Steel for Pittsburgh. Patriot for Boston. Partners, because that's the only way we know how to work.
Steel Patriot Partners was built by people who had already been through it.
Before this company existed, the founders had spent careers deep inside the space — as contractors, as engineers, as operators building some of the first cloud environments to go through FedRAMP, as business owners who had personally navigated the compliance journey their clients now face. They didn't build this firm to sell compliance services from the outside. They built it because they knew what it looked like from the inside, and they believed that difference mattered.
It still does.
"Blue collar isn't transactional. You're with someone. You're with them to support them."
— Jason Ford, Co-Founder & CEOThat sequence is intentional. It means we start with your business — what it does, what's at risk, what a real solution looks like for your specific situation — before we talk frameworks. It means we go all the way down into the technical work, the infrastructure, the parts most firms hand off or leave alone. And it means the compliance layer reflects reality, not just paperwork.
Blue collar isn't a style. It's a commitment. You're not hiring us to check a box. You're bringing us in to actually solve something. That's how we show up.
The buyers we work with are done with vendor noise. They're done with firms that hand them a framework and call it consulting. What they trust is someone who's been through it — a business owner first, who knows what's actually at stake. That's why we built SPP the way we did. And it's why the conversations we have tend to turn into long relationships.
We don't disappear after we start.
Most compliance engagements follow a pattern: assess, deliver a report, hand it off. We're built differently. We stay in the program — through the build, through the operations, through the audits, through the moments when something breaks and needs to be fixed right.
Our five service areas — Program Assessment, Program Build, Program Operations, Program Engineering, and Executive Advisement — aren't products on a menu. They're the stages of a relationship. Most clients engage us at one point and stay through all of them.
That's not an accident. It's the model. Federal compliance doesn't end. Neither do we.
Our team is 100% US. In the federal compliance space — where access to sensitive infrastructure and government systems is routine — this isn't a differentiator we lead with. It's a baseline we hold without exception, because the work demands it and the clients we serve expect it.
100% located in the US. Our entire team. Required, not incidental — because the work we do demands it.
Jason has been in this space since 1997, when he started as a contractor at the FBI. In 2004, he co-founded BlackMesh — one of the first cloud service providers to go through FedRAMP — and spent over a decade building it before exiting in 2017. After the acquisition, he stayed on as CISO and CTO, establishing FedRAMP governance across the combined organization before stepping away to build something new.
Steel Patriot Partners is that something new — built specifically to go after the work that others won't touch. Not just the compliance layer. The infrastructure. The vulnerabilities sitting in large environments that most firms walk past because they're afraid to break something. Jason's view has always been the opposite: go touch it, understand it, fix it properly.
His background in electrical engineering and federal compliance isn't incidental to how he runs this company. It's the whole point.
"We get things a lot of people won't even touch. Most people leave it sitting there because they're afraid. I want to go touch it, break something, and put it back together."
Read Jason’s Latest Insight
FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers
Learn how FedRAMP 2026 changes, certification classes, and FedRAMP Ready retirement impact cloud providers pursuing federal business.
Read Jason’s Latest Insight
CMMC Flow-Down Requirements: An Engineering Guide for Prime Contractors
Learn how primes can enforce CMMC and DFARS flow-down requirements by engineering secure enclaves, access controls, and evidence-ready systems.
Read Jason’s Latest Insight
The Business of Trust: What Steel Patriot Partners Is Watching at RSAC 2026
What matters most at RSAC 2026: trust, cybersecurity ROI, and compliance trends shaping federal and commercial markets.
Read Jason’s Latest Insight
Automating Audit Readiness: Five Scripts Every Security Team Should Use
Learn five simple scripts that can automate audit readiness, reduce compliance risk, and make IT security audits easier to pass.
Read Jason’s Latest Insight
Everything You Need to Know Before Bringing in an Assessor
Everything you need to know before hiring a FedRAMP or CMMC assessor—timelines, readiness, red flags, and how to choose wisely.
