For product developers in the defense sector, the transition to structured cybersecurity requirements marks a significant shift in how projects are managed and secured. At the core of this shift is the Cybersecurity Maturity Model Certification (CMMC). Achieving compliance is not a simple self-attestation, but a tiered CMMC verification process that serves as a prerequisite for contract awards.
This article provides a roadmap for understanding CMMC levels and explains how to configure your PLM environment to protect your business.
The Department of War (DoW) established the Cybersecurity Maturity Model Certification (CMMC) Program to verify contractors have implemented the required security framework to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The program was created to secure the Defense Industrial Base (DIB) sector against evolving cybersecurity threats and move from a “self-attestation” model to one of structured requirements.

The structure and requirements are designed to achieve the primary goals of the internal review:
CMMC Program key features:
The CMMC program relies heavily on security requirements of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations” (referred to as NIST SP 800-171). More information can be found here.
Achieving CMMC Compliance can be complicated, depending on the level of compliance needed.

Level 3 – 134 requirements (110 from NIST SP 800-171 R2 plus 24 from NIST SP 800-172). DIBCAC Certification assessment every 3 years, plus annual affirmation.
Level 2 – 110 requirements aligned with NIST SP 800-171 R2. C3PAO certification assessment every 3 years or self-assessment every 3 years for select programs, and annual affirmation.
Level 1 – 15 requirements aligned with FAR 52.204-21. Annual Self-Assessment and Annual Affirmation are required.
Level 1 can be achieved by following the guidelines in FAR 52.20421 and can typically be done by a contractor’s IT and Information Security teams. The regulation speaks to basic safeguarding requirements and procedures to protect covered contractor information systems. There are 15 core requirements. Level 1 can be done via self-assessment by following this general guide.
Level 2 is much more complicated and typically involves contracting with a 3rd party firm to help with the contractor’s compliance efforts. This level is the minimum that must be achieved to act as a contractor for the DoW and is required to interact with FCI and CUI. In the publication NIST SP 800-171 R2, you will find 110 requirements that cover 14 families, including, but not limited to, Access Control, ID and Authentication, Physical Protection, Media Protection, Incident Response, Personnel Security, and Risk Assessment.
Level 2 self-assessment must be completed by the contractor, followed by a 3rd party certification by a Certified 3rd party Assessor Organization (C3PAO). The C3PAO will provide a plan of action and milestones (POA&M) with gaps to achieve compliance. There are many C3PAO’s in the marketplace.
Level 3 compliance requires Level 2 compliance, plus it incorporates NIST SP 800-172 and uses Organization-Defined Parameters (ODPs). Level 3 incorporates 24 additional requirements that cover 10 families including, but not limited to, Risk Assessment, System and Communications Protection, and System and Information Integrity.
Individual Certifications
Registered Practitioners (RPs) - provide advice, consulting, and recommendations to prepare for audits, but cannot conduct official CMMC assessments.
CMMC Certified Professional (CCP) – foundational certification for those working on the CMMC implementation and/or assessment.
CMMC Certified Assessor (CCA) – credentialed professional who can lead CMMC Level 2 assessments. The CCA must be part of a CMMC 3rd Party Assessment Organization (C3PAO).
Lead CMMC Certified Assessor (LCCA) – is the highest credentialed professional authorized to lead Level 2 assessments.
Organizational Certifications
CMMC Registered Provider Organization (RPO) – organization that can provide pre-assessment consulting services and readiness preparation for CMMC Level 2 certification. The RPO cannot perform the final certification audit.
CMMC 3rd Party Assessment Organization (C3PAO) – organization authorized to conduct independent assessments for Level 2 assessments.
CMMC Approved Training Provider (ATP) – organization approved to train CMMC assessors.
CMMC Approved Publishing Provider (APP) – organization approved to publish training materials.
The Cyber AB is the official accreditation body of the CMMC ecosystem and the only authorized non-governmental partner of the DoW in implementing CMMC.
Partners can be found here. Contractors will likely need to hire an RPO for CMMC readiness and a C3PAO for assessment.
Yes. GoEngineer supports product data management (PDM) and product lifecycle management (PLM) solutions for thousands of clients in many different industries, including defense. PDM is generally considered a component of PLM, so we will refer to both solution sets as part of PLM. GoEngineer implements and supports several PLM solutions; however, we will focus on SOLIDWORKS PDM and 3DEXPERIENCE solutions, both developed by Dassault Systèmes.


