Peerless achieves CMMC Level 2 with A-LIGN and IntelliGRC
  • Services
        • SOC Assessments 

        • SOC 1
        • SOC 2
        • ISO Certifications 

        • ISO 27001
        • ISO 27701
        • ISO 22301
        • ISO 42001
        • ISO 45001 
        • ISO 14001
        • ISO 9001
        • Federal Assessments 

        • All Government
        • FedRAMP
        • GovRAMP
        • FISMA
        • CMMC
        • NIST 800-171
        • Healthcare Assessments 

        • All Healthcare
        • HITRUST
        • HIPAA
        • Cybersecurity 

        • Penetration testing
        • Red team services
        • Ransomware preparedness assessment
        • Social engineering
        • Vulnerability assessment service
        • Privacy 

        • GDPR
        • CCPA/CPRA
        • PCI Assessments 

        • PCI DSS
        • PCI SSF
        • Additional Services 

        • International Services
        • Multi-Framework
        • AI Governance
        • AS9100
        • Microsoft SSPA
        • NIS2
        • C5
        • SOX 404
        • CSA STAR
        • Business Continuity & Disaster Recovery
        • Limited Access Death Master File
        • All Services
  • Platform
  • Company
        • About Us
        • Partners
        • Meet our team
        • Board of Directors
        • Careers
        • Community
        • image

          With audit demands at an all-time high, A-LIGN is enabling global organizations to modernize compliance,…

          Learn more
  • Customers
  • Resources
        • Quick links

        • Resource Center
        • Blogs
        • Case Studies 
        • Videos
        • Events
        • By service

        • SOC 2 
        • ISO 27001 
        • ISO 42001 
        • CMMC
        • FedRAMP
        • HITRUST 
        • PenTest
        • Featured Resources

          image
          image
          image
          image
  • A-SCEND Login
  • Careers
CONTACT US

How Peerless achieved a perfect CMMC Level 2 score with A-LIGN and IntelliGRC

by: A-LIGN 5 min

CMMC

  • SHARE

Peerless Tech Solutions provides managed IT, security, and compliance services for defense contractors. Founded in southern Maryland near Patuxent River Naval Air Station, it grew from a general IT provider into a dedicated partner for defense cybersecurity certification, ongoing compliance, and security monitoring.

In the summer of 2026, Peerless completed its own CMMC Level 2 certification assessment. The company engaged A-LIGN as its independent CMMC Third-Party Assessor Organization (C3PAO) and IntelliGRC as its governance, risk, and compliance (GRC) platform to complete the journey.

The challenge

Peerless has helped defense contractors meet federal cybersecurity requirements since CMMC program guidelines first came out in 2020, staying current as the requirements evolved over time. Long before seeking its own certification, Peerless built its IT services, security monitoring, and division of responsibilities with clients around these same requirements, so its own operations were already designed to meet the standards it helps clients achieve. The environment Peerless brought to the audit was the production environment its entire team works in every day, the same compliant environment it deploys and configures for the majority of its clients.

Peerless’ own documentation had been assessment-ready for some time, and the company set its sights on certifying during CMMC Phase 1, after the program’s November 10, 2025 kickoff date. Peerless searched for a C3PAO it could trust to run its independent assessment on a tight timeline and a GRC platform to operationalize its readiness on the path to certification.

When speaking to the benefit of achieving certification with a trusted C3PAO, “The benefit is confidence. Our clients’ confidence in us. We are asking DIB companies to trust us with the environments where their FCI and CUI live, and certification is proof that we are prepared to protect that information the way the government expects.”
-Ismail McCowin, Director of Cybersecurity & Compliance

Why A-LIGN

Peerless found both of its CMMC partners at the same industry event: CS5 in Washington, D.C. Several MSPs exhibiting at the conference pointed the Peerless team specifically toward A-LIGN, and after sitting through A-LIGN’s presentation, Peerless came away confident in the choice.

At the same event, Peerless attended an IntelliGRC session and received a product demonstration from a team member who turned out to be a Peerless alum. During that conversation, Peerless learned that IntelliGRC had itself been certified by A-LIGN for FedRAMP 20x, reinforcing confidence in both organizations at once.

From the kickoff call forward, Peerless found A-LIGN’s engagement to be professional and predictable. The timeline A-LIGN outlined at kickoff matched the actual timeline of the assessment, which ran for two weeks, with no moving targets. A-LIGN’s audit team was explicit about evidentiary expectations throughout the process, an approach Peerless describes as educational and beneficial rather than purely transactional.

IntelliGRC played a direct role in making that evidence process manageable: Peerless aggregated documentation and evidence inside the platform, exported it, and uploaded for A-LIGN’s auditors for review.

“From the beginning, A-LIGN was professional across the board. They had real availability, and the timeline they outlined on the kickoff call is exactly how the assessment ran. No moving targets, no hassle.” 
-Ismail McCowin, Director of Cybersecurity & Compliance

Results

Interviews wrapped on schedule, with every control met, pending final quality assurance review.

Additional evidence follow-up questions arrived, and a second review week began. Then, on July 13, the Department of War suspended Phase 2 of the CMMC program while Peerless’ results were still pending. The suspension paused the rollout of mandatory third-party assessments for contractors handling controlled unclassified information and opened a broader review of the certification framework.

For a company that had already done the work and was waiting on results, the timing raised an obvious question: would the certification still mean anything if the requirement behind it was under review? When official confirmation arrived that Peerless had met all 110 CMMC Level 2 controls — a perfect score — the reaction was relief first, then pride: proof that the certification stood on its own, independent of whatever the program’s future holds.

