Issue link: https://iconnect007.uberflip.com/i/1546025
28 SMT007 MAGAZINE I AUGUST 2026 CMMC 2.0 Level 2 certification provides customers with verified assurance that suppliers meet the cybersecurity standards required to handle government and defense program data, and that this assur- ance is ongoing. As part of the certi- fication, we conduct annual cyberse- curity evaluations and must undergo full recertification every three years. The certification also strengthens supply chain security beyond our own walls. We hold our vendors and manufacturing partners to the same standards, creating consistent security expecta- tions across every link in the chain rather than only at the prime contractor level. For customers working on programs where data protection is a contractual requirement, consistency matters. A Process That Started Before It Was Required We didn't start this process because a contract required it. We started it in 2019 because we saw where DoD cybersecurity requirements were headed and recognized that getting ahead of them was the right thing to do for our customers and our business. We began implementing NIST 800-171 controls in 2019, aligned with early DoD requirements for contractor self-assessment and in anticipation of stricter compliance expectations. Recognizing the scope of the effort, we hired a DFARS compliance firm with more than a decade of influence on federal cybersecurity policy, including involvement in the creation of DIB-CSI, the original DFARS clause, and subsequent updates. That partnership guided the implementation of NIST 800-171 controls, closure of security gaps, and development of formal poli- cies and procedures that would later hold up under audit scrutiny. By mid-2025, we were positioned to pursue third-party certification ahead of the Phase 2 deadline of Nov. 10, 2026, when we understood that mandatory C3PAO certification requirements would take effect for applicable DoD contracts. (Note: That requirement was suspended on July 13, 2026, pending a 60-day review.) Achieving CMMC 2.0 Level 2 certifica- tion required a sustained, company- wide effort that touched every part of our operations, from IT infrastructure to employee workflows. We started this work years before it became a contractual requirement because we understood what our defense customers needed from a supplier: not just capability but verified accountability. The Biggest Hurdles in CMMC Certification For most organizations, the hardest part of CMMC certification isn't understanding the requirements; it's ensuring that technology, process, and docu- mentation all stay aligned at the same time. On the technical side, we found that existing tools for storing or sharing customer files, whether hosted on-premises or in the cloud, may not meet CMMC requirements. If a current system isn't compliant, the organization must either recon- figure or migrate to a compliant alternative, such as a platform listed on the FedRAMP Marketplace. Either path introduces costs, operational disrup- tions, and changes to employee workflows that must be managed carefully. Documentation is another major area that has required significant effort. Auditors review the entire environment, the individual systems within it, and the flow of CUI assessed through a combination of configuration evidence and formal written poli- cies and procedures. What we learned is that docu- mentation can't be an afterthought. Clear, finalized documentation helps auditors understand the envi- ronment and gives employees consistent guidance. As systems evolve, keeping documentation aligned with actual configurations is an ongoing obligation, not a one-time deliverable. Common Issues Companies Face Beyond the core technical and docu- mentation requirements, several issues come up consistently across organizations pursuing CMMC certi- fication, regardless of company size or how far along they are in the process. Daniel Porton Alex Danovich

