Viavi Aerospace Division Earned CMMC Level 2 Status
The certification confirms that Viavi meets federal cybersecurity standards required for handling sensitive defense contract data.
Updated on Sept. 25, 2026 in Cybersecurity

Live Poll
Should defense contractors be required to meet stricter federal cybersecurity standards?
Viavi’s Aerospace and Defense division has successfully completed CMMC Level 2 certification, a milestone verified by third-party assessor A-LIGN. This status ensures the company’s alignment with mandatory security protocols for managing federal information under Department of Defense contracts.
Why it matters
The certification is a necessary baseline for organizations operating within the U.S. defense industrial base, ensuring contractors can securely manage controlled unclassified information. It highlights the increasingly rigorous security requirements mandated for suppliers to maintain eligibility for defense-related projects.
The division achieved CMMC Level 2 certification, which benchmarks security practices against the NIST SP 800-171 standard. This compliance covers the firm's radio test, avionics, synthetic and modular, and PNT product lines.
The players
Viavi Aerospace and Defense
A division of a technology firm specializing in network testing, monitoring, and assurance solutions for communications and aerospace industries.
A-LIGN
A specialized cybersecurity and compliance firm that conducts third-party assessments for companies seeking official security certifications.
U.S. Department of Defense
The federal executive department responsible for coordinating and supervising all agencies and functions of the government concerned directly with national security and the United States Armed Forces.
The details
The certification process, managed by A-LIGN, involved a rigorous third-party assessment of the company’s internal cybersecurity practices and information handling processes. Compliance requires proving that an organization can protect both Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) from unauthorized access or exfiltration. This level of oversight is mandated by the U.S. Department of Defense to ensure the integrity of the broader defense supply chain.
Timeline
2025: Viavi acquired Inertial Labs.
September 25, 2026: Viavi announced the completion of its CMMC Level 2 certification.
The Tech Race
The certification aligns the company's internal security infrastructure with the federal baseline defined by NIST SP 800-171 requirements. This move follows a broader industry trend where defense contractors must demonstrate rigorous compliance to remain viable in the supply chain.
This certification allows the company to continue bidding on and fulfilling U.S. Department of Defense contracts that require high-level security clearance. Future efforts will focus on migrating these same security standards to product lines acquired from Inertial Labs.
The takeaway
Maintaining CMMC compliance is now a critical barrier to entry for firms participating in the defense industrial base. Stakeholders should monitor the company's progress on integrating its 2025 acquisition, Inertial Labs, into this same security framework to ensure consistent compliance across its entire portfolio.
Further reading
For broader trends in enterprise and defense security, visit Cybersecurity.
Live Poll
Should defense contractors be required to meet stricter federal cybersecurity standards?







