Dragonfli
Dragonfli Group is a Washington, DC-based, founder-led cybersecurity and AI governance advisory firm serving federal agencies, Fortune 500 financial institutions, and defense contractors with senior-practitioner consulting and the CMMC Accelerator SaaS readiness platform.
- Company typePrivate
- Founded2008
- HeadquartersWashington, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Dragonfli does
Dragonfli Group LLC is a Washington, DC-based, founder-led cybersecurity, AI governance, and technology advisory firm founded in 2008 by CEO Glenn Ballard. The company serves US federal agencies, Fortune 500 financial institutions, defense industrial base contractors, and critical infrastructure operators with senior-practitioner-led consulting engagements across three service pillars: Cybersecurity Services (threat detection, zero trust architecture, GRC, IAM, critical infrastructure, incident response), AI Governance & Security (NIST AI RMF and EU AI Act alignment, model risk management, agentic AI security, post-quantum cryptography), and Technology & IT Advisory (operational resilience, DevSecOps, vCISO, cloud security, systems integration). The firm explicitly staffs every engagement with certified senior practitioners and does not maintain a junior bench.
In 2025–2026 Dragonfli added a productized revenue stream through the CMMC Accelerator, a self-service SaaS platform that assesses defense contractors against all 110 NIST SP 800-171 Rev 2 controls, computes estimated SPRS scores using the DoD Assessment Methodology (32 CFR 170.24), and produces AI-assisted (Anthropic Claude) draft System Security Plans and Plans of Action & Milestones that are reviewed by CyberAB-certified CMMC Registered Practitioners before delivery. The platform offers a free Pulse Check, a $3,500 Full Assessment (creditable toward follow-on T1/T2/T3 remediation services priced $5,000–$30,000+), and a $1,500/year annual reassessment subscription. The firm is a CyberAB-verified Registered Practitioner Organization and operates without disclosed external funding, positioning itself as a senior-only boutique with both enterprise field sales and product-led self-serve distribution.
Dragonfli firmographics
Firmographics- Name
- Dragonfli
- Legal name
- Dragonfli Group LLC
- Website
- https://dragonfligroup.com
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Dragonfli Group is a Washington, DC-based, founder-led cybersecurity and AI governance advisory firm serving federal agencies, Fortune 500 financial institutions, and defense contractors with senior-practitioner consulting and the CMMC Accelerator SaaS readiness platform.
- Ownership category
- akta.pro rank
Dragonfli industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO)
- akta.pro secondary industries
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK), Regulatory Change Management (RCM) (HDADAIAG), AI Governance, Risk & Compliance (GRC) Platforms (HDAAAMAA)
Keywords
Where Dragonfli is headquartered
LocationHeadquarters
- HQ city
- Washington
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Dragonfli business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- CMMC Accelerator SaaS Platform: Self-service CMMC readiness assessment subscription. The Free Pulse Check generates a quick risk snapshot at no charge. The Full Assessment Package ($3,500 paid up front, or $325/month for 12 months) covers all 110 NIST SP 800-171 requirements, produces Dragonfli-reviewed SSP and POA&M drafts, and includes a readout call. The assessment fee credits in full toward follow-on remediation engagements.
- Professional Services — CMMC Remediation: Tiered professional services engagements scoped from assessment results: T1 Validate ($5,000–$12,000) for nearly-ready organizations; T2 Remediate ($12,000–$30,000) for organizations with defined gaps; T3 Build ($30,000+, custom scoped) for full security program build-out. Also includes vCISO services (ongoing fractional security leadership) and annual reassessment + affirmation support ($1,500/year).
- Cybersecurity and Technology Advisory Consulting: Senior practitioner-led engagements covering cybersecurity services (threat detection, zero trust, GRC, IAM, critical infrastructure security, incident response), AI governance and security services (AI governance frameworks, model risk management, agentic AI security, post-quantum cryptography), and IT strategy and transformation (operational resilience, DevSecOps, vCISO, cloud security, systems integration). Revenue is project-based and varies by engagement scope.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free Pulse Check — top-of-funnel quick assessment (~10 minutes, no credit card) |
| Subscription | Pay-as-you-go | Full Assessment & Dragonfli-Reviewed Report Package — all 110 NIST SP 800-171 controls, Dragonfli-reviewed SSP and POA&M drafts |
| One time/ perpetual license | Multi-year contract | T1 Validate — evidence compilation, SSP/POA&M finalization, C3PAO preparation |
| One time/ perpetual license | Multi-year contract | T2 Remediate — structured gap closure with policy and technical implementation support |
| Outcome Based/ Performance | Multi-year contract | T3 Build — full security program build-out to C3PAO assessment readiness |
| Subscription | Annual | Annual Reassessment & Affirmation Support |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Dragonfli product offering
Product offeringCore offering
Dragonfli Group delivers senior-practitioner-led cybersecurity services, AI governance advisory, and technology/IT transformation consulting to federal agencies, Fortune 500 financial institutions, defense contractors, and critical infrastructure operators. The firm also operates the CMMC Accelerator — a self-service SaaS platform enabling defense contractors to assess CMMC Level 2 readiness against all 110 NIST SP 800-171 Rev 2 requirements, generate AI-assisted SSP and POA&M documents reviewed by CMMC Registered Practitioners, and convert into tiered remediation engagements (T1 Validate, T2 Remediate, T3 Build).
