Kiteworks and A-LIGN Team Up to Boost CMMC 2.0 Readiness for the Defense Industrial Base

0
1

Key Takeaways

  • Kiteworks and A‑LIGN have formed a strategic partnership to help Defense Industrial Base (DIB) contractors achieve CMMC 2.0 Level 2 readiness, even as the Department of Defense reviews the program.
  • Although CMMC Phase II was paused on July 13, 2026 for a 60‑day review, existing obligations—including Phase I self‑assessments and DFARS 252.204‑7012—remain in force; the review aims to streamline, not weaken, cybersecurity expectations.
  • The Kiteworks Control Plane addresses a large portion of CMMC Level 2 controls out of the box, reducing common evidence gaps identified during third‑party assessments.
  • A‑LIGN will serve solely as an independent CMMC C3PAO assessor; it will not provide consulting, remediation, or implementation guidance, preserving assessor independence.
  • Kiteworks brings strong federal credentials: FedRAMP High In Process, FedRAMP Moderate Authorized, FIPS 140‑3 validation, nine years of continuous monitoring years of 3PAO audits covering 325 NIST 800‑53 controls, and Hold‑Your‑Own‑Key (HYOK) encryption.
  • Leadership from both firms emphasizes that durable data‑security practices—not a single deadline—are the true goal, ensuring organizations stay audit‑ready regardless of how the CMMC timeline evolves.

Partnership Announcement and Strategic Goals
Kiteworks, a provider of secure private data exchange and risk‑management solutions, announced a strategic partnership with A‑LIGN, a leading Cybersecurity Maturity Model Certification (CMMC) Third Party Assessor Organization (C3PAO). The collaboration is designed to support Defense Industrial Base (DIB) organizations in strengthening their cybersecurity posture and preparing for CMMC 2.0 Level 2 certification. By combining Kiteworks’ data‑centric security platform with A‑LIGN’s assessment expertise, the partnership aims to give contractors a practical path to meet stringent federal requirements while maintaining flexibility to work with any authorized C3PAO. The initiative underscores a shared vision: building data‑security practices that remain effective regardless of shifts in compliance timelines or assessment schedules.

CMMC Phase II Review and Ongoing Compliance Requirements
On July 13, 2026 the Department of Defense paused CMMC Phase II, initiating a 60‑day review of the program. Despite this pause, the department has stressed that existing cybersecurity obligations remain unchanged. Contractors must still satisfy Phase I self‑assessment requirements and comply with DFARS 252.204‑7012, which mandates safeguarding Controlled Unclassified Information (CUI). The review is intended to streamline compliance processes, not to lower the bar for protecting the defense supply chain. Consequently, organizations continue to face the same imperatives to protect CUI against increasingly sophisticated cyber threats, even while awaiting the outcome of the department’s evaluation.

Kiteworks Control Plane: Out‑of‑the‑Box CMMC Level 2 Coverage
Through the partnership, Kiteworks offers its Control Plane as a ready‑made solution that addresses a substantial majority of CMMC Level 2 requirements straight out of the box. The platform includes controls that frequently appear as evidence gaps during third‑party assessments, such as access control, audit and accountability, and system and communications protection. Once these controls are deployed, organizations can independently engage A‑LIGN—or any other accredited C3PAO—to undergo a formal assessment. This approach reduces the implementation burden and helps contractors achieve audit readiness more quickly, regardless of where they stand in their CMMC journey.

A‑LIGN’s Role as an Independent C3PAO Assessment Provider
A‑LIGN’s participation in the partnership is strictly limited to performing independent CMMC assessments. The organization will not provide consulting, remediation, or implementation guidance, thereby preserving the objectivity required of a C3PAO. Contractors retain the freedom to select any authorized or accredited assessor for their evaluation. A‑LIGN’s assessment teams examine the full scope of CMMC Level 2 requirements, covering governance, personnel, physical security, and organizational controls, ensuring that evidence presented meets federal expectations for rigor and completeness.

Kiteworks’ Credentials: FedRAMP, FIPS, HYOK, and Single‑Tenant Architecture
Kiteworks brings a robust federal compliance pedigree to the partnership. The platform is FedRAMP High In Process and FedRAMP Moderate Authorized, backed by nine consecutive years of annual 3PAO audits that validate 325 NIST 800‑53 controls since 2017. It is also FIPS 140‑3 validated and deployed as a hardened single‑tenant virtual appliance, which helps organizations avoid CUI isolation issues that often trigger remediation delays during CMMC certification. Additionally, Kiteworks offers Hold‑Your‑Own‑Key (HYOK) encryption, allowing DIB contractors to retain ownership of their cryptographic keys, thereby reducing audit scope and mitigating third‑party risk.

Leadership Perspective: Kurt Michael on Durable Data Security Practices
Kurt Michael, Chief Revenue Officer at Kiteworks, emphasized that protecting the DIB is not about meeting a single deadline but about establishing data‑security practices durable enough to withstand any changes in the compliance timeline. He noted that Kiteworks and A‑LIGN share this vision, with Kiteworks supplying comprehensive controls at the data layer and A‑LIGN providing the experience and rigor needed to validate those controls through independent assessment. Whether an organization is just beginning its CMMC effort or is already underway, the partnership equips them with the right controls to enter the assessment room confidently prepared.

A‑LIGN’s Assessment Expertise and Market Position
A‑LIGN ranks among the market’s leading C3PAOs, having completed nearly 100 CMMC Level 2 assessments for DIB organizations of varying sizes. Beyond CMMC, the firm is also rated in the top three FedRAMP assessors and has extensive experience helping clients document and defend compliance evidence in line with federal agency expectations. Its assessment teams evaluate the full breadth of CMMC Level 2 requirements, including governance, personnel, physical security, and organizational controls, ensuring that contractors receive a thorough, objective evaluation of their cybersecurity posture.

Leadership Perspective: Nicholas Ludy on Preparedness Amid Review
Nicholas Ludy, Chief Growth Officer at A‑LIGN, acknowledged the current uncertainty surrounding when and in what form CMMC’s third‑party assessment requirements will return from the department’s review. He stressed, however, that the underlying requirements have not disappeared and that the commitment to securing the DIB does not hinge on any single implementation date. As CMMC requirements evolve, Kiteworks will continue to give DIB organizations a practical route to stronger data security and audit readiness, while A‑LIGN will deliver rigorous, independent assessments so that organizations remain prepared whenever the certification timeline is finalized.

Company Overviews: Kiteworks and A‑LIGN
Kiteworks’ mission is to empower organizations to manage risk in every send, share, receive, and use of private data. Its platform unifies, tracks, controls, and secures sensitive data moving within, into, and out of an organization, delivering data governance, compliance, and protection in a unified control plane. Headquartered in Silicon Valley, Kiteworks protects over 100 million end‑users and thousands of global enterprises and government agencies.

A‑LIGN is a leading cybersecurity compliance partner trusted by more than 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech‑enabled delivery model and deep domain expertise, it has completed more than 36,000 audits across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST. Founded in 2009, A‑LIGN is the #1 issuer of SOC 2 reports and a top three FedRAMP assessor. For more information, visit https://www.a-lign.com.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here