NEWS
The CMMC Pause Receives Recommendations
|
On July 13, The U.S. Department of Defense (DoD) issued an indefinite suspension of Phase II of its Cybersecurity Maturity Model Certification (CMMC) framework, pending a 60-day review period. At the time, the DoD issued a statement stressing that the cyber-readiness and reliability goals of the CMMC had not changed; it merely sought to review the potentially severe burden the current framework might place on small-to-midsized defense contractors, subcontractors, and suppliers.
On August 17, the Office of Advocacy formally submitted its recommendations to the DoD probe: namely, to more realistically scale and financially support the transition from Phase I to Phase II, allowing smaller contractors an easier path to certification. To date, no official or government body has suggested backing off the CMMC entirely—the safeguarding of sensitive U.S. data (such as military information) is seen as vital for national security. Nevertheless, there are worrying signs that defense contractors, whether prime or sub, are mistaking the temporary suspension for permanent relief.
IMPACT
Smaller Defense Contractors Are Deferring Essential Investments
|
When pushing back on CMMC Phase II, many defense manufacturers cited cost as a key issue. Securing Phase II compliance means undergoing a third-party audit from a Certified Third-Party Assessment Organization (C3PAO). In addition to stating that the number of C3PAOs was too low, the Small Business Administration pushed back on investment costs, saying that Phase II certification would cost roughly US$500,000. Cybersecurity experts have pushed back, stating the assessment itself cost less than US$100,000. The issue is that certain defense contractors are compounding additional investments, such as the cost of software implementation and employee readiness.
Data support this claim. An alarming number of prime contractors have yet to make the appropriate investments regarding CMMC readiness, and this issue worsens when applied to subcontractors and suppliers. Many contractors report their engineering data, or Controlled Unclassified Information (CUI), are not secured, a crucial step that must happen before an audit takes place. Additionally, defense manufacturers—especially smaller ones—struggle with the National Institute of Standards and Technology (NIST), as they lack the appropriate in-house expertise to navigate its nuances and complexities.
This adoption or readiness problem is echoed across manufacturing in dozens of scenarios and with numerous digital transformation technologies such as digital twins, the industrial metaverse, and Artificial Intelligence (AI). The issue is not really the final technology itself, it is a lack of prepared infrastructure. In the Manufacturing Execution System (MES) space right now, for instance, providers are having to pivot from talking about AI capabilities to the importance of contextualized data. Why? The foundation is not there. Defense contractors are in a similar position.
RECOMMENDATIONS
Proactive Defense Contractors Have a Giant Competitive Opening
|
Harsh reality is coming for those defense contractors counting on the DoD to either pay the entire cost of cyber readiness or perpetually delay the CMMC or whatever cybersecurity standard follows. However, for those in defense that are more proactive, a key competitive opportunity is emerging. Defense contractors will lose business if they do not comply within the appropriate timeline, and the majority are very aware of this fact. This means newly available contracts and income for those contractors realistic enough to realize that the CMMC—or something quite like it—is inevitable.
There have already been reports of defense contractors cancelling appointments with C3PAOs. This is short-sighted business and a direct way to remove themselves from future (and existing) defense contracts. For those contractors that have already received or have yet to cancel their audit, this certification should be front and center. Cybercrime is only going to escalate in the age of AI, and any defense contractor attempting to perpetually get out of cybersecurity spending and investments will remove themselves from contract competition.
It is also crucial to remember that the CMMC is not the only new standard pushing defense contractors forward. There are numerous projects occurring worldwide that are accelerating the shift toward digital infrastructure adoption in defense, such as the Joint All-Domain Command and Control (JADC2) initiative. Such programs require investment in software-defined systems and deterministic connectivity throughout every new system (for more information, please see ABI Research’s Operational Technology Ethernet in Defense and Military report (AN-6596). Effective investment and innovation are essential for defense and, for proactive contractors working with and adjacent to the DoD, 2027 will likely mark a year of heightened growth potential.