Petronella Secure Data Suite

Encrypted Data, Email, and CUI Vault for CMMC, ITAR, HIPAA, and Beyond

End-to-end encrypted email, encrypted file sharing, an encrypted vault for CUI and ePHI, and the ComplianceArmor® documentation backbone, operated and supported by Petronella Technology Group, Inc., a Raleigh, NC firm anchored by CMMC RPO #1449 and four CMMC Registered Practitioners since 2002.

CMMC RPO #1449, verifiable on the Cyber AB registry
4 CMMC-RP practitioners on staff
Founded 2002, A+ BBB Accredited
FedRAMP Moderate Equivalent platform, FIPS 140-3
Direct answer

What does enterprise-grade data protection look like in 2026? A NIST-validated end-to-end encryption layer on email and storage; a documentation system that produces an assessment-ready SSP, SOPs, and Shared Responsibility Matrix; twenty-four-seven managed detection and response on the endpoint, network, identity, and cloud telemetry that surrounds your data; a vCISO who owns risk decisions in writing; and an MSP that operates the controls every business day. Petronella Technology Group, Inc. delivers all five in one accountable engagement under CMMC RPO #1449.

Petronella Technology Group, Inc. secure operations center monitoring encrypted client data in Raleigh NC

Vendor compliance accelerators sell documentation. Petronella operates the documentation system, the encrypted fabric, and the MSP that keeps both running.

If you have priced compliance over the past year, you have probably been pitched a "compliance accelerator" or "compliance-in-a-box" product. Almost all of them are software-only, you receive a license to a documentation generator, maybe pre-filled templates for one regulatory framework, and a video library that explains the controls. You are then on your own to integrate the documentation with a real encryption platform, a real monitoring service, and a real human governance program. Two years later, when an auditor or a Department of Defense supplier flow-down request arrives, you discover the documentation is only as good as the operational reality it describes, and there is no operational reality.

Petronella Technology Group, Inc. solves a different problem. We deliver the documentation, the encrypted data and email fabric that the documentation describes, the managed detection and response service that protects that fabric, the Petronella vCISO who owns risk decisions in writing, and the managed-IT operations team that keeps the controls running on a daily basis. One firm, one accountable provider, one phone number, under CMMC RPO #1449 and four CMMC-RP practitioners with verifiable credentials on the Cyber AB registry. We have been the operator of regulated environments in Raleigh, North Carolina since 2002.

This page describes the Petronella Secure Data Suite, our brand for the encrypted data and email fabric, and how it integrates with our other PTG-owned services to deliver auditable compliance across CMMC, HIPAA, FTC Safeguards, GLB, FERPA, CJIS, PCI DSS, ISO 27001, and SOC 2 from a single point of contact.

The Petronella Secure Data Suite: what it is

Petronella Secure Data Suite is our branded encrypted data and email system. Inside, it is built on a FedRAMP Moderate Equivalent platform with FIPS 140-3 validated cryptographic modules and Controlled Unclassified Information (CUI) storage in AWS GovCloud. The architectural anchor is straightforward: encryption keys are generated and stored on user devices, never on a vendor server. There is no central key store for an attacker, an insider, or a subpoena to compromise. Every message and every file is encrypted before it leaves the sender's device and remains encrypted until it reaches the recipient's device.

For your users, the experience is unchanged from the email and file-sharing tools they already know. Outlook, Outlook on the Web, Gmail, Apple Mail, Windows File Explorer, Mac Finder, iOS, Android, and any modern browser are all supported through native integrations. The address on your business card stays the same. The send button is in the same place. Internal mail and file shares are encrypted by default; external recipients without an encrypted account receive a secure web portal link, which they can claim with a free third-party account and reuse for every future exchange with your firm.

End-to-end encrypted email

Outlook, Gmail, and Apple Mail send and receive encrypted by default. Existing mailbox addresses preserved. External recipients claim free third-party accounts, no per-guest licensing cost.

