Skip to main content

Purdue obtains federal cybersecurity certification

In July 2026, Purdue achieved a significant cybersecurity milestone. Following an independent assessment by an authorized Certified Third-Party Assessment Organization (C3PAO), Purdue obtained the Cybersecurity Maturity Model Certification (CMMC) Level 2, earning a perfect score and satisfying all 110 required security controls.

CMMC is a U.S. Department of Defense (DoD) program designed to validate the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Federal agencies increasingly require CMMC certification for organizations seeking to participate in DoD-sponsored research involving FCI (Level 1) and CUI (Level 2).

The certification effort represented a major university-wide accomplishment requiring extensive collaboration among Purdue IT, Research Security and Export Controls (RSEC), Administrative Operations, Human Resources, numerous campus partners and external consultants.

To support these requirements, Purdue IT partnered with RSEC to develop and deploy the Purdue Hybrid Agile System for Research (PHASR). PHASR combines the Rosen Center for Advanced Computing's secure, cost-effective on-premises high-performance computing resources, including the Weber system, with a secure Microsoft 365 Azure cloud environment in Microsoft GCC High. This environment enables secure collaboration and rapid provisioning of research-focused virtual systems. CMMC requirements also extend to laboratory systems, and the Aerospace Sciences Lab became Purdue's first research environment to implement CMMC Level 2-certified systems integrated with PHASR.

In November 2025, Purdue published the Controlled Unclassified Information in Research (S-32) Standard along with the associated CMMC Compliance Program, establishing the framework for managing and protecting CUI across the University's research environment.

Today, more than 150 researchers and support personnel utilize PHASR to conduct and support research that serves critical national interests.

Although the Department of Defense announced on July 13, 2026, that it was suspending the requirement for C3PAO-assessed certification pending a comprehensive review of the CMMC program, organizations must still maintain self-affirmed compliance.

"The decision by the DoD to pause certification requirements does not detract from the outstanding accomplishment the team has achieved,” said Chief Information Security Officer Bob Geswein. “Purdue’s certification places the University further ahead of the curve and into a much stronger position regarding our CUI environment, processes, and ability to work on government contracts."

Purdue's successful certification strengthens its research security posture, demonstrates leadership in protecting sensitive government information and enhances the University's ability to compete for future government-sponsored research opportunities.