Cherokee Federal, a major federal contractor, announced on April 24, 2026, that it has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2. This certification is a critical milestone for any company operating in the Defense Industrial Base (DIB). It signifies that Cherokee Federal has successfully implemented and had independently verified a comprehensive set of cybersecurity controls designed to protect sensitive government information. This achievement not only demonstrates a mature security posture but also provides a significant competitive advantage as the U.S. Department of Defense (DoD) prepares to make CMMC certification a mandatory requirement for contracts involving Controlled Unclassified Information (CUI).
The CMMC program is a DoD initiative designed to enforce cybersecurity standards across the DIB. CMMC Level 2 is a key tier in this model, focused on the protection of CUI.
This development primarily affects:
To achieve CMMC Level 2, Cherokee Federal had to demonstrate the implementation and operationalization of all 110 security controls from NIST SP 800-171. These controls span 14 domains, including:
This requires not just having policies in place, but also providing evidence that the controls are consistently and effectively enforced throughout the organization's systems that process, store, or transmit CUI.
Cherokee Federal's early achievement places it well ahead of the deadline and the majority of its competitors.
The business impact for Cherokee Federal is overwhelmingly positive. It establishes them as a low-risk, trusted partner for sensitive government missions and provides a clear competitive differentiator. As thousands of other DIB companies scramble to achieve certification before the deadline, Cherokee Federal can focus on capturing new business. For the broader DIB, this serves as a case study and a motivator, highlighting that CMMC Level 2 is an achievable, albeit rigorous, standard. The operational impact within Cherokee Federal involved a significant investment in security infrastructure, processes, and personnel to meet and maintain the 110 controls.
As CMMC becomes a contractual requirement, the penalty for non-compliance is straightforward: the inability to bid on or be awarded contracts that involve CUI. This could effectively lock non-certified companies out of a significant portion of the DoD market. Falsifying compliance information can also lead to severe penalties under the False Claims Act.
For other DIB companies seeking to follow Cherokee Federal's path, the process involves several key steps:
CMMC Level 2 requires extensive logging and auditing capabilities to monitor for and respond to security incidents.
Implementing MFA is a core requirement within the NIST SP 800-171 framework for protecting access to systems containing CUI.
Mapped D3FEND Techniques:
Enforcing the principle of least privilege is a fundamental concept throughout the CMMC controls.
Cherokee Federal announced its successful achievement of CMMC Level 2 certification.
Projected start date for the DoD to begin phasing in CMMC Level 2 as a contract requirement.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats