Clark Dynamic Test Laboratory is proud to announce that we have successfully achieved Cybersecurity Maturity Model Certification (CMMC) Level 2, demonstrating compliance with the U.S. Department of Defense’s rigorous cybersecurity requirements for organizations that process, store, or transmit Controlled Unclassified Information (CUI). The certification covers both of Clark’s in-scope defense operations under CAGE Code 70FC4 and CAGE Code 0VVV6, validating that our secure computing environment, cybersecurity program, and operational practices have been independently assessed against the 110 security requirements of NIST SP 800-171 Rev. 2 through an authorized third-party CMMC assessment. This milestone reflects years of strategic investment in cybersecurity, secure infrastructure, employee training, and compliance, reinforcing Clark’s commitment to protecting sensitive customer information while supporting the mission-critical testing needs of the Defense Industrial Base.
Why the Department of Defense Created CMMC
The United States Defense Industrial Base (DIB) is comprised of hundreds of thousands of organizations that collectively design, manufacture, test, maintain, and support the systems relied upon by our nation’s military. While many of these organizations are not prime defense contractors, they routinely handle Controlled Unclassified Information (CUI) and other sensitive technical data essential to the development and sustainment of defense programs. As cyber threats targeting the defense supply chain have grown in both frequency and sophistication, the Department of Defense recognized that protecting this information requires more than contractual obligations or cybersecurity self-attestations.
To strengthen the security of the Defense Industrial Base, the Department of Defense established the Cybersecurity Maturity Model Certification (CMMC) program. Built upon the security requirements defined in NIST Special Publication 800-171 Revision 2, CMMC requires organizations entrusted with Controlled Unclassified Information to implement comprehensive cybersecurity safeguards and demonstrate their effectiveness through an independent assessment performed by an authorized Certified Third-Party Assessment Organization (C3PAO). The result is a standardized cybersecurity framework that helps ensure every organization handling sensitive defense information, regardless of size, meets a consistent baseline for protecting that information against today’s evolving cyber threats.
What CMMC Level 2 Certification Requires
Achieving CMMC Level 2 Certification is far more than completing documentation or implementing a handful of cybersecurity tools. Organizations must demonstrate that a comprehensive cybersecurity program has been fully implemented across their environment and is operating effectively to protect Controlled Unclassified Information (CUI). The certification is based on the 110 security requirements defined in NIST Special Publication 800-171 Revision 2, covering a broad range of cybersecurity disciplines including access control, multi-factor authentication, audit logging, configuration management, incident response, risk assessment, media protection, physical security, personnel security, security awareness training, system maintenance, vulnerability management, and continuous monitoring.
Unlike previous self-attestation models, CMMC Level 2 requires an independent assessment conducted by an authorized Certified Third-Party Assessment Organization (C3PAO). During the assessment, organizations must provide objective evidence demonstrating that required security controls are properly implemented and consistently followed throughout day-to-day operations. Policies, procedures, technical safeguards, employee interviews, system configurations, and operational practices are all evaluated to verify compliance with the Department of Defense’s cybersecurity requirements.
Clark’s Path to CMMC Level 2 Certification
Achieving CMMC Level 2 Certification represents the culmination of a multi-year commitment to strengthening Clark Dynamic Test Laboratory’s cybersecurity program and supporting the evolving security requirements of the Defense Industrial Base. Rather than approaching CMMC as a compliance exercise, Clark viewed the certification as an opportunity to build a resilient cybersecurity program capable of protecting Controlled Unclassified Information (CUI) entrusted to us by our customers and government partners.
Preparation for the assessment required significant investment across our organization. Clark developed a dedicated secure computing environment supporting our in-scope defense operations, implemented advanced cybersecurity technologies, enhanced physical and logical access controls, strengthened incident response and risk management processes, expanded employee cybersecurity awareness training, and established the policies, procedures, and continuous monitoring practices necessary to meet the Department of Defense’s cybersecurity requirements.
Following extensive internal preparation, mock assessments, and evidence collection, Clark successfully completed its independent CMMC Level 2 assessment through an authorized Certified Third-Party Assessment Organization (C3PAO). The certification was achieved on our initial assessment and required no Plans of Action and Milestones (POA&Ms), demonstrating that all applicable security requirements were fully implemented and validated at the time of assessment. The certification encompasses both of Clark’s in-scope defense operations under CAGE Code 70FC4 and CAGE Code 0VVV6.
What CMMC Level 2 Certification Means for Our Customers
For organizations operating within the Defense Industrial Base, selecting qualified suppliers extends beyond technical capability and testing expertise. Customers must also have confidence that sensitive project information will be protected throughout the entire lifecycle of a program. Clark’s CMMC Level 2 Certification provides independent verification that our cybersecurity program has been assessed against the Department of Defense’s established requirements for safeguarding Controlled Unclassified Information.
Whether supporting product development, environmental qualification, vibration testing, EMI/EMC testing, structural testing, or other defense-related programs, our customers can be confident that Clark has implemented the people, processes, and technology necessary to securely manage sensitive project information. This commitment helps reduce supply chain cybersecurity risk while supporting organizations that require trusted testing partners capable of meeting today’s evolving defense cybersecurity expectations.
As cybersecurity requirements continue to expand across Department of Defense contracts, Clark’s certification reinforces our long-standing commitment to quality, technical excellence, and the protection of customer information. We remain dedicated to continuous improvement, ensuring our cybersecurity program evolves alongside emerging threats while continuing to provide the secure, reliable testing services our customers expect.
Cybersecurity Is a Continuous Commitment
Achieving CMMC Level 2 Certification is a significant milestone, but it is not the end of Clark’s cybersecurity journey. The cyber threat landscape continues to evolve, and maintaining a strong security posture requires ongoing vigilance, continuous improvement, and a commitment to adapting to emerging risks. Cybersecurity is not a one-time project or annual compliance exercise. It is an integral part of how we operate, support our customers, and protect the sensitive information entrusted to our organization.
Clark will continue to invest in our cybersecurity program through continuous monitoring, employee training, technology modernization, risk assessments, and ongoing evaluation of our security controls. As Department of Defense cybersecurity requirements continue to mature, we remain committed to maintaining compliance while providing our customers with the confidence that their Controlled Unclassified Information is protected by a secure, independently validated environment.
We appreciate the trust our customers place in Clark Dynamic Test Laboratory and look forward to continuing our support of the Defense Industrial Base with the same commitment to technical excellence, quality, and cybersecurity that has defined our organization for decades.
