Westfield, IN — July 27, 2026 — SEP, one of Indiana’s largest software development firms, has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 certification for its development environment, reflecting full implementation of all 110 NIST SP 800-171 Rev 2 security controls with a perfect SPRS score of 110/110. CMMC Level 2 is a Department of Defense certification confirming a contractor fully implements the 110 security controls required to handle Controlled Unclassified Information (CUI) on defense programs.
SEP has served aerospace and defense clients since 1989, building software across web, mobile, desktop, embedded, and cloud systems. A small fraction of companies in the Defense Industrial Base (DIB) currently hold CMMC certification, and SEP pursued certification early, building with CyberSheath and assessed by A-LIGN, to give existing and prospective defense clients confidence in how their most sensitive data is handled.
“Too many contractors treat CMMC as a box to check. We approached certification to ensure continuity for the defense clients we already serve, and to build a foundation for the work ahead,” said Marty Draper, Vice President of IT, Security, and Compliance at SEP. “It was important to us that we could keep supporting our existing defense clients while building toward what’s next, without reworking how we operate.”
SEP partnered with CyberSheath, one of the most experienced CMMC compliance firms in the Defense Industrial Base, to architect the security controls, access policies, and system configurations behind the certification. The environment was independently assessed by A-LIGN, a Certified Third-Party Assessor Organization (C3PAO).
SEP’s certification is scoped to its defense development environment, which CyberSheath architected alongside SEP’s internal IT & Security team to keep pace with SEP’s broader business. That structure lets SEP bring on new defense clients within the existing compliance boundary, without expanding scope or reworking the architecture project by project.
“Congratulations to SEP for achieving CMMC Level 2 certification. This accomplishment demonstrates a strong commitment to safeguarding valuable information to protect our nation, developing a competitive advantage, and creating a culture of security,” said Petar Besalev, EVP of Compliance and Cybersecurity Services at A-LIGN. “We’re proud to support this integral step in SEP’s compliance journey with a high-quality assessment process and deep expertise in federal compliance.”
“SEP’s accomplishment demonstrates a strong commitment to safeguarding valuable information to protect our nation, developing a competitive advantage, and creating a culture of security.”
Petar Besalev
EVP of Compliance and Cybersecurity Services at A-LIGN
Contractors and subcontractors that handle CUI are legally obligated to safeguard it under DFARS clause 252.204-7012, independent of where CMMC’s broader certification framework lands. According to the Cyber AB, as of March 2026 only 1,074 organizations nationwide had achieved CMMC Level 2 certification, against a Defense Industrial Base the Department of War has estimated at roughly 80,000 contractors.
“This certification is a foundation, not a finish line. We built it to support the defense clients we serve today and to give us room to grow with the ones we haven’t met yet,” said Draper. “As the requirements around this work continue to evolve, we intend to continue to be a leader in the strategic adoption of them.”

About SEP
SEP designs and builds custom software for organizations ranging from Fortune 100 companies to scale-ups. One of Indiana’s largest software development firms, SEP’s services span the full product lifecycle: strategy, development, design, data, and AI. SEP works across industries including aerospace and defense, heavy machinery, pharma, precision ag, fintech, life sciences and medical devices, consumer IoT, and industrial IoT.
For more information, visit sep.com.
✨ AI Post Recap
SEP, an Indiana software development firm serving aerospace and defense clients since 1989, has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 with a perfect SPRS score of 110 out of 110. The certification confirms SEP fully implements all 110 NIST SP 800-171 Rev 2 security controls required to handle Controlled Unclassified Information for Department of Defense programs. CyberSheath architected the security controls, and A-LIGN, a Certified Third-Party Assessor Organization, conducted the independent assessment.
What is CMMC Level 2 certification? CMMC Level 2 is a Department of Defense cybersecurity certification confirming a contractor fully implements all 110 NIST SP 800-171 security controls needed to handle Controlled Unclassified Information (CUI) on defense programs.
Does SEP have experience working in aerospace and defense? Yes. SEP has served aerospace and defense clients since 1989, building web, mobile, desktop, embedded, and cloud software for the industry. Links to the A&D industry page.
Who helped SEP get CMMC Level 2 certified? CyberSheath architected SEP’s security controls and access policies, and A-LIGN, a Certified Third-Party Assessor Organization (C3PAO), conducted the independent assessment.