BlueAllyBlueAlly
Jul 30, 2026
Press Release

BlueAlly Achieves Perfect 110/110 Score on CMMC Level 2 Assessment

Compliance, Security

Atlanta, GeorgiaBlueAlly, an IT services and solutions provider, today announced it has achieved a perfect score of 110 out of 110 on its Cybersecurity Maturity Model Certification (CMMC) Level 2 assessment, with zero Plans of Action and Milestones (POA&Ms) and zero gaps identified.

CMMC is the Department of Defense’s framework for verifying that contractors handling sensitive government information can protect it effectively. Level 2 is the tier required to handle Controlled Unclassified Information (CUI) and maps to 110 security requirements from NIST SP 800-171, spanning access control, audit logging, incident response, personnel screening, media protection, and system integrity.

The assessment was conducted by a Certified Third-Party Assessment Organization (C3PAO), which spent weeks reviewing evidence, interviewing staff, testing controls, and confirming that documented practices matched what was actually happening across the organization. Most organizations pursuing CMMC Level 2 do not pass on the first attempt. Most receive a conditional certification with one or more POA&Ms, requiring gaps to be closed within 180 days.

BlueAlly received the full certification. No conditions. No gaps to close.

What the Score Confirms

A perfect score means an independent assessor examined every control BlueAlly claims to operate and verified that each one is real, functioning, and effective. That includes access controls, Security Operations Center (SOC) monitoring, encryption, incident response, supply chain vetting, and personnel practices.

For clients working with the Department of Defense, the certification places BlueAlly on the approved vendor list without qualification. For commercial and mid-market clients, it is independent, third-party evidence that the security program behind BlueAlly’s services holds up under a federal standard, not just in a sales conversation. For lean IT teams that cannot staff this level of compliance work on their own, it means the depth of a much larger security operation is already built into the partnership.

The CMMC Level 2 badge is now live on BlueAlly’s Trust Center at trust.blueally.com, alongside the company’s SOC 2 Type II, ISO 27001, ISO 9001, and ISO 42001 certifications. The page serves as a single source of truth for clients evaluating BlueAlly’s security posture during a proposal, a security questionnaire, or a direct conversation about risk.

“This is more than a certification,” said Mike Perry, Director of IT and Security Operations, BlueAlly. “It’s the kind of result that changes what clients ask us to do next.”

 


 

About BlueAlly

BlueAlly is a leading IT services and solutions provider that helps clients reduce complexity and harness the power of technology to improve organizational outcomes. With over 450+ highly skilled professionals, 2,000+ industry certifications and 10,000+ satisfied customers served, BlueAlly is a trusted partner known for turning complex technical challenges into strategic business opportunities.

Media Contact: Ian Daum — idaum@blueally.com