Secure-Centric
Secure-Centric is a Los Angeles-based CMMC compliance consulting firm helping defense contractors and the defense industrial base achieve Cybersecurity Maturity Model Certification. It delivers professional services including risk and gap assessments, virtual CISO support, and NIST 800-171 implementation for clients nationwide.
- Company typePrivate
- Founded2020
- HeadquartersLos Angeles, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Secure-Centric does
Secure-Centric is a Los Angeles–based professional services firm specializing in Cybersecurity Maturity Model Certification (CMMC) compliance consulting for the U.S. defense industrial base. Founded in 2020 by Jake "EJ" Celler and Shawn Phan (Son Phan), the firm guides defense contractors, federal contractors, and downstream SaaS/IT service providers through CMMC Level 1, 2, and 3 certification, NIST 800-171 implementation, and ongoing compliance maintenance. Its primary customers are organizations that store, process, or transmit Controlled Unclassified Information (CUI) under Department of Defense contracts, with named engagements spanning non-profits (Los Angeles Food Bank), education (Santa Clarita School District), healthcare (Marina), municipal government (City of San Diego), professional services (BCG, Davis Elen), sports/entertainment (New York City Football Club), and food/agriculture (Mt. Olive).
The firm's service portfolio is anchored on CMMC Compliance Services and a Virtual CISO (vCISO) offering, supported by modular add-ons including Risk Assessment (four-stage methodology covering managerial, environmental, internal, and external controls), Gap Assessment, Tabletop Exercises, NIST 800-171 standalone engagements, and On-Demand CMMC Specialists. Secure-Centric's core proprietary asset is its "Universal Assessments" framework, a NIST-grounded evaluation system designed to extend beyond baseline compliance checks and align with CMMC, AWIA, CCPA, CIS, FFIEC, FINRA, GLBA, HIPAA, PCI, and other regulatory frameworks. Top-of-funnel content assets (CMMC Level 1 and 2.0 checklists, Unmarked CUI Detection Template, free 2-minute Readiness Assessment tool) feed an enterprise field-sales motion that converts through website consultation booking. Technology partnerships with CrowdStrike, Rubrik, Illumio, Veza, and Expel provide a curated cybersecurity stack that the firm packages into client engagements.
Secure-Centric monetizes through quote-based, multi-year professional services engagements and operates a sales-led, enterprise-field-sales go-to-market. The firm holds Registered Practitioner Organization (RPO) status for CMMC (CPN 61907) and maintains federal and state procurement vehicles including GSA MAS (#47QSWA18D008F), NCPA, and NASPO via Golden State Technologies (#AR2472). The company is privately held, bootstrapped (no external funding rounds disclosed), with a headcount of 11–50 employees and recognition including the 2025 Inc. 5000 (#452) and the 2024 CRN MSP 500 Security 100.
Secure-Centric firmographics
Firmographics- Name
- Secure-Centric
- Legal name
- Secure-Centric Inc.
- Website
- https://secure-centric.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Secure-Centric is a Los Angeles-based CMMC compliance consulting firm helping defense contractors and the defense industrial base achieve Cybersecurity Maturity Model Certification. It delivers professional services including risk and gap assessments, virtual CISO support, and NIST 800-171 implementation for clients nationwide.
- Ownership category
- akta.pro rank
Secure-Centric industry classification
Industry- Product category
- Cybersecurity Compliance Consulting
- NAICS
- Security Systems Services (56162), Security Systems Services (except Locksmiths) (561621), Investigation, Guard, and Armored Car Services (56161)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Confidential Computing & Hardware-backed Protection (TEE/HSM) (HDADAFAJ)
- akta.pro secondary industry
- Secure Communications, Cryptography & Key Management Systems (IMABAOAK)
Keywords
Where Secure-Centric is headquartered
LocationHeadquarters
- HQ city
- Los Angeles
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Secure-Centric business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D
Revenue model
- Professional Services - CMMC Consulting: Consulting services providing comprehensive guidance for defense contractors navigating the complex cybersecurity compliance landscape. Expert team works closely with organizations to assess current security postures, develop tailored remediation strategies, and prepare for CMMC assessments.
- Virtual CISO Services: Ongoing vCISO engagement providing access to top-level CMMC specialists for organizations requiring security proficiency and support. Offers security protocols aligned with business goals and quantifiable improvement to security framework.