Encrypted file storage and sharing

Windows Explorer and Mac Finder drives, mobile apps, browser access. Granular share permissions, revoke at any time, two-gigabyte file size ceiling supports large CAD, BIM, and discovery file transfer.

Encrypted data rooms

Auditable shared spaces for sensitive transactions, mergers and acquisitions, litigation discovery, due diligence, regulator response, board collaboration. Each room ships with cryptographic activity logs.

Customer-managed keys, zero-trust architecture

Device-stored keys mean no shared passwords to steal, no central key vault to breach. Approval Groups require multi-party consent for high-impact admin actions. Built for the zero-trust threat model.

CUI vault that satisfies NIST 800-171 r3 storage

Storage tier validated against the NIST SP 800-171 r3 media protection control family, with CUI residency in AWS GovCloud and documented mapping to every applicable control inside your SSP.

One hundred plus of one hundred and ten controls

The encrypted fabric plus ComplianceArmor® procedures plus PTG-operated MSP processes address every NIST SP 800-171 control. Each control is tied to the responsible Petronella service inside the System Security Plan.

Compliance frameworks supported

Petronella Secure Data Suite is most commonly deployed for CMMC, but the same encrypted data and email and CUI vault architecture is engineered to meet the encryption, key-management, and audit requirements of every framework below. Coverage is full unless noted.

FrameworkCoverageHow Petronella Secure Data Suite satisfies it
CMMC Level 2 / Level 3FullEnd-to-end encrypted CUI handling, FIPS 140-3 modules, AWS GovCloud storage, mapped to NIST SP 800-171 r3 controls inside every ComplianceArmor SSP
ITAR § 120.54FullEnd-to-end encryption with keys generated and stored on US-controlled user devices, satisfying the § 120.54 carveout for ITAR-controlled technical drawings
NIST SP 800-171 r3FullOver 100 of the 110 controls covered directly by the encrypted data and email layer; remainder covered by Petronella vCISO governance and ComplianceArmor procedures
NIST SP 800-172FullAdvanced encryption and audit logging meets the enhanced security requirements for CMMC Level 3 and CUI workloads with APT risk
HIPAAFull plus Safe HarborNIST-standard encryption at rest and in transit, with a signed Business Associate Agreement; ComplianceArmor generates the HIPAA Security Risk Analysis
FERPAFullEncrypted student records with role-based access and complete audit trail satisfy the education-records protection standard
CJISFullFIPS-validated encryption and audit logging meets the FBI Criminal Justice Information Services Security Policy
FTC Safeguards RuleFullEncryption, access controls, monitoring, and incident response inside one integrated stack with documented qualified-individual oversight
Gramm-Leach-BlileyFullCustomer information safeguards via end-to-end encryption and access logging, with a documented Information Security Program through ComplianceArmor
PCI DSS 4.0.1FullEncrypted cardholder data storage, audit logging, and key management satisfy the PCI requirements; ComplianceArmor generates the ROC-supporting evidence
ISO 27001:2022FullAnnex A controls covered by the encrypted stack and governance; ComplianceArmor generates the Statement of Applicability
SOC 2 Type I and Type IIFullAll five Trust Services Criteria covered with documented evidence; assessor-ready package
CCPAFullEncrypted PII storage with documented access logs supports the right-to-know and right-to-delete obligations

ComplianceArmor®: the documentation backbone

An encrypted data fabric without documentation is not auditable. ComplianceArmor® is the multi-framework documentation platform we built and operate, and it is the second pillar of Petronella Secure Data Suite. ComplianceArmor® generates System Security Plans, Standard Operating Procedures across every NIST SP 800-171 control family, the Shared Responsibility Matrix between Petronella Technology Group, Inc. and your organization, Network and CUI Flow Diagrams, and assessment-ready checklists. It covers CMMC, HIPAA, SOC 2 Type I and Type II, PCI DSS 4.0.1, ISO 27001, and CCPA in one platform, broader than any single-framework documentation accelerator we have seen.

