Key Takeaways
- Georgia Tech’s secure research environment, Shield, earned Level 2 Cybersecurity Maturity Model Certification (CMMC) after an independent C3PAO assessment.
- The certification confirms that Shield meets all 110 CMMC‑required security practices and received the highest Supplier Performance Risk System rating of 110.
- Shield was created in 2025 to support Defense‑related research involving Controlled Unclassified Information (CUI) and to satisfy DoD cybersecurity mandates.
- The achievement validates Georgia Tech’s integrated research‑operations, IT, and cybersecurity teams, reinforcing its reputation as a trusted partner for government‑sponsored projects.
- The credential enhances the Institute’s ability to retain existing DoD contracts and compete for future opportunities that demand proven cybersecurity controls.
Overview of Shield’s CMMC Certification
Georgia Tech’s Shield research enclave has successfully attained Level 2 certification under the Cybersecurity Maturity Model Framework (CMMC). This milestone follows a rigorous evaluation performed by a Certified Third‑Party Assessor Organization (C3PAO). The assessment verified that Shield’s cybersecurity controls align with the U.S. Department of Defense’s standards for protecting Controlled Unclassified Information (CUI). By achieving this certification, Georgia Tech joins a small cadre of institutions that have independently validated their ability to safeguard sensitive defense‑related data.
Scope of the CMMC Level 2 Assessment
The C3PAO review examined Shield against the full suite of Level 2 requirements, which encompass 110 distinct security practices across multiple domains. Evaluators inspected access control mechanisms, incident‑response procedures, configuration‑management protocols, system‑security hardening, and risk‑management processes. Each domain was tested for both the existence of policies and the effectiveness of their implementation, ensuring that Shield not only documents best practices but also operates them consistently in day‑to‑day research activities.
Leadership Perspectives on the Achievement
Bill Dracos, Georgia Tech’s chief Research operations officer, emphasized that strong research rests on solid operational foundations. He noted that the CMMC validation confirms the Institute’s integrated systems, processes, and partnerships are capable of protecting sensitive information while supporting researchers. Joe Lewis, associate vice president for Information Technology and chief information security officer, called the perfect score a “significant milestone” that reflects months of coordinated planning, collaboration, and dedication from teams across the Institute. Both leaders highlighted that the certification underscores Georgia Tech’s commitment to maintaining a secure environment for federally sponsored work.
Origins and Purpose of the Shield Initiative
In 2025, the Office of the Executive Vice President for Research partnered with the Office of Information Technology’s Cybersecurity department to launch Shield. The initiative was conceived to provide researchers and principal investigators with a secure, functional platform for conducting sponsored research that involves CUI and requires heightened cybersecurity measures. Shield’s design explicitly addresses DoD security requirements, offering a vetted environment where investigators can focus on scientific inquiry without compromising data protection.
Impact on Existing and Future DoD‑Sponsored Research
Earning the CMMC Level 2 credential strengthens Georgia Tech’s capacity to continue supporting current Department of Defense contracts. It also positions the Institute favorably for upcoming opportunities that mandate compliance with federal cybersecurity standards. Sponsors and partners can now rely on independently verified evidence that Georgia Tech has implemented the necessary controls to protect CUI, reducing perceived risk and facilitating smoother award processes for new projects.
Broader Implications for Research Excellence and Compliance
Joe Lewis added that the achievement demonstrates Georgia Tech’s dedication to research excellence, cybersecurity, and regulatory compliance. The certification reflects a campus‑wide commitment to building secure research capabilities that serve both internal investigators and external sponsors. By aligning operational practices with federal expectations, Georgia Tech reinforces its role as a leader in responsible, high‑impact research that meets the stringent demands of national security agencies.
Conclusion
Georgia Tech’s Shield enclave now stands as a demonstrably secure conduit for defense‑related research, backed by a flawless CMMC Level 2 assessment. The certification not only validates existing safeguards but also signals to the DoD and other federal agencies that the Institute is prepared to handle increasingly stringent cybersecurity requirements. As cyber threats evolve, Shield’s validated framework will continue to enable Georgia Tech to pursue cutting‑edge research while maintaining the trust and confidence of its government sponsors.

