Kimmell Cybersecurity & Forensic Services
Kimmell Cybersecurity & Forensic Services is a CMMC Level 2 certified MSP/MSSP and C3PAO headquartered in Akron, Ohio, providing cybersecurity assessments, managed IT/security services, and digital forensics to Defense Industrial Base contractors, healthcare organizations, and mid-market enterprises.
- Company typePrivate
- Founded2017
- HeadquartersFairlawn, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Kimmell Cybersecurity & Forensic Services does
Kimmell Cybersecurity & Forensic Services (KCFS, LLC) is a privately held Managed Service Provider (MSP) and Managed Security Service Provider (MSSP) headquartered in Akron, Ohio, with a satellite office serving Central Texas. Founded by Brett Kimmell, the firm delivers cybersecurity assessments, compliance consulting, managed IT and security services, and digital forensics to Defense Industrial Base contractors, healthcare organizations, retail and payment processing companies, and mid-market enterprises. The company is founder-led, with Brett Kimmell serving as Managing Member and Principal, and Abdullah Alkhulaiwi serving as Partner and Senior Cybersecurity Consultant. Headcount is reported in the 11-50 range, consistent with a boutique consultancy.
The company's core offering portfolio centers on regulatory compliance capabilities anchored by its Certified Third-Party Assessment Organization (C3PAO) status and its CMMC Level 2 certification for MSP and MSSP services, achieved in July 2025 — a credential held by only a small number of firms authorized to both assess and provide Level 2 certified services. Products include DFARS and CMMC assessments, HIPAA risk assessments, INFOSEC assessments, PCI DSS compliance, vulnerability and penetration testing, digital forensics, and 24/7/365 managed IT and security monitoring built around NIST SP 800-171 Rev 2. Technical differentiators include CMMC-compliant monitoring infrastructure, a documented impartiality management system for CMMC assessing activities, and SOC 3 attestation. Leadership holds CISSP, CISA, CISM, CPA, CITP, CCA, and CCP certifications.
The business operates on a professional services and managed services revenue model with quote-based pricing and multi-year contracts. Go-to-market is primarily direct enterprise field sales targeting DoD contractors and healthcare organizations, supplemented by content marketing (blog and articles), organic social presence on LinkedIn, Facebook, and Twitter, and earned media coverage including Crain's Cleveland. Geographic focus is Northeast Ohio and Texas with stated national reach. No institutional investment, PE backing, or parent company has been disclosed, and the firm operates as an independent entity governed by Ohio law.
Kimmell Cybersecurity & Forensic Services firmographics
Firmographics- Name
- Kimmell Cybersecurity & Forensic Services
- Legal name
- KCFS, LLC
- Website
- https://kimmell.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Kimmell Cybersecurity & Forensic Services is a CMMC Level 2 certified MSP/MSSP and C3PAO headquartered in Akron, Ohio, providing cybersecurity assessments, managed IT/security services, and digital forensics to Defense Industrial Base contractors, healthcare organizations, and mid-market enterprises.
- Ownership category
- akta.pro rank
Kimmell Cybersecurity & Forensic Services industry classification
Industry- Product category
- Cybersecurity Managed Services & Compliance Consulting
- NAICS
- Computer Facilities Management Services (541513), Computer Systems Design and Related Services (54151), Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
- akta.pro secondary industries
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG), Remote Monitoring & Management (RMM) Services (BPAEABAA)
Keywords
Where Kimmell Cybersecurity & Forensic Services is headquartered
LocationHeadquarters
- HQ city
- Fairlawn
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Kimmell Cybersecurity & Forensic Services business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Managed IT Services: Ongoing managed IT and security services including 24/7 monitoring, device provisioning, account management, vendor security management, service availability monitoring, backup monitoring, and incident response.
- Compliance Assessments: CMMC, DFARS, HIPAA, INFOSEC, and PCI DSS compliance assessments and consulting services delivered by certified assessors.
- Security Testing: Vulnerability assessments, penetration testing, and web application security testing services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Quote-based professional services |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
Kimmell Cybersecurity & Forensic Services product offering
Product offeringCore offering
Kimmell Cybersecurity is a CMMC Level 2 certified Managed Service Provider (MSP) and Managed Security Service Provider (MSSP) that sells compliance assessments (CMMC, DFARS, HIPAA, INFOSEC, PCI DSS), managed IT and security services, vulnerability and penetration testing, and digital forensics investigations primarily to DoD contractors, healthcare organizations, and enterprises. The firm operates as a Certified Third-Party Assessment Organization (C3PAO) authorized to both audit and provide compliant managed services at CMMC Level 2.