The platform uses a large language model only for intake, asking the right questions, extracting information from your existing policies, and explaining what a given control means in plain English. The generated artifacts themselves are produced from PTG-authored templates that have been refined across hundreds of regulated client engagements since 2002. Author attestation on every SSP we ship traces back to RPO #1449. A Department of Defense procurement officer or a HIPAA auditor can independently verify that number against the Cyber AB registry.

Learn more at /compliance/compliancearmor/, including the framework-specific deep dives for CMMC compliance software, HIPAA compliance software, and the broader CMMC Compliance Guide.

Compliance documentation generation with ComplianceArmor across CMMC, HIPAA, SOC 2, PCI DSS, ISO 27001, and CCPA

Petronella XDR: live detection and response

Encryption protects your data from interception in motion and from exposure at rest. It does not detect an attacker who has already compromised a workstation, stolen a privileged credential, or planted persistence inside your perimeter. The third pillar of Petronella Secure Data Suite is Petronella XDR: our extended detection and response service that monitors endpoint, network, identity, and cloud telemetry around the clock, with response actions executed by our security operations team.

Petronella XDR runs as a managed service, which means we own the alert triage, the playbook execution, and the after-action documentation. Your internal IT team does not have to learn a new SIEM, write detection rules, or staff a twenty-four-seven watch desk. We take that off the table and surface only the incidents that require client decisions or notifications. The two layers are complementary by design: encryption keeps data confidential even if a device is stolen or coerced; XDR detects and contains the intrusion before encrypted data can be exfiltrated under attacker control.

Details and pricing at /managed-xdr/.

Petronella vCISO: governance and risk decisions in writing

The fourth pillar is the Petronella vCISO. Blake Rea, CMMC-RP, leads the vCISO practice. Craig Petronella, CMMC-RP and founder of Petronella Technology Group, Inc. since 2002, serves as the executive sponsor on every vCISO engagement involving regulated data. The vCISO program produces the documents that an auditor, an insurance underwriter, a Department of Defense customer, or a regulator will ask for: the risk register, the documented risk acceptance decisions, the third-party risk reviews, the incident response runbooks, and the annual security program report to the board.

For organizations preparing for a CMMC assessment, Blake Rea functions as the lead practitioner and signs off on the readiness package. For organizations that need a CISO-level signature on a HIPAA Security Risk Analysis, a SOC 2 description of services, or a PCI DSS scoping memorandum, the same governance program produces that artifact. The vCISO sits one layer above the operational delivery team, separating the "who decides" from the "who executes", which is a control most small firms cannot afford to maintain internally.

Program details at /solutions/vciso/.

MSP-grade operations: the controls run every day

The fifth pillar is the part most security firms quietly skip. Documentation, encryption, monitoring, and governance only deliver compliance if they are operated every day. Petronella Technology Group, Inc. has been a Raleigh, North Carolina managed-IT services provider since 2002, which means we own the unglamorous side of compliance: patching, backup verification, drift detection, license adjustments, account-provisioning workflow, joiner-mover-leaver discipline, mobile device management, browser hardening, secure-baseline enforcement, and the help desk that resolves the user lockout at 7:42 a.m. so your CFO can sign payroll on time.

This is the operational reality that gives the documentation its meaning. When a client SSP states "user accounts are reviewed quarterly," the MSP runs that review on the calendar with an artifact archived to the audit folder. When the SSP states "endpoint baselines are enforced," the RMM and the EDR enforce it and produce the evidence. There is no gap between the document and the practice. This is why we lead with the whole stack rather than a single product.

See /it-services/managed-it-services/ for the managed-IT program and /managed-it-services-raleigh-nc/ for the Raleigh-local engagement model.