Read Jason’s Latest Insight
Why Purpose-Built Systems and Maintained Templates Are Crucial for Federal and Government SaaS Compliance
Purpose-built systems and maintained templates reduce risk, cost, and audit friction for FedRAMP, CMMC, GovRAMP, and federal SaaS compliance.
Read Jason’s Latest Insight
Equipping Leadership to Champion the Cybersecurity ROI Story
Get equipped to champion your Cybersecurity ROI Story by understanding how to overcome objections and align with corporate goals.
Read Jason’s Latest Insight
Maximizing Value in Cybersecurity Vulnerability and Benchmark Management
Enhance your cybersecurity posture with our comprehensive guide to Cybersecurity Vulnerability and Benchmark Management. Get expert insights and stay secure.
Read Jason’s Latest Insight
Security Blind Spots: Why GRC Software Must Meet Your Core Cybersecurity Standards
Discover why GRC Software must meet core cybersecurity standards. Learn about potential vulnerabilities and expected certifications like FedRAMP, GovRAMP, or NI…
Read Jason’s Latest Insight
FedRAMP Accelerators: Shortcut or Setback for Compliance Success?
Accelerators promise faster FedRAMP compliance—but at what cost? Learn the real trade-offs and smarter paths to secure authorization.
Read Jason’s Latest Insight
Unlock the GRC Software ROI: Maximize Your Investment
Maximize ROI with GRC software—cut audit prep, reduce costs, and turn compliance into a competitive advantage.
Read Jason’s Latest Insight
After the ATO: Maintaining Security Posture and Compliance
Navigate your post-ATO responsibilities with confidence. Explore ongoing compliance, security assessments, and risk management essentials.
Read Jason’s Latest Insight
Security Technical Implementation Guides (STIGs): The Essentials
Discover how Security Technical Implementation Guides (STIGs) can strengthen your cybersecurity posture with DoD standards and best practices for hardening
Read Jason’s Latest Insight
StateRAMP and GovRAMP Compliance: What You Need to Know
Learn about StateRAMP rebranded as GovRAMP compliance, Fast Track, security requirements, and certifications that meet state and local government standards
Read Jason’s Latest Insight
How to Pick a 3PAO or C3PAO
Select the right 3PAO or C3PAO for your company to navigate assessments for the Federal Contracts, Department of Defense, cloud services, and other contracting …
Read Jason’s Latest Insight
NIST CSF: Complete Guide to Cybersecurity Framework
Discover how NIST CSF helps organizations improve their cybersecurity posture, manage risks, and protect critical infrastructure through a comprehensive framewo…
Read Jason’s Latest Insight
Choosing a FedRAMP 3PAO: Selection Guide
Learn how to select a FedRAMP 3PAO as a cloud service provider. Discover key criteria, best practices, and essentials to ensure compliance and security.
Read Jason’s Latest Insight
The Path to Cyber Insurance: GRC Software
Discover how GRC software cyber insurance can safeguard from digital threats using risk assessment, compliance, and data protection solutions.
Read Jason’s Latest Insight
FedRAMP GRC Automation: Strategies to Streamline Compliance
Streamline your FedRAMP compliance with GRC automation. Discover strategies to enhance security, reduce costs, and accelerate your certification process.
Read Jason’s Latest Insight
Continuous Monitoring in FedRAMP: Secure Cloud Solutions
Discover Continuous Monitoring in FedRAMP ensures secure CSOs continued FedRAMP authorization and compliance requirements and best practices for CSPs.
Read Jason’s Latest Insight
Essentials for the FedRAMP Annual Assessment
Discove key requirements for a FedRAMP Annual Assessment. Learn to maintain compliance, manage risks, and ensure continuous monitoring for cloud services.
Read Jason’s Latest Insight
Pitfalls in FedRAMP Penetration Testing
Uncover common pitfalls in FedRAMP penetration testing and learn to secure government data effectively with best practices and expert insights.
