Services
Three disciplines,
one standard of care
Every engagement is scoped to the facility and the program, and led by a principal. Start with an assessment, or bring us in at whichever point needs senior attention.
01Entry point
Physical Security & Construction Surveillance
Threat and vulnerability assessments, owner-side security design and engineering, ICD 705 secure-space support, and cleared Construction Surveillance Technicians (CST) on secure builds.
Physical security & CST →02
Cybersecurity Assessments & Compliance
NIST SP 800-171 gap assessments, SPRS scoring, SSP and POA&M development, CMMC readiness and mock assessment, and CUI programs a real team can run.
Cyber & CMMC →03
TSCM Sweeps
Technical surveillance countermeasure inspections of boardrooms, program spaces, labs, and secure areas — RF, physical, and infrastructure, documented discreetly.
TSCM sweeps →How To Engage
Four ways clients actually start
-
A fixed-fee assessment
The most common entry. Physical, cyber, or both, scoped to one facility or program. You get a prioritized, costed roadmap you own — executable with anyone, including without us.
-
A single sweep
One room, one floor, one event. No relationship required. Many clients meet us this way and never need anything else; some discover they need considerably more.
-
Project support
CST coverage on a secure build, design review through commissioning, or compliance artifact development against a deadline. Defined scope, defined end.
-
Standing counsel
A quiet, senior, fractional security function — periodic sweeps, annual affirmations, accreditation cycles, inspection readiness, and the phone call before a decision.
How We Practice
The constraints are the point
Candor over contract value. If you don't need us, we say so. If the cheaper fix works, we recommend it.
Vendor neutrality. We sell no hardware, resell no monitoring, and take no referral fees. Our only product is judgment.
Independence from the assessment. We are not a C3PAO and not an accrediting authority. We prepare you for those decisions instead of grading them.
Discretion. We don't name clients, publish case studies with fingerprints, or market on your risk.
Standards as floor, not ceiling. Compliance is where protection starts, not where it ends.
Who We Serve
Built for industries carrying national risk
Our practice is deliberately narrow: organizations whose compromise would be measured in national or economic terms rather than inconvenience.
- Data centers & AI compute campuses — hyperscale, colocation, enterprise, and the new generation of training and inference facilities
- Aerospace & space systems — launch, satellite and payload manufacturing, integration and test
- Defense technology & advanced manufacturing — autonomy, munitions, microelectronics, and the new primes
- Network & energy infrastructure — switching centers, carrier hotels, substations, and on-site generation
- Cleared industry & federal-adjacent programs — organizations carrying NISPOM, FAR/DFARS, or program-specific obligations
Next Step
Not sure which engagement fits?
Describe the facility or the program in one paragraph. A principal will tell you what we'd recommend — and what we wouldn't bother with.
Prefer to talk? 866.960.7475 · info@orbitalfederal.com