Save

Coalfire

Low Traffic

coalfire.com

Overview

Coalfire is a cybersecurity advisory and assessment firm specializing in compliance, risk management, and technical security services for enterprises and technology companies. The company is best known for its FedRAMP, CMMC, and cloud security expertise, helping clients navigate complex regulatory environments. Its platform automates compliance across 85+ regulatory frameworks, making it a trusted partner for regulated industries including government, healthcare, and financial services.

IndustryCybersecurity & Compliance Services
Founded2001
HQGreenwood Village, Colorado
Team Size1,000-2,000

By the Numbers

85+
Regulatory Frameworks Supported
automated compliance platform coverage
136
HackerNews Mentions
community recognition in security space
10+
Years as Accredited 3PAO
one of the longest-tenured FedRAMP assessors
Since 2002
Domain Age
domain registered December 2002

Founders

Rick DakinCo-Founder & CEO

Rick Dakin has led Coalfire since its founding, building it into one of the most recognized independent cybersecurity and compliance advisory firms in the US. He has decades of experience in IT security and audit.

Dakin helped pioneer the commercial FedRAMP audit market, making Coalfire one of the first accredited 3PAOs (Third Party Assessment Organizations) for the US federal government cloud program.

Tom McAndrewCo-Founder

Tom McAndrew was a key technical co-founder who helped shape Coalfire's early penetration testing and assessment capabilities. He contributed to building the firm's hacker-level testing methodology.

McAndrew's focus on offensive security techniques helped Coalfire differentiate its services from traditional compliance-only firms early in its history.

Funding

~$500M+
Last RoundBuyout/Private Equity
ValuationUndisclosed
The Carlyle GroupWarburg Pincus

Competitors

Schellman

Focused exclusively on security compliance assessments and certifications, particularly SOC reports and FedRAMP, without broad advisory services

Mandiant (Google Cloud)

Backed by Google with stronger threat intelligence and incident response capabilities at global scale

Optiv

Larger managed security services and product resale focus, broader IT security portfolio

Tevora

Smaller boutique firm competing in the same compliance and pen testing niche but at smaller scale

Kratos Defense

Primarily a defense contractor with cybersecurity as a component, different federal market approach

Bishop Fox

Specializes more heavily in offensive security and red teaming rather than compliance frameworks

Key People

Andrew LeibelChief Financial Officer

Andrew Leibel oversees Coalfire's financial operations and strategy, supporting the company's growth initiatives under Carlyle Group ownership.

Mike WeberVP, Labs

Mike Weber leads Coalfire Labs, the company's research and advanced testing division, which produces threat intelligence and develops cutting-edge security assessment techniques.

Brent ChapmanManaging Director, FedRAMP

Brent Chapman leads Coalfire's FedRAMP practice, one of the most critical and high-revenue service lines, guiding cloud service providers through federal authorization processes.

Revenue & Model

$200M-$400M ARR
Business ModelProfessional Services & SaaS — combination of advisory/assessment project fees and platform subscription revenue for compliance automation
Headcount~1,500Stable
View pricing →

Hiring Signals

~60open rolesStable
Other
5
Sales
10
Marketing
5
Engineering
15
Consulting/Advisory
25

Tech Stack

Google Tag ManagerSalesforceHubSpotAWSMicrosoft AzureDrupalJavaScriptPythonSplunk

Notable Customers

US Department of Defense contractorsMicrosoft Azure (FedRAMP assessments)Various US Federal agencies (cloud service providers)Major healthcare systemsFinancial services enterprises

Web Presence

Global traffic rank#346,775
Domain registered2002-12-11 (23 yrs)
RegistrarGoDaddy.com, LLC
Hacker News mentions136

Verified from public records — not AI-estimated.

Trackers & Analytics

1service detected
Tag Managers
Google Tag Manager

Scanned from the HTML coalfire.comserves — scripts a tag manager injects later won't appear here.

How They're Doing

Growing

Coalfire remains one of the most prominent independent cybersecurity compliance and assessment firms in the US, particularly in the FedRAMP and CMMC markets as federal cloud adoption accelerates. The company has expanded its AI risk advisory services and red teaming capabilities to meet growing enterprise demand. Under Carlyle Group ownership since 2018, Coalfire has grown through strategic acquisitions and organic expansion.

Expanded AI security and risk advisory practice to address growing enterprise AI adoption concerns

Continued to be a leading FedRAMP 3PAO as government cloud adoption surged post-pandemic

Prognosis

Bullish

Coalfire is well-positioned to benefit from the rapid expansion of CMMC compliance mandates across the US defense industrial base, which will drive significant demand for its assessment services. The company's early investment in AI risk advisory and its deep federal compliance expertise create durable competitive advantages. A potential IPO or secondary buyout remains possible given its maturity and scale under private equity ownership.

Opportunities

CMMC 2.0 rollout creating massive new compliance assessment demand across thousands of defense contractors

Growing enterprise AI adoption driving need for AI risk assessments and governance frameworks

Increased cloud adoption in regulated industries expanding FedRAMP and cloud security advisory demand

International expansion of compliance services as global data protection regulations multiply

Risks

Increasing commoditization of compliance services with new entrants and automated tools

Talent shortage in cybersecurity making it difficult to scale expert-level assessment teams

Potential consolidation by larger managed security or big-4 consulting firms squeezing margins

Regulatory changes or simplification of frameworks could reduce demand for third-party assessments

Recent News

2024-03

Coalfire expands AI risk advisory services to help enterprises govern generative AI deployments

Coalfire Blog

2023-11

Coalfire publishes annual 'Penetration Risk Report' highlighting trends in enterprise attack surfaces

Coalfire Labs

2023-06

Coalfire recognized as a leading CMMC Registered Provider Organization as CMMC 2.0 nears implementation

Industry Report

2022-09

Coalfire acquires Denim Group to expand application security testing capabilities

Press Release

Acquisitions

Veris Group2019
Undisclosed
Denim Group2021
Undisclosed

Fun Facts

  • 01Coalfire was one of the very first companies to become an accredited FedRAMP Third Party Assessment Organization (3PAO), giving it a first-mover advantage in the rapidly growing government cloud market.
  • 02Despite being known for compliance, Coalfire maintains a dedicated red team called 'Coalfire Labs' that conducts advanced adversarial simulations rivaling offensive security boutiques.
  • 03The company's domain was registered in December 2002, suggesting the firm's roots predate the commonly cited founding story, with early advisory work predating its formal corporate structure.

Timeline

2024

Expands AI risk advisory and governance services to address enterprise generative AI security needs

2022

Launches expanded CMMC assessment practice ahead of CMMC 2.0 mandate rollout

2021

Acquires Denim Group, adding application security testing expertise

2019

Acquires Veris Group to expand federal cybersecurity capabilities

2018

The Carlyle Group acquires majority stake in Coalfire, accelerating growth and M&A strategy

2012

Coalfire becomes one of the first accredited FedRAMP Third Party Assessment Organizations (3PAOs)

2002

Domain coalfire.com registered, formalizing online presence

2001

Coalfire founded in Colorado as a cybersecurity and IT compliance advisory firm