SecureStrux
SecureStrux is a Lancaster, PA-based cybersecurity firm providing CMMC, RMF, FISMA, and CORA compliance consulting, engineering, and the proprietary PowerStrux toolset primarily to Defense Industrial Base contractors and federal agencies.
- Company typePrivate
- Founded2013
- HeadquartersLancaster, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What SecureStrux does
SecureStrux, LLC is a privately held cybersecurity consulting firm headquartered in Lancaster, Pennsylvania, founded in 2013 by Nathan Shea. The company delivers end-to-end cybersecurity compliance and engineering services — CMMC (as an Authorized C3PAO), RMF, FISMA, CORA/CCRI, DFARS, and SIPRNet integration — alongside penetration testing and cybersecurity staffing, primarily to Defense Industrial Base contractors and federal civilian and DoD agencies. Customers span large prime contractors (L3Harris, Lockheed Martin, Raytheon, SAIC, Peraton, Sierra Nevada, Thales Defense) and federal agencies (DISA, MDA, DLA, Army National Guard, U.S. Navy Fourth Fleet, NRL, NSWC, DNFSB, DC3), supported by contract vehicles including GSA MAS/HACS, MDA SHIELD, Seaport NxG, FAA eFAST, DLA JETS, and IAC MAC.
The firm's underlying technology centers on the proprietary PowerStrux™ suite — Windows Auditor, Linux Auditor, ACAS Validator (Tenable-integrated), and Active Directory Auditor — which leverage Windows PowerShell and PowerShell Core to automate NIST 800-53 AU-2 event auditing and compliance reporting. The suite is used by 500+ companies and is offered on a freemium 14-day-trial model alongside quote-based enterprise licensing. SecureStrux maintains ISO 27001 and ISO 9001:2015 certifications, a TS Facility Clearance, and reports greater than 80% cleared staff, with a leadership team comprising former DISA, NSA, USAF, and U.S. Army Signal Corps officers.
The business model is predominantly professional services (compliance consulting, engineering, staffing) with a smaller recurring software subscription component via PowerStrux. Revenue is generated through direct enterprise field sales to federal and DIB clients, channel partners via prime contract vehicles, and an emerging indirect sales motion built around the dedicated PowerStrux sales representative and a recently hired Strategic Sales & Partnership Leader. The company has been recognized four times on the Inc. 5000 list (2018, 2019, 2020, 2023) and reported 85% revenue growth over the trailing three years in its 2023 Inc. 5000 entry.
SecureStrux firmographics
Firmographics- Name
- SecureStrux
- Legal name
- SecureStrux, LLC
- Website
- https://securestrux.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SecureStrux is a Lancaster, PA-based cybersecurity firm providing CMMC, RMF, FISMA, and CORA compliance consulting, engineering, and the proprietary PowerStrux toolset primarily to Defense Industrial Base contractors and federal agencies.
- Ownership category
- akta.pro rank
Where SecureStrux is headquartered
LocationHeadquarters
- HQ city
- Lancaster
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
SecureStrux business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity Compliance Consulting Services: Core revenue stream from compliance and inspection services including CMMC, RMF, FISMA, CORA/CCRI, DFARS, and SIPRNet compliance. Services include gap analysis, remediation support, and continuous monitoring.
- Engineering Solutions: Network security implementation, specialized network design, systems administration, vulnerability assessment and management, SIEM services (Splunk and Microsoft Sentinel), endpoint security, virtualization, and cloud security services.
- Cybersecurity Staffing: Placement of cybersecurity professionals including program managers, security architects, cyber analysts, auditors, vulnerability analysts, ISSOs, RMF specialists, system/network engineers, penetration testers, and cloud engineers.
- PowerStrux Software Products: Proprietary continuous monitoring tools sold as software products including Windows Auditor, Linux Auditor, ACAS Validator, and AD Auditor. Offered with 14-day free trial.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | PowerStrux 14-day free trial |
Go-to-market motion2 records
Distribution channels7 records
Marketing channels7 records
SecureStrux product offering
Product offeringCore offering
SecureStrux provides end-to-end cybersecurity compliance, engineering, and staffing services to the U.S. Defense Industrial Base (DIB), federal/state/local government agencies, higher education institutions engaged in DoD research, and other critical infrastructure sectors. As an authorized C3PAO, the firm conducts official CMMC assessments and delivers compliance services spanning RMF, FISMA, CORA/CCRI, DFARS, and SIPRNet. It complements these services with the proprietary PowerStrux suite of continuous monitoring and auditing tools for Windows, Linux, ACAS/Tenable, and Active Directory environments.
