Profile Merlin Group's three-part cyber engineCapital meets compliance meets government distributionCGC reached FedRAMP Certified status in 2026Merlin Ventures closed more than $75M Profile Merlin Group's three-part cyber engineCapital meets compliance meets government distributionCGC reached FedRAMP Certified status in 2026Merlin Ventures closed more than $75M

Company Profile / Cybersecurity

Merlin Group Built a Three-Engine Shortcut Into Government Cybersecurity

Most cyber investors write checks. Merlin Group pairs capital with a FedRAMP platform and a federal sales engine - an unusually literal attempt to turn promising security software into government-ready products.

The least glamorous obstacle in cybersecurity may be the one that decides who gets to sell. A startup can spot a novel threat, hire exacting engineers and build a sharp product, then arrive at the edge of the U.S. government market to find a second company waiting to be built: compliant infrastructure, documentation, continuous monitoring, contract vehicles, field support and people who understand how an agency buys. Merlin Group has organized itself around that awkward second act.

From Tysons, Virginia, the privately held group operates three affiliated businesses. Merlin Ventures backs seed-stage security companies. Constellation GovCloud, or CGC, provides a managed cloud and compliance path for software aimed at regulated public markets. Merlin Cyber supplies the sales, engineering, labs, marketing and government-affairs muscle that moves products toward federal, defense, state, local, education and critical-infrastructure customers. The verbs on the company wall are spare: invest, enable, scale.

That structure makes Merlin hard to place in a single box. It resembles a venture firm when founders need capital, a compliance platform when a cloud service needs authorization, and a specialized distributor when an agency needs a deployable solution. The ambiguity is deliberate. Merlin's product is partly the handoff between those functions.

Abstract Swiss-style illustration of three cybersecurity systems circulating around a protected core
Three engines, one guarded center. The orange blocks bring the capital; the teal gates mind the authorization paperwork; the yellow network knows where the buyers live. Even the arrows appear to have clearance.

The moat is made of paperwork

Cybersecurity has no shortage of incubators, resellers or investors. Merlin's distinction is the way it stacks those roles around one costly bottleneck. Commercial software cannot simply wander into a federal system. Cloud services must satisfy security controls, produce evidence, survive assessment and remain under continuous monitoring. The process protects public data, but for a small vendor it can consume time, money and executive attention before the first meaningful agency revenue arrives.

CGC is designed for that middle. The FedRAMP Marketplace describes it as a public-cloud platform-as-a-service architecture supporting Merlin-operated SaaS applications. In February 2026, CGC reached FedRAMP Certified status at the Moderate level through an agency path. Its listed services include Cynamics AI, Hyperproof Gov and Infosec Global Federal's AgileSec Analytics. The useful idea is a shared, managed boundary: let a security company concentrate more of its energy on the product while CGC handles much of the environment and recurring compliance machinery.

1997Predecessor business founded
$75M+Inaugural Merlin Ventures fund
400+CISOs and security executives in the stated community

The platform does not eliminate authorization, nor should it. It changes the starting point. That can matter in a market where timing is strategic: a threat category may become urgent years before a young vendor has the certifications, procurement relationships or support organization to address it. Merlin's proposition is that commercial speed and public accountability can meet sooner if the scaffolding already exists.

“The real product is the passage from interesting technology to something a public agency can actually buy and operate.”

A venture check with field equipment attached

Merlin Ventures formalizes the front of the pipeline. The firm says it typically invests $2 million to $6 million in seed rounds for enterprise cybersecurity companies in the United States and allied countries, with a particular focus on Israel. In June 2025, it closed an oversubscribed inaugural fund above its $75 million target. Managing partners Seth Spergel and Shay Michel manage the fund with Merlin Group founder and CEO David Phelps.

The check is only the entry ticket. Portfolio companies can use Merlin's physical and digital labs, business-development team, government-market expertise and network of security practitioners. The group says its broader community includes more than 400 CISOs and security executives. Merlin Ventures also favors small, curated gatherings - closer to 30 decision-makers in a room than thousands of badge scans in a convention hall. For an early founder, a candid conversation about procurement, deployment and an incumbent's weaknesses can be more valuable than another broad lead list.

