Mid-Atlantic Cybersecurity and Compliance Firm:

Duffy Compliance is a consulting firm with an enterprise-level background based in Maryland, serving companies nation-wide. We provide the guidance businesses need to get and stay compliant.

Our main goal is simple: to simplify your compliance process, safeguard your information systems, and help you achieve accreditation with as little stress on your part as possible.

We bring decades of enterprise-level experience and knowledge to our current clients. We have several solutions to meet a multitude of different environments.  We have been working with NIST 800-171 since its inception.  We do our best to offer our extensive experience at an affordable rate.

Executive:

Shawn Duffy, President of Duffy Compliance

Shawn Duffy, CISSP

President

Duffy Compliance Services President and CEO Shawn Duffy has been involved in the IT security industry since the moment he left college in 1992. In one of his first roles, he became the lead administrator in support of an environment containing 250 remote sites. He has worked with early firewall appliances and built some of the first Access Control Lists (ACLs) before many network devices even had the capability to use them.

Shawn Duffy has a proven track record with extensive experience in leading and supporting Information Assurance and System Security programs. He has experience in sales, security engineering, and as a contributor with large contractors, such as Northrop Grumman and General Dynamics, as well as in risk and vulnerability management and government compliance.  Focus areas include: CMMC, DFARS/CUI, FISMA, Threat Management, Vulnerability, Assessments and Penetration Testing.

Shawn Duffy, President of Duffy Compliance

Why Shawn Founded Duffy Compliance

I believe every business should be as knowledgeable about their systems as possible. Whether you are looking to validate the work of your IT staff or just looking to augment their capabilities, we want to be a part of your solution as trusted consultants. Risk is not about which products you choose to protect your network, it is about your resistance to exposure.

I founded Duffy Compliance Services because I believe people deserve better. After serving as a cybersecurity subject matter expert and helping my previous employer succeed, I was let go—not for performance, but because they no longer saw the value in information assurance. That experience showed me how vulnerable professionals can be when leadership doesn’t understand the true value of their people.

I built this company to change that. Our mission is to empower both our clients and our team with clarity, security, and purpose. We believe strong businesses are built on trust, transparency, and the right people are doing their best work — protected, respected, and empowered. That’s the standard we live by, and the mindset we bring to every client engagement.

– Shawn Duffy, President, Duffy Compliance Services, LLC.

Our Leadership Team:

Dawn Michelle Shuler - Duffy Compliance Services

Dawn Shuler

Integrator

Dawn Shuler is the Integrator for Duffy Compliance Services. (Integrator is akin to Chief Operating Officer and comes from the EOS – Entrepreneurial Operating System – made famous by Gino Wickman in his book Traction.) As Integrator, Dawn coordinates the three main areas of the business: Marketing & Sales, Operations, and Finance & Administration. She brings more than two decades of experience assisting, managing, and leading businesses, and she has a deep passion for systems and processes. She loves being creative, and she gets excited creating a spreadsheet or new system. Dawn lives in Virginia with her husband Mark and cat Kojo, and occasionally is visited by her two adult daughters. In her spare time, she hikes, quilts, and paints.

Don DeWitt - Senior Compliance Consultant - Duffy Compliance

Don DeWitt

Senior Compliance Consultant

Don DeWitt has been involved with US Government Compliance since 2011 starting with FISMA, NIST 800-53, and RMF (Risk Management Framework) compliance. After 6 years in the US Air Force, he shifted his efforts into broader government compliance with CMMC v0.7 and NIST 800-171. He is also a CCP (CMMC Certified Practitioner), and he finds it rewarding to guide companies through the complicated maze of cybersecurity compliance. Don lives with his family along the Savannah River, and in his spare time, he plays video games and travels, enjoying showing his children different experiences and cultures.

Scott Campbell

Scott Campbell

Senior Security Consultant

Scott Campbell has over 15 years of cybersecurity experience spanning penetration testing, federal compliance, and cloud security. At Duffy Compliance, he leads offensive security engagements (external, internal, web application, and cloud assessments) and supports CMMC/NIST 800-171 compliance, RMF/ATO efforts, and vCISO advisory services. He holds certifications including CISSP, CCSP, GPEN, GWAPT, and CMMC Certified Assessor (CCA), and is actively building capabilities in AI red-teaming aligned to the OWASP LLM Top 10 and NIST AI RMF. Scott loves the puzzle of finding the gap an attacker would exploit before they do — and helping clients close it. He lives in southern Louisiana with his family and their basset hound, and outside of work is an avid 3D printing hobbyist and retro gaming enthusiast.

Justin Greene - Executive Assistant at Duffy Compliance

Justin Greene

Executive Assistant

Justin Greene holds the position of Executive Assistant at Duffy Compliance where he makes sure nothing gets dropped through the cracks. He brings five years’ sales and management experience as well as generous amount of enthusiasm and go-get-’em-ness. In this role, he loves seeing things through to the end and taking responsibilities off the team’s plates. Justin lives in Michigan with a variety of animals and enjoys gaming, making videos for TikTok and YouTube, and writing and producing Hip-Hop and R&B music.

History of Duffy

1/9/14
1/9/14

Started Duffy

2014
2014

1st Client

2015
2015

1st Patented Logo

2015
2015

1st Hire

2016
2016

1st Rebrand

2017
2017

Partnered w/MEP

2018
2018

C3PAO Candidate

2023
2023

1st OSC Completed

2024
2024

2nd Rebrand

Subscribe to Our Monthly Newsletter

Free education for cybersecurity.

Name(Required)

Your personal information will not be shared and you are able to unsubscribe at any time.