Protect CUI. Meet CMMC. Win Government Contracts.
Defense contractors and government vendors face strict cybersecurity requirements. We deliver penetration testing and security assessments aligned to CMMC, NIST 800-171, and FedRAMP -helping you protect Controlled Unclassified Information and maintain contract eligibility.
Why this sector gets targeted
Government contractors and defense suppliers are targets of nation-state cyber espionage. APT groups systematically target the defense industrial base (DIB) to steal Controlled Unclassified Information (CUI), technical data, and intellectual property. The Department of Defense has responded with CMMC 2.0, which requires third-party assessment of cybersecurity practices for all contractors handling CUI. Central Florida has a massive defense presence -Lockheed Martin, Raytheon, L3Harris, and Northrop Grumman all operate in the region -creating a deep supply chain of subcontractors who must also meet CMMC requirements. Non-compliance means losing the ability to bid on DoD contracts.
Who we work with here
What we usually run
Scoped for this sector rather than sold as a catalogue. Each one is fixed scope with retest included.
CMMC Penetration Testing
Validate your CMMC Level 2 controls with an independent penetration test.
How it runs →Active Directory Testing
Government networks rely on AD. Test for privilege escalation and lateral movement.
How it runs →Cloud Security Testing
Validate GovCloud, Azure Government, and AWS security configurations.
How it runs →Red Team Operations
Simulate nation-state adversary techniques against your environment.
How it runs →Vulnerability Management
Continuous scanning and patch validation for NIST 800-171 compliance.
How it runs →Web Application Penetration Testing
Test government-facing portals, contractor systems, and internal web apps.
How it runs →What you get working with Lorikeet
- Testing methodology aligned to NIST 800-171 and CMMC Level 2 requirements
- Experience with defense contractor environments, CUI protection, and government compliance
- Located in Central Florida -heart of the aerospace and defense corridor
Asked on almost every call
CMMC 2.0 Level 2 requires implementation of all 110 NIST 800-171 controls. While penetration testing is not a standalone CMMC requirement, it validates the effectiveness of your security controls and is strongly recommended as part of your assessment preparation. Many C3PAOs expect to see pentest results.
Government engagements require additional operational security, controlled handling of findings, and alignment to specific frameworks (NIST 800-53, NIST 800-171, FedRAMP). We scope our testing to focus on CUI boundaries, enclave security, and the specific control families relevant to your authorization or certification.
Yes. Our penetration testing identifies gaps in your CMMC control implementation before your C3PAO assessment. We provide findings mapped to specific NIST 800-171 controls, so your remediation directly addresses assessment criteria. We also partner with audit firms that perform CMMC assessments.
Yes. Lorikeet Security is based in the Orlando metro area, home to major defense contractors including Lockheed Martin, Raytheon, L3Harris, and Northrop Grumman. We understand the local defense supply chain and the specific compliance challenges subcontractors face.
Yes. We test AWS GovCloud, Azure Government, and other FedRAMP-authorized environments. We follow the cloud service provider security guidelines and coordinate with your cloud team to ensure testing stays within authorized boundaries.
Scope it in one call
Tell us what is in scope and we come back with a fixed price and a start date.