About
Compliance expertise built inside the agencies that write the rules.
ManageIT Security is an authorized CMMC Third-Party Assessment Organization specializing in Level 2 certification assessments, founded and led by Rosalyn Foltz.

Rosalyn Foltz
CISSP, Lead Certified CMMC Assessor
Rosalyn Foltz founded ManageIT Security to give organizations something the compliance market makes surprisingly hard to find: an assessor with no stake in the outcome. The firm is an authorized C3PAO, one of roughly a hundred organizations cleared to conduct CMMC Level 2 certification assessments.
Rosalyn Foltz has spent 18 years in cybersecurity compliance — first inside the federal government, then advising the organizations regulated by it. She has led more than 40 CMMC Level 2 assessments.
Her career spans audit work at the Government Accountability Office, advisory engagements at KPMG, security program work at the U.S. Department of State, and enterprise compliance at E*TRADE. That combination — regulator, auditor, and practitioner — shapes how every ManageIT Security assessment is run.
She works with clients directly. Assessments are not delegated.
Depth beyond CMMC
CMMC assessments are the entire practice today, but the judgment behind them was built across a wider field. Rosalyn has worked through NIST 800-53, FedRAMP and FISMA environments, in defense, healthcare, finance and federal agencies, and spent years inside E*TRADE Financial, the U.S. Department of State, KPMG and the Government Accountability Office.
That range matters in an assessment. Controls rarely fail in isolation, and an assessor who has only ever seen one framework tends to read a finding narrowly. Knowing how the same control behaves under different regimes is what separates a checklist from an informed judgment.
We no longer offer advisory work in any of those frameworks. The experience stays; the conflict does not.
Credentials
- C3PAOAuthorized CMMC Third-Party Assessment Organization (C3PAO)
- Lead Certified CMMC Assessor (LCCA)
- Certified Information Systems Security Professional (CISSP)
- B.S. Management Information Systems, George Mason University
- M.A. Global Affairs, IT Policy concentration, George Mason University
Background
GAO
Federal audits of agency information security programs.
KPMG
Advisory engagements across regulated industries.
U.S. Department of State
Security program and control assessment work.
E*TRADE
Enterprise security compliance in financial services.
We assess. We do not consult.
A certification assessment is only worth what the assessor's independence is worth. As an authorized C3PAO, that independence is not a preference, it is the basis on which we are allowed to do this work.