Josh has spent over twenty (20) years in the Testing, Inspection, and Certification (TIC) vertical, specifically focused on FIPS 140, NIAP/Common Criteria, CSfC, DoDIN APL, FedRAMP/GovRAMP, and CMMC, as a Vice President/Director of Global Sales and Business Development for Consultants, Testing Labs, and Third-Party Assessment Organizations (3PAOs). While working for the service provider, Josh has always taken a client's perspective when providing guidance, business strategy, and sometimes "out of the box" technical approaches to help mitigate impact to resources and maximize the client's possible Return on Investment (ROI)... understanding that acting as a true Trusted Advisor to the client is a win-win that will yield long term business relationships.
Connect on LinkedInAbout JLS
Your certification management team
JLS Consulting Group provides strategic business and certification consulting services to vendors seeking product security certifications such as FIPS 140-3, NIAP and EAL Common Criteria (CC), Commercial Solutions for Classified (CSfC), DISA SWFT (Software Fast Track) STIG & UCR – CORE (formerly DoDIN APL), FedRAMP & GovRAMP, and the Cybersecurity Mature Model Certification (CMMC) as well as European requirements for EUCC and the CRA (Cyber Resilience Act).
The value proposition
No FUD, just FACTS.
JLS Consulting Group is a boutique firm specializing in security certification consulting services. We provide strategic business guidance to vendors seeking security certifications required by the US Federal government such as FedRAMP, FIPS 140, NIAP Common Criteria, CSfC (Commercial Solutions for Classified), DoDIN APL (Dept. of Defense Information Network Approved Products List), and CMMC (Cybersecurity Maturity Model Certification).
With over twenty (20) years of experience, we've been there and done that and are here to help you avoid the obstacles and stumbling blocks on your climb to the certification summit. With over ninety (90) combined years working for testing labs, consultants, and 3PAOs, JLS has first-hand experience guiding vendors through the often overwhelming and confusing cybersecurity product certifications required to be successful in the US Federal and international governmental marketplace.
Our team
Subject matter experts, consultants, assessors, and testing labs.
Our network of Subject Matter Experts (SMEs), Consultants, Assessors, and Testing Labs consists of highly skilled professionals with extensive experience in various certification domains that bring a diverse range of expertise, and therefore multiple points of view, to help our clients navigate complex challenges and achieve their security certification goals.
Jussi has over two decades of hands-on consultancy, engineering, documentation, and evaluation experience in Common Criteria with eight (8) CC schemes and several major evaluation facilities. He has set up and enhanced the capabilities of several testing labs on three (3) continents and is a well-known and highly regarded expert within the international Common Criteria community. No major R&D company is absent from the list of vendors Jussi has worked with. As the domestic and international evaluation and certification world is constantly evolving, Jussi is exactly the right person to have on your team.
Joshua brings more than twenty (20) years of experience leading complex cybersecurity certification and regulatory compliance programs for global technology organizations. As the former Senior Director of Security Evaluations at Oracle, he led worldwide Common Criteria, FIPS 140, and other security certification initiatives supporting cloud services, operating systems, databases, hardware, and cryptographic technologies. Joshua has extensive experience working with NIST, CMVP, NIAP, international Common Criteria schemes, accredited testing laboratories, and government stakeholders to successfully navigate evolving regulatory requirements. A recognized industry leader, he chairs the international Common Criteria in the Cloud Technical Working Group and has been a frequent speaker, moderator, and advisor on Common Criteria, FIPS 140, FedRAMP, the EU Cyber Resilience Act, post-quantum cryptography, and global cybersecurity policy. Joshua is known for translating complex technical and regulatory challenges into practical business strategies that help organizations reduce risk, accelerate certifications, and bring products to market more efficiently.
Randy possesses a wide range of skills and experience from a 30-year career focusing on Software Architecture and Engineering. Since 2010, Randy has focused on the Security Certification field, initially performing algorithm and functional/operational testing for FIPS 140-2. Over the years, Randy has developed tools, techniques, and experience in testing a wide variety of software and hardware systems against several international certification programs. Randy has been responsible for the testing of more than 200 products on the FIPS 140 validation list, both current and sunset.
What we stand for
Trusted advisor
We take the client's perspective, even when we're the ones being paid. Long-term relationships beat one-off billings.
Deep SME network
Over 90 combined years across FIPS, Common Criteria, CSfC, FedRAMP, and CMMC, with a bench of labs, 3PAOs, and C3PAOs.
End-to-end program
From strategy through certification and re-certification. We relieve the burden so your engineers can stay focused on the product.
Not sure which service you need?Start with a discovery call.
Book a discovery callContact
Let's plan the climb.
Tell us what you're building, which framework is blocking a deal, and when you'd like to be certified. We'll reply within one business day.
