Cape has achieved a Final CMMC Level 2 (C3PAO) certification with all 110 security requirements met and no Plan of Action and Milestones.
Following a formal assessment conducted by Insight Assurance, an authorized CMMC Third-Party Assessment Organization (C3PAO), Cape's Controlled Unclassified Information (CUI) Enclave has been certified against the full set of security requirements in NIST SP 800-171 Rev 2, as incorporated by reference in 32 CFR Part 170. The certification is valid through August 2029.
What this means
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's (DoD) program for verifying that defense contractors protect sensitive government information. Level 2 is the standard required for organizations that handle Controlled Unclassified Information (CUI), and third-party certification is its most rigorous form. An independent, DoD-authorized assessor examined our implementation of all 110 NIST SP 800-171 requirements and validated each one of them.
We passed with no Plan of Action and Milestones (POA&M), meaning no deferred fixes and no conditional status. Every requirement was fully met at the time of assessment.
For our government customers and partners, this provides independent verification that Cape meets the DoD's bar for safeguarding controlled information.
What was certified
This certification applies to Cape's CUI Enclave: the dedicated, hardened internal environment where we handle Controlled Unclassified Information related to our government contracts.
It is not a certification of Cape's product or network infrastructure. CMMC certifies Cape as a contractor trusted to handle sensitive government information; it is separate from any product-level authorization. The security of our platform is addressed through our broader security program, which you can explore via our Trust Center.
Why we did it
Cape provides secure mobile communications for people whose privacy is mission-critical, and many of them work in and around national defense. Serving those customers means receiving and handling their controlled information. We wanted that handling verified by an independent assessor against the DoD's own standard, rather than asserted by us.
We pursued this certification while the requirement was suspended. In July 2026, DoD paused Phase 2 of the CMMC rollout—the phase that would have made Level 2 (C3PAO) certification a condition of contract award. As of this writing, third-party certification is not something a contracting officer can require.
We completed a third-party assessment anyway. The pause changed the verification mechanism, not the standard. DFARS 252.204-7012 and the 110 requirements in NIST SP 800-171 still apply to every contractor that handles CUI, and self-assessed scores posted to the Supplier Performance Risk System (SPRS) still carry the same legal weight and the same annual affirmation of continuous compliance.
Where to verify our status
For DoD Contracting Officers, our third-party status is recorded in SPRS, submitted by our C3PAO. SPRS is the authoritative source for CMMC status and is accessible through PIEE. Our CMMC Unique Identifier is available upon request.
Our certification status and other compliance documentation are available on our Trust Center.
Share it