Product overview
Kimmell Cybersecurity & Forensic Services operates as a Managed Service Provider (MSP) and Managed Security Service Provider (MSSP) offering a portfolio of cybersecurity services and assessments. The core offerings include Managed Security Solutions for policy development, Managed IT Services for 24/7 infrastructure management, and specialized compliance assessments including DFARS & CMMC Assessments, HIPAA Risk Assessments, INFOSEC Assessments, PCI DSS Compliance, and Vulnerability & Penetration Testing. Digital Forensics services address investigation and litigation support needs. The company holds CMMC Level 2 certification for its MSP and MSSP offerings, making it one of the few C3PAOs to both assess and provide certified services at Level 2. Services like Cloud Solutions, Backup & Recovery, Multi-Location Support, Network Security, and Mobile Device Management are integrated features within the managed services framework.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Security Solutions Enterprise security policy, standards, and procedures development and assessment services that analyze an organization's existing policies, procedures, and standards against industry best practices to strengthen its overall security posture. Targeted at businesses seeking to formalize or improve their information security governance.
- Managed IT Services 24/7 monitoring, management, and problem resolution for all IT systems within a business, including new device and account provisioning, account management, vendor security management, service availability monitoring, hardened configurations, DNS management, backup monitoring, IT asset inventory, software licensing, incident response, and help desk ticket resolution. Offered to businesses that want to outsource IT operations to a CMMC-aware provider.
- DFARS & CMMC Assessments Cybersecurity Maturity Model Certification (CMMC) and Defense Federal Acquisition Regulation Supplement (DFARS) compliance assessments that audit DoD contractors against the 110 controls in 14 control families and assign a CMMC maturity level, enabling contractors handling Controlled Unclassified Information to bid on and maintain DoD contracts. Delivered by a Certified Third Party Assessor Organization (C3PAO).
- HIPAA Risk Assessments Risk assessments for organizations handling protected health information (PHI) that review administrative, physical, and technical safeguards to uncover potential weaknesses in security policies, processes, and systems, helping to prevent electronic health information data breaches. Targeted at healthcare providers and business associates.
- INFOSEC Assessments Independent, enterprise-wide assessment of corporate security covering enterprise-wide policy, security staffing adequacy, IT asset management lifecycle, personnel security, physical security, VOIP and mobile communications, network security, application security, business continuity and disaster recovery, cybersecurity awareness training, incident response planning, core information systems, internet connectivity, cloud computing, and regulatory compliance.
- PCI DSS Compliance Compliance services helping companies that process, transmit, or store credit card data comply with PCI DSS 3.0 standards, providing a more secure environment for processing credit card transactions. Targeted at retailers, e-commerce companies, and payment processors.
- Vulnerability & Penetration Testing External penetration testing and vulnerability scanning services that use automated vulnerability assessment software and ethical hacking techniques to proactively identify weaknesses in an organization's computer systems and networks, including protection against insider threats. Generates reports that organizations can use to improve security.
- Digital Forensics
- CMMC Level 2 Compliant Managed IT Services CMMC Level 2 certified managed services that meet the rigorous standards of the CMMC Level 2 and NIST SP 800-171 Rev 2 framework, providing DoD contractors handling Controlled Unclassified Information with a fully compliant managed service environment delivered by one of the few C3PAOs authorized to both assess and provide services at this level.
Quantifiable outcome
- CMMC Level 2 Certification achieved for MSP and MSSP services
Companies that use Kimmell Cybersecurity & Forensic Services
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles4 records
Kimmell Cybersecurity & Forensic Services technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Kimmell Cybersecurity & Forensic Services partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- Defense Industrial Base (DoD contractors)coreCore customer base of DoD contractors requiring CMMC compliance. The company serves as both assessor and service provider for this ecosystem.
- Healthcare OrganizationscoreHealthcare sector clients requiring HIPAA compliance and risk assessments for protected health information.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Kimmell Cybersecurity & Forensic Services competitors and assessment
Company assessmentDirect peers
- Summit 7 (now ATSG): Specialized CMMC/DFARS managed services and compliance firm serving Defense Industrial Base contractors; near-direct competitor to Kimmell with overlapping assessment plus managed services delivery model.
- Redspin (now part of Coalfire Federal): Authorized C3PAO providing CMMC assessments plus broader cybersecurity services; competes head-to-head with Kimmell for CMMC Level 2 assessment work in the DIB.
- A-LIGN: Cybersecurity compliance assessor offering SOC, ISO, HITRUST, PCI and CMMC services; comparable in compliance assessment plus advisory mix targeting mid-market and regulated enterprises.
- Schellman & Co: Top-tier compliance assessor covering SOC, ISO, HITRUST, PCI DSS and FedRAMP; competes with Kimmell for assessment engagements from regulated mid-market and federal-adjacent clients.
- BARR Advisory: Cybersecurity and compliance advisory firm offering SOC, ISO, HITRUST, PCI and CMMC services; similar mid-market assessor profile with both consulting and managed service elements.
- Pivot Point Security: C3PAO and CMMC-focused consultancy providing readiness, assessment, and managed services to DoD contractors; comparable niche positioning to Kimmell in the DIB market.
- SecureStrux: CMMC/DFARS/NIST 800-171 consultancy and managed services firm targeting defense industrial base; similar assessment plus managed compliance delivery model to Kimmell.
Broad incumbents
- Coalfire: Large cybersecurity advisory with deep CMMC, FedRAMP, and PCI practice; competes on larger federal and enterprise assessments where Kimmell is typically not engaged.
- Kforce (formerly Kforce Government Solutions): Large staffing and compliance services provider with federal cybersecurity and CMMC practice; provides scale and bench depth Kimmell lacks, particularly on government contracts.
Regional players
- MBL Technologies: Federal cybersecurity services firm serving DoD and intelligence clients; comparable in CMMC/NIST expertise but typically operates at larger enterprise and federal agency scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Kimmell Cybersecurity & Forensic Services social profiles
Digital presenceKimmell Cybersecurity & Forensic Services compliance and trust
Trust signalCompliance5 records
Kimmell Cybersecurity & Forensic Services financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kimmell Cybersecurity & Forensic Services leadership team
Management profileNumber of profiles
Profiles2 records
Kimmell Cybersecurity & Forensic Services funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kimmell Cybersecurity & Forensic Services M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kimmell Cybersecurity & Forensic Services
What does Kimmell Cybersecurity & Forensic Services do?
Kimmell Cybersecurity is a CMMC Level 2 certified Managed Service Provider (MSP) and Managed Security Service Provider (MSSP) that sells compliance assessments (CMMC, DFARS, HIPAA, INFOSEC, PCI DSS), managed IT and security services, vulnerability and penetration testing, and digital forensics investigations primarily to DoD contractors, healthcare organizations, and enterprises. The firm operates as a Certified Third-Party Assessment Organization (C3PAO) authorized to both audit and provide compliant managed services at CMMC Level 2.
Is Kimmell Cybersecurity & Forensic Services a public or private company?
Kimmell Cybersecurity & Forensic Services is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Kimmell Cybersecurity & Forensic Services founded?
Kimmell Cybersecurity & Forensic Services was founded in 2017. It employs 11 to 50 people.
Where is Kimmell Cybersecurity & Forensic Services based?
Kimmell Cybersecurity & Forensic Services is headquartered in Fairlawn, United States, in the North America region.
How does Kimmell Cybersecurity & Forensic Services make money?
Three revenue lines are on record. Managed IT Services are the primary driver. The others are compliance Assessments and security Testing.
Who are Kimmell Cybersecurity & Forensic Services's main competitors?
Direct peers on record are Summit 7 (now ATSG), Redspin (now part of Coalfire Federal), A-LIGN, Schellman & Co, BARR Advisory, Pivot Point Security and SecureStrux. Broad incumbents are Coalfire and Kforce (formerly Kforce Government Solutions). MBL Technologies is listed as a regional player.
Does Kimmell Cybersecurity & Forensic Services have an API?
No public API is recorded for Kimmell Cybersecurity & Forensic Services.
What industry is Kimmell Cybersecurity & Forensic Services in?
Kimmell Cybersecurity & Forensic Services's product category is Cybersecurity Managed Services & Compliance Consulting. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of HDADAGAG, Managed Detection & Response (MDR) & SOC Services. Its NAICS code is 541513 and its SIC code is 7370.