Kiteworks Partners with A-LIGN to Help Defense Industrial Base Organizations Advance CMMC 2.0 Readiness

Kiteworks, a provider of secure private data exchange and risk management solutions, has announced a strategic partnership with A-LIGN, a leading Cybersecurity Maturity Model Certification (CMMC) Third Party Assessor Organization (C3PAO), to support Defense Industrial Base (DIB) organizations in strengthening cybersecurity and preparing for CMMC 2.0 Level 2 certification.

Although the Department of War paused CMMC Phase II on July 13, 2026, initiating a 60-day review of the program, existing cybersecurity obligations remain unchanged. Organizations are still required to meet Phase I self-assessment requirements and comply with DFARS 252.204-7012. The department has emphasized that the review is intended to streamline compliance processes—not reduce cybersecurity expectations. Safeguarding Controlled Unclassified Information (CUI) across the DIB remains a critical priority for protecting the defense supply chain against increasingly advanced cyber threats.

Through the partnership, Kiteworks and A-LIGN aim to help DIB contractors improve their protection of sensitive data regardless of where they are in the CMMC journey. Organizations can deploy the Kiteworks Control Plane to address a substantial majority of CMMC Level 2 requirements out of the box, including controls that frequently become evidence gaps during third-party assessments. Once those controls are implemented, organizations may independently engage A-LIGN to evaluate compliance through its formal assessment process. As part of the partnership, A-LIGN’s role is strictly limited to independent assessments and does not include consulting, remediation, or implementation guidance. Organizations remain free to work with any authorized or accredited C3PAO.

Kiteworks is FedRAMP High In Process and FedRAMP Moderate Authorized, supported by nine consecutive years of annual 3PAO audits validating 325 NIST 800-53 controls since 2017. The platform is also FIPS 140-3 validated and is deployed as a hardened single-tenant virtual appliance, helping organizations avoid CUI isolation issues that commonly delay CMMC certification through remediation requirements. Additionally, Kiteworks offers Hold Your Own Key (HYOK) encryption, allowing DIB organizations to maintain ownership of their cryptographic keys while reducing audit scope and third-party risk.

“Protecting the DIB was never about a single deadline, but rather about building data security practices durable enough to hold up no matter how the compliance timeline evolves,” said Kurt Michael, Chief Revenue Officer, Kiteworks. “Kiteworks and A-LIGN share that same vision. Through our partnership, Kiteworks helps organizations put comprehensive controls at the data layer, and A-LIGN, a top C3PAO, brings the experience and rigor to help validate that work through independent assessment. Whether an organization is early in the process or already underway, Kiteworks helps them get the right controls in place so they can walk into the assessment room prepared.”

A-LIGN is among the market’s leading C3PAOs, having completed nearly 100 CMMC Level 2 assessments for DIB organizations of varying sizes. Its assessment teams evaluate the complete scope of CMMC Level 2 requirements, including governance, personnel, physical security, and organizational controls. Beyond CMMC, A-LIGN is also ranked among the top three FedRAMP assessors and brings extensive experience helping organizations document and defend compliance evidence in accordance with federal agency expectations.

“There’s some uncertainty right now about when, and in what form, CMMC’s third-party assessment requirements will return from the Department’s review, but the underlying requirements haven’t gone anywhere,” said Nicholas Ludy, Chief Growth Officer, A-LIGN. “The commitment to securing the DIB doesn’t hinge on any single implementation date. As CMMC requirements evolve, Kiteworks will keep giving DIB organizations a practical path to stronger data security and audit readiness, and A-LIGN will continue to deliver rigorous, independent assessments, so organizations are prepared whenever the certification timeline is finalized.”

 

_______

About Kiteworks

Kiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies.

About A-LIGN

A-LIGN is the leading cybersecurity compliance partner, trusted by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN has completed more than 36,000 audits. It is the #1 issuer of SOC 2 reports and a top three FedRAMP assessor. Founded in 2009, A-LIGN delivers high-quality, efficient audits across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST. To learn more, visit: https://www.a-lign.com.

Join our LinkedIn group Information Security Community!

No posts to display