Kiteworks and A-LIGN have partnered to help Defense Industrial Base contractors strengthen data security and prepare for CMMC 2.0 Level 2 assessments. The partnership integrates the Kiteworks secure data exchange platform with independent assessment services from A-LIGN, giving MSSPs and resellers a two-vendor offering for clients working through security controls, documentation, and audit readiness.The announcement comes as the Pentagon reviews the next phase of CMMC implementation. While the expansion of third-party assessment requirements has been paused, Phase I self-assessments, DFARS 252.204-7012 obligations, and requirements to protect Controlled Unclassified Information remain in place. DIB contractors still need to identify control gaps, document security practices and produce evidence that can stand up during an assessment.Under the partnership, organizations can use the Kiteworks Control Plane to manage how sensitive data is sent, shared, received, and stored. The platform supports controls tied to CMMC Level 2, including encryption, data governance, access management, and the isolation of CUI. A-LIGN can then independently evaluate the organization’s evidence and control environment. The companies said A-LIGN will remain separate from implementation and remediation work, preserving its role as an independent C3PAO.For MSSPs and resellers, the partnership gives them a clearer role in helping DIB clients prepare for assessment. That includes putting controls in place, organizing evidence, and fixing gaps before an assessor gets involved. CMMC timelines may change, but defense contractors still need to show that sensitive data is properly protected.




