Ciseve
CISEVE is a Cyber AB-accredited C3PAO delivering CMMC Level 2 assessments, FISMA, ISO, and ICS cybersecurity compliance services to U.S. Defense Industrial Base contractors, federal agencies, and state and local jurisdictions. The firm earns revenue through professional services engagements and an ongoing Assessment Assurance subscription.
- Company typePrivate
- Founded-
- HeadquartersLas Vegas, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Ciseve does
CISEVE Inc. is a Las Vegas-headquartered cybersecurity compliance and assessment firm serving the U.S. Defense Industrial Base (DIB), federal agencies, state and local jurisdictions, and critical infrastructure operators. The company is one of the first organizations accredited by Cyber AB as a CMMC Third-Party Assessment Organization (C3PAO), authorized to conduct official Cybersecurity Maturity Model Certification Level 2 assessments against the 110 NIST SP 800-171 security controls required for DoD contractors handling Controlled Unclassified Information (CUI). The CEO, Michael Dempsey, is among the first Certified CMMC Assessors (CCA) and brings prior Chief Security Officer experience from the Massachusetts Department of Health & Human Services along with credentials including CISSP, CISA, and PMP.
The firm's service portfolio is centered on the CMMC assessment lifecycle — official Level 2 assessments (renewable every 3 years), pre-assessment Mock Assessments for gap identification, and an Assessment Assurance subscription providing ongoing POA&M support and locked-in multi-year pricing. Adjacent services extend the platform into FISMA compliance (NIST SP 800-53), ISO certification consulting, pen testing and vulnerability scanning, ICS/SCADA assessments for utilities and manufacturing, and state/local compliance work. CISEVE also partners with SecureCMMC enclave and conducts joint webinars with MNS Group and Evolved Cyber to round out its advisory ecosystem. Registered government contractor credentials include NAICS 541519 and CAGE 8VNW0, with a dual-coast footprint in Las Vegas, NV and Burlington, MA.
Commercially, CISEVE operates as a sales-led, consultative enterprise field sales organization targeting defense contractors through direct phone outreach (888-4CISEVE), website contact forms, free consultations, content marketing via an active blog, and webinar-driven thought leadership. Pricing is quote-based across engagement scope and complexity, with the Assessment Assurance program offering the only recurring/managed revenue stream. The company is privately held with no disclosed external funding, a 1-10 person team, and no reported revenue figures; the business model is fundamentally professional services — selling accredited human expertise and methodology rather than a software product.
Ciseve firmographics
Firmographics- Name
- Ciseve
- Legal name
- CISEVE Inc.
- Website
- https://ciseve.com
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- CISEVE is a Cyber AB-accredited C3PAO delivering CMMC Level 2 assessments, FISMA, ISO, and ICS cybersecurity compliance services to U.S. Defense Industrial Base contractors, federal agencies, and state and local jurisdictions. The firm earns revenue through professional services engagements and an ongoing Assessment Assurance subscription.
- Ownership category
- akta.pro rank
Ciseve industry classification
Industry- Product category
- Cybersecurity Compliance & Assessment Services
- NAICS
- Testing Laboratories and Services (54138)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Third-Party Certification, Code Compliance & Regulatory Inspection (ASME/API/ISO) (EUAEAHAN)
Keywords
Where Ciseve is headquartered
LocationHeadquarters
- HQ city
- Las Vegas
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Ciseve business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure, Others
Revenue model
- CMMC Assessments: Official CMMC Level 2 assessments conducted by authorized C3PAO assessors. Organizations require this certification to win Defense contracts involving CUI. Revenue generated through one-time assessment fees with renewals required every 3 years.
- Mock Assessments: Pre-assessment services simulating CMMC audit experience to identify gaps. Includes gap analysis, remediation recommendations, and roadmap creation.
- Assessment Assurance Program: Ongoing compliance support and program management services to maintain certification status, including long-term budgeting and locked-in pricing.
- FISMA Compliance Services: Federal Information Security Modernization Act compliance including new system documentation, annual continuous monitoring, contingency plans, incident response plans, vulnerability scanning, and penetration testing.
- State and Local Compliance Services: Cybersecurity assessments and resource augmentation for state and local jurisdictions, including NIST SP 800-171 evaluations.
- ICS Assessments: Industrial Control Systems assessments for utilities, manufacturing, transportation, and environmental systems including SCADA, DCS, and PLC evaluations.