Use case 1: DoD supplier with CUI

For a defense subcontractor handling Controlled Unclassified Information under a Department of Defense flow-down, three architectural patterns are available and each makes sense in different scenarios. Pattern A is Microsoft GCC High, a sovereign Microsoft 365 tenant designed for CUI workloads. Pattern B is a Petronella encrypted enclave layered on top of your commercial Microsoft 365 or Google Workspace tenant, with the Petronella Secure Data Suite isolating CUI from non-CUI workflows and pairing with de-identified commercial Power BI for reporting. Pattern C is Power BI Report Server running on-premises inside your CUI authorization boundary.

For most small and mid-size defense suppliers we work with, Pattern B is the right answer, faster to deploy, materially less expensive than a GCC High migration, and operable with the staff a thirty-person shop already has. For organizations with deep dependencies on Microsoft 365 services that GCC High alone provides, or with explicit contract language calling out GCC High, Pattern A is the right answer and we will say so on the scoping call. Pattern C is reserved for shops with air-gapped CNC machines or floor-network constraints that argue against any cloud option.

The full three-pattern decision tree lives at /cmmc-power-bi-reporting/. For the broader CMMC readiness path, see the CMMC Compliance Guide.

Use case 2: Healthcare practice with electronic protected health information

For a clinical practice, behavioral health provider, dental group, or specialty clinic moving electronic protected health information (ePHI) across email and file-sharing channels, the regulatory anchor is the HIPAA Security Rule plus the HIPAA Breach Notification Rule's Safe Harbor for encrypted data. When ePHI is encrypted to NIST standards at the time of unauthorized access, the breach notification obligation does not attach. The Petronella Secure Data Suite encrypted email and storage layer meets that NIST standard, and Petronella Technology Group, Inc. signs a Business Associate Agreement with every healthcare client before any ePHI touches the platform.

ComplianceArmor® generates the HIPAA Security Risk Analysis and Risk Management Plan that complete the Safe Harbor evidence chain. The architecture pattern pairs with role-based access, sensitivity labels, audit-log retention, and a documented prohibition on Publish-to-Web for any Power BI dashboards built on top of the same data. See the broader HIPAA architecture playbook at /power-bi-hipaa-dashboards/ for reporting use cases, and /compliance/compliancearmor/hipaa-software/ for the documentation deep dive.

Use case 3: Law firm with privileged matter data

For a law firm, the data protection problem has unusual breadth. A single firm may simultaneously handle Controlled Unclassified Information for a defense industrial base client, electronic protected health information for a healthcare client, financial data subject to Gramm-Leach-Bliley for a banking client, attorney-client privileged communications across every matter, eDiscovery materials under judicial protective order, and donor or board records in the firm's own books. Maintaining a separate compliance stack for each regulatory regime is unworkable.

The Petronella Secure Data Suite covers all of these on a single platform. Encrypted matter rooms isolate privileged communications by case. Free third-party accounts let clients, expert witnesses, and outside counsel claim encrypted access at no per-seat cost, material for a firm handling fifty external matters. Cryptographic activity logs satisfy eDiscovery audit requirements and court-defensible retention. ABA Model Rule 1.6 confidentiality obligations and the more recent state bar opinions on attorney duty of competence with respect to client data security are addressed by the same platform that satisfies CMMC and HIPAA, without separate procurement, separate licensing, or separate user training. Sector deep dive at /power-bi-for-law-firms/ for the reporting and analytics layer.

Use case 4: Manufacturer with ITAR drawings on the shop floor

For a manufacturing firm, particularly a CNC shop, a fabrication shop, or a contract manufacturer producing parts under International Traffic in Arms Regulations (ITAR) drawings or Controlled Defense Information, the data protection challenge sits across air-gapped machine controllers, engineering workstations carrying CAD and BIM files, and the email channel through which the prime contractor ships work orders. ITAR § 120.54 provides an end-to-end encryption carveout: an ITAR-controlled technical drawing transmitted under end-to-end encryption where the keys never leave United States-controlled devices is not, under that rule, a controlled export.