- Compliance Assessment Services: Comprehensive assessment services including risk assessments, gap assessments, and CMMC compliance evaluations to help organizations identify vulnerabilities and prepare for certification audits.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Customized consulting engagement based on organizational needs |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels6 records
Secure-Centric product offering
Product offeringCore offering
Secure-Centric provides CMMC cybersecurity compliance consulting services to defense contractors, federal contractors, and organizations handling Controlled Unclassified Information (CUI). The firm guides clients through CMMC certification via Virtual CISO engagements, risk and gap assessments, NIST 800-171 implementation, tabletop exercises, and ongoing compliance monitoring built on its proprietary Universal Assessment methodology.
Product overview
Secure-Centric is a CMMC compliance consulting firm offering a unified portfolio of services rather than a software platform. The core offering centers on CMMC Compliance Services and Virtual CISO (vCISO) services, which provide organizations with expert guidance through the CMMC certification process. Supporting these flagship services are specialized add-on modules including Risk Assessment, Gap Assessment, Tabletop Exercises, and NIST 800-171 Compliance support. The company also provides downloadable resources and templates including the CMMC Level 1 Readiness Checklist, CMMC Level 2.0 Compliance Checklist, and How to Detect Unmarked CUI Template, plus a CMMC 2.0 Readiness Assessment Form tool. On-Demand CMMC Specialists provide flexible expert support as needed. Together, these services guide defense contractors through the complete CMMC compliance lifecycle from initial assessment through certification and ongoing maintenance.
Differentiator
Problem solved
Functional benefit
Products and services
- CMMC Compliance Services Cybersecurity Maturity Model Certification (CMMC) compliance consulting and certification support services, providing guidance through all three CMMC levels (1, 2, and 3), preparation for third-party C3PAO assessments, and ongoing compliance monitoring. Targeted at defense contractors and organizations handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI).
- Virtual CISO (vCISO) On-demand Chief Information Security Officer service providing access to senior compliance experts who guide organizations through CMMC certification, assess security programs, and develop tailored security procedures aligned with business goals. Includes ongoing vCISO engagement for organizations requiring sustained security leadership and quantifiable improvement to their security framework.
- Risk Assessment Comprehensive four-stage risk assessment covering managerial, environmental, internal, and external controls to identify and measure CMMC compliance-related vulnerabilities. Helps organizations prioritize and optimize investments in safeguarding data and prepare for certification.
- Gap Assessment Compliance gap analysis examining how well an organization's CMMC program aligns with mandated criteria across CMMC, NIST 800-171, and other regulatory frameworks (AWIA, CCPA, CIS, FERC/NERC, FFIEC, FINRA, GLBA, HIPAA, NIST 800-53, NIST CSF, NYDFS, PCI, SOPPA). Provides tailored recommendations to achieve compliance.
- Tabletop Exercises Interactive incident response and disaster recovery simulations tailored for CMMC compliance, helping organizations identify gaps and prepare for theoretical security scenarios through facilitated exercises.
- NIST 800-171 Compliance Specialized consulting for organizations implementing NIST 800-171 requirements to protect Controlled Unclassified Information (CUI), including tailored assessments, gap analyses, and actionable remediation strategies.
- On-Demand CMMC Specialists On-call access to CMMC experts providing guidance and support for identifying and addressing compliance gaps, enhancing implementation strategies, and managing required security practices. Designed for organizations needing flexible, expert support without a full engagement.
Quantifiable outcome
- Organizations achieve CMMC certification and maintain compliance with ongoing support
- +1 more outcomes
Companies that use Secure-Centric
Customer profileNamed customers9 records
Segments3 records
Ideal customer profiles3 records
Secure-Centric technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Secure-Centric partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core.
- RubrikcoreTechnology integration partner providing data protection and ransomware recovery solutions. Rubrik logo appears on partner/client logos section indicating active partnership or integration relationship.
- IllumiocoreTechnology partner providing zero trust segmentation and security solutions. Logo featured in technology partner section.
- CrowdStrikecoreTechnology integration partner providing endpoint protection and cybersecurity solutions. Logo displayed in partner section.
- NCPA (National Cooperative Purchasing Alliance)corePublic sector contract vehicle enabling access to cooperative purchasing programs. Contract available for public sector entities seeking CMMC compliance services.
- NASPO (National Association of State Procurement Officials)corePublic procurement contract vehicle through Golden State Technologies. Contract # AR2472. Enables state government agencies to procure CMMC compliance services.
