Skip to main content
About Steel Patriot Partners | Federal Cybersecurity Compliance
About Steel Patriot Partners

The name isn't branding.
It's biography.

Steel for Pittsburgh. Patriot for Boston. Partners, because that's the only way we know how to work.

Where We Come From

Built by people who had already been through it.

Steel Patriot Partners was built by people who had already been through it.

Before this company existed, the founders had spent careers deep inside the space — as contractors, as engineers, as operators building some of the first cloud environments to go through FedRAMP, as business owners who had personally navigated the compliance journey their clients now face. They didn't build this firm to sell compliance services from the outside. They built it because they knew what it looked like from the inside, and they believed that difference mattered.

They knew what it looked like from the inside. And they believed that difference mattered.

It still does.

How We Think About This Work

Business owners first. Engineers second. Compliance people third.

"Blue collar isn't transactional. You're with someone. You're with them to support them."

— Jason Ford, Co-Founder & CEO

That sequence is intentional. It means we start with your business — what it does, what's at risk, what a real solution looks like for your specific situation — before we talk frameworks. It means we go all the way down into the technical work, the infrastructure, the parts most firms hand off or leave alone. And it means the compliance layer reflects reality, not just paperwork.

Blue collar isn't a style. It's a commitment. You're not hiring us to check a box. You're bringing us in to actually solve something. That's how we show up.

The buyers we work with are done with vendor noise. They're done with firms that hand them a framework and call it consulting. What they trust is someone who's been through it — a business owner first, who knows what's actually at stake. That's why we built SPP the way we did. And it's why the conversations we have tend to turn into long relationships.

What This Looks Like in Practice

We don't disappear after we start.

Most compliance engagements follow a pattern: assess, deliver a report, hand it off. We're built differently. We stay in the program — through the build, through the operations, through the audits, through the moments when something breaks and needs to be fixed right.

Our five service areas — Program Assessment, Program Build, Program Operations, Program Engineering, and Executive Advisement — aren't products on a menu. They're the stages of a relationship. Most clients engage us at one point and stay through all of them.

That's not an accident. It's the model. Federal compliance doesn't end. Neither do we.

A Standard, Not a Selling Point

Our team is 100% US. In the federal compliance space — where access to sensitive infrastructure and government systems is routine — this isn't a differentiator we lead with. It's a baseline we hold without exception, because the work demands it and the clients we serve expect it.

🇺🇸

100% located in the US. Our entire team. Required, not incidental — because the work we do demands it.

Jason Ford, Co-Founder & CEO, Steel Patriot Partners
Jason Ford
Co-Founder & CEO
Areas of Expertise IT Architecture & Design · Cybersecurity Operations · FedRAMP & Federal Compliance · Business Transformation · Cloud Engineering
Education MA, Telecommunications & Business — George Mason University
BS, Electrical Engineering — University of Pittsburgh
LinkedIn
Co-Founder & CEO

Jason Ford

Jason has been in this space since 1997, when he started as a contractor at the FBI. In 2004, he co-founded BlackMesh — one of the first cloud service providers to go through FedRAMP — and spent over a decade building it before exiting in 2017. After the acquisition, he stayed on as CISO and CTO, establishing FedRAMP governance across the combined organization before stepping away to build something new.

Steel Patriot Partners is that something new — built specifically to go after the work that others won't touch. Not just the compliance layer. The infrastructure. The vulnerabilities sitting in large environments that most firms walk past because they're afraid to break something. Jason's view has always been the opposite: go touch it, understand it, fix it properly.

His background in electrical engineering and federal compliance isn't incidental to how he runs this company. It's the whole point.

"We get things a lot of people won't even touch. Most people leave it sitting there because they're afraid. I want to go touch it, break something, and put it back together."