Product overview
SecureStrux is a cybersecurity firm offering both proprietary software products and professional services. The core product is the PowerStrux™ Suite of continuous monitoring tools, which includes four specialized tools: Windows Auditor (for Microsoft Windows systems), Linux Auditor (for Red Hat Enterprise Linux), ACAS Validator (for Tenable integration), and Active Directory Auditor. These tools work together to automate security auditing and compliance monitoring across different platforms. Beyond software products, SecureStrux provides comprehensive cybersecurity services including C3PAO-certified CMMC assessments, CORA/CCRI assessments, RMF compliance, FISMA compliance, SIPRNet integration, DFARS compliance, penetration testing, engineering solutions (network security, SIEM, endpoint security), and cybersecurity staffing solutions. The company operates as an Authorized C3PAO (Certified Third Party Assessor Organization) for DoD cybersecurity assessments.
Differentiator
Problem solved
Functional benefit
Brands
- PowerStrux™: Suite of continuous monitoring tools designed to safeguard essential data, covering Microsoft Windows, Microsoft Active Directory, Red Hat Enterprise Linux, and ACAS Validator tool that works with Tenable. Includes Windows Auditor, Linux Auditor, ACAS Validator, and Active Directory Auditor products.
Products and services
- PowerStrux Windows Auditor A standalone auditing utility for monitoring system and user activity on Microsoft Windows systems; leverages Microsoft's built-in PowerShell scripting language to parse and report on account management, security group management, data transfers, and system auditing events. Trusted by 500+ companies.
- PowerStrux Linux Auditor An auditing tool tailored for Red Hat Enterprise Linux (RHEL) systems providing monitoring of system and user activities; parses and reports on account management, group management, and system auditing events for standalone systems and small networks.
- PowerStrux ACAS Validator A lightweight Microsoft Windows-based compliance assessment tool that validates Assured Compliance Assessment Solution (ACAS) implementations against Department of War TASKORD 20-0020 requirements; automatically evaluates ACAS configurations and operational settings to identify compliance gaps before formal assessments.
- PowerStrux Active Directory (AD) Auditor An enterprise-level solution for Active Directory auditing using Microsoft's inherited language; runs from any domain-joined system by any domain user, exporting Active Directory domain, computer, user, and group information. Monitors domain, user, computer, and group membership categories for offensive and defensive security teams.
- CMMC Assessment & Compliance Services Partnering with DIB contractors to protect Controlled Unclassified Information (CUI) and achieve CMMC certification. SecureStrux is an authorized C3PAO conducting official CMMC assessments as well as providing consulting/gap analysis and remediation support.
- Risk Management Framework (RMF) Compliance & Authorization Services Assessment and authorization services throughout the six-step RMF lifecycle for DoD Agencies and partners. Includes STIG evaluations, end-to-end documentation development, eMASS administration, and continuous monitoring.
- Cyber Operational Readiness Assessment (CORA) Services Helping DoD Agencies and Defense Industrial Base partners gain insight into their day-to-day operations and alignment with established cybersecurity standards. Formerly known as CCRI (Command Cyber Readiness Inspection).
- FISMA Compliance Services Assisting Federal, Civilian, and DoD Agencies to enhance their security posture with end-to-end documentation development, POA&Ms, SSPs, and proprietary PowerStrux tools for continuous monitoring.
- SIPRNet Integration & Compliance Services Comprehensive SIPRNet integration and compliance services encompassing on-site assessment, configuration, risk management, and training for secure network connectivity.
- DFARS Compliance Services Translating DFARS CUI regulations and improving SPRS scores. Assists with DFARS Clause 252.204-7012, 7019, and 7021 requirements.
- Penetration Testing Services Testing from inside and outside environments to identify exploitable vulnerabilities. Includes vulnerability scanning, physical penetration testing, and wireless penetration testing services.
- Engineering Solutions Network security implementation, specialized network design, systems administration, vulnerability assessment and management, SIEM services (Splunk and Microsoft Sentinel), endpoint security, virtualization, and cloud security services.
- Cybersecurity Staffing Services Placement of cybersecurity professionals including program managers, security architects, cyber analysts, auditors, vulnerability analysts, ISSOs, RMF specialists, system/network engineers, penetration testers, and cloud engineers.
Quantifiable outcome
- 85% revenue growth over 3 years
- +5 more outcomes
Companies that use SecureStrux
Customer profileNamed customers21 records
Segments4 records
Ideal customer profiles4 records
SecureStrux technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
Feature5 records
SecureStrux partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core and minor.
- GSA Multiple Award Schedule (MAS) / HACScoreContract Number: GS-35F-279DA. Prime contractor vehicle enabling direct procurement of cybersecurity and compliance services by federal government customers through GSA schedules program.
- MDA SHIELD Multiple Award IDIQcoreContract Vehicle Number: HQ085926DF514. Prime contract vehicle with Missile Defense Agency for cybersecurity services and solutions.