- GSA (General Services Administration)coreGeneral Services Administration Multiple Award Schedule (MAS) contract # 47QSWA18D008F. Enables federal agencies to procure services through established government contracting vehicle.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Secure-Centric competitors and assessment
Company assessmentBroad incumbents
- Booz Allen Hamilton: Booz Allen Hamilton is a major federal consulting prime with deep DoD cybersecurity and CMMC capabilities, serving large defense contractors with end-to-end compliance programs. Competes in the same market from a much larger scale and with embedded federal contract relationships.
- Baker Tilly: Baker Tilly is a top-tier advisory firm with a dedicated CMMC, NIST, and government contractor cybersecurity practice. Serves many of the same DIB clients as Secure-Centric but from a larger multi-service advisory platform with cross-sell into audit and tax.
- KPMG: KPMG's U.S. advisory practice includes a substantial federal cyber and CMMC compliance team serving large defense primes and their supply chains. Represents the Big Four incumbent alternative for enterprises that prefer brand-name advisory providers over specialist RPOs.
- BDO USA: BDO USA's Government Contractor practice includes CMMC readiness, NIST 800-171 advisory, and cybersecurity consulting for DIB clients of similar mid-market size to Secure-Centric's target. Competes for the same compliance consulting wallet but offers broader tax/audit cross-sell.
- Crowe LLP: Crowe is a top-10 U.S. accounting and advisory firm with an active cybersecurity and CMMC compliance practice serving government contractors. Significantly larger and broader portfolio, but directly competes for the same mid-market DIB CMMC consulting engagements.
Direct peers
- Schellman: Schellman is a top-tier cybersecurity attestation and CMMC advisory firm offering readiness assessments, vCISO, and authorized C3PAO assessments. Direct competitor in the same niche serving defense industrial base clients with similar multi-framework (NIST, CMMC, ISO, SOC) expertise.
- Linford & Co: Linford & Co is a registered CMMC RPO providing CMMC readiness, NIST 800-171 implementation, and managed compliance services to defense contractors. Closely matched mid-market firm with comparable CMMC-exclusive positioning and consulting-led delivery.
- A-LIGN: A-LIGN is a cybersecurity compliance and audit firm with active CMMC practice, FedRAMP, ISO, SOC, and PCI services. Directly comparable as a mid-sized compliance-focused consultancy serving defense and federal contractors with assessment-led delivery models.
- RSI Security: RSI Security is a cybersecurity consultancy with strong CMMC, NIST 800-171, and federal compliance practice serving defense and government contractors. Similar services-led model with comparable mid-market RPO/RPA credentials and vCISO offerings.
- Coalfire: Coalfire is one of the largest pure-play CMMC advisory and C3PAO assessment firms in the U.S., offering RPO-equivalent consulting, gap assessments, and authorized certification assessments for defense contractors. Direct overlap with Secure-Centric on CMMC readiness, vCISO, and NIST 800-171 services targeting the same DIB customer base.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Secure-Centric social profiles
Digital presenceSecure-Centric compliance and trust
Trust signalCompliance3 records
Secure-Centric financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secure-Centric leadership team
Management profileNumber of profiles
Profiles3 records
Secure-Centric funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secure-Centric M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secure-Centric
What does Secure-Centric do?
Secure-Centric provides CMMC cybersecurity compliance consulting services to defense contractors, federal contractors, and organizations handling Controlled Unclassified Information (CUI). The firm guides clients through CMMC certification via Virtual CISO engagements, risk and gap assessments, NIST 800-171 implementation, tabletop exercises, and ongoing compliance monitoring built on its proprietary Universal Assessment methodology.
Is Secure-Centric a public or private company?
Secure-Centric is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Secure-Centric founded?
Secure-Centric was founded in 2020. It employs 11 to 50 people.
Where is Secure-Centric based?
Secure-Centric is headquartered in Los Angeles, United States, in the North America region.
How does Secure-Centric make money?
Three revenue lines are on record. Professional Services - CMMC Consulting is the primary driver. The others are virtual CISO Services and compliance Assessment Services.
Who are Secure-Centric's main competitors?
Broad incumbents on record are Booz Allen Hamilton, Baker Tilly, KPMG, BDO USA and Crowe LLP. Direct peers are Schellman, Linford & Co, A-LIGN, RSI Security and Coalfire.
Does Secure-Centric have an API?
No public API is recorded for Secure-Centric.
What industry is Secure-Centric in?
Secure-Centric's product category is Cybersecurity Compliance Consulting. Its primary akta.pro industry code is HDADAFAJ, Confidential Computing & Hardware-backed Protection (TEE/HSM), with a secondary code of IMABAOAK, Secure Communications, Cryptography & Key Management Systems. Its NAICS code is 56162 and its SIC code is 7381.