Read Jason’s Latest Insight FedRAMP's Consolidated Rules for 2026: What It Means for Cloud Providers Learn how FedRAMP 2026 changes, certification classes, and FedRAMP Ready retirement impact cloud providers pursuing federal business. Read Jason’s Latest Insight CMMC Flow-Down Requirements: An Engineering Guide for Prime Contractors Learn how primes can enforce CMMC and DFARS flow-down requirements by engineering secure enclaves, access controls, and evidence-ready systems. Read Jason’s Latest Insight The Business of Trust: What Steel Patriot Partners Is Watching at RSAC 2026 What matters most at RSAC 2026: trust, cybersecurity ROI, and compliance trends shaping federal and commercial markets. Read Jason’s Latest Insight Automating Audit Readiness: Five Scripts Every Security Team Should Use Learn five simple scripts that can automate audit readiness, reduce compliance risk, and make IT security audits easier to pass. Read Jason’s Latest Insight Everything You Need to Know Before Bringing in an Assessor Everything you need to know before hiring a FedRAMP or CMMC assessor—timelines, readiness, red flags, and how to choose wisely. Read Jason’s Latest Insight Why Purpose-Built Systems and Maintained Templates Are Crucial for Federal and Government SaaS Compliance Purpose-built systems and maintained templates reduce risk, cost, and audit friction for FedRAMP, CMMC, GovRAMP, and federal SaaS compliance. Read Jason’s Latest Insight Equipping Leadership to Champion the Cybersecurity ROI Story Get equipped to champion your Cybersecurity ROI Story by understanding how to overcome objections and align with corporate goals. Read Jason’s Latest Insight Maximizing Value in Cybersecurity Vulnerability and Benchmark Management Enhance your cybersecurity posture with our comprehensive guide to Cybersecurity Vulnerability and Benchmark Management. Get expert insights and stay secure. Read Jason’s Latest Insight Security Blind Spots: Why GRC Software Must Meet Your Core Cybersecurity Standards Discover why GRC Software must meet core cybersecurity standards. Learn about potential vulnerabilities and expected certifications like FedRAMP, GovRAMP, or NI… Read Jason’s Latest Insight FedRAMP Accelerators: Shortcut or Setback for Compliance Success? Accelerators promise faster FedRAMP compliance—but at what cost? Learn the real trade-offs and smarter paths to secure authorization. Read Jason’s Latest Insight Unlock the GRC Software ROI: Maximize Your Investment Maximize ROI with GRC software—cut audit prep, reduce costs, and turn compliance into a competitive advantage. Read Jason’s Latest Insight After the ATO: Maintaining Security Posture and Compliance Navigate your post-ATO responsibilities with confidence. Explore ongoing compliance, security assessments, and risk management essentials. Read Jason’s Latest Insight Security Technical Implementation Guides (STIGs): The Essentials Discover how Security Technical Implementation Guides (STIGs) can strengthen your cybersecurity posture with DoD standards and best practices for hardening Read Jason’s Latest Insight StateRAMP and GovRAMP Compliance: What You Need to Know Learn about StateRAMP rebranded as GovRAMP compliance, Fast Track, security requirements, and certifications that meet state and local government standards Read Jason’s Latest Insight How to Pick a 3PAO or C3PAO Select the right 3PAO or C3PAO for your company to navigate assessments for the Federal Contracts, Department of Defense, cloud services, and other contracting … Read Jason’s Latest Insight NIST CSF: Complete Guide to Cybersecurity Framework Discover how NIST CSF helps organizations improve their cybersecurity posture, manage risks, and protect critical infrastructure through a comprehensive framewo… Read Jason’s Latest Insight Choosing a FedRAMP 3PAO: Selection Guide Learn how to select a FedRAMP 3PAO as a cloud service provider. Discover key criteria, best practices, and essentials to ensure compliance and security. Read Jason’s Latest Insight The Path to Cyber Insurance: GRC Software Discover how GRC software cyber insurance can safeguard from digital threats using risk assessment, compliance, and data protection solutions. Read Jason’s Latest Insight FedRAMP GRC Automation: Strategies to Streamline Compliance Streamline your FedRAMP compliance with GRC automation. Discover strategies to enhance security, reduce costs, and accelerate your certification process. Read Jason’s Latest Insight Continuous Monitoring in FedRAMP: Secure Cloud Solutions Discover Continuous Monitoring in FedRAMP ensures secure CSOs continued FedRAMP authorization and compliance requirements and best practices for CSPs. Read Jason’s Latest Insight Essentials for the FedRAMP Annual Assessment Discove key requirements for a FedRAMP Annual Assessment. Learn to maintain compliance, manage risks, and ensure continuous monitoring for cloud services. Read Jason’s Latest Insight Pitfalls in FedRAMP Penetration Testing Uncover common pitfalls in FedRAMP penetration testing and learn to secure government data effectively with best practices and expert insights. Read Jason’s Latest Insight Avoiding Missteps in the FedRAMP Authorization Boundary Understand the intricacies of defining your FedRAMP authorization boundary to ensure compliance and secure federal data. Read Jason’s Latest Insight Vulnerability Scans Outsized Impact on FedRAMP ATO Discover how vulnerability scans significantly impact your FedRAMP ATO process. Learn best practices for effective scanning and compliance success. Read Jason’s Latest Insight FedRAMP Implementation: What the Checklist Won't Tell You What the Checklist Won't Tell You - Understand the Nuances and Challenges Involved in FedRAMP Implementation Compliance. Read Jason’s Latest Insight Managing Technical Debt in the FedRAMP Compliance Journey Manage your technical debt compliance as a CSP effectively during your FedRAMP journey with expert guidance for secure cloud migration and modernization. Read Jason’s Latest Insight SOC2 Implementation: Overcoming Critical barriers in Healthcare Security Master SOC 2 Implementation and tackle the critical barriers to build a resilient trust ecosystem and safeguard your data privacy and security in healthcare. Read Jason’s Latest Insight The Critical Path to FedRAMP Authorization Expertly navigate the FedRAMP authorization process with our comprehensive guide, empowering you to achieve FedRAMP authorization seamlessly. Read Jason’s Latest Insight Increase Visibility to Reduce Risk with SIEM Increase visibility and reduce risk in healthcare organizations with a single view of events. Learn how to increase visibility to reduce risk with SIEM.
Amy Ford, Co-Founder & COO, Steel Patriot Partners
Amy Ford
Co-Founder & COO
Areas of Expertise GRC Program Leadership · Third-Party Risk · Federal & Healthcare Compliance · Business Operations · Risk Assessment
Certifications & Education HITRUST Certified CSF Practitioner · PHR, SHRM
Business Administration — Liberty University
LinkedIn
Co-Founder & COO

