Schnabel Achieves CMMC Level 2 Certification
Schnabel has officially earned Cybersecurity Maturity Model Certification (CMMC) Level 2 certification – a Department of Defense (DoD) program that ensures defense contractors meet existing information security requirements to help protect Controlled Unclassified Information (CUI).
Achieving CMMC Level 2 is a significant milestone for any contractor working with the DoD because it verifies that an organization can reliably protect sensitive defense information from modern cyber threats. For Schnabel, this certification expands our ability to pursue and deliver federal projects that involve CUI in the defense and national security space.
“Cybersecurity is a governance priority for our organization,” says Patrick Vanderpool, Assistant General Counsel and Vice President. “Completing our CMMC audit reflects our commitment to protecting federal information, strengthening internal controls, and maintaining trust with our clients and partners.”
“Achieving CMMC Level 2 certification is a critical milestone for Schnabel Engineering,” adds Scott Narron, Chief Information Officer. “This reinforces our commitment to protecting client data and meeting the highest standards of cybersecurity expected by our federal and defense-sector clients. In addition, this certification reflects executive leadership’s sustained investment in security, compliance, and internal controls.”
A Companywide Commitment
Reaching this level of certification required significant coordination and support across the organization. Schnabel leadership made protecting client information a priority, dedicating significant focus and resources behind earning the certification. They created a dedicated working group of senior leaders – including Chief Operating Officer Chad Mayers – to ensure the collaborative effort aligned with operational needs and had full support across the company throughout the certification process.
Schnabel began implementing the DoD requirements in 2017 with new security controls like multifactor authentication. When the CMMC program was formally published in 2024, the IT team designed and built a secure, isolated IT system (an enclave) specifically for handling CUI that is not connected to any other Schnabel systems. With separate laptops, email addresses, and other required tools, IT developed a System Security Plan covering all 110 required controls, and built new policies and procedures on how to appropriately store, transmit, and destroy CUI. IT also created an Incident Response Plan and training materials to comprehensively address the new procedures related to CUI storage.
Recognizing the Team Behind the Achievement
This certification reflects the dedication, expertise, and persistence of many people across Schnabel – especially our IT team.
“Achieving CMMC Level 2 certification represents the successful execution of a comprehensive security and compliance program built to meet the DoD requirements,” says Garrett McGowan, Information Security Manager, who led the dedicated working group. “From implementing technical controls to maturing governance, risk, and documentation practices, this effort shows our committed approach to protecting and securing client data.”
Patrick adds, “Achieving this certification was an incredibly heavy lift for Schnabel’s IT department, and Garrett in particular. The third-party audit was about much more than just saying we met requirements; we had to demonstrate our solution in action over the course of a week-long, real-time audit. Garrett had to know every corner of our IT solution and be prepared to demonstrate anything the auditor requested.”
A Milestone Few Have Reached
Schnabel is now among the first 1,000 companies – out of roughly 100,000 federal contractors expected to need the certification – to earn this three-year certification, which became a DoD requirement in November 2025. Schnabel received the official certification following a rigorous assessment by third-party vendor C3PAO, Ignyte Platform Inc.
If you are pursuing a federal contract and need team members who are equipped to navigate CUI requirements, please reach out to Sharon Krock, Federal Market Pursuit Director, at skrock@schnabel-eng.com.
Achieving CMMC Level 2 certification is a critical milestone for Schnabel Engineering. This reinforces our commitment to protecting client data and meeting the highest standards of cybersecurity expected by our federal and defense-sector clients. In addition, this certification reflects executive leadership’s sustained investment in security, compliance, and internal controls.