Read Jason’s Latest Insight
Avoiding Missteps in the FedRAMP Authorization Boundary
Understand the intricacies of defining your FedRAMP authorization boundary to ensure compliance and secure federal data.
Read Jason’s Latest Insight
Vulnerability Scans Outsized Impact on FedRAMP ATO
Discover how vulnerability scans significantly impact your FedRAMP ATO process. Learn best practices for effective scanning and compliance success.
Read Jason’s Latest Insight
FedRAMP Implementation: What the Checklist Won't Tell You
What the Checklist Won't Tell You - Understand the Nuances and Challenges Involved in FedRAMP Implementation Compliance.
Read Jason’s Latest Insight
Managing Technical Debt in the FedRAMP Compliance Journey
Manage your technical debt compliance as a CSP effectively during your FedRAMP journey with expert guidance for secure cloud migration and modernization.
Read Jason’s Latest Insight
SOC2 Implementation: Overcoming Critical barriers in Healthcare Security
Master SOC 2 Implementation and tackle the critical barriers to build a resilient trust ecosystem and safeguard your data privacy and security in healthcare.
Read Jason’s Latest Insight
The Critical Path to FedRAMP Authorization
Expertly navigate the FedRAMP authorization process with our comprehensive guide, empowering you to achieve FedRAMP authorization seamlessly.
Read Jason’s Latest Insight
Increase Visibility to Reduce Risk with SIEM
Increase visibility and reduce risk in healthcare organizations with a single view of events. Learn how to increase visibility to reduce risk with SIEM.
Amy's path into this space came through operations, not engineering — and that's exactly what makes her perspective indispensable. She spent years running IT teams that provided around-the-clock support for a FedRAMP cloud service provider, managing human resources, finance, and compliance programs simultaneously.
She built solutions for FedRAMP, PCI DSS, and HIPAA across multiple government agencies — not because she was handed the assignment, but because the work needed to get done and she was the one who made sure it did.
At SPP, Amy leads GRC services — FedRAMP, CMMC, HITRUST, SOC2, ISO27001, and more — and brings the same orientation she always has: understand the organization first, understand the risk second, build the program around both. She has never believed compliance exists for its own sake. It exists to protect something real.
"The goal is never the certification. The goal is what the certification makes possible for your business."
Read Amy’s Latest Insight
CJIS Security Policy 6.0: What Cloud Providers Need to Know
Learn how CJIS Security Policy 6.0 impacts cloud providers, strengthens cybersecurity, and expands opportunities in the public sector.
Read Amy’s Latest Insight
CMMC Flow-Down Compliance: What Prime Contractors Need to Document
Learn how primes can demonstrate CMMC and DFARS flow-down compliance with supplier evidence, oversight, and assessment-ready processes.
Read Amy’s Latest Insight
CMMC Compliance Pitfalls: What to Avoid
Struggling with CMMC? Discover common mistakes, compliance risks, and how to prepare for audits and protect DoD contract eligibility.
Read Amy’s Latest Insight
Keys to Cybersecurity ROI that Boards Understand
Demonstrate cybersecurity ROI to your board by linking security investments to business growth, using metrics, automation, and training for financial impact.
Read Amy’s Latest Insight
Expanding your TAM with a CJIS Security Addendum
Expand your total addressable market with CJIS Security Addendum. Learn how to enhance your cybersecurity and meet state and local criminal justice requirements…
Read Amy’s Latest Insight
Cybersecurity Framework Selection: Understand the ROI
Discover how to boost your cybersecurity framework ROI by selecting the right frameworks for your industry. Get a step-by-step guide on evaluating and maximizin…
Read Amy’s Latest Insight
Getting value from your POA&M
Learn how to maximize your POA&M's value and reduce challenges with our expert guide. Discover best practices for managing POA&M and achieving success.
