IMPRES Achieves CMMC Level 2 Certification with Perfect Score

Independent C3PAO assessment validates IMPRES’s cybersecurity posture with a score of 110 out of 110 and no Plan of Action & Milestones (POA&M), reinforcing the company’s commitment to protecting Controlled Unclassified Information across defense and federal operations.

Table of Content

Introduction

IMPRES Technology Solutions, Inc. is proud to announce that it has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 through an independent assessment conducted by an authorized CMMC Third-Party Assessment Organization (C3PAO). The certification was awarded on March 2, 2026 and is recorded in the Supplier Performance Risk System (SPRS) under CAGE Code 3UTC7.

IMPRES received a perfect score of 110 out of 110 on the assessment, meeting every security requirement defined by NIST SP 800-171 Revision 2 with no Plan of Action & Milestones (POA&M). This result reflects a Final Level 2 (C3PAO) status, the highest achievable outcome under the CMMC Level 2 certification process, confirming that IMPRES’s CUI enclave fully satisfies all 110 security controls without exception.

With CMMC requirements beginning to appear in DoD solicitations and contracts as of November 2025, and mandatory C3PAO certification requirements expanding in November 2026, IMPRES is positioned well ahead of the compliance timeline to continue supporting defense and federal customers without interruption.

Certification Details

Detail Information
  • CMMC Unique Identifier (UID) – L200001619
  • CMMC Status – Final Level 2 (C3PAO)
  • Assessment Date – March 2, 2026
  • Assessment Scope – Enclave
  • CAGE Code – 3UTC7
  • Score – 110 / 110
  • POA&M – None
  • Affirmation Expiration Date – March 2, 2027
  • CMMC Status Expiration Date – March 1, 2029
  • Applicable Standard – NIST SP 800-171 Rev. 2 (110 controls)

What Is CMMC Level 2?

The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense program designed to verify that defense contractors adequately protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The program establishes three levels of cybersecurity maturity, with Level 2 applying to organizations that process, store, or transmit CUI.

CMMC Level 2 requires implementation of all 110 security requirements from NIST SP 800-171 Revision 2, spanning 14 control families including Access Control, Incident Response, System and Communications Protection, and Risk Assessment. A Level 2 (C3PAO) certification specifically requires an independent assessment conducted by an accredited Third-Party Assessment Organization, the most rigorous form of Level 2 validation available.

Key aspects of CMMC Level 2 (C3PAO) certification include:

  • Independent validation – Assessment performed by a C3PAO accredited by The Cyber AB, not a self-assessment
  • Complete control coverage – All 110 NIST SP 800-171 security requirements must be fully implemented
  • Three-year certification cycle – Certification is valid for three years with annual affirmation of continuous compliance
  • SPRS reporting – Results are entered into the CMMC Enterprise Mission Assurance Support Service (eMASS), which automatically transmits to the Supplier Performance Risk System (SPRS)

Why This Matters

As DoD phases in CMMC requirements across its acquisition programs, certification is quickly becoming a prerequisite for contract eligibility. For defense customers and partners, IMPRES’s CMMC Level 2 certification provides:

  • Contract readiness – IMPRES meets the cybersecurity certification requirements being added to DoD solicitations and contracts, ensuring uninterrupted eligibility across current and future opportunities
  • Verified protection of CUI – A perfect score with no POA&M confirms that IMPRES’s CUI enclave operates with all required security controls fully in place, not conditionally or with outstanding remediation items
  • Supply chain assurance – As a certified member of the Defense Industrial Base, IMPRES strengthens the cybersecurity posture of the broader supply chain for every prime contractor and agency it supports
  • Early certification advantage – With fewer than 100 authorized C3PAOs serving over 80,000 organizations that will need Level 2 certification by 2028, IMPRES’s early achievement avoids the growing assessment bottleneck facing the defense industrial base

This certification complements IMPRES’s existing portfolio of compliance credentials, including ISO 9001:2015 and CMMI SVC/3 certifications, and supports the company’s work across multiple DoD contract vehicles including GSA MAS, SEWP V, ITES-4H, and OASIS+.

Quote
Statement from IMPRES

Achieving a perfect CMMC Level 2 score with no POA&M is a direct reflection of the investment IMPRES has made in building and maintaining a security-first culture. This is a commitment to our defense customers that we take protection of their information as seriously as they do. We’re proud to achieve this certification and ready to support the missions that depend on it.

Jon Flowers
Vice President, Information Technology
For more information, contact us.
For procurement inquiries contracts@imprestechnology.com
For technical briefings solutions@imprestechnology.com

Related news.

View all news
tradeshows image
Contracts and Awards
November 20, 2025
IMPRES Awarded Position on U.S. Army’s $10 Billion ITES-4H Contract

IMPRES Technology Solutions has been selected as one of 49 qualified contractors on the Army’s premier IT hardware acquisition vehicle, expanding the company’s ability to serve defense customers across the globe.

Read more
data center
Contracts and Awards
November 01, 2025
IMPRES Secures Position on Department of Commerce $750M NETS BPA

Award enables IMPRES to deliver enterprise networking equipment and solutions to Commerce bureaus including NOAA, Census, NIST, and USPTO.

Read more
Rectangle 156(1)
Contracts and Awards
October 17, 2025
IMPRES Awarded GSA OASIS+ HUBZone Small Business Contract

Best-in-Class governmentwide contract enables federal agencies to access IMPRES professional services across multiple domains with streamlined acquisition.

Read more
View all news