VIAVI secures CMMC Level 2 certification

VIAVI secures CMMC Level 2 certification

VIAVI has completed CMMC Level 2 certification across defence products. The assessed scope covers radio test, avionics, synthetic and modular test, and Position, Navigation and Timing systems used across its aerospace and defence business.


IN Brief:

  • VIAVI's Level 2 assessment covers radio test, avionics, synthetic and modular test, and PNT product lines.
  • Certified third-party assessment organisation A-LIGN conducted the assessment of the covered environment.
  • CMMC Phase II requirements remain suspended while Phase I self-assessment and underlying controlled-information safeguards continue.

VIAVI Solutions has completed Cybersecurity Maturity Model Certification Level 2 across product lines covering radio test, avionics, synthetic and modular test, and Position, Navigation and Timing. The assessment gives the company’s aerospace and defence operation an independently examined security baseline for information systems used to support those parts of its portfolio.

Certified third-party assessment organisation A-LIGN conducted the assessment. CMMC addresses the protection of sensitive US government information held on contractor systems rather than the technical performance of the test equipment itself, making the certification relevant to the engineering, support and programme data surrounding VIAVI products.

The covered lines sit across several areas where suppliers can encounter Controlled Unclassified Information during development, integration, maintenance or customer support. Radio test equipment can carry configuration and waveform information, avionics support may involve aircraft system data, and PNT products can form part of architectures intended to maintain navigation and timing when satellite signals are degraded or unavailable.

Separating product capability from information assurance is important. A piece of equipment may meet its electrical, RF or environmental specification while the systems used to design, configure or support it still have to satisfy contractual cybersecurity controls. Access management, system configuration, incident handling, data transfer and software maintenance therefore sit alongside conventional product assurance in defence supply relationships.

VIAVI intends to extend the certification to product lines acquired with Inertial Labs in 2025. Certification scope does not automatically cover every system or business unit owned by a company, so integrating acquired operations requires the relevant information environment, processes and controls to be brought within the assessed boundary.

The regulatory position around CMMC has changed during 2026. The US defence department suspended the planned Phase II requirements in July, halting the expansion that had been scheduled for November. Phase I self-assessment requirements remain in force while the department reviews the programme, and NIST SP 800-171 Revision 2 continues to underpin safeguarding requirements for covered controlled information.

VIAVI’s certification therefore exists alongside a procurement framework that is being revised. The assessment remains evidence that the covered environment has undergone third-party examination against the Level 2 standard, but suppliers still have to follow the requirements attached to each individual contract rather than assuming certification alone resolves every cybersecurity obligation.

Defence electronics businesses face a particularly broad implementation problem because sensitive data can pass through engineering workstations, laboratories, calibration systems, development networks, customer support channels and supplier interfaces. Protecting a conventional office environment is only part of the task when design files, test results and equipment configurations move between technical teams.

Configuration management becomes equally important after certification. Software is patched, staff change roles, new equipment enters laboratories and companies acquire businesses with their own networks and operating practices. Each alteration can change the assessed environment, so maintaining compliance requires continuous control rather than treating certification as a one-off audit exercise.

The manufacturing and support chain adds another layer. Specialist subcontractors may receive limited portions of technical information yet still fall within contractual safeguarding requirements. Prime contractors consequently need confidence that controlled data does not move into unmanaged systems when test, repair or engineering tasks are passed down the supply chain.

VIAVI’s defence-facing portfolio gives the certification a practical engineering connection. Military radio and avionics test equipment is used to verify systems whose availability depends on controlled calibration, software and configuration data, while resilient PNT technologies are being developed for increasingly contested electromagnetic environments. The security of the information supporting those systems has become part of programme assurance even where the supplied hardware itself is not a cyber product.

The planned inclusion of the Inertial Labs portfolio will provide the next measure of how VIAVI applies that control model across a broader organisation. Bringing an acquired business into a common assessed environment requires alignment of identity systems, policies, technical controls and evidence without disrupting engineering or customer support.

The Level 2 result gives VIAVI a documented position while CMMC policy continues to evolve. Future procurement rules will determine how frequently third-party certification is required and where self-assessment remains sufficient, but controlled defence information still has to be protected throughout the review period. Maintaining the assessed environment as products, staff and corporate structures change will be the longer-term test.


Discover more from IN Defence

Subscribe to get the latest posts sent to your email.


  • VIAVI secures CMMC Level 2 certification

    CGI tests quantum tools for contested logistics

    CGI Federal will test quantum computing for contested logistics operations. The Quantum Pathfinder initiative with DLA and the University of Tennessee will examine warehouse orchestration, reverse logistics, and resilient inventory positioning.


  • VIAVI secures CMMC Level 2 certification

    VIAVI secures CMMC Level 2 certification

    VIAVI has completed CMMC Level 2 certification across defence products. The assessed scope covers radio test, avionics, synthetic and modular test, and Position, Navigation and Timing systems used across its aerospace and defence business.