The Petronella Secure Data Suite is designed to satisfy the § 120.54 conditions. Combined with Petronella XDR on the engineering workstations and an MSP-operated secure handoff workflow to the shop floor, the architecture lets a small shop ship CMMC Level 2 readiness and ITAR-compliant drawing handling without ripping out commercial Microsoft 365.

Use case 5: Tax or accounting firm under the FTC Safeguards Rule

For a CPA firm, an enrolled agent, or a tax preparer, the regulatory drivers in 2026 are the Federal Trade Commission Safeguards Rule (updated 2023, enforcement teeth attached), IRS Publication 4557's Written Information Security Plan requirement, and the Gramm-Leach-Bliley Act. The Safeguards Rule requires a designated qualified individual responsible for the information security program, a written risk assessment, encryption of customer information at rest and in transit, multi-factor authentication, regular monitoring, and an annual report to the board or owner.

The Petronella Secure Data Suite covers the encryption mandate end to end. ComplianceArmor® produces the Written Information Security Plan, the risk assessment, and the annual report. The Petronella vCISO program supplies the qualified individual designation where the firm does not have one in-house. Petronella XDR delivers the monitoring requirement. Free third-party accounts let clients return signed 1040s, K-1s, and engagement letters through the encrypted portal at no per-client cost, material for a firm handling four hundred returns per season. Sector pillar at /ftc-safeguards-rule-compliance/.

Petronella partners with regulated industries for encrypted data protection and compliance

Some vendors sell an accelerator product. Petronella operates the full stack.

The honest version of the competitive picture: many vendors will sell you a compliance accelerator product. We have evaluated them. Most are competent at the slice of the problem they address. None of them deliver the surrounding stack, the encrypted data fabric, the managed detection and response, the vCISO governance, and the MSP-grade daily operations, under one accountable provider with verifiable Cyber AB credentials.

Capability Typical single-vendor accelerator product Petronella Technology Group, Inc.
Multi-framework documentation One framework (usually CMMC only) CMMC + HIPAA + SOC 2 + PCI DSS + ISO 27001 + CCPA
Encrypted email layer Sometimes bundled, sometimes not Always, Petronella Secure Data Suite
Encrypted file and data-room storage Rarely Always, same encrypted substrate
Managed detection and response on endpoints, network, identity, cloud No, separate procurement Petronella XDR, bundled
vCISO governance with executive sponsor signature No, separate consultancy Blake Rea leads, Craig Petronella sponsors
MSP-grade daily operations of the controls No, your problem Petronella MSP since 2002
Author attestation against CMMC Registered Provider Organization Sometimes RPO #1449 on every SSP
CMMC Registered Practitioners on staff Varies Four (Craig, Blake, Justin, Jonathan)
Local Raleigh, NC delivery option No, remote-only Raleigh-headquartered since 2002

For organizations that want to compare framework breadth specifically, ComplianceArmor® is the broadest documentation platform we have benchmarked, and we benchmark every quarter. It is built for the regulated SMB that has more than one compliance driver, almost every business we work with does.

Engagement model

Engagements are fixed-fee with published scope. Initial fixed-fee milestones are paid one hundred percent upfront at contract execution before kickoff, in line with our standard payment terms. Three engagement tiers are typical:

  • Foundation: encrypted email layer plus encrypted drive plus the first ComplianceArmor® SSP draft for one framework. Typical scope: five to twenty-five users. Ships in two to six weeks. Pairs with an annual Petronella XDR Operations Retainer and an optional Petronella vCISO Light retainer.
  • Compliance Sprint: Foundation plus full framework documentation (SSP, SOPs, CRM, network and CUI flow diagrams, assessment checklists) plus vCISO governance program plus Petronella XDR rollout. Typical scope: twenty-five to two hundred fifty users. Ships in eight to fourteen weeks. Designed for clients with a known external assessment date.
  • Enterprise Anchor: Compliance Sprint plus multi-framework documentation (any combination of CMMC, HIPAA, SOC 2, PCI DSS, ISO 27001), MSP-grade operations, Petronella XDR with extended retention, and full Petronella vCISO Standard. Typical scope: two hundred fifty to two thousand users or complex multi-entity organizations. Ships in twelve to twenty weeks.

