The Green Building Bulletin

Insights, Policies + Strategies

Back to all articles

Why GBI’s CMMC Level 2 Certification Matters for Federal and Defense-Adjacent Projects 

Green Building Initiative recently achieved Final CMMC Level 2 (C3PAO) certification, confirming that GBI’s information systems meet the security requirements of NIST Special Publication 800-171 Rev. 2. The independent assessment was conducted by an Authorized C3PAO over a multi-day audit in June 2026, with the certification valid through June 2029. 

If you’re pursuing Guiding Principles Compliance (GPC) for federal and defense-adjacent projects, here’s what that means.

What is CMMC? 

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s framework for verifying that contractors and their partners adequately protect sensitive information, including Controlled Unclassified Information (CUI), across the defense industrial base. Level 2 is the tier required for organizations that handle CUI. While any organization can self-attest to Level 2 compliance, obtaining Level 2 certification goes a step further by undergoing an independent, third-party assessment by an Authorized C3PAO against the full NIST SP 800-171 control set, a testament to how seriously GBI treats data security. 

“We’re excited to expand our ability to support clients working on projects that involve CUI, particularly as we’re seeing these requirements become more common across Department of Defense projects,” said Kate Callahan, Associate Vice President, Go-To-Market at GBI. “Establishing a secure CMMC enclave allows us to continue supporting these clients through their certification journey, maintain important relationships, and help drive progress across their federal project portfolios.”

What does this mean for your project? 

GBI takes data security seriously as an organization and has taken the necessary steps to support project teams achieving Third Party Certification while protecting CUI.  

Projects involving CUI, including many federal projects pursuing Guiding Principles Compliance, require heightened protection of sensitive government data. Documentation for these projects may include facility layouts, security infrastructure details, occupancy patterns, and other information tied to government-owned or -leased space that is designated as CUI. Any third party touching that data, including a certification provider like GBI, should adhere to security practices that align with federal requirements. 

GBI’s CMMC Level 2 status means our organization has been independently assessed against the same security framework the federal government requires of its own contractor base, providing federal clients with confidence that CUI is being handled in accordance with rigorous security standards. 

What this means in practice for GPC clients 

  • Lower friction in security reviews. GBI’s CMMC Level 2 status ensures seamless and secure reviews of project documentation without guesswork or special measures needing to be taken to provide the necessary access. 
  • Dedicated Support.  Receive the same responsive, expert support you expect from GBI, with the added assurance that all staff and third-party assessors supporting CUI projects are trained in CMMC Level 2 requirements and work within GBI’s secure, controlled CMMC environment. 

What this doesn’t mean 

This CMMC Level 2 certification is about the security of GBI’s information system. It is not a claim that GBI generates, stores, or transmits classified information or CUI on behalf of every client, and it doesn’t replace a client’s own CMMC obligations if they are a DoD contractor in their own right. It simply means that when GBI does handle CUI, our systems meet a rigorous, independently assessed standard. 

What to do next 

Certification bodies ask building owners to trust them with real project data. GBI’s CMMC Level 2 status demonstrates that our standards meet the same rigor around data security that we ask certified buildings to meet around performance data. 

If you’re working on a federal facility and evaluating certification partners, we’re here to help you find the right solution. Schedule a time to speak with one of the experts on our team for free. Talk to a specialist.

Explore Guiding Principles Compliance

Third-party building assessment program designed specifically for federal agencies to evaluate compliance with the federal Guiding Principles.

Learn More

Speak with a GBI specialist

we’re here to help you find the right solution. Schedule a time to speak with one of the experts on our team for free

Speak with our team