Amy Ford

Amy's path into this space came through operations, not engineering — and that's exactly what makes her perspective indispensable. She spent years running IT teams that provided around-the-clock support for a FedRAMP cloud service provider, managing human resources, finance, and compliance programs simultaneously.

She built solutions for FedRAMP, PCI DSS, and HIPAA across multiple government agencies — not because she was handed the assignment, but because the work needed to get done and she was the one who made sure it did.

At SPP, Amy leads GRC services — FedRAMP, CMMC, HITRUST, SOC2, ISO27001, and more — and brings the same orientation she always has: understand the organization first, understand the risk second, build the program around both. She has never believed compliance exists for its own sake. It exists to protect something real.

"The goal is never the certification. The goal is what the certification makes possible for your business."

Read Amy’s Latest Insight CJIS Security Policy 6.0: What Cloud Providers Need to Know Learn how CJIS Security Policy 6.0 impacts cloud providers, strengthens cybersecurity, and expands opportunities in the public sector. Read Amy’s Latest Insight CMMC Flow-Down Compliance: What Prime Contractors Need to Document Learn how primes can demonstrate CMMC and DFARS flow-down compliance with supplier evidence, oversight, and assessment-ready processes. Read Amy’s Latest Insight CMMC Compliance Pitfalls: What to Avoid Struggling with CMMC? Discover common mistakes, compliance risks, and how to prepare for audits and protect DoD contract eligibility. Read Amy’s Latest Insight Keys to Cybersecurity ROI that Boards Understand Demonstrate cybersecurity ROI to your board by linking security investments to business growth, using metrics, automation, and training for financial impact. Read Amy’s Latest Insight Expanding your TAM with a CJIS Security Addendum Expand your total addressable market with CJIS Security Addendum. Learn how to enhance your cybersecurity and meet state and local criminal justice requirements… Read Amy’s Latest Insight Cybersecurity Framework Selection: Understand the ROI Discover how to boost your cybersecurity framework ROI by selecting the right frameworks for your industry. Get a step-by-step guide on evaluating and maximizin… Read Amy’s Latest Insight Getting value from your POA&M Learn how to maximize your POA&M's value and reduce challenges with our expert guide. Discover best practices for managing POA&M and achieving success. Read Amy’s Latest Insight Essentials Guide to CMMC 2.0 Compliance Essential CMMC Compliance requirements, certification, and implementation steps to protect controlled unclassified information and secure defense contracts Read Amy’s Latest Insight Reducing Cyber Risk with GRC Software GRC software reduces cyber risk by streamlining governance, risk management + compliance. Enhance your security posture by Reducing Risk with GRC software. Read Amy’s Latest Insight GRC Software for Healthcare Cybersecurity: Guide to the Essentials Discover how GRC healthcare cybersecurity solutions streamline compliance, mitigate risks, and enhance patient safety. See key features and benefits. Read Amy’s Latest Insight Healthcare Compliance Management: A Single Source of Truth Healthcare compliance management requires a single source of truth powered by GRC software. Simplify regulatory adherence, reduce risks, + data governance. Read Amy’s Latest Insight GRC Governance for IT: Business Alignment and Effectiveness Discover how GRC Governance for IT aligns business goals with technology, enhancing effectiveness and ensuring regulatory compliance in your organization. Read Amy’s Latest Insight Simplify Federal Compliance Complexity with GRC Software Learn how cloud-based GRC software transforms federal compliance complexity from a burden to a business enabler, supporting NIST, FedRAMP, CMMC frameworks. Read Amy’s Latest Insight Evaluating the ROI of GRC Software: Examining Cost Benefit Discover the financial benefits of GRC software and evaluate its ROI. Reduce compliance costs, mitigates risks, and improves operational efficiencies. Read Amy’s Latest Insight GRC Software Powered Risk Registers Streamline Risk Management Streamline risk management with GRC software-powered risk registers. Enhance compliance, mitigate threats, optimize risk response strategies. Read Amy’s Latest Insight Overcoming Federal GRC Software Implementation Challenges Navigate the complexity of GRC software implementation challenges with expert insights. Get strategies to overcome obstacles to ensure successful adoption. Read Amy’s Latest Insight Clear Perspectives on the FedRAMP Timeline Navigate your path to compliance with an essential guide on Planning for the FedRAMP Timeline, tailored for cloud service providers. Read Amy’s Latest Insight Implementing HITRUST GRC for Healthcare: Streamlining Security Explore how HiTRUST Governance, Risk and Compliance software, GRC healthcare streamlines your data protection and compliance with robust security measures and r… Read Amy’s Latest Insight HIPAA Compliance with GRC: Confidence and Risk Reduction Master HIPAA compliance with robust GRC strategies to mitigate risk and demonstrate principled healthcare governance. Read Amy’s Latest Insight Fireside Chat: RiskInsiders to the Rescue GRC Compliance Programs RiskInsiders to the Rescue with Amy Ford, COO and co-founder at Steel Patriot Partners, discussing GRC and successfully completing a compliance journey. Read Amy’s Latest Insight Preparing for a HITRUST Assessment: A Comprehensive Roadmap to Success Learn how to define the scope, conduct a gap analysis, prioritize and remediate, simulate an audit, and maintain documentation for a HITRUST certification Read Amy’s Latest Insight 5 Best Practices for Risk Management: Enhancing Governance Compliance Discover the top five best practices for risk management and how they impact cybersecurity, compliance, and governance. Read Amy’s Latest Insight Case Study: Healthcare ASO Outsourcing Cybersecurity for SOC2 - HIPAA Meet the challenge of compliance with Health Insurance Portability and Accountability Act (HIPAA) and Service Organization Control 2 (SOC2) compliance
Michael Parisi, Chief Growth Officer, Steel Patriot Partners
Michael Parisi
Chief Growth Officer
Areas of Expertise Business Development · Federal Compliance · Client Acquisition · Strategic Partnerships · Market Expansion
Background Former VP, HITRUST · PwC Director · Schellman Head of Client Acquisition
LinkedIn
Chief Growth Officer

Michael Parisi

Michael brings over 20 years of experience across professional services, federal compliance, and cybersecurity certification. He's held senior roles at HITRUST, PwC, and Schellman — organizations at the center of how the compliance industry actually works — which means he understands the gap between what firms promise and what clients actually need.

