in ,

MarCom Group Earns CMMC Level 2 Certification After Two-Year Preparation

MarCom Group Earns CMMC Level 2 Certification After Two-Year Preparation
Photo: Lauren Rainford/LinkedIn
  • MarCom Group previously achieved CMMC Level 1 and ISO/IEC 27001:2022 certification
  • CMMC Level 2 requires compliance with 110 security controls aligned with NIST SP 800-171
  • The company’s preparation involved cybersecurity documentation, testing, collaboration and reviews

MarCom Group, a woman-owned creative agency serving federal clients, has earned Cybersecurity Maturity Model Certification Level 2 after more than two years of preparation.

The Arlington, Virginia-based company said Wednesday the effort involved work on its cybersecurity processes, personnel and technology.

What Does CMMC Level 2 Cover?

CMMC establishes cybersecurity requirements for organizations in the defense industrial base that handle controlled unclassified information. Level 2 requires organizations to implement 110 security requirements aligned with federal security standards, including National Institute of Standards and Technology Special Publication 800-171.

Lauren Rainford, CEO and owner of MarCom Group, said the certification reflects how central cybersecurity is to the way the company works and supports its customers.

“Our federal clients trust us with important missions, information, and responsibilities. We take that trust seriously,” said Rainford.

Olivia Bird, vice president of technology and innovation, said the Level 2 effort required the company to examine its information protection practices throughout the organization.

How Did MarCom Group Prepare for CMMC?

MarCom Group said its preparation involved documentation, testing, collaboration and reviews of its cybersecurity practices. The creative agency had previously achieved CMMC Level 1 and received ISO/IEC 27001:2022 certification in 2025, providing earlier certifications in its cybersecurity efforts.

The certification comes as the Department of War reviews CMMC after suspending Phase II requirements in July. Phase I self-assessment requirements remain in place during the review.

MarCom Group said its cybersecurity work will continue as requirements for federal contractors evolve, with the agency citing ongoing attention to its personnel, technology and internal processes.

ExecutiveBiz Logo

Sign Up Now! ExecutiveBiz provides you with Daily Updates and News Briefings about Cybersecurity

mm

Written by Miles Jamison

SolarWinds Report Outlines AI Governance Gaps In Public Sector IT
SolarWinds Report Outlines AI Governance Gaps In Public Sector IT
Former AWS, Google Sales Leader Jim Young Takes On VP Role at Blitzy
Former AWS, Google Sales Leader Jim Young Takes On VP Role at Blitzy