Both SOLIDWORKS PDM and 3DEXPERIENCE software are PLM tools that a DoW contractor can use to support product development or process workflows in a compliant way. The software itself is neither compliant nor noncompliant, but it can be implemented to support CMMC compliance initiatives, given the proper environment and processes.
CMMC Level 2 compliance governs FCI and CUI data, which would typically be stored in the PLM software application, making the application a critical item in the compliance project. The approach for compliance depends on whether the contractor is hosting the software application in their facilities or using the Dassault Systèmes public or private cloud.
In this section, we will review GoEngineer PLM solutions and things to consider when considering CMMC Level 2.
Currently, the 3DEXPERIENCE public cloud will not support CMMC compliance Level 2, because it is not suitable for FC or CUI storage due to data sovereignty (international tech support access) and FedRAMP status.
In this scenario, the contractor has 100% responsibility for meeting the 110 requirements in CMMC Level 2.
You must secure the servers (SQL Database, 3DPassport, Foundation, File Collaboration) running the 3DEXPERIENCE system.
CMMC requires robust identification. Standard username/password is insufficient.
In this scenario, the contractor has 100% responsibility for meeting the 110 requirements in CMMC Level 2.
You must secure the servers (SQL Database, Archive Servers) running the SOLIDWORKS PDM system.
CMMC requires robust identification. Standard username/password is insufficient.
PLM applications can help with CUI data storage, access control, and documentation approval workflows. Even with a PLM system, most of the CMMC Level 2 certification requirements are related to your corporate infrastructure.
The following table provides a high-level breakdown of which requirements are supported by the SOLIDWORKS PDM and 3DEXPERIENCE on-premises PLM applications.
| CMMC Domain | Total Practices | SOLIDWORKS PDM | 3DEXPERIENCE | Coverage | Key Content |
| Access Control | 22 | 11 | 12 | ~50-55% | 3DX Edge: Offers better, more granular permissions and document categorization. Both rely on OS/IT for physical and device-level access limits. |
| Audit & Accountability | 9 | 8 | 8 | 89% | Core Strength: Both tools excel here via immutable audit trails, electronic signatures, and secure version history. |
| Configuration Management | 9 | 1 | 1 | 11% | Shared Responsibility: Primarily an IT network/hardware responsibility. Software only covers specific file-level baselines. |
| Identification & Auth | 11 | 10 | 10 | 91% | Core Strength: High coverage achieved through integration with Windows Active Directory, SSO, and IP Export Controls. |
| System & Comms Protection | 16 | 2 | 2 | ~12% | Shared Responsibility: Relies heavily on external firewalls, network encryption, and endpoint security outside the PLM/PDM scope. |
Your IT and Information Security teams will need to build a System Security Plan (SSP). You should work with a CMMC Registered Provider Organization (RPO) to support your efforts. You need FIPS-validated hardware, configured to NIST 800-171 standards, and a PLM system to meet your data access requirements.
Contact GoEngineer to get help with the implementation and configuration needs of your PLM system. Our team can work with your CMMC RPO to support your project.
Partners can be found here.
Learn more about CMMC here.
Stop Using Network Drives - Maximize SOLIDWORKS Performance with Cloud Services
3DEXPERIENCE: 3DDrive vs 3DSpace
SOLIDWORKS PDM vs 3DEXPERIENCE CLOUD PDM: Workflows, Licensing & More
About Justin Webster
Justin Webster is Vice President of Professional Services at GoEngineer, where he has spent over 22 years focused on product lifecycle management. Since joining CATI (later acquired by GoEngineer) he has worked as a consultant, project manager, and applications engineer before moving into leadership. He has led service and application engineering teams for the past 18 years. Justin holds a B.S. in Agricultural Engineering from the University of Illinois Urbana-Champaign and is certified in ENOVIA V6 Program Management.
Get our wide array of technical resources delivered right to your inbox.
Unsubscribe at any time.