NewsSecurity

Kiteworks, A-LIGN Launch Partnership to Support CMMC 2.0 Compliance

Kiteworks has announced a strategic partnership with cybersecurity compliance assessor A-LIGN to help organizations within the U.S. Defense Industrial Base (DIB) strengthen their cybersecurity posture and prepare for Cybersecurity Maturity Model Certification (CMMC) 2.0 Level 2 requirements.

The partnership comes as the U.S. Department of War has paused CMMC Phase II implementation for a 60-day review following the suspension announced on July 13, 2026. While the certification timeline is under review, existing cybersecurity obligations—including Phase I self-assessments and DFARS 252.204-7012 requirements—remain in effect, maintaining the focus on protecting Controlled Unclassified Information (CUI) across the defence supply chain.

Under the partnership, Kiteworks will provide its Control Plane platform to help organisations implement a significant portion of CMMC Level 2 security controls, while A-LIGN, an accredited CMMC Third Party Assessor Organization (C3PAO), will independently assess compliance. The companies emphasised that A-LIGN’s role is limited to conducting independent assessments and does not include consulting or remediation services.

Kiteworks said its platform is designed to simplify compliance by offering built-in security capabilities aligned with CMMC requirements. The company noted that it is FedRAMP Moderate Authorised and currently FedRAMP High In Process. It has also completed nine consecutive years of third-party assessments covering 325 NIST 800-53 security controls since 2017.

The platform also features FIPS 140-3 validated encryption, a hardened single-tenant virtual appliance architecture, and Hold Your Own Key (HYOK) encryption, enabling customers to retain control of their cryptographic keys while reducing audit complexity.

“Protecting the Defense Industrial Base is about establishing long-term data security practices rather than meeting a single compliance deadline,” said Kurt Michael, Chief Revenue Officer at Kiteworks. “By combining Kiteworks’ data protection capabilities with A-LIGN’s independent assessment expertise, organisations can implement the right controls and approach certification with greater confidence.”

A-LIGN is among the leading C3PAOs supporting CMMC assessments and has conducted nearly 100 CMMC Level 2 assessments across organisations of varying sizes. In addition to CMMC, the company is also one of the largest FedRAMP assessment providers, with experience evaluating security controls for federal cloud environments.

Nicholas Ludy, Chief Growth Officer at A-LIGN, said that while the timing of CMMC’s third-party assessment requirements remains uncertain, cybersecurity expectations for defence contractors have not changed.

“The commitment to securing the Defense Industrial Base extends beyond any individual implementation date,” Ludy said. “This partnership ensures organisations can continue strengthening their security posture and remain prepared for certification as CMMC requirements evolve.”

The companies said the collaboration aims to help DIB organisations address security control gaps, improve audit readiness, and enhance the protection of sensitive defence-related information as compliance requirements continue to mature.

Show More

Chris Fernando

Chris N. Fernando is an experienced media professional with over two decades of journalistic experience. He is the Editor of Arabian Reseller magazine, the authoritative guide to the regional IT industry. Follow him on Twitter (@chris508) and Instagram (@chris2508).

Related Articles

Back to top button