Coalfire
Low Trafficcoalfire.com
Overview
Coalfire is a cybersecurity advisory and assessment firm specializing in compliance, risk management, and technical security services for enterprises and technology companies. The company is best known for its FedRAMP, CMMC, and cloud security expertise, helping clients navigate complex regulatory environments. Its platform automates compliance across 85+ regulatory frameworks, making it a trusted partner for regulated industries including government, healthcare, and financial services.
By the Numbers
Founders
Rick Dakin has led Coalfire since its founding, building it into one of the most recognized independent cybersecurity and compliance advisory firms in the US. He has decades of experience in IT security and audit.
Dakin helped pioneer the commercial FedRAMP audit market, making Coalfire one of the first accredited 3PAOs (Third Party Assessment Organizations) for the US federal government cloud program.
Tom McAndrew was a key technical co-founder who helped shape Coalfire's early penetration testing and assessment capabilities. He contributed to building the firm's hacker-level testing methodology.
McAndrew's focus on offensive security techniques helped Coalfire differentiate its services from traditional compliance-only firms early in its history.
Funding
Competitors
Focused exclusively on security compliance assessments and certifications, particularly SOC reports and FedRAMP, without broad advisory services
Backed by Google with stronger threat intelligence and incident response capabilities at global scale
Larger managed security services and product resale focus, broader IT security portfolio
Smaller boutique firm competing in the same compliance and pen testing niche but at smaller scale
Primarily a defense contractor with cybersecurity as a component, different federal market approach
Specializes more heavily in offensive security and red teaming rather than compliance frameworks
Key People
Andrew Leibel oversees Coalfire's financial operations and strategy, supporting the company's growth initiatives under Carlyle Group ownership.
Mike Weber leads Coalfire Labs, the company's research and advanced testing division, which produces threat intelligence and develops cutting-edge security assessment techniques.
Brent Chapman leads Coalfire's FedRAMP practice, one of the most critical and high-revenue service lines, guiding cloud service providers through federal authorization processes.
Revenue & Model
Hiring Signals
Tech Stack
Notable Customers
Web Presence
Verified from public records — not AI-estimated.
Trackers & Analytics
Scanned from the HTML coalfire.comserves — scripts a tag manager injects later won't appear here.
How They're Doing
Coalfire remains one of the most prominent independent cybersecurity compliance and assessment firms in the US, particularly in the FedRAMP and CMMC markets as federal cloud adoption accelerates. The company has expanded its AI risk advisory services and red teaming capabilities to meet growing enterprise demand. Under Carlyle Group ownership since 2018, Coalfire has grown through strategic acquisitions and organic expansion.
●Expanded AI security and risk advisory practice to address growing enterprise AI adoption concerns
●Continued to be a leading FedRAMP 3PAO as government cloud adoption surged post-pandemic
Prognosis
Coalfire is well-positioned to benefit from the rapid expansion of CMMC compliance mandates across the US defense industrial base, which will drive significant demand for its assessment services. The company's early investment in AI risk advisory and its deep federal compliance expertise create durable competitive advantages. A potential IPO or secondary buyout remains possible given its maturity and scale under private equity ownership.
●CMMC 2.0 rollout creating massive new compliance assessment demand across thousands of defense contractors
●Growing enterprise AI adoption driving need for AI risk assessments and governance frameworks
●Increased cloud adoption in regulated industries expanding FedRAMP and cloud security advisory demand
●International expansion of compliance services as global data protection regulations multiply
●Increasing commoditization of compliance services with new entrants and automated tools
●Talent shortage in cybersecurity making it difficult to scale expert-level assessment teams
●Potential consolidation by larger managed security or big-4 consulting firms squeezing margins
●Regulatory changes or simplification of frameworks could reduce demand for third-party assessments
Recent News
Coalfire expands AI risk advisory services to help enterprises govern generative AI deployments
Coalfire Blog
Coalfire publishes annual 'Penetration Risk Report' highlighting trends in enterprise attack surfaces
Coalfire Labs
Coalfire recognized as a leading CMMC Registered Provider Organization as CMMC 2.0 nears implementation
Industry Report
Coalfire acquires Denim Group to expand application security testing capabilities
Press Release
Acquisitions
Fun Facts
- 01Coalfire was one of the very first companies to become an accredited FedRAMP Third Party Assessment Organization (3PAO), giving it a first-mover advantage in the rapidly growing government cloud market.
- 02Despite being known for compliance, Coalfire maintains a dedicated red team called 'Coalfire Labs' that conducts advanced adversarial simulations rivaling offensive security boutiques.
- 03The company's domain was registered in December 2002, suggesting the firm's roots predate the commonly cited founding story, with early advisory work predating its formal corporate structure.
Timeline
Expands AI risk advisory and governance services to address enterprise generative AI security needs
Launches expanded CMMC assessment practice ahead of CMMC 2.0 mandate rollout
Acquires Denim Group, adding application security testing expertise
Acquires Veris Group to expand federal cybersecurity capabilities
The Carlyle Group acquires majority stake in Coalfire, accelerating growth and M&A strategy
Coalfire becomes one of the first accredited FedRAMP Third Party Assessment Organizations (3PAOs)
Domain coalfire.com registered, formalizing online presence
Coalfire founded in Colorado as a cybersecurity and IT compliance advisory firm