The portfolio shows Merlin's preferred terrain: products where technical novelty meets a stubborn enterprise need. Cyolo focuses on secure access for operational technology. Tamnoon works on cloud-security remediation. Cynamics applies sampling and AI to network detection. Earlier investments include secure messenger Wickr, enterprise-browser company Talon, data-security company Dig and application-security company Oxeye. Those four were acquired by larger platforms including Amazon Web Services, Palo Alto Networks and GitLab.

This record also exposes the model's tension. Merlin advises, invests in and helps distribute cyber products while cultivating buyer relationships. That creates valuable information loops, but it demands clear boundaries around diligence, customer choice and portfolio conflicts. The group presents curation as a benefit: fewer products, technically vetted and matched to mission requirements. Buyers will judge the system by whether the curation stays sharper than a conventional catalog.

Two customers, opposite anxieties

On one side is the founder, worried that a long public-sector cycle will drain cash before it produces revenue. On the other is the agency security leader, worried that a promising startup will not understand mission constraints, survive procurement or provide dependable support. Merlin stands in the middle and sells reassurance in both directions.

Merlin Cyber is the outward-facing engine. It assembles public-sector solutions across Zero Trust pillars - identity, devices, networks, applications and data - and supports partners with sales operations, marketing, engineering and government affairs. Its work is not confined to startups Merlin funds. A 2025 partnership with Rimini Street, for example, pairs lower-cost support for Oracle, SAP and VMware environments with public-sector modernization. The pitch is almost budgetary judo: reduce spending on legacy upkeep, then redirect some of the savings toward security and automation.

Competitors usually own one section of this map. Cyber-focused funds such as YL Ventures, Team8 and Cyberstarts compete for founders. Distributors and solution providers such as Carahsoft and GuidePoint Security compete for vendor and government relationships. Compliance specialists such as Coalfire, stackArmor and Second Front help products cross regulated-cloud hurdles. Merlin's argument is not that those services are absent. It is that feedback travels faster when investment, authorization and go-to-market teams share an institutional roof.

Built on an older federal playbook

The flywheel language is new; the underlying habit is not. Phelps founded Merlin Technical Solutions in 1997 after a career that included the U.S. Navy, aerospace companies, satellite command-and-control systems and high-performance computing. The company adapted commercial technology for federal customers and grew quickly. By 2005 it ranked first on Washington Technology's Fast 50. In 2006 it adopted the Merlin International name as it pursued a broader geographic and commercial footprint.

That history matters because government distribution is difficult to manufacture on demand. Contract knowledge, technical credibility and agency trust accumulate in small increments. Merlin has turned those increments into a corporate architecture. The transformation is visible in its leadership: former CISA executive Matt Hartman became chief strategy officer in 2025, and former CISA CIO Robert Costello joined in 2026 to lead digital strategy, technology architecture and enterprise AI.

What customers can do with Merlin

Founders can seek seed backing, test products in lab environments, prepare cloud services for regulated use and build a federal sales motion. Government and critical-infrastructure teams can evaluate emerging tools with a partner that understands authorization, procurement and deployment. Neither side gets a magic door. Both get a guide who has walked the corridor.

The culture Merlin advertises follows the model: startup energy in service of public missions, with engineers, investors, policy specialists and sellers expected to collaborate. The company received Great Place to Work certification in 2024 and later launched a hiring push across cloud engineering, compliance, partner success and Zero Trust practices. LinkedIn places the workforce in the 51-to-200 range, while supplied company data estimates roughly 220 people. As with many private firms, current revenue and valuation are not public.

Where Merlin fits now

Merlin occupies a narrow but expanding strip of the enterprise market: emerging cyber technology that wants access to highly regulated buyers. The same approach can extend beyond classic security software into AI, cloud infrastructure and mission technology, areas the group now names in its hiring and strategy. The challenge will be maintaining specialization while the platform broadens. A curated ecosystem loses its point if it becomes another shelf crowded with overlapping logos.

For founders, Merlin is most useful when government and critical infrastructure are core markets rather than decorative slides in a pitch deck. For agencies, it is useful when the need is genuinely new and established suppliers have not caught up. And for competitors, the lesson is stealable: money is abundant compared with credible distribution. Build around the customer's hardest non-product work, and the service layer may become the moat.

Merlin's three engines will not make federal buying simple. Nothing credible does. But the group has identified a set of delays that repeatedly strand good technology and made those delays legible, serviceable and investable. That is a quieter ambition than inventing the next security category. It may also be the reason more of those inventions reach the people they were supposed to protect.

Explore Merlin's ecosystem