GTSC Achieves CMMC Level 2 Certification
Achievement reinforces our commitment to protecting controlled unclassified information, even as federal certification requirements change
A Milestone Built on Trust
Government Technical Services Corporation (GTSC) is proud to announce that GTSC and its family of companies, GST, The Bowen Group, AEITS and Datawiz, achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 following a formal third-party assessment conducted by an accredited Certified Third-Party Assessor Organization (C3PAO), Cybersec Investments. CMMC Level 2 confirms that our security controls are implemented and maintained in alignment with NIST SP 800-171, the federal standard for protecting controlled unclassified information (CUI) on nonfederal systems.
For our government customers, prime contractors and industry partners, this certification confirms something we have said consistently: protecting your information, and the information entrusted to you by your own agency customers, is a daily discipline at GTSC, not a onetime event tied to a single audit.
Proceeding as Planned, Even as Requirements Changed
On July 13, 2026, the Department of War (DoW) announced an immediate 60-day suspension of CMMC Phase II requirements, pausing the third-party certification mandate while a newly formed CMMC Reform Task Force reviews the program’s design. Phase I self-assessment obligations, DFARS clause 252.204-7012, and NIST SP 800-171 compliance all remain fully in effect. Only the C3PAO certification milestone tied to the program’s Nov. 10, 2026, rollout was paused, and DoW is now gathering industry feedback before deciding how the program moves forward.
GTSC was roughly two weeks from its scheduled third-party assessment when that announcement was made. We had a choice: pause and wait for the review to conclude, or proceed as planned. We chose to proceed. Our clients and partners do not stop handling CUI because a federal deadline moved, and neither did we. This certification reflects a level of security assurance that stands on its own, independent of any single regulatory milestone.
“We were two weeks from our scheduled assessment when the federal requirement paused. We did not treat that as a reason to stop. Our clients trust us with their most sensitive information, and that trust does not pause for a 60-day review. Completing this certification on schedule was the right call for our people, our partners and our mission.”
Robert Lech, COO, GTSC
What This Means for Our Clients and Partners
- Your CUI is protected by controls independently assessed against CMMC Level 2 and NIST SP 800-171, verified by a third party rather than taken on faith.
- Our commitment to cybersecurity does not depend on which federal requirements happen to be active at a given moment.
- You can reference this certification in your own compliance and risk conversations with your program offices and contracting officers.
A Commitment Beyond Compliance
The CMMC program itself is still evolving, and GTSC will continue to track the Reform Task Force’s recommendations over the coming weeks. What will not change is our approach. Quality and security are embedded in how we operate, not added on to satisfy a single audit or a single mandate. Achieving CMMC Level 2 across our entire family of companies — GTSC, GST, The Bowen Group, AEITS and Datawiz — is one more proof point of that commitment to our clients, our partners and the missions we support together.
Have questions about our CMMC Level 2 certification or our broader quality and cybersecurity programs? Reach out to your GTSC program contact — we are glad to talk through what this means for your requirements.





Laurie Sanger
Lisa Schulze
PAMELA EGAN
MARY PROVUS
DON SHOFF
ROBERT LECH
RAYMOND ROBERTS