
SAN JOSE, CA — June 1, 2026 — Naprotek, LLC, an electronics manufacturing services (EMS) provider specializing in high-reliability and regulated markets, today announced it has achieved Cybersecurity Maturity Model Certification (CMMC) 2.0 Level 2, reflecting the company's sustained investment in cybersecurity and protection of sensitive customer information. The certification extends to SemiGen, Naprotek's RF Assembly & Components Center of Excellence.
CMMC Level 2 is among the most demanding cybersecurity standards applied to the Defense Industrial Base (DIB), requiring organizations to implement and demonstrate adherence to all 110 security controls outlined in NIST Special Publication 800-171 Revision 2. Independent third-party assessment confirms that Naprotek's information environment meets the requirements established by the Department of Defense (DoD) for organizations handling Controlled Unclassified Information (CUI).
"Cybersecurity is foundational to the trust our defense customers place in us," said Tim Filteau, President and CEO of Naprotek and SemiGen. "This certification is the product of a sustained, company-wide commitment to the people, processes, and infrastructure needed to protect controlled unclassified information. We're proud to give our customers across both Naprotek and SemiGen confidence that their data and programs are in accountable hands."
For prime contractors and program offices managing cybersecurity compliance across their supplier networks, Naprotek and SemiGen's certified environment is designed to reduce supply chain risk and simplify onboarding for defense programs with CMMC requirements. Customers and procurement teams are encouraged to contact us directly to update supplier security questionnaires and compliance documentation.
As CMMC requirements become standard across the DIB, Naprotek and SemiGen are prepared to support the evolving cybersecurity demands of their defense customers with confidence and accountability. This certification adds to an existing portfolio of quality and compliance credentials including ISO 9001, AS9100D, ISO 13485, and ITAR registration and reinforces both companies' position as trusted manufacturing partners for mission-critical programs.
On September 3, 2026, the Department of War (Department of Defense) issued DARS Class Deviation 2026-O0025, Revision 3. The memo doesn't create a new CMMC policy. It carries forward the Department's July 13, 2026 decision to pause the move to CMMC Phase 2 requirements. Contractors that handle Controlled Unclassified Information (CUI) still have to meet NIST SP 800-171 under DFARS 252.204-7012.
What this means for Naprotek and Semigen customers
The Phase 2 pause doesn't change our standing or our commitment. Naprotek, including its Semigen RF & microwave division, remains CMMC Level 2 certified. The controls that protect your CUI, technical data and program information are still fully in place and are reviewed on an ongoing basis.
Deadlines may shift, but the requirements are still important. Our certification already meets the CMMC cybersecurity standards and demonstrates our proof of adherence so defense customers can work with us without any added compliance risk.