Orbital FederalFederal

National Security Infrastructure

The facilities that carry
national risk need more than a vendor.

Data centers, aerospace, defense technology, and advanced manufacturing. Orbital Federal secures the physical layer, closes the cyber-compliance gap, and sweeps the rooms where the sensitive conversations happen — to the standards the government wrote for its own programs.

  • PhysicalCST · ICD 705 · assessments
  • CyberCMMC · NIST SP 800-171
  • TechnicalTSCM sweeps
  • OwnershipService-disabled veteran-owned

01Why Now

National security stopped being a government address.

The capability the country depends on is being built inside private companies. AI compute is going into commercial data centers. Launch and satellite production sit on commercial campuses. Autonomy, munitions, and microelectronics are being built by firms that did not exist a decade ago.

Those companies inherited the government's threat environment without inheriting its security apparatus. The requirements arrive anyway — in a DFARS flow-down, a customer's ICD number, a facility clearance, an insurer's condition, a program office's inspection.

Meanwhile the exposure is rarely where the budget is. Most security spending goes to the network. But the sensitive program sits in a room that has never been swept, behind a perimeter designed by a civil engineer, built by trades nobody vetted, on a site where the drawings themselves were the leak.

We work the whole surface. One threat picture, three disciplines, one firm accountable for the answer.

03The Seam

The gap between the guard and the firewall

Physical and cyber security are still bought from different vendors, reported to different executives, and audited on different calendars. Adversaries work the seam.

An access control system is a network of credentialed doors — and a network. A building management system runs on the same plant as the compute it cools. An uncleared electrician on a secure construction site defeats a $2M network investment with a drill. A conference room with an unmanaged smart display is an uncontrolled microphone inside a program space.

We assess these together because the NIST physical and environmental protection family, ICD 705, and NISPOM all assume someone is doing exactly that. Usually nobody is.

04Our Baseline

We speak the standards.

The strongest security doctrine in the world was written for government facilities and programs. We apply it fluently, and translate it for private owners.

  • ICD 705 & the IC Tech Spec — design, construction, and management of SCIFs and secure spaces, including construction security and CST practice
  • 32 CFR Part 117 (NISPOM) — the National Industrial Security Program rule for cleared industry
  • CMMC (32 CFR Part 170) & NIST SP 800-171 — CUI protection, SPRS scoring, and assessment readiness
  • DFARS 252.204-7012 / -7019 / -7020 / -7021 — the clauses through which cyber obligations actually reach you
  • NIST SP 800-53 physical & environmental controls — the PE family, where physical and cyber compliance meet
  • NERC CIP-014, UFC 4-010-01, TIA-942 — grid, antiterrorism, and data center criteria
The full standards ledger →

Or read our plain answers to common questions →

05How It Works

A deliberate path, not a pitch deck

  1. A direct conversation

    Thirty minutes with a principal — no business-development layer. You describe the facility, the program, or the concern. We tell you honestly what we would look at and whether you need us at all.

  2. Assessment

    We walk the site, review the drawings and the system security plan, sweep the room if that is the question, and test assumptions against threat and standard alike. You get a prioritized, costed roadmap you own — whether or not we execute it.

  3. Execution support

    We embed with your architects, engineers, integrators, and IT — vendor-neutral, owner-side. On secure construction we put cleared CSTs on site. On compliance we build the artifacts an assessor will actually ask for.

  4. Standing counsel

    Programs evolve; so do threats and rules. Most clients keep us as a quiet senior resource — periodic sweeps, annual affirmations, accreditation cycles, and the phone call before a decision.

06Who's Behind It

Two principals. Federal-grade, private-sector fast.

Orbital Federal is founded and led by two principals — both service-disabled veterans, both shaped by careers across multiple federal agencies, both MBAs who crossed into the private sector deliberately.

We kept the firm small on purpose. The people who assess your facility are the people whose names are on the door, and the standard of care is the one we learned protecting the government's own.

SDVVeteran-owned & led
.govMultiple agencies
MBA ×2Both principals
1:1Principal-delivered

The country's most sensitive work now happens on private property. The security has to travel with it.

Orbital Federal · Firm Ethos

07Common Questions

Asked by almost every owner, the first time

What does Orbital Federal actually do?
Three things. Physical security — assessments, owner-side design, and cleared Construction Surveillance Technicians (CST) for secure construction under ICD 705. Cybersecurity — NIST SP 800-171 and CMMC readiness assessments, SSP and POA&M development, and CUI program work. And TSCM — technical surveillance countermeasure sweeps of sensitive spaces. All three for companies whose work carries a national security nexus.
Why do data centers, aerospace, and defense companies need one firm for all three?
Because the adversary does not respect the org chart. A cleared program with a hardened network and an unswept conference room is not protected. Neither is a data center with a perfect SOC and an uncontrolled construction site. We work the physical, cyber, and technical layers against one threat picture instead of three disconnected vendors.
Are you a C3PAO or an accrediting authority?
No, and that is deliberate. Accreditation decisions rest with the cognizant government office, and CMMC certification rests with an authorized C3PAO. We prepare you for those decisions and sit on your side of the table when they are made. Being independent of the assessment is what lets us be honest about what we find.
Do you sell hardware or place guards?
Neither. We take no referral fees, resell no systems, and staff no guard posts. Our only product is judgment. The exception is CST support, which is a specialist security role we deploy directly because the standard requires cleared personnel who answer to security, not to the builder.
How do engagements start?
Thirty minutes with a principal. You describe the facility, the program, or the concern; we tell you what we would look at, in what order, and whether you need us at all. Most work then begins with a fixed-fee assessment.

Next Step

Find out where you actually stand.

A direct conversation with a principal costs nothing and commits you to nothing. If you don't need us, we'll say so.

Prefer to talk? 866.960.7475 · info@orbitalfederal.com