All three include a written Shared Responsibility Matrix making it explicit who owns each control, an annual program review with the executive sponsor, and access to the four-person CMMC-RP bench. Each tier has a published "From" starting price disclosed in the written proposal, scoped to your user count, data sources, regulatory framework, and integration footprint. We do not bill hourly for delivery work.

For organizations with an in-flight active engagement, retention pricing is asymmetric, the loyalty credit applies on continuation of the same tier and does not transfer to a downgrade. This is in line with our published pricing policy.

Frequently asked questions

Does the Petronella Secure Data Suite replace Microsoft GCC High?
It can, depending on your data, your contracts, and your CUI flow. For roughly nine out of ten small and mid-size defense suppliers we work with, an end-to-end encrypted enclave plus ComplianceArmor® documentation plus Petronella XDR is a faster, less disruptive, and less expensive path to CMMC Level 2 readiness than a GCC High tenant migration. For organizations with broad Microsoft 365 dependencies on CUI workflows or specific contract clauses calling out GCC High, GCC High remains the right answer and we will tell you so on the assessment call. The three-pattern decision tree at /cmmc-power-bi-reporting/ breaks the choice down line by line.
Is the encrypted system FedRAMP Moderate Equivalent and FIPS 140-3 validated?
Yes. The platform we operate inside Petronella Secure Data Suite is built on a FedRAMP Moderate Equivalent foundation with cryptographic modules validated against FIPS 140-3, with CUI stored in AWS GovCloud. End-to-end encryption keys are generated and stored on user devices, never on a vendor server, which means there is no central key store for an attacker or insider to compromise. We document the mapping of these controls to NIST SP 800-171 r3 and CMMC Level 2 inside every client SSP we generate through ComplianceArmor®.
How does this compare to a single-vendor compliance accelerator product?
A typical vendor compliance accelerator sells you a single product bundle aimed at one framework. Petronella Technology Group, Inc. delivers the full stack, the encrypted data and email substrate, the multi-framework documentation platform, the Petronella XDR managed detection and response service, the Petronella vCISO led by Blake Rea, and MSP-grade daily operations. You get one accountable provider for the entire control set rather than a license plus a stack of consultants you have to coordinate yourself.
What CMMC controls does the encrypted system cover?
The encrypted data and email layer addresses more than one hundred of the one hundred and ten NIST SP 800-171 controls that anchor CMMC Level 2, access control, audit and accountability, identification and authentication, media protection, system and communications protection, and system and information integrity in particular. The remaining controls (physical protection, awareness and training, supply chain risk management) are covered by Petronella vCISO governance, ComplianceArmor® procedures, security awareness training, and MSP operations. We map each control to the responsible Petronella service inside the client SSP.
Is data protection only for DoD contractors?
No. The same encrypted substrate that satisfies NIST SP 800-171 for DoD suppliers also satisfies the HIPAA Security Rule transmission and storage encryption requirements, the FTC Safeguards Rule for accounting firms and auto dealerships, the Gramm-Leach-Bliley Act for financial institutions, IRS Publication 4557 for tax preparers, attorney-client privilege protections for law firms, FERPA for higher education, and CJIS for law enforcement adjacency.
Will Outlook, Gmail, or Apple Mail break?
No. The encrypted email layer integrates with Outlook (desktop and Outlook on the Web), Gmail, and Apple Mail through native add-ins. Your existing mailbox addresses are unchanged. Internal users send encrypted by default; external users without an encrypted account get a secure web portal link, which they can claim with a free third-party account.
Does HIPAA Safe Harbor apply if we use this system?
Yes, under the conditions specified by HHS. The Breach Notification Rule provides a Safe Harbor when protected health information was encrypted to NIST standards at the time of unauthorized access. The encrypted email and storage layer meets that NIST encryption standard. Petronella Technology Group, Inc. signs a Business Associate Agreement with every healthcare client. ComplianceArmor® generates the HIPAA Security Risk Analysis and Risk Management Plan that complete the Safe Harbor evidence chain.
How long does deployment take?
A typical small to mid-size deployment ships in two to six weeks. A larger CMMC Level 2 readiness engagement that adds vCISO governance, MSP onboarding, and Petronella XDR rollout ships in roughly twelve weeks. Every engagement is fixed-fee with milestones paid one hundred percent upfront at contract execution.
Who actually delivers the engagement?
Petronella Technology Group, Inc. carries four staff with the CMMC Registered Practitioner credential, Craig Petronella, Blake Rea, Justin Summers, and Jonathan Wood. Blake Rea leads the Petronella vCISO program. Craig Petronella, founder since 2002, serves as executive sponsor and senior reviewer on every engagement involving regulated data. We hold CMMC RPO designation number 1449, a verifiable credential on the Cyber AB registry.
Do free third-party accounts cost anything?
No. External recipients can claim a free third-party account to receive and reply to encrypted messages. For a law firm handling fifty external matters or a CPA firm handling four hundred clients per tax season, this is a meaningful economic advantage versus tenant-licensed alternatives where every external collaborator typically needs a paid guest license.
What does Petronella XDR add on top of encryption?
Encryption protects data in motion and at rest, but it does not detect an attacker who has already compromised a user device or a privileged account. Petronella XDR is our managed extended detection and response service, twenty-four-seven monitoring of endpoint, network, identity, and cloud telemetry with response actions executed by our security operations team. The two layers are complementary.
How do I request a quote?
Submit the form on this page or call Penny at (919) 348-4912. We will schedule a fifteen-minute scoping call, confirm your regulatory drivers and user count, and send a written fixed-fee proposal within three business days. Most engagements kick off within two weeks of contract execution.

