Pegasus Technologies

Pegasus Technologies

Speciality: External and Internal Network Penetration Testing

23 employees
[01] About

Cybersecurity company providing penetration testing and vulnerability scanning services; operates multiple Pennsylvania offices including Kennett Square, Media, Bethlehem, and Wayne; explicitly states pentest services with detailed testing methodologies.

Cybersecurity company providing penetration testing and vulnerability scanning services; operates multiple Pennsylvania offices including Kennett Square, Media, Bethlehem, and Wayne; explicitly states pentest services with detailed testing methodologies.
[02] Services
[03] Certifications
CMMC Level 2

CMMC Level 2: Origin


The Cybersecurity Maturity Model Certification (CMMC) was created by the U.S. Department of Defense (DoD) in January 2020 in response to growing concerns about cybersecurity threats to the defense industrial base. The framework was developed to ensure that contractors and subcontractors handling sensitive government information, particularly Controlled Unclassified Information (CUI), implement adequate cybersecurity practices. CMMC Level 2 specifically aligns with NIST SP 800-171 requirements and was designed to verify that defense contractors have moved beyond self-assessment to demonstrate actual implementation of essential security controls.


Industry Importance and Value


CMMC Level 2 certification is crucial for companies seeking to work with the DoD, as it has become a contractual requirement for bidding on and maintaining defense contracts involving CUI. The certification demonstrates that an organization has implemented comprehensive cybersecurity practices, making it more trustworthy to government agencies and prime contractors. Beyond regulatory compliance, achieving CMMC Level 2 provides competitive advantages in the defense sector, enhances overall cybersecurity posture, and signals to clients that the organization takes data protection seriously. As supply chain attacks become increasingly sophisticated, this third-party validated certification helps ensure the entire defense industrial base maintains a baseline level of security resilience.

NIST 800-171

NIST 800-171: Origin and Importance


Origin


NIST Special Publication 800-171 was created by the National Institute of Standards and Technology (NIST), a non-regulatory agency within the U.S. Department of Commerce. First published in June 2015 and subsequently revised, it was developed in response to Executive Order 13556, which aimed to establish standards for protecting Controlled Unclassified Information (CUI). The framework was specifically designed to help non-federal organizations that handle, store, or process CUI on behalf of the federal government implement appropriate security controls to protect sensitive government information outside of federal systems.


Industry Importance


NIST 800-171 has become critically important in the defense industrial base and federal contracting sectors, as compliance is now mandatory for organizations working with the Department of Defense and other federal agencies that handle CUI. The certification demonstrates that an organization has implemented 110 security requirements across 14 control families, covering areas such as access control, incident response, and system integrity. Beyond contractual requirements, achieving NIST 800-171 compliance has become a competitive differentiator and trust signal in the marketplace, showing clients and partners that an organization takes cybersecurity seriously and follows recognized best practices for protecting sensitive information.