At SPP, Michael leads growth — but his orientation is the same as the rest of the team: business owners first. He doesn't route people through sales cycles. He connects them directly to the right individuals, the right programs, and the right conversations. His network in the federal compliance space is deep, and he uses it to move fast.

Michael is Bay Area–based and is the face of SPP at industry events — including RSAC Conference, where he's known for the kind of direct, no-hype conversations that actually lead somewhere.

"We're business owners first, engineers second, compliance people third. That's not a tagline. That's the order of operations."

Read Michael’s Latest Insight FedRAMP 20x Explained: The Future of Federal Cloud Compliance Learn how FedRAMP 20x uses automation, KSIs, and continuous evidence to transform federal cloud compliance and security. Read Michael’s Latest Insight CMMC Flow-Down Requirements: A Business Risk Guide for Prime Contractors Discover how primes can manage CMMC and DFARS flow-down requirements as a business risk across contracts, suppliers, and revenue. Read Michael’s Latest Insight Why Most Tool Selections Fail—and How Fit-Gap Assessments Fix Them Learn how to conduct a fit-gap assessment to select the right tools, reduce costs, and align security, compliance, and engineering outcomes. Read Michael’s Latest Insight How to Choose the Right Assessor for Your Compliance and Security Needs How to choose the right security assessor for SOC 2, CMMC, FedRAMP, or ISO. Avoid red flags and protect audit credibility. Read Michael’s Latest Insight Configuring and Running Security Tools: From Checkbox to True Risk Reduction Maximize security ROI by configuring and monitoring tools, not just buying them. Learn to avoid tool sprawl, compliance risks, and hidden vulnerabilities. Read Michael’s Latest Insight Cybersecurity ROI: Speaking the Language of the C-Suite Learn how to effectively communicate Cybersecurity ROI to the C-Suite. Discover the top concerns and value of cybersecurity in the boardroom. Read Michael’s Latest Insight Cybersecurity Strategies to Expand TAM in Regulated Industries Cybersecurity Strategies to Expand TAM in Regulated Markets. Explore the demands of financial, healthcare and other restricted markets to maximize ROI Read Michael’s Latest Insight Five Key Pitfalls in State and Local (SLED) Cybersecurity Compliance Discover the critical challenges and effective strategies for SLED cybersecurity compliance to protect public trust and ensure robust data security. Read Michael’s Latest Insight Expanding Your TAM: Unlocking DoD Market Opportunities with CMMC Expand your business TAM with CMMC compliance. Learn how to increase your market reach, credibility, and ROI in the US defense industry. Read Michael’s Latest Insight Cybersecurity Continuous Monitoring: Finding the Right Support Safeguard your digital assets with expert Cybersecurity Continuous Monitoring solutions that adapt to threats and compliance including Federal ZenGRC Read Michael’s Latest Insight FedRAMP vs. GovRAMP: Path to ROI Doing Business with the Government FedRAMP vs. GovRAMP: Understand the differences and find the best way to start selling into government. Maximize ROI with the right compliance strategy. Read Michael’s Latest Insight Guide to Selecting a Cybersecurity Framework Choose the cybersecurity framework for your company serving in the state and federal arena to ensure compliance, risk management, and enhanced security Read Michael’s Latest Insight Understanding Cybersecurity ROI Discover how to measure your cybsecurity compliance roi through data-driven strategies, risk assessment frameworks, and tailored cost-benefit analysis Read Michael’s Latest Insight DOD Impact Levels: Understanding Security Classifications DOD Impact Levels and their critical role in protecting sensitive data across cloud environments. Discover the process and value of compliance.
Let's Talk

If this sounds like the kind of firm you've been looking for —

The ROI Workshop is the fastest way to find out where you stand and what it would actually take to move forward. Or just schedule a call. Either way, we pick up where the noise leaves off.

Not sure where you stand?

Find your path forward.

Answer three quick questions and we'll help you find the right starting point.

Find Your Path →