Ocean Power Technologies Clears Pentagon Cybersecurity Threshold, Positioning for Expanded Federal Work
Ocean Power Technologies achieves CMMC Level 2 compliance, meeting DoD cybersecurity standards required for sensitive defense contracts.
Ocean Power Technologies (OPT), a developer of ocean-based power and data systems for defense and maritime applications, has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2 compliance, the company announced. The certification, verified through a third-party assessment organization, confirms that OPT’s information systems meet the 110 security practices outlined in the National Institute of Standards and Technology’s Special Publication 800-171 — a baseline the Department of Defense has increasingly required of companies handling controlled unclassified information. As the Pentagon accelerates its integration of autonomous and unmanned maritime platforms, meeting these standards is becoming a threshold requirement rather than a competitive differentiator, a trend that intersects with broader unmanned systems expansion across the services.
According to OPT’s announcement, the certification positions the company to compete for and retain contracts involving controlled unclassified information, a category that spans a significant portion of defense acquisition work. CMMC Level 2 sits at the intermediate tier of the DoD’s three-level framework, applying to contractors whose work touches sensitive but unclassified defense data. Companies operating below that threshold face growing risk of disqualification from new contract awards as the DoD phases in mandatory certification requirements across its supply chain.

Where OPT Operates Within the Defense Ecosystem
OPT’s core product portfolio centers on its PowerBuoy platform — autonomous, wave-powered systems designed to provide persistent power and communications capability at sea without the logistical burden of crewed vessels or conventional fuel supply chains. The company has pursued defense customers in areas including undersea domain awareness, unmanned surface and subsurface operations, and long-duration maritime surveillance. Those mission sets have drawn increased Pentagon attention as competition for ocean-domain presence intensifies, particularly in the Indo-Pacific.
The CMMC achievement is notably procedural rather than technological, but its operational implications are direct: without it, OPT would be ineligible to handle the categories of defense data that accompany most serious military contracts. The certification process required OPT to implement and document controls across access management, incident response, system integrity, and audit practices, among other domains. The company stated that an accredited third-party assessment organization conducted the evaluation, satisfying the independent verification requirement the DoD now mandates at Level 2.

Broader Implications for Small Defense Contractors
OPT’s move reflects a wider compliance pressure building across the defense industrial base. The DoD’s CMMC rule, which became effective in December 2024 after years of development and revision, is being incorporated into contracts on a rolling basis. Small and mid-size contractors — precisely the segment where many advanced maritime and unmanned technology developers sit — have faced the steepest compliance burden, given limited internal cybersecurity resources compared with large prime contractors.
For companies in OPT’s tier, achieving Level 2 certification signals operational seriousness to program offices and prime contractors alike. It also reduces the legal exposure associated with self-attestation, the previous standard that allowed contractors to assert compliance without independent verification. As the DoD continues expanding requirements for persistent maritime surveillance capabilities and long-endurance unmanned systems — domains where smaller innovators often lead development — the ability to handle controlled data securely is becoming inseparable from the ability to compete. The convergence of cybersecurity compliance and defense technology development is reshaping which companies can realistically pursue federal maritime contracts in the years ahead, a dynamic that extends well beyond any single certification milestone.
