-

CyberSheath Helps SEP Achieve CMMC Level 2 Certification With Scalable Enclave Built for Defense Business Growth

RESTON, Va.--(BUSINESS WIRE)--CyberSheath helped SEP, one of Indiana’s largest software development companies, achieve CMMC Level 2 certification to support current defense operations and future business development.

SEP has served aerospace and defense clients since 1989, building software across web, mobile, desktop, embedded systems, and cloud. With the Department of Defense estimating that over 118,000 companies will need CMMC Level 2 certification, SEP pursued early certification to maintain eligibility for defense contracts and position itself competitively as fewer companies in the defense industrial base achieve compliance.

“Too many contractors are treating CMMC as a box to check instead of a competitive advantage. SEP approached CMMC certification to ensure continuity for the defense clients they already serve and to position themselves for growth, so we architected their solution to match,” said Emil Sayegh, CEO of CyberSheath. “The environment that CyberSheath created is designed so SEP can bring on new defense clients within the existing compliance scope, without reworking the architecture or expanding the boundary every time.”

CyberSheath architected an enclave compliance framework, defining the security controls, access policies, and system configurations required to meet CMMC standards. The enclave was scoped exclusively to SEP's defense operations, leaving its commercial activities across pharmaceutical, agricultural technology, financial services, and life sciences unaffected. SEP's technical team supported key aspects of the implementation, and both organizations operated under a shared responsibility model that reflected each party's ownership of specific tools, systems, and infrastructure.

“CyberSheath helped us design a solution that met our compliance requirements without significantly changing how we operate. It was important to us that we could continue supporting our existing defense clients while also building a foundation to expand that work going forward,” said Marty Draper, Vice President of IT, Security, & Compliance at SEP.

SEP’s Level 2 certification gives its defense clients assurance that software development involving CUI is being performed in a certified environment and positions SEP to take on new defense work as CMMC requirements expand across Department of Defense contracts.

Learn more about how CyberSheath helps defense contractors build, operate, and continuously improve secure environments.

About CyberSheath
Established in 2012, CyberSheath is one of the most experienced and trusted IT security services partners for the U.S. defense industrial base. The company helps defense contractors assess, implement, operate, and continuously improve secure environments that meet DOD cybersecurity requirements, including NIST SP 800-171, DFARS, and CMMC. Learn more at www.cybersheath.com.

About SEP
Founded in 1988, SEP is one of Indiana's largest software development firms and is 100 percent employee-owned. With 180 employees, the company designs and builds custom software for organizations ranging from Fortune 100 enterprises to high-growth companies, serving clients across regulated and safety-critical industries. SEP is consistently recognized for its workplace culture. For more information, visit www.sep.com.

Contacts

CyberSheath
Kristen Morales
Kristen.Morales@cybersheath.com

Lexie Capperella
Gregory on behalf of CyberSheath
cybersheath@gregoryagency.com

CyberSheath


Release Versions

Contacts

CyberSheath
Kristen Morales
Kristen.Morales@cybersheath.com

Lexie Capperella
Gregory on behalf of CyberSheath
cybersheath@gregoryagency.com

Social Media Profiles
More News From CyberSheath

CyberSheath Reopens Free Defense Contractor Cybersecurity Compliance Training Program as the DIB Races Toward CMMC Phase 2 Deadline

RESTON, Va.--(BUSINESS WIRE)--With the Phase 2 Cybersecurity Maturity Model Certification (CMMC) deadline arriving Nov. 10, 2026, defense contractors that haven’t started preparing face a shrinking window to get certified before third-party assessments become mandatory. The most recent State of the DIB Report, conducted by Merrill Research, found that only 1% of defense contractors felt fully prepared for CMMC assessments, and 69% rated achieving and maintaining compliance at 7 out of 10 or hig...

CyberSheath Opens Registration for CMMC CON 2026 as Phase 2 Deadline and Assessor Shortage Bear Down on Defense Contractors

RESTON, Va.--(BUSINESS WIRE)--The Cybersecurity Maturity Model Certification (CMMC) program’s phased rollout reaches a critical milestone on Nov. 10, 2026, when Phase 2 makes third-party assessments mandatory for most defense contracts. However, there are only 103 authorized C3PAOs that serve the roughly 80,000 organizations that need Level 2 certification. Against that backdrop, CyberSheath has opened registration for CMMC CON 2026, the longest-running CMMC event and now in its seventh year. T...

CyberSheath Helps Tunnell Consulting Achieve CMMC Level 2 Certification Through a Strategically Scoped CUI Environment

RESTON, Va.--(BUSINESS WIRE)--CyberSheath, the largest Cybersecurity Maturity Model Compliance (CMMC) managed service vendor, helped Tunnell Consulting, a consulting firm that provides specialized scientific and technical expertise to government agencies and commercial clients, achieve CMMC Level 2 certification with a perfect 110 score using a targeted enclave solution designed around the Company’s limited controlled unclassified information (CUI) handling requirements. With defense spending c...
Back to Newsroom