- ISO Services: International Organization for Standardization consulting for all ISO standards including certification preparation, document review, and management system development.
- Gap Analysis: Evaluation of organizational security posture versus regulatory or contract requirements to identify compliance gaps.
- Pen Testing: Vulnerability scanning and penetration testing services to identify and exploit system weaknesses.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | CMMC Level 2 Assessment - Full scope assessment for organizations handling CUI |
| Other | Multi-year contract | Mock Assessment - Pre-assessment gap identification service |
| Subscription | Annual | Assessment Assurance - Ongoing compliance program management |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
Ciseve product offering
Product offeringCore offering
CISEVE is an authorized CMMC Third-Party Assessment Organization (C3PAO) that conducts official CMMC Level 2 assessments, Mock Assessments, and ongoing Assessment Assurance for Defense Industrial Base contractors. The firm also delivers complementary cybersecurity compliance services spanning FISMA, ISO certification consulting, Gap Analysis, Pen Testing, State and Local compliance, and Industrial Control System assessments. Engagements are quote-based professional services delivered by certified CMMC Assessors and senior cybersecurity practitioners.
Product overview
CISEVE offers a unified portfolio of cybersecurity assessment and compliance services centered on CMMC certification. The core offerings include CMMC Assessments (Level 2 third-party assessment by authorized C3PAO), Mock Assessments for gap identification, and Assessment Assurance for ongoing compliance maintenance. Supporting services include Gap Analysis, FISMA Compliance, ISO Services, Pen Testing, State & Local Compliance, and ICS Assessments. CISEVE also partners with SecureCMMC Enclave, a FedRAMP High-based compliant environment solution that organizations can use to meet CMMC requirements without infrastructure overhaul.
Differentiator
Problem solved
Functional benefit
Products and services
- CMMC Level 2 Assessments Official CMMC Level 2 assessments conducted by authorized C3PAO assessors to verify implementation of NIST SP 800-171 security controls for DoD contractors handling Controlled Unclassified Information. Required every three years for DoD contract eligibility.
- Mock Assessments Pre-assessment simulation that mirrors the CMMC audit experience to identify process gaps before official certification, helping organizations prepare on their own timeline without the scoring risk of a real assessment.
- Assessment Assurance Ongoing compliance program providing long-term tracking, POA&M support, and advisory services to maintain CMMC certification across the 3-year renewal cycle, with locked-in pricing and support for the Affirming Official's yearly attestation.
- Gap Analysis Evaluation service that identifies where an organization stands versus required compliance levels for specific regulations, contract requirements, or desired security posture improvements.
- FISMA Compliance Services FISMA compliance services for federal agencies and contractors, including new system documentation, annual continuous monitoring, contingency plans, incident response plans, vulnerability scanning, and penetration testing aligned to NIST SP 800-53.
- ISO Services Consulting and certification preparation for ISO standards, including management system development, document review, and audit training for organizations pursuing or maintaining ISO certification.
- Pen Testing Vulnerability scanning and penetration testing services that identify potential weaknesses and exploit system vulnerabilities to evaluate an organization's security posture.
- State and Local Compliance Services Cybersecurity assessments and resource augmentation for state and local jurisdictions that store, transmit, or maintain citizen information, including current status assessments, recommendations, and NIST SP 800-171-aligned evaluations.
- ICS Assessments Industrial Control System assessments covering SCADA, distributed control systems (DCS), and Programmable Logic Controllers (PLC) for utilities, manufacturing, transportation, and environmental systems.
Quantifiable outcome
- CMMC Level 2 certification valid for 3 years
- +2 more outcomes
Companies that use Ciseve
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles4 records
Ciseve technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Ciseve partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- MNS GroupcoreMNS Group is a strategic partner that co-hosts webinars with CISEVE on CMMC compliance topics. CISEVE CEO Michael Dempsey speaks with MNS Group's Tobias Musser on CMMC-related webinars including SecureCMMC enclave discussions.
- Cyber ABcoreCyber AB is the official accreditation body for the CMMC ecosystem. CISEVE holds authorized C3PAO status granted by Cyber AB, which manages training and certification of assessors and C3PAO organizations.