Read Amy’s Latest Insight
Essentials Guide to CMMC 2.0 Compliance
Essential CMMC Compliance requirements, certification, and implementation steps to protect controlled unclassified information and secure defense contracts
Read Amy’s Latest Insight
Reducing Cyber Risk with GRC Software
GRC software reduces cyber risk by streamlining governance, risk management + compliance. Enhance your security posture by Reducing Risk with GRC software.
Read Amy’s Latest Insight
GRC Software for Healthcare Cybersecurity: Guide to the Essentials
Discover how GRC healthcare cybersecurity solutions streamline compliance, mitigate risks, and enhance patient safety. See key features and benefits.
Read Amy’s Latest Insight
Healthcare Compliance Management: A Single Source of Truth
Healthcare compliance management requires a single source of truth powered by GRC software. Simplify regulatory adherence, reduce risks, + data governance.
Read Amy’s Latest Insight
GRC Governance for IT: Business Alignment and Effectiveness
Discover how GRC Governance for IT aligns business goals with technology, enhancing effectiveness and ensuring regulatory compliance in your organization.
Read Amy’s Latest Insight
Simplify Federal Compliance Complexity with GRC Software
Learn how cloud-based GRC software transforms federal compliance complexity from a burden to a business enabler, supporting NIST, FedRAMP, CMMC frameworks.
Read Amy’s Latest Insight
Evaluating the ROI of GRC Software: Examining Cost Benefit
Discover the financial benefits of GRC software and evaluate its ROI. Reduce compliance costs, mitigates risks, and improves operational efficiencies.
Read Amy’s Latest Insight
GRC Software Powered Risk Registers Streamline Risk Management
Streamline risk management with GRC software-powered risk registers. Enhance compliance, mitigate threats, optimize risk response strategies.
Read Amy’s Latest Insight
Overcoming Federal GRC Software Implementation Challenges
Navigate the complexity of GRC software implementation challenges with expert insights. Get strategies to overcome obstacles to ensure successful adoption.
Read Amy’s Latest Insight
Clear Perspectives on the FedRAMP Timeline
Navigate your path to compliance with an essential guide on Planning for the FedRAMP Timeline, tailored for cloud service providers.
Read Amy’s Latest Insight
Implementing HITRUST GRC for Healthcare: Streamlining Security
Explore how HiTRUST Governance, Risk and Compliance software, GRC healthcare streamlines your data protection and compliance with robust security measures and r…
Read Amy’s Latest Insight
HIPAA Compliance with GRC: Confidence and Risk Reduction
Master HIPAA compliance with robust GRC strategies to mitigate risk and demonstrate principled healthcare governance.
Read Amy’s Latest Insight
Fireside Chat: RiskInsiders to the Rescue GRC Compliance Programs
RiskInsiders to the Rescue with Amy Ford, COO and co-founder at Steel Patriot Partners, discussing GRC and successfully completing a compliance journey.
Read Amy’s Latest Insight
Preparing for a HITRUST Assessment: A Comprehensive Roadmap to Success
Learn how to define the scope, conduct a gap analysis, prioritize and remediate, simulate an audit, and maintain documentation for a HITRUST certification
Read Amy’s Latest Insight
5 Best Practices for Risk Management: Enhancing Governance Compliance
Discover the top five best practices for risk management and how they impact cybersecurity, compliance, and governance.
Read Amy’s Latest Insight
Case Study: Healthcare ASO Outsourcing Cybersecurity for SOC2 - HIPAA
Meet the challenge of compliance with Health Insurance Portability and Accountability Act (HIPAA) and Service Organization Control 2 (SOC2) compliance
Michael brings over 20 years of experience across professional services, federal compliance, and cybersecurity certification. He's held senior roles at HITRUST, PwC, and Schellman — organizations at the center of how the compliance industry actually works — which means he understands the gap between what firms promise and what clients actually need.
