American Rheinmetall Achieves CMMC Level 2 Certification Across All Manufacturing Plants
[Photo: Rheinmetall]
American Rheinmetall has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 across all of its manufacturing facilities in ME, MI, and OH, reinforcing the company’s commitment to protecting Controlled Unclassified Information (CUI) and supporting the security requirements of the U.S. Department of War (DoW). The company completed its final audit in February, bringing its entire manufacturing footprint into full CMMC Level 2 compliance.
The CMMC Level 2 certification, assessed by a Certified Third-Party Assessor Organization (C3PAO), validates implementation of the 110 security requirements outlined in NIST SP 800-171. The certification establishes a standardized cybersecurity framework designed to safeguard sensitive defense information throughout the Defense Industrial Base.
Strengthening Readiness for Future Defense Programs
With CMMC compliance becoming mandatory for new DoW contract solicitations, Level 2 certification positions American Rheinmetall to compete for larger, more security-sensitive programs while reinforcing its role as a trusted defense manufacturing partner.
“CMMC accreditation is required to perform future work within the Defense Industrial Base,” said Jasper Recto, Vice President of Information Technology at American Rheinmetall. “More importantly, it establishes a baseline security ecosystem that protects our organization from evolving cyber threats while fostering a security-conscious culture throughout the company.”
As cyber threats grow increasingly sophisticated, cybersecurity in defense manufacturing extends beyond technical controls. It requires enterprise-wide collaboration, leadership commitment, and disciplined operational practices.
Company-Wide Cybersecurity Commitment
Achieving CMMC Level 2 across multiple manufacturing plants required several years of preparation, including implementation of advanced security solutions, policy development, system configuration, testing, and employee training.
NIST 800-171, the foundation of CMMC Level 2, maps 110 security requirements to more than 320 assessment objectives. Meeting these standards required coordinated efforts across IT, leadership, operations, compliance, and the broader workforce.
“Security is not just a technical methodology, it’s a mentality,” said Matt Warnick, Chief Executive Officer at American Rheinmetall. “It must be driven by leadership, enabled by IT, and embraced across the organization. I’m especially proud of our IT team for the years of configuration and testing required, and equally proud of our employees for adopting new security measures that strengthen our overall posture.”
Protecting Critical Information in a High-Risk Environment
Cybercrime has cost the manufacturing industry billions of dollars in downtime and intellectual property loss in recent years. For defense manufacturers, safeguarding sensitive information is not only a regulatory requirement but a national security imperative.
By achieving CMMC Level 2, American Rheinmetall demonstrates its proactive approach to mitigating cyber risk, protecting customer data, and ensuring operational continuity in an increasingly complex threat landscape.
Rheinmetall
Content preview only. Full article available at source. View Full Article
American Rheinmetall achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 across all its manufacturing facilities in Maine, Michigan, and Ohio in February 2023. This certification validates the implementation of 110 security requirements and is essential for competing in future Department of War contracts. The company emphasizes its commitment to protecting sensitive information and enhancing its cybersecurity posture.
- American Rheinmetall achieved CMMC Level 2 certification across all manufacturing plants.
- The certification was completed in February 2023.
- CMMC Level 2 compliance is mandatory for new Department of War contract solicitations.
- The certification validates implementation of 110 security requirements outlined in NIST SP 800-171.
- Achieving CMMC Level 2 positions the company for larger defense contracts.