Product overview
Dragonfli Group offers two distinct portfolios: (1) The CMMC Accelerator — a self-service SaaS platform for defense contractors seeking CMMC Level 2 certification readiness. It consists of a free Pulse Check quick assessment, a paid Full Assessment ($3,500) with AI-generated SSP and POA&M drafts reviewed by CMMC Registered Practitioners, and three follow-on remediation service tiers (T1 Validate at $5,000–$12,000, T2 Remediate at $12,000–$30,000, and T3 Build at $30,000+). The platform covers all 110 NIST SP 800-171 requirements and estimates SPRS scores using the DoD Assessment Methodology. (2) Professional services including Cybersecurity Services (threat detection, zero trust, GRC, IAM, OT/ICS, incident response), AI Governance & Security (AI governance frameworks, model risk management, agentic AI security, post-quantum cryptography), and Technology & IT Advisory (operational resilience, DevSecOps, vCISO, cloud security, systems integrations).
Differentiator
Problem solved
Functional benefit
Brands
- CMMC Accelerator: Dragonfli's CMMC Level 2 readiness assessment platform that helps defense contractors assess their cybersecurity posture against NIST SP 800-171 requirements and prepare for C3PAO certification.
Products and services
- CMMC Accelerator (SaaS Platform) Self-service web platform enabling defense contractors to assess CMMC Level 2 readiness against all 110 NIST SP 800-171 Rev 2 requirements, with AI-assisted draft SSPs and POA&Ms reviewed by CMMC Registered Practitioners, estimated SPRS scoring, gap analysis, and a what-if score simulator.
- CMMC Accelerator Full Assessment Package Paid tier of the CMMC Accelerator covering all 110 NIST SP 800-171 requirements with estimated SPRS score, Dragonfli-reviewed draft SSP and POA&M documents, gap analysis, executive summary, remediation roadmap, and a 30-minute readout call; priced at $3,500 (credited toward follow-on remediation services).
- CMMC Accelerator Free Pulse Check Free, no-credit-card-required quick assessment covering the five highest-risk CMMC requirement areas, returning an instant readiness score and risk tier in approximately 10 minutes.
- T1 Validate (CMMC Remediation Engagement) Professional services engagement for CMMC remediation for organizations nearly ready for C3PAO assessment, including evidence compilation, SSP/POA&M finalization, C3PAO selection support, and mock-assessment readiness review; priced $5,000–$12,000.
- T2 Remediate (CMMC Remediation Engagement) Professional services engagement for CMMC remediation for organizations with defined control gaps, including structured gap closure, policy and procedure development, technical control implementation support, and POA&M execution and tracking; priced $12,000–$30,000.
- T3 Build (CMMC Remediation Engagement) Custom-scoped professional services engagement for full security program build-out from a low security baseline, including CUI enclave design and implementation, managed remediation across all 14 NIST SP 800-171 domains, and ongoing support through C3PAO assessment; priced $30,000+.
- Cybersecurity Services Senior-practitioner-led cybersecurity advisory covering threat detection and SOC, zero trust architecture, GRC and compliance across 50+ frameworks, IAM/PAM, critical infrastructure security (NERC CIP), and incident response.
- AI Governance & Security Advisory services for AI governance framework development aligned to NIST AI RMF and EU AI Act, model risk management, agentic AI security, post-quantum cryptography readiness, AI threat detection, and executive/board AI briefings.
- Technology & IT Advisory Senior-practitioner advisory covering operational resilience (BC/DR), DevSecOps integration, vCISO services, IT strategy and transformation, cloud security architecture, and systems integrations.
- vCISO Services Fractional CISO model providing senior security strategy and oversight on demand without the cost or commitment of a full-time executive hire, including engagement-driven GRC leadership and audit readiness support.
Quantifiable outcome
- Dragonfli-reviewed CMMC readiness reports delivered in days vs. 6–12 weeks for traditional consulting firms
- +3 more outcomes
Companies that use Dragonfli
Customer profileNamed customers6 records
Segments5 records
Ideal customer profiles5 records
Dragonfli technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability3 records
Feature4 records
Dragonfli partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- Cyber Accreditation Body (CyberAB)coreDragonfli Group is a CyberAB-verified CMMC Registered Practitioner Organization (RPO). CyberAB is the official accreditation body established by the DoD to oversee the CMMC certification ecosystem, including accreditation of RPOs and C3PAOs. Dragonfli's RPO status enables it to provide CMMC consulting, assessment preparation, and implementation support to defense contractors, with Dragonfli's credentials verified on the CyberAB Marketplace.
- CMMC Third-Party Assessment Organizations (C3PAOs)coreDragonfli prepares defense contractors for C3PAO certification assessments through its T1/T2/T3 remediation engagements. The RPO-to-C3PAO pipeline is a core part of Dragonfli's service model: Dragonfli prepares clients for the official certification audit conducted by an independent C3PAO. The 88-or-refund guarantee reflects confidence in assessment readiness.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Dragonfli competitors and assessment
Company assessmentBroad incumbents
- Booz Allen Hamilton: Large federal integrator with substantial federal cybersecurity, zero trust, CMMC, and AI governance practices serving the same US federal agency and DIB buyer base — broader portfolio and bench than Dragonfli.
- KPMG US Cyber Practice: Big Four advisory firm with a major cybersecurity and GRC practice serving Fortune 500 and federal clients across CMMC, ISO, NIST, and AI governance — overlaps Dragonfli's mid-market and enterprise compliance advisory.
- Leidos: Large federal contractor delivering cybersecurity, zero trust, and IT modernization services to US government and DIB clients — competes for federal cyber and CMMC readiness work at scale.
Emerging players
- NXTKey Corporation: Smaller CMMC-focused consulting firm and CyberAB RPO serving defense contractors — emerging direct competitor in the niche CMMC readiness segment that Dragonfli's CMMC Accelerator targets.
- Pivot Point Security: Cybersecurity consulting firm specializing in CMMC, vCISO, and NIST 800-171 services for SMBs in the Defense Industrial Base — comparable niche focus and buyer base.
Direct peers
- BARR Advisory: Compliance-focused advisory firm specializing in SOC 2, ISO 27001, and CMMC for SaaS and regulated industries — directly comparable boutique advisory targeting similar compliance-driven buyers.
- RISCPoint: CMMC and federal compliance advisory firm and CyberAB RPO focused on the Defense Industrial Base and regulated industries — head-to-head competitor for DIB readiness spend.
- Schellman & Co: Top-tier compliance and cybersecurity advisory firm (SOC 2, ISO 27001, CMMC, FedRAMP) serving similar Fortune 500 and federal/defense clients — comparable senior-practitioner-led boutique model.
- Coalfire: Large cybersecurity advisory firm with deep CMMC advisory practice (CyberAB RPO) and FedRAMP/GRC services serving federal agencies and Fortune 500 — directly competes with Dragonfli in the same buyer base.
- A-LIGN: Compliance and cybersecurity firm delivering CMMC readiness, ISO 27001, SOC 2, and FedRAMP services to mid-market and enterprise clients — overlaps Dragonfli's DIB and Fortune 500 customer profile.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Dragonfli social profiles
Digital presenceDragonfli compliance and trust
Trust signalCompliance4 records
Dragonfli financial estimates
Financial estimateRevenue estimate
Valuation estimate
Dragonfli leadership team
Management profileNumber of profiles
Profiles1 record
Dragonfli funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Dragonfli M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Dragonfli
What does Dragonfli do?
Dragonfli Group delivers senior-practitioner-led cybersecurity services, AI governance advisory, and technology/IT transformation consulting to federal agencies, Fortune 500 financial institutions, defense contractors, and critical infrastructure operators. The firm also operates the CMMC Accelerator — a self-service SaaS platform enabling defense contractors to assess CMMC Level 2 readiness against all 110 NIST SP 800-171 Rev 2 requirements, generate AI-assisted SSP and POA&M documents reviewed by CMMC Registered Practitioners, and convert into tiered remediation engagements (T1 Validate, T2 Remediate, T3 Build).
Is Dragonfli a public or private company?
Dragonfli is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Dragonfli founded?
Dragonfli was founded in 2008. It employs 11 to 50 people.
Where is Dragonfli based?
Dragonfli is headquartered in Washington, United States, in the North America region.
How does Dragonfli make money?
Three revenue lines are on record. CMMC Accelerator SaaS Platform is the primary driver. The others are professional Services — CMMC Remediation and cybersecurity and Technology Advisory Consulting.
Who are Dragonfli's main competitors?
Broad incumbents on record are Booz Allen Hamilton, KPMG US Cyber Practice and Leidos. Emerging players are NXTKey Corporation and Pivot Point Security. Direct peers are BARR Advisory, RISCPoint, Schellman & Co, Coalfire and A-LIGN.
Does Dragonfli have an API?
No public API is recorded for Dragonfli.
What industry is Dragonfli in?
Dragonfli's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAHAFAO, Compliance Technology, GRC Platforms & Controls Automation Advisory, with a secondary code of HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms. Its NAICS code is 5415 and its SIC code is 7373.