- Seaport-NxGcoreContract Number: N0017819D8483. Navy Seaport-NxG contract vehicle for professional services including cybersecurity.
- FAA eFASTminorFAA eFAST Contract Number: DTFAWA17A-00068. Federal Aviation Administration contracting vehicle for IT services.
- DLA J6 Enterprise Technology Services (DLA JETS)minorSubcontract vehicle with Defense Logistics Agency for IT and cybersecurity services.
- Information Analysis Center Multiple Award Contract (IAC MAC)minorSubcontract vehicle for cybersecurity and IT professional services.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
SecureStrux competitors and assessment
Company assessmentDirect peers
- Redspin: Redspin is a direct CMMC-focused cybersecurity consultancy and authorized C3PAO serving DoD contractors. Like SecureStrux, it provides CMMC readiness, RMF, and federal compliance services to DIB clients, making it one of the most head-to-head comparables in the niche.
- Coalfire Federal: Coalfire is a major cybersecurity advisory firm with deep federal/DoD practice including CMMC, RMF, and FISMA services. It competes head-to-head with SecureStrux for DIB compliance engagements and shares a C3PAO-adjacent advisory model.
- By Light Professional IT Services: By Light is a mid-tier federal IT and cybersecurity services firm focused on DoD, DIB, and intelligence community customers. It provides RMF, cyber engineering, and CMMC-related services similar to SecureStrux's core offering.
Broad incumbents
- ManTech International: ManTech (acquired by Carlyle) is a large federal IT services prime delivering cybersecurity, RMF, and cyber operations support to DoD. It overlaps with SecureStrux on RMF/ATO and DIB cybersecurity but at much greater scale and scope.
- SAIC: SAIC is a major federal IT and cybersecurity services prime with extensive DoD cybersecurity, RMF, and compliance work. It serves the same DIB customer base as SecureStrux but at significantly larger scale and broader portfolio.
- Booz Allen Hamilton: Booz Allen is the dominant federal cybersecurity consultancy with deep DoD and intelligence-community relationships. It competes for the same RMF, CMMC advisory, and cyber engineering engagements that SecureStrux services, particularly through its Applied Insight acquisition.
- Leidos: Leidos is a top-tier federal systems integrator with a large cybersecurity practice covering RMF, cyber operations, and DIB support. It pursues many of the same DoD customers as SecureStrux at a substantially larger scale.
- CACI International: CACI is a large federal IT services prime with significant DoD cybersecurity, RMF, and intelligence community work. It competes for adjacent engagements with SecureStrux in CMMC advisory and DIB cybersecurity support.
- Optiv: Optiv is a broad commercial cybersecurity services and solutions provider with a federal practice. It overlaps with SecureStrux on compliance advisory, vulnerability management, and SIEM integration, primarily serving larger enterprise clients.
Emerging players
- SteelCloud: SteelCloud builds STIG and compliance automation tools for DoD and federal customers, directly adjacent to SecureStrux's PowerStrux product line. It is smaller and more product-focused, competing for similar compliance-tooling budgets.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
SecureStrux social profiles
Digital presenceSecureStrux compliance and trust
Trust signalCompliance20 records
SecureStrux financial estimates
Financial estimateRevenue estimate
Valuation estimate
SecureStrux leadership team
Management profileNumber of profiles
Profiles10 records
SecureStrux funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SecureStrux M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SecureStrux
What does SecureStrux do?
SecureStrux provides end-to-end cybersecurity compliance, engineering, and staffing services to the U.S. Defense Industrial Base (DIB), federal/state/local government agencies, higher education institutions engaged in DoD research, and other critical infrastructure sectors. As an authorized C3PAO, the firm conducts official CMMC assessments and delivers compliance services spanning RMF, FISMA, CORA/CCRI, DFARS, and SIPRNet. It complements these services with the proprietary PowerStrux suite of continuous monitoring and auditing tools for Windows, Linux, ACAS/Tenable, and Active Directory environments.
Is SecureStrux a public or private company?
SecureStrux is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SecureStrux founded?
SecureStrux was founded in 2013. It employs 11 to 50 people.
Where is SecureStrux based?
SecureStrux is headquartered in Lancaster, United States, in the North America region.
How does SecureStrux make money?
Four revenue lines are on record. Cybersecurity Compliance Consulting Services are the primary driver. The others are engineering Solutions, cybersecurity Staffing and powerStrux Software Products.
Who are SecureStrux's main competitors?
Direct peers on record are Redspin, Coalfire Federal and By Light Professional IT Services. Broad incumbents are ManTech International, SAIC, Booz Allen Hamilton, Leidos, CACI International and Optiv. SteelCloud is listed as an emerging player.
Does SecureStrux have an API?
No public API is recorded for SecureStrux.