Placeholder site · Plumbline Works LLC · Full site in development
Cybersecurity Compliance Consultancy · Berkeley Springs, WV

Information assurance, grounded in truth.

We help federal, Defense Industrial Base, and commercial organizations achieve and sustain compliance, with documentation and outcomes built on evidence, not checklists, and engineered to withstand independent assessment.

Who we are

Plumbline Works is a West Virginia cybersecurity compliance firm serving the Defense Industrial Base, federal agencies, and commercial clients.

We deliver advisory, assessment, and audit-readiness work for the CMMC program and the NIST Risk Management Framework, and we are building scalable training to help close the national shortage of qualified CMMC professionals.

18+Years of assurance experience
50+Federal systems supported
L1–2CMMC readiness & assessment prep
Our philosophy
“We stand on the shoulders of giants — we honor their work by remembering.”

As a generation of information-assurance pioneers retires, the understanding of why these processes exist is becoming scarce. We carry forward the discipline behind the foundational certification-and-accreditation lineage as a new generation steps in, evaluating the cross-functional process that produces a result, not just the field in a GRC tool.

TCSECDITSCAPDIACAPFISMA / RMFCMMC
Current services

What we do today

Senior-led delivery available now, resting on existing expertise, no certification required to begin.

01

CMMC Readiness & Assessment Prep

Levels 1–2 readiness, gap assessments, and C3PAO assessment preparation that substantiates the controls you've truly implemented.

02

NIST 800-171 / 800-53 / 800-53A

Implementation and assessment against the NIST control families, applied with audit-grade rigor.

03

RMF & cATO Enablement

Security categorization (FIPS 199 / SP 800-60), control assessment, continuous ATO enablement, and FedRAMP advisory.

04

SSPs, POA&Ms & Policy

System Security Plans, Plans of Action & Milestones, and policies and procedures built to withstand independent scrutiny.

05

Independent Control Assessment

Security control assessment and analyst support, delivered directly or as a subcontractor to C3PAOs, ATPs, and primes.

06

vCISO & GRC Advisory

Fractional virtual-CISO retainers and governance, risk & compliance advisory suited to small and mid-size DIB clients.

Differentiators

Why it's different

Audit-grade evidence, not checklist compliance
AICPA attestation discipline (control design vs. operating effectiveness, sufficiency of evidence, burden of proof) applied to CMMC and NIST assessment work.
The process behind the checkbox
Grounded in legacy C&A lineage, we evaluate the cross-functional process that produces a result, with disciplined categorization rather than approximate impact levels.
Automation that earns its place
Firmly pro-automation and cATO, but never zero-to-autonomous overnight. We target real bottlenecks and deliver near-term efficiency without hollowing out the rigor beneath.
Senior-led delivery
18+ years of hands-on assurance: experienced judgment over junior hand-offs and checkbox tooling.
Where we're going

Training roadmap

A deliberate credential ladder building toward authorized CMMC certification instruction: CCP and CCA training courses delivered as, or under, an ISACA Approved Training Provider.

Available now

Independent readiness trainingLive

Workshops, executive briefings, CUI-handling training, and implementation courses, sold on expertise alone, requiring no ecosystem approval.

Phase 1: In development

Self-study video curriculum

Recorded, on-demand courseware for CMMC and NIST RMF, a build-once, learn-anywhere product that scales beyond live delivery.

CCP earned
Phase 2: Planned

Assessment & advanced courses

Expanded assessment support and RMF training as the Certified Assessor credential comes online and an ATP / C3PAO relationship is established.

CCA earned
Phase 3: The destination

Authorized CCP / CCA certification training

Official, instructor-led CMMC certification training delivered as, or under, an ISACA Approved Training Provider, taught by a CMMC Certified Instructor.

CCI earnedATP authorized
N Founder & Managing Member

Noah Walley

Berkeley Springs, West Virginia
CISM, ISACA IBM Generative & Agentic AI Architect CMMC CCP / CCA / CCI (in progress)
The person behind the work

Eighteen years of federal cybersecurity and compliance.

Noah leads Plumbline Works after delivery leadership at IBM Consulting, where he supported federal cybersecurity across 50+ systems in AWS GovCloud, Azure Government, and IBM Cloud, including audit readiness for FedRAMP High, DISA IL4/5, HIPAA, and NIST RMF, most recently leading federal cyber threat management.

Earlier work spans GRC and audit support for federal financial systems under FISCAM and FFMIA, independent NIST SP 800-53 assessment, and system authorization and control testing under DIACAP, FISMA, and early RMF: the full arc of modern federal assurance practice.

Get in touch

Let's talk about your compliance goals.

Emailcontact@plumblineworks.com
Location

Berkeley Springs, Morgan County, WV

NAICS

541512 · 541519 · 541611 · 541690