 800-171 readiness work for the Defense Industrial Base within Tevora's cybersecurity and compliance consulting, helping IT and security leaders in the Defense Industrial Base get ready for CMMC. Former Identity and Access Management Specialist at Quest Software (2010–2012).
Kevin Hogg
LinkedInExperience: Cyber Security Advisor · Eccalon, LLC
Cyber Security Advisor at Eccalon, LLC since 2025. Former Senior Information Security Analyst at Security Compliance Associates (2021–2025) and CISO Manager at National Semiconductor (2004–2021). The profile describes a senior consultant and certified LCCA who advises clients on CMMC and NIST SP 800-171 compliance, carries out assessments, identifies gaps and works with organizations to implement requirements.
Martin Musters
LinkedInExperience: CMMC Compliance Consultant Independent Freelance · Freelance
CMMC Compliance Consultant Independent Freelance since 2021, and former Senior Consultant as an independent contractor (2022–2025). Former Director of Forensics at Computer Forensics Inc (2006–2021) and Corporate IT Security Officer at Bruce Power (1990–2006). The profile lists CISSP and CISA and describes supporting government, defense, critical infrastructure and regulated organizations on cybersecurity governance and compliance.
Michael Medina
LinkedInExperience: FedRAMP CMMC Lead Consultant · NCC Group
FedRAMP CMMC Lead Consultant at NCC Group since 2023. Former FedRAMP Consultant at Coalfire Federal (2021–2023) and Principal Information Systems Security Manager at L3Harris Technologies (2018–2020). The profile describes FedRAMP and CMMC cybersecurity consulting with NIST 800-53/171 expertise, supporting ATO readiness, compliance and continuous monitoring.
Mike Olivier
LinkedInExperience: President · 171Comply
President of 171Comply since 2018 and Senior Cybersecurity Consultant at CommTech Systems Inc since 2014. The profile describes 171Comply as focused on cybersecurity planning, policies and compliance, helping organizations meet the system security planning requirements of the Cybersecurity Maturity Model Certification (CMMC) model and NIST 800-171.
Choose the right perspective
Decide first whether you need readiness help, implementation help or someone with assessor experience, since the profiles differ in which of these they emphasize. Check that the person's certifications and recent engagements match the CMMC level your contracts require.
Questions to take into the conversation
- 01How do you define our CMMC assessment boundary and decide which systems handle controlled unclassified information?
- 02Which NIST 800-171 controls do companies like ours most often fail, and which should we fix first?
- 03How long does it usually take to go from a gap assessment to being ready for a CMMC Level 2 assessment?
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal