In June, Omega EMS announced its intention to achieve CMMC Level 2 before the U.S. Department of Defense’s mandatory November 2026 implementation timeline for organizations handling Controlled Unclassified Information (CUI). We caught up with Omega EMS CEO Chris Alessio to discuss the company’s certification journey, the investment required, and what CMMC means for Omega’s military and aerospace business. Note: The DoD has suspended its November requirement pending a 60-day review.
Nolan Johnson: Chris, where are you at with the Level 2 CMMC certification?
Chris Alessio: We have successfully completed both our CMMC Level 1 and Level 2 self-assessments. Those assessments identified the remaining gaps, and we've developed a structured remediation plan with clear milestones to achieve formal CMMC Level 2 certification before the Department of Defense enforcement timeline. We expect to complete certification in late September or early October, providing additional schedule margin before enforcement begins.
Johnson: Can you help us better understand the CMMC process to become certified?
Alessio: Our IT and compliance teams have been leading this initiative for several months alongside experienced CMMC advisors. It's a significant investment, not only financially but organizationally, but one we believe is essential.
We've been ITAR-registered for many years and maintain certifications, including AS9100 and ISO 13485. CMMC builds on that foundation by introducing a much deeper level of cybersecurity governance, access control, continuous monitoring, and protection of CUI.
More importantly, it changes culture. As companies grow, processes that worked at $20 million don't necessarily work at $100 million. CMMC forces organizations to mature their cybersecurity practices across technology, processes, and people, ultimately making Omega a stronger company.
To continue reading this interview, which appeared in the August 2026 SMT007 Magazine, click here.