“A perfect score is not produced during an assessment window. It validates the hard work our team members put in every day supporting our clients, because the practices A-LIGN evaluated are simply how our teams operate.” 
-Sean Meyers, Director of Business Development

The business impact followed quickly. Response from marketing campaigns centered around certification has been positive, business development representatives reported a sharp increase in inbound interest within the first month after certification, and Peerless is now positioned to compete for the growing segment of DIB contractors who will engage only certified External Service Providers.

Peerless’ business depends on clients trusting it with their sensitive data. Earning certification, with the expertise of A-LIGN and IntelliGRC, backed up that trust with independent proof from reputable partners.

Advice to other Organizations Seeking Certification (OSCs)

Peerless’ advice to organizations pursuing CMMC assessment is direct: stay the course.

The suspension paused the third-party certification gate, not the underlying security requirements. DFARS 252.204-7012, NIST SP 800-171, self-assessments, SPRS scores, and annual affirmations all remain fully in force, and Peerless argues that an accurate, defensible SPRS score matters more during a period of increased reliance on self-attestation, not less. The company also encourages organizations to use any pause in mandatory timelines to complete the unglamorous work, organizing evidence and mapping it to assessment objectives, before a deadline forces it.

“For organizations seeking assessment, stay the course, just as we did. Our own certification was completed during the suspension, which makes the case better than any argument could. The suspension paused the third-party certification gate, not the security requirements behind it.”
-Sean Meyers, Director of Business Development

As Peerless prepares for the eventual shift to NIST SP 800-171 Revision 3, the company’s underlying rationale for pursuing certification remains constant. Peerless asks DIB clients to trust it with the environments where their FCI and CUI live, and independent assessment, delivered by A-LIGN and supported by IntelliGRC, is how Peerless demonstrates that the trust is warranted.

About Peerless Tech Solutions

Peerless Tech Solutions is a CMMC Level 2 certified managed services and managed security provider supporting Department of Defense, Defense Industrial Base, and Federal contractors. Peerless helps organizations achieve and maintain compliance with CMMC, NIST SP 800-171, and DFARS through a complete lifecycle of services that includes Gap Assessments, remediation, GCC High migrations and enclaves, GRC as a Service, managed IT, SIEM, and ongoing compliance support. Founded in 2014 and operating as a fully remote, U.S.-based team, Peerless partners with clients for the long term to turn compliance requirements into operational strength. Learn more at www.getpeerless.com.

About IntelliGRC

IntelliGRC delivers advanced governance, risk management, and compliance solutions tailored to simplify complex regulatory processes through automation and intelligent tools. With a focus on enabling secure, efficient, and compliant operational environments, IntelliGRC equips clients to confidently manage compliance requirements and make proactive, informed decisions. For more information, visit www.intelligrc.com.

A-LIGN is the leading cybersecurity compliance partner, trusted by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN delivers high-quality, efficient audits across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST.

CONTACT US
  • Services
  • SOC 1
  • SOC 2
  • ISO 27001
  • ISO 42001
  • CMMC
  • HITRUST
  • FedRAMP
  • Penetration Testing
  • PCI DSS
  • HIPAA
  • International Services
  • Multi-Framework
  • AI Governance
  • All Services
  • Company 
  • About us
  • Partners
  • Platform
  • Careers
  • Our Team
  • Community
  • Trust Center
  • Contact Us
  • Customers 
  • Customer Stories 
  • Resources
  • Resource Center
  • Blogs
  • Case Studies
  • Videos
  • Events
  • Newsletter Sign-up
  • Guides
  • SOC 2 Compliance
  • ISO 27001 Certification
  • CMMC Compliance
  • ISO 42001 Compliance
  • HITRUST Certification
  • ISO Certificate Directory
  • Privacy Policy
  • Cookie Policy
  • Impartiality and Inquiries
  • Acceptable Use Policy
  • Sitemap
  • AI Information

Price and Associates CPAs, LLC dba A-LIGN ASSURANCE is a licensed certified public accounting firm registered with the Public Company Accounting Oversight Board (PCAOB). A-LIGN Compliance and Security, Inc. dba A-LIGN is a leading cybersecurity and compliance professional services firm.

A-LIGN 2026. All rights reserved.

  • Services
    • SOC Assessments
      • SOC 1
      • SOC 2
    • ISO Certifications 
      • ISO 27001
      • ISO 27701
      • ISO 22301
      • ISO 42001
      • ISO 45001 
      • ISO 14001
      • ISO 9001
    • Healthcare Assessments 
      • All Healthcare
      • HITRUST
      • HIPAA
    • Federal Assessments
      • All Government
      • FedRAMP
      • StateRAMP
      • FISMA
      • CMMC
      • NIST 800-171
    • PCI Assessments
      • PCI DSS
      • PCI SSF
    • Cybersecurity
      • Penetration testing
      • Red team services
      • Ransomware preparedness assessment
      • Social engineering
      • Vulnerability assessment service
    • Privacy
      • GDPR
      • CCPA/CPRA
    • Additional Services
      • International Services 
      • Multi-Framework 
      • AS9100
      • Microsoft SSPA
      • NIS2
      • C5
      • SOX 404
      • CSA STAR
      • Business Continuity & Disaster Recovery
      • Limited Access Death Master File
    • All Services
  • Platform
  • Company
    • About Us
    • Partners
    • Meet our team
    • Board of Directors
    • Careers
    • Community
  • Customers
  • Resources
    • Resource Center
    • Blogs
    • Case Studies 
    • Videos 
    • Events
    • By Service
      • SOC 2 
      • ISO 27001 
      • ISO 42001 
      • CMMC
      • FedRAMP
      • HITRUST
      • PenTest 
  • A-SCEND Login
  • Careers
CONTACT US