About the author

Craig Petronella, founder of Petronella Technology Group, Inc.

Craig Petronella is the founder of Petronella Technology Group, Inc. (Raleigh, NC, est. 2002). He holds the CMMC Registered Practitioner (CMMC-RP) designation through the Cyber AB, Cisco CCNA (CSCO13961360), Certified Wireless Network Expert (CWNE) through CWNP, Hubbell Certified, and Digital Forensic Examiner License 604180-DFE. He is a #1 Amazon Best-Selling Author of fourteen-plus cybersecurity titles including "How HIPAA Can Crush Your Medical Practice" and "The Ultimate Guide to CMMC," and is an MIT Sloan AI Implications for Business Strategy program alumnus.

Craig serves as executive sponsor and senior reviewer on every Petronella Technology Group, Inc. engagement involving regulated data. Blake Rea, also CMMC-RP, leads the day-to-day Petronella vCISO program and is the lead practitioner on CMMC governance engagements. Justin Summers and Jonathan Wood, also CMMC-RP, complete the four-person Registered Practitioner bench.

Petronella Technology Group, Inc. operates under CMMC Registered Provider Organization #1449, verifiable on the Cyber AB registry.

Request a data protection quote

Tell us what you need to protect and what frameworks apply. Blake Rea or Craig Petronella replies within four business hours, often sooner.

Ready to protect your data the way an auditor will look at it?

Petronella Technology Group, Inc. delivers data protection, compliance documentation, managed detection and response, vCISO governance, and managed-IT operations from Raleigh, North Carolina under CMMC Registered Provider Organization number 1449 and four CMMC-RP practitioners. One firm, one accountable provider, one phone number.

See also: data protection for healthcare HIPAA.