News · August 24, 2026

Lastwall Clears CMMC Level 2 — While Washington Has the Program on Pause

The identity-security firm headquartered at Fredericton's Knowledge Park Cyber Centre passed an independent C3PAO assessment against 110 NIST 800-171 controls — six weeks after the Pentagon suspended the phase that would have made that assessment mandatory.

By NB Tech News Staff · 5 min read

Abstract checklist and lock on a dark green field marking a third-party cybersecurity assessment

Lastwall has a new procurement receipt, and it went and got it during a pause. In an August 20 release carrying a Fredericton dateline, the identity-security company headquartered at Knowledge Park's Cyber Centre said it earned Cybersecurity Maturity Model Certification Level 2 after an independent third-party assessment — the bar U.S. defence contractors need to handle Controlled Unclassified Information.

It does not replace the May $16-million StrongNorth round. It is the compliance step that raise was meant to support.

What Level 2 actually is

CMMC Level 2 is not a logo a vendor prints itself. Lastwall's release says a Certified Third-Party Assessment Organization (C3PAO) verified implementation of 110 security controls aligned with NIST SP 800-171 — Revision 2, the version the CMMC program still assesses against, not the newer Rev. 3. That is the control set for protecting CUI on non-federal systems. Federal Contract Information sits in the same framing at a lower bar.

The distinction that matters is who checked. Level 2 comes in two flavours: a self-assessment the contractor scores itself, and a certification assessment run by an accredited outside firm. Lastwall took the second one. Under the program rules, a C3PAO assessment can also close as a Conditional status — controls outstanding, a plan of action, 180 days to finish — before it converts to Final. The release does not say which one Lastwall holds, and that is the one number missing from an otherwise dated, specific announcement.

Certified into a suspended program

Here is the context the announcement soft-pedals. On July 13, 2026, the Pentagon suspended Phase 2 of the CMMC rollout — the phase that would have made exactly this kind of third-party certification a condition of contract award for CUI work starting November 10, 2026. DoD CIO Kirsten Davies signed the memo; a CMMC Reform Task Force got 60 days to review the program, and Phases 3 and 4 went on hold with it. Phase 1 — self-assessments, SPRS scores, annual affirmations — stayed in force.

So the mandate Lastwall just cleared is, for now, not a mandate. The company's own release nods at it: "While the Department of Defense continues refining implementation of the CMMC program, the need for independently validated cybersecurity has never been greater," it reads, arguing contractors should certify "ahead of regulatory deadlines — not because they're required to, but because mission success depends on them."

That is marketing language wrapped around a real bet. If the task force restores third-party certification, Lastwall is already through a queue that will get long. If Phase 2 never comes back in its old form, the company spent an assessment cycle on a credential its competitors skipped — and still gets to point at an independent audit no self-attestation matches.

Holmqvist's line

Founder and CEO Karl Holmqvist, in the release: "Security isn't something organizations should build only to satisfy regulatory requirements — it's something that must be embedded into every system from day one. Achieving CMMC Level 2 reflects years of investment in security-first engineering and independently validates the standards our customers rely on every day."

The rest of the stack

CMMC lands on a compliance shelf Lastwall has been stacking for years. The company already held FedRAMP Moderate Authorization when it raised in May — the civilian-agency counterpart to CMMC's defence-industrial-base scope. The release adds two items our earlier coverage did not have: U.S. DoD Impact Level 2 (IL2) compliance with IL4 in progress, and adherence to the NIST SP 800-53/63 control sets. IL4 is the higher bar for hosting CUI in DoD cloud environments; "in progress" is the honest label for it.

The release also dates the defence relationship to 2017 and names the customer as the "U.S. Department of War" — the department's current name. Our May coverage traced that same 2017 start to the Defense Innovation Unit. The Government of Canada remains a customer.

Why it matters in Fredericton

The May raise, led by BDC Capital's StrongNorth Fund with NBIF's largest-ever cheque, was pitched as bringing a U.S.-proven platform home to Canadian critical infrastructure. CMMC Level 2 is the other direction of the same bet: a Cyber Centre tenant staying eligible for the U.S. defence supply chain while that Canadian expansion is still being built.

On the recurring question of how New Brunswick this company is, the release settles more than argument does — it went out on a Fredericton, NB dateline. The fuller history is in ONB's January 2023 account: incorporated in 2014 after Holmqvist returned to Canada from the Middle East and teamed with CTO Troy Nelson; Hawaii's Elemental Excelerator in 2016; first real commercial win with the U.S. defence department; head office into the Cyber Centre in May 2022. Holmqvist himself lives in Vancouver, and the company still lists Honolulu and Vancouver offices alongside Fredericton on its careers board, where on-site Fredericton engineering roles are live. Proved in the U.S. federal market, then planted headquarters and growth here — that is the accurate version, and it is the one the company tells.

It is a process milestone, not a customer announcement. The next public proofs are still procurement ones — contracts that rarely make releases. But a dated, independently assessed certification, obtained while the program that demands it is under review, is the kind of receipt Fredericton's security cluster actually produces.

Sources

Related coverage

Tags: lastwall, fredericton, cybersecurity, cmmc, defence