
Northern Virginia · Cybersecurity
Testing, gap assessments, and remediation support for NoVA contractors and SaaS vendors — advisory only, with clear boundaries on certifications we cannot issue.
Capabilities
Northern Virginia concentrates defense tech, integrators, and cloud shops facing overlapping customer questionnaires. We translate frameworks into prioritized fixes your engineers can schedule.
Gap assessments against SP 800-171, CSF 2.0, and CMMC Level 2 practices — POA&M and evidence prep included.
External, internal, web app, and phishing engagements with executive and engineer-readable reports.
Authenticated scanning plus analyst review — prioritized by business risk, not raw CVSS alone.
Playbooks, tabletop exercises, and retainer-based response support — roles defined upfront.
Identity, segmentation, and cloud control reviews for hybrid environments common in NoVA.
DC-headquartered with daily NoVA client work — on-site kickoffs in Arlington or Herndon when useful, Eastern-time incident calls, and assessors who understand FedRAMP-adjacent language without overclaiming.
We do not sell certifications or attestations we cannot legally provide.
Findings your team can ticket — not PDFs that gather dust.
Calendar slots for assessments within weeks, not quarters.
Priorities tied to business impact and customer contract language.
Outcomes
Illustrative benchmarks from past work — your mileage depends on offer, traffic, and sales follow-up.
A transparent, milestone-driven engagement from first call to launch.
Systems, data classes, and compliance drivers captured in the SOW.
Testing or gap analysis with daily check-ins on critical findings.
Executive summary plus technical detail with remediation steps.
Retest or readiness review before customer audit windows.
FAQ
Straight answers — scoped to what you sell and who has to sign off.
Next step
Share the framework and timeline — we respond with a scoped assessment or remediation plan.
Based at 1717 N Street NW, Washington, DC · hello@thoriumdc.com · (202) 666-9377