- Evolved Cyber, LLCminorEvolved Cyber, LLC co-presented a webinar with CISEVE on 48 CFR regulations and CMMC compliance, featuring President Brian Hubbard alongside CISEVE CEO Michael Dempsey.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Ciseve competitors and assessment
Company assessmentDirect peers
- RISC Point: RISC Point is an authorized C3PAO delivering CMMC assessments, CMMC readiness, and managed compliance services to DIB contractors, competing in the same target segment with similar service packaging.
- MNS Group: MNS Group is a strategic webinar co-host and CMMC ecosystem partner delivering defense cybersecurity services to DIB contractors, with overlapping customer base and assessment-adjacent offerings.
- Pondurance: Pondurance provides CMMC assessment services alongside managed detection, response, and compliance consulting for defense contractors and critical infrastructure operators.
- Coalfire Federal: Coalfire Federal is a large authorized C3PAO providing CMMC, FedRAMP, FISMA, and cybersecurity assessment services to federal agencies and contractors, directly overlapping with CISEVE's full compliance portfolio.
- Summit 7: Summit 7 is an authorized C3PAO specializing in CMMC assessments and Microsoft GCC High cloud enablement for defense contractors, competing head-to-head in the same DIB certification market.
- Redspin (A-LIGN): A-LIGN is one of the most established authorized C3PAOs providing CMMC Level 2 assessments, FISMA, ISO, and broader cybersecurity compliance audits — directly comparable as a competing C3PAO serving the same DIB market.
- Schellman & Co. Schellman is a major CMMC C3PAO and ISO certification body providing cybersecurity and compliance assessments, directly comparable in methodology, customer type, and accreditation profile.
Broad incumbents
- Booz Allen Hamilton: Booz Allen is a large federal consulting incumbent providing FISMA, FedRAMP, and CMMC-adjacent cybersecurity services to DoD and federal agencies, offering overlapping capabilities as part of a much broader portfolio.
- Deloitte (Cyber & Strategic Risk): Deloitte's cyber practice delivers FISMA, CMMC readiness, ISO certification support, and ICS assessments to federal and DIB clients — a broad incumbent with overlapping services but not a pure-play C3PAO.
Others
- SecureCMMC: SecureCMMC provides the FedRAMP High enclave solution referenced by CISEVE for CUI handling under CMMC; it is a technology partner / infrastructure provider rather than a direct assessment competitor.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Ciseve social profiles
Digital presenceCiseve compliance and trust
Trust signalCompliance2 records
Ciseve financial estimates
Financial estimateRevenue estimate
Valuation estimate
Ciseve leadership team
Management profileNumber of profiles
Profiles1 record
Ciseve funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Ciseve M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Ciseve
What does Ciseve do?
CISEVE is an authorized CMMC Third-Party Assessment Organization (C3PAO) that conducts official CMMC Level 2 assessments, Mock Assessments, and ongoing Assessment Assurance for Defense Industrial Base contractors. The firm also delivers complementary cybersecurity compliance services spanning FISMA, ISO certification consulting, Gap Analysis, Pen Testing, State and Local compliance, and Industrial Control System assessments. Engagements are quote-based professional services delivered by certified CMMC Assessors and senior cybersecurity practitioners.
Is Ciseve a public or private company?
Ciseve is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Ciseve founded?
Ciseve was founded in -1. It employs 1 to 10 people.
Where is Ciseve based?
Ciseve is headquartered in Las Vegas, United States, in the North America region.
How does Ciseve make money?
Nine revenue lines are on record. CMMC Assessments are the primary driver. The others are mock Assessments, assessment Assurance Program, FISMA Compliance Services, state and Local Compliance Services, ICS Assessments, ISO Services, gap Analysis and pen Testing.
Who are Ciseve's main competitors?
Direct peers on record are RISC Point, MNS Group, Pondurance, Coalfire Federal, Summit 7, Redspin (A-LIGN) and Schellman & Co.. Broad incumbents are Booz Allen Hamilton and Deloitte (Cyber & Strategic Risk). SecureCMMC is listed as an others.
Does Ciseve have an API?
No public API is recorded for Ciseve.
What industry is Ciseve in?
Ciseve's product category is Cybersecurity Compliance & Assessment Services. Its primary akta.pro industry code is EUAEAHAN, Third-Party Certification, Code Compliance & Regulatory Inspection (ASME/API/ISO). Its NAICS code is 54138 and its SIC code is 8734.