At SPP, Michael leads growth — but his orientation is the same as the rest of the team: business owners first. He doesn't route people through sales cycles. He connects them directly to the right individuals, the right programs, and the right conversations. His network in the federal compliance space is deep, and he uses it to move fast.
Michael is Bay Area–based and is the face of SPP at industry events — including RSAC Conference, where he's known for the kind of direct, no-hype conversations that actually lead somewhere.
"We're business owners first, engineers second, compliance people third. That's not a tagline. That's the order of operations."
Read Michael’s Latest Insight
FedRAMP 20x Explained: The Future of Federal Cloud Compliance
Learn how FedRAMP 20x uses automation, KSIs, and continuous evidence to transform federal cloud compliance and security.
Read Michael’s Latest Insight
CMMC Flow-Down Requirements: A Business Risk Guide for Prime Contractors
Discover how primes can manage CMMC and DFARS flow-down requirements as a business risk across contracts, suppliers, and revenue.
Read Michael’s Latest Insight
Why Most Tool Selections Fail—and How Fit-Gap Assessments Fix Them
Learn how to conduct a fit-gap assessment to select the right tools, reduce costs, and align security, compliance, and engineering outcomes.
Read Michael’s Latest Insight
How to Choose the Right Assessor for Your Compliance and Security Needs
How to choose the right security assessor for SOC 2, CMMC, FedRAMP, or ISO. Avoid red flags and protect audit credibility.
Read Michael’s Latest Insight
Configuring and Running Security Tools: From Checkbox to True Risk Reduction
Maximize security ROI by configuring and monitoring tools, not just buying them. Learn to avoid tool sprawl, compliance risks, and hidden vulnerabilities.
Read Michael’s Latest Insight
Cybersecurity ROI: Speaking the Language of the C-Suite
Learn how to effectively communicate Cybersecurity ROI to the C-Suite. Discover the top concerns and value of cybersecurity in the boardroom.
Read Michael’s Latest Insight
Cybersecurity Strategies to Expand TAM in Regulated Industries
Cybersecurity Strategies to Expand TAM in Regulated Markets. Explore the demands of financial, healthcare and other restricted markets to maximize ROI
Read Michael’s Latest Insight
Five Key Pitfalls in State and Local (SLED) Cybersecurity Compliance
Discover the critical challenges and effective strategies for SLED cybersecurity compliance to protect public trust and ensure robust data security.
Read Michael’s Latest Insight
Expanding Your TAM: Unlocking DoD Market Opportunities with CMMC
Expand your business TAM with CMMC compliance. Learn how to increase your market reach, credibility, and ROI in the US defense industry.
Read Michael’s Latest Insight
Cybersecurity Continuous Monitoring: Finding the Right Support
Safeguard your digital assets with expert Cybersecurity Continuous Monitoring solutions that adapt to threats and compliance including Federal ZenGRC
Read Michael’s Latest Insight
FedRAMP vs. GovRAMP: Path to ROI Doing Business with the Government
FedRAMP vs. GovRAMP: Understand the differences and find the best way to start selling into government. Maximize ROI with the right compliance strategy.
Read Michael’s Latest Insight
Guide to Selecting a Cybersecurity Framework
Choose the cybersecurity framework for your company serving in the state and federal arena to ensure compliance, risk management, and enhanced security
Read Michael’s Latest Insight
Understanding Cybersecurity ROI
Discover how to measure your cybsecurity compliance roi through data-driven strategies, risk assessment frameworks, and tailored cost-benefit analysis
Read Michael’s Latest Insight
DOD Impact Levels: Understanding Security Classifications
DOD Impact Levels and their critical role in protecting sensitive data across cloud environments. Discover the process and value of compliance.
The ROI Workshop is the fastest way to find out where you stand and what it would actually take to move forward. Or just schedule a call. Either way, we pick up where the noise leaves off.
Answer three quick questions and we'll help you find the right starting point.
Find Your Path →