Kiteworks and A-LIGN have formed a strategic partnership to help Defense Industrial Base (DIB) organizations strengthen sensitive-data controls and prepare for CMMC Level 2 assessments, creating a new compliance-services opportunity for MSPs and MSSPs serving federal contractors.
CMMC review creates uncertainty, not a compliance pause
The announcement comes as the federal government conducts a 60-day review of the next phase of CMMC implementation. Although that review has created uncertainty around the timing and structure of third-party assessments, existing self-assessment and DFARS cybersecurity obligations remain in effect.
That distinction matters for channel partners whose customers may interpret a delayed compliance deadline as permission to pause security projects. Defense contractors still need to protect Controlled Unclassified Information and demonstrate that required safeguards are operating effectively.
“Protecting the DIB was never about a single deadline, but rather about building data security practices durable enough to hold up no matter how the compliance timeline evolves,” said Kurt Michael, chief revenue officer at Kiteworks, in a statement.
Kiteworks said its Control Plane addresses a substantial majority of CMMC Level 2 requirements, including areas that frequently produce evidence gaps during assessments. The platform centralizes the governance and protection of sensitive information as it moves into, out of, and within an organization.
Its capabilities include Hold Your Own Key encryption and deployment as a single-tenant virtual appliance. Kiteworks is also FedRAMP Moderate Authorized, FedRAMP High In Process, and FIPS 140-3 validated.
A-LIGN maintains assessment independence
Organizations can deploy Kiteworks to strengthen their data controls and separately engage A-LIGN to evaluate the resulting evidence. The companies stressed that A-LIGN will remain an independent assessor and will not consult on or remediate control implementations.
Customers also retain the ability to select another authorized C3PAO.
A-LIGN has conducted nearly 100 CMMC Level 2 assessments, according to the company. Its assessments extend beyond technology to governance, personnel, physical security, and other organizational requirements.
MSPs can build services around CMMC readiness
For MSPs and MSSPs, the opportunity is not limited to deploying another security platform. Partners can help defense contractors inventory CUI, redesign data-sharing workflows, implement controls, document evidence, and remediate weaknesses before a formal assessment begins.
“There’s some uncertainty right now about when, and in what form, CMMC’s third-party assessment requirements will return,” said Nicholas Ludy, chief growth officer at A-LIGN. “But the underlying requirements haven’t gone anywhere.”
“The commitment to securing the DIB doesn’t hinge on any single implementation date. As CMMC requirements evolve, Kiteworks will keep giving DIB organizations a practical path to stronger data security and audit readiness, and A-LIGN will continue to deliver rigorous, independent assessments, so organizations are prepared whenever the certification timeline is finalized,” Ludy’s statement continued.
Kiteworks is also focused on bringing compliance support to Canadian partners and customers. Read our conversation with VP of Global Channels David Byrnes to learn more about the company’s international approach to security and governance.





