Westfield, IN — July 27, 2026 — SEP, one of Indiana’s largest software development firms, has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 certification for its development environment, reflecting full implementation of all 110 NIST SP 800-171 Rev 2 security controls with a perfect SPRS score of 110/110. CMMC Level 2 is a Department of Defense certification confirming a contractor fully implements the 110 security controls required to handle Controlled Unclassified Information (CUI) on defense programs.

SEP has served aerospace and defense clients since 1989, building software across web, mobile, desktop, embedded, and cloud systems. A small fraction of companies in the Defense Industrial Base (DIB) currently hold CMMC certification, and SEP pursued certification early, building with CyberSheath and assessed by A-LIGN, to give existing and prospective defense clients confidence in how their most sensitive data is handled.

“Too many contractors treat CMMC as a box to check. We approached certification to ensure continuity for the defense clients we already serve, and to build a foundation for the work ahead,” said Marty Draper, Vice President of IT, Security, and Compliance at SEP. “It was important to us that we could keep supporting our existing defense clients while building toward what’s next, without reworking how we operate.”

SEP partnered with CyberSheath, one of the most experienced CMMC compliance firms in the Defense Industrial Base, to architect the security controls, access policies, and system configurations behind the certification. The environment was independently assessed by A-LIGN, a Certified Third-Party Assessor Organization (C3PAO).

SEP’s certification is scoped to its defense development environment, which CyberSheath architected alongside SEP’s internal IT & Security team to keep pace with SEP’s broader business. That structure lets SEP bring on new defense clients within the existing compliance boundary, without expanding scope or reworking the architecture project by project.

“Congratulations to SEP for achieving CMMC Level 2 certification. This accomplishment demonstrates a strong commitment to safeguarding valuable information to protect our nation, developing a competitive advantage, and creating a culture of security,” said Petar Besalev, EVP of Compliance and Cybersecurity Services at A-LIGN. “We’re proud to support this integral step in SEP’s compliance journey with a high-quality assessment process and deep expertise in federal compliance.”

Contractors and subcontractors that handle CUI are legally obligated to safeguard it under DFARS clause 252.204-7012, independent of where CMMC’s broader certification framework lands. According to the Cyber AB, as of March 2026 less than 1,100 organizations nationwide had achieved CMMC Level 2 certification, against a Defense Industrial Base the Department of War has estimated at roughly 80,000 contractors.

“This certification is a foundation, not a finish line. We built it to support the defense clients we serve today and to give us room to grow with the ones we haven’t met yet,” said Draper. “As the requirements around this work continue to evolve, we intend to continue to be a leader in the strategic adoption of them.”