Cybersecurity & Compliance
Committed to security and compliance:
A&M Industrial protects our customers' sensitive information to U.S. Department of Defense standards. A&M Industrial has invested in a modern, independently framed cybersecurity program so our defense and manufacturing customers can trust us with sensitive and controlled information. Our program is built on the U.S. Government's NIST SP 800-171 standard and aligned to CMMC 2.0 Level 2.
What we have in place:
- CMMC 2.0 Level 2 (self-assessment): a perfect NIST SP 800-171 Rev 2 score of 110 of 110, recorded in the DoD Supplier Performance Risk System (SPRS)
- A dedicated CUI enclave: Controlled Unclassified Information is handled only in an end-to-end-encrypted, FedRAMP-Moderate-equivalent environment using FIPS 140-3 validated cryptography
- 24/7 managed detection and response (MDR) and endpoint protection across our systems
- Multi-factor authentication, encryption, centralized security monitoring (SIEM), data-loss prevention, and enforced device controls
- Ongoing security-awareness training and phishing simulation for our workforce
What it means for our partners:
We are a trusted supplier for defense and controlled-information work. Your data is protected to a recognized federal standard. Choosing A&M Industrial reduces supply-chain and compliance risk for your program.
Please note: A&M Industrial's CMMC 2.0 Level 2 status is based on a self-assessment recorded in SPRS in accordance with U.S. Department of Defense requirements. “Certified” status via a C3PAO third-party assessment is a separate process; we do not claim C3PAO certification. Figures current as of 2026-09-04.
