Arcadis NV

09/04/2026 | Press release | Distributed by Public on 09/04/2026 07:09

Arcadis achieves CMMC level 2 certification

Arcadis achieves gold standard of Department of Defense cybersecurity compliance with CMMC Level 2 Certification

Strengthening protection of sensitive information and expands opportunities to support U.S. federal and defense clients

Arcadis, a global leader in intelligence-driven sustainable design, engineering, and consultancy solutions for natural and built assets, has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2, a cybersecurity standard established by the U.S. Department of Defense (DoD) for organizations that handle controlled unclassified information (CUI). The certification demonstrates Arcadis' ability to meet rigorous cybersecurity requirements to support federal and defense clients with the secure handling of sensitive information.

CMMC Level 2 is a key requirement for companies pursuing many U.S. defense contracts and validates that an organization has implemented cybersecurity controls aligned with National Institute of Standards and Technology (NIST) SP 800-171 requirements. According to the DoD, the framework is designed to strengthen cybersecurity across the Defense Industrial Base and safeguard sensitive government information. By achieving CMMC Level 2 certification, Arcadis can continue supporting defense and federal projects while positioning itself for future opportunities as cybersecurity requirements become increasingly prevalent across government contracting.

Jen Mayers, Defense & Security Sector Executive for Arcadis, said: "Achieving CMMC Level 2 certification is a significant milestone for Arcadis' Defense and Security sector globally. It allows us to continue supporting defense and government clients that entrust us with sensitive information while positioning Arcadis for future growth in these critical markets. Most importantly, it demonstrates our commitment to cybersecurity, protecting our clients' data and maintaining the trust they place in us every day."

The certification follows a multi-month, cross-functional effort by Arcadis teams across technology, information security, governance and federal operations, with the Technology team leading a significant share of the delivery given its ownership of more than 80% of the NIST SP 800-171 controls required for certification. To prepare for the assessment, the company conducted independent readiness evaluations and implemented a dedicated secure government cloud environment designed to meet stringent federal cybersecurity requirements. Microsoft's continuous support throughout the program was critical to achieving certification within the accelerated timeframe, providing the technical expertise, guidance and responsiveness needed to help Arcadis meet the required controls and audit expectations at pace. Arcadis was assessed by a Certified Third-Party Assessment Organization (C3PAO) and achieved a perfect score during the audit. Arcadis, Microsoft and strategic partners collaborated to deliver a secure enclave environment that met all 110 security requirements and 320 assessment objectives without advisories or follow-up actions.

John McCarthy, U.S. Country Director for Arcadis, said: "Achieving CMMC Level 2 certification is the result of the collaborative efforts across our technology, information security, governance, and federal teams. By prioritizing cybersecurity and strengthening our information protection capabilities, we are emphasizing our commitment to delivering exceptional outcomes for our clients and protecting the critical information they share with us."

Arcadis NV published this content on September 04, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 04, 2026 at 13:09 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]