About JLS

Your certification management team

JLS Consulting Group provides strategic business and certification consulting services to vendors seeking product security certifications such as FIPS 140-3, NIAP and EAL Common Criteria (CC), Commercial Solutions for Classified (CSfC), DISA SWFT (Software Fast Track) STIG & UCR – CORE (formerly DoDIN APL), FedRAMP & GovRAMP, and the Cybersecurity Mature Model Certification (CMMC) as well as European requirements for EUCC and the CRA (Cyber Resilience Act).

20+ yrs hands-onCertification expertiseLabs & assessorsTrusted guidance90+ combined yrsJLS

The value proposition

No FUD, just FACTS.

JLS Consulting Group is a boutique firm specializing in security certification consulting services. We provide strategic business guidance to vendors seeking security certifications required by the US Federal government such as FedRAMP, FIPS 140, NIAP Common Criteria, CSfC (Commercial Solutions for Classified), DoDIN APL (Dept. of Defense Information Network Approved Products List), and CMMC (Cybersecurity Maturity Model Certification).

With over twenty (20) years of experience, we've been there and done that and are here to help you avoid the obstacles and stumbling blocks on your climb to the certification summit. With over ninety (90) combined years working for testing labs, consultants, and 3PAOs, JLS has first-hand experience guiding vendors through the often overwhelming and confusing cybersecurity product certifications required to be successful in the US Federal and international governmental marketplace.

Our team

Subject matter experts, consultants, assessors, and testing labs.

Our network of Subject Matter Experts (SMEs), Consultants, Assessors, and Testing Labs consists of highly skilled professionals with extensive experience in various certification domains that bring a diverse range of expertise, and therefore multiple points of view, to help our clients navigate complex challenges and achieve their security certification goals.

What we stand for

Trusted advisor

We take the client's perspective, even when we're the ones being paid. Long-term relationships beat one-off billings.

Deep SME network

Over 90 combined years across FIPS, Common Criteria, CSfC, FedRAMP, and CMMC, with a bench of labs, 3PAOs, and C3PAOs.

End-to-end program

From strategy through certification and re-certification. We relieve the burden so your engineers can stay focused on the product.

Not sure which service you need?Start with a discovery call.

Book a discovery call

Contact

Let's plan the climb.

Tell us what you're building, which framework is blocking a deal, and when you'd like to be certified. We'll reply within one business day.