Dragos Public Sector Achieves CMMC Level 2 Certification

Table of Contents

Dragos Public Sector (DPS) has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 certification following an independent assessment by a Certified Third-Party Assessment Organization (C3PAO). The assessment demonstrated that the DPS enterprise environment, built in a FedRAMP High authorized cloud, has implemented the safeguards required to securely process, store, and transmit Controlled Unclassified Information (CUI). That environment supports Dragos’s work with the U.S. Department of War (DoW) and organizations across the Defense Industrial Base (DIB) that must protect CUI under DFARS 252.204-7012 and meet CMMC requirements under DFARS 252.204-7021.

CMMC Level 2 requires organizations to demonstrate that safeguards protecting CUI are implemented and operating, not simply documented in policies and procedures. During a C3PAO assessment, assessors examine technical configurations, policies, procedures, processes, and other objective evidence to determine whether each requirement is being met in practice.

For DPS, that meant demonstrating how security requirements were implemented and enforced across the assessed enterprise environment. The assessment examined areas including:
• Identity, Multi-Factor Authentication (MFA), and privileged access
• Endpoint security and vulnerability management
• Configuration management
• Cryptographic protections and controlled remote access
• Centralized security logging and monitoring

These protections have to work together. Access controls must restrict CUI to authorized users and approved systems, cryptographic protections must safeguard information where required, security-relevant activity must be logged and reviewed, and vulnerabilities and system changes must be actively managed.

That is what makes CMMC Level 2 different from a documentation exercise. The assessment tests whether cybersecurity requirements can be demonstrated through technology, people, and repeatable operational processes.

DPS demonstrated implementation of all 110 security requirements in NIST SP 800-171 Rev. 2 with no Plans of Action and Milestones (POA&Ms). A zero-POA&M result means the required safeguards were in place at the time of the assessment rather than being deferred for future remediation.

The 110 requirements span 14 security requirement families, including access control, audit and accountability, configuration management, identification and authentication, incident response, risk assessment, system and communications protection, and system and information integrity. Meeting all 110 required DPS to demonstrate not only individual technical controls, but also the policies, processes, monitoring, and evidence supporting their continued operation.

That result directly supports DPS’s obligations for protecting CUI under DFARS 252.204-7012 and CMMC requirements under DFARS 252.204-7021. It also reflects the same disciplined approach Dragos applies to Operational Technology (OT) cybersecurity, regulatory readiness, and the protection of critical infrastructure.

DPS pursued independent C3PAO validation because internal assurance is not the same as independent verification. CMMC implementation timelines and external assessment requirements continued to evolve while DPS was preparing its environment, but DPS moved forward with an independent assessment rather than waiting for external certification to become a contractual requirement.

The assessment put the DPS enterprise architecture, security technologies, operating processes, and supporting evidence under independent scrutiny. Successfully completing that process demonstrated that those safeguards work together in the assessed environment and can be supported with objective evidence.

For public-sector customers and DIB partners, that provides something concrete: an independently assessed DPS enterprise environment designed to support work involving CUI. It also positions DPS for future opportunities where CMMC Level 2 certification may be required, while providing independent validation of the security capabilities already in place. It strengthens the security foundation behind the technology, threat intelligence, incident response, and cybersecurity expertise Dragos provides to organizations responsible for protecting critical infrastructure.

Protecting sensitive information is part of the same mission as protecting the operational environments that depend on it.

If your organization is part of the Defense Industrial Base and needs support addressing CMMC, DFARS, or CUI protection requirements, talk to Dragos Public Sector

contact us today

Sarah Formwalt is an Associate Principal IT Security Engineer and Information System Security Manager for the Dragos Public Sector, where she is responsible for managing cybersecurity and compliance for systems supporting Dragos’s federal government operations. In this role, she advances security architecture and risk management aligned to federal regulatory frameworks, ensuring the protection of systems that support critical infrastructure.