Built by operators. Bound to standards.
Who we are, how we're credentialed, how we separate consulting from assessment, and how we handle your data. The credibility checklist before you engage.
Who we are
Praedyn LLC
Praedyn is a Colorado-based cybersecurity and compliance consultancy serving the Defense Industrial Base. We work with defense contractors implementing NIST SP 800-171 controls and preparing for CMMC Level 2 and Level 3 assessments.
Our practice is built on a decade of direct DoD and Risk Management Framework (RMF) program work — not theory, not adjacent corporate IT. The advisors who scope your engagement are the advisors who execute it. There is no delivery pyramid; what you see in your kickoff is what you get at closeout.
We are deliberately focused. We do CMMC readiness, implementation, mock pre-assessment, documentation, OT/ICS scope architecture, and ongoing compliance retainer work. We do not do generic managed IT, generic SOC services, or anything outside the CMMC and adjacent compliance lanes. The narrower the focus, the deeper the bench.
Lead practitioner
Daniel Flynn, Principal
Active Secret clearance · 10+ years in DoD and Risk Management Framework program leadership across defense and critical infrastructure environments.
Current and recent roles include IT Program Management at the United States Air Force Academy (Cyber and Network Operations), prior Information Systems Security Manager (ISSM) work in Army environments, and direct OT/ICS recovery experience on AVEVA System Platform-driven SCADA environments. Substantial NIST SP 800-171 Rev. 2 implementation reps across contractor, government civilian, and DoD environments.
Current credentials include CompTIA SecurityX (CASP+), CompTIA Security+. SecurityX maps to DoD Cyber Workforce Framework (DCWF) Code 612 (Security Control Assessor) at the Intermediate proficiency level under DoDM 8140.03 — a qualifying foundational credential for CCA candidacy.
Credential roadmap: Praedyn is registering as a Cyber AB Registered Provider Organization (RPO) in 2026. Cyber AB Registered Practitioner (RP) and Advanced Registered Practitioner (RPA) certifications follow. CMMC Certified Professional (CCP) certification through ISACA / CAICO is the 6-12 month milestone. CMMC Certified Assessor (CCA) candidacy at 12-18 months. The CCA path requires Final Level 2 personal exam plus 3 years cyber experience plus 1 year audit experience plus an 8140-qualifying foundational credential, all of which are tracked on this timeline.
Standards we operate against
CMMC framework
32 CFR Part 170
DoDM 8140.03
Control baselines
NIST SP 800-171 Rev. 2
NIST SP 800-172
NIST SP 800-82 Rev. 3
Assessment methodology
NIST SP 800-171A
DoD Assessment Methodology v1.2.1
Contract clauses
DFARS 252.204-7012
DFARS 252.204-7021
DFARS 252.240-7997
FAR 52.240-93
OT / ICS
NIST SP 800-82 Rev. 3
ISA/IEC 62443
UFC 4-010-06
Cloud authorization
FedRAMP Moderate / High
DoD IL4 / IL5
Ethical separation
We do not assess our own clients.
The Cyber AB and 32 CFR Part 170 require strict separation between organizations that prepare a contractor for CMMC certification and the C3PAO that conducts the assessment. Praedyn does not perform C3PAO assessments on its own consulting clients. We will not refer you to an assessor we have a financial relationship with, and we do not accept referral fees from C3PAOs.
When the time comes for your formal assessment, we help you scope and select an independent C3PAO from the Cyber AB Marketplace. We will support your team through the assessment as your advisor — answering assessor questions, providing context, and helping close findings — but we hold no role in scoring decisions.
This is a regulatory requirement, not a positioning choice. Firms that try to play both sides risk decertification of any assessment they touch. If you are speaking with a CMMC consultant who offers to both prepare and assess you, that is a hard signal something is wrong.
CUI handling
Your CUI stays in your custody.
Praedyn does not store Controlled Unclassified Information on its own systems during the consulting engagement. Detailed CUI inventories, network diagrams containing CUI flows, and contract documents are reviewed inside your environment — your Microsoft 365 GCC High tenancy, your Azure Government enclave, or whatever FedRAMP-equivalent platform you operate.
The intake form on this site explicitly does not collect CUI. It captures scope and environment metadata only — counts, categories, postures, contract clause presence. Detailed sensitive material is exchanged only after engagement and only through your approved channels.
Praedyn personnel sign your NDAs and work under your data-handling rules during engagements. We bring our credentials and process; you retain custody of your data.
How to verify us
Verification paths
Cyber AB Marketplace: RPO listing in progress. Once registered, our RPO number will appear at cyberab.org/marketplace and we will publish it here.
Clearance verification: Active Secret clearance under DoD CAF. Verifiable through standard government channels with appropriate need-to-know.
Credentials verification: Individual practitioner credentials verifiable through the CompTIA verification portal. Cyber AB and ISACA / CAICO credentials posted here as obtained.
References: We provide professional references from prior DoD program work on request, subject to the source organization's permission.
— Ready to scope an engagement