Nobody Is Checking Your Homework Anymore. That Should Worry You.

What the CMMC Phase II suspension actually changed for manufacturers — and what it quietly did not. 

In the middle of July, the Department of War announced that it was suspending Phase II of the Cybersecurity Maturity Model Certification program, and for a good number of manufacturers the news arrived as something close to relief. The requirement that had been looming over the defense supply chain for years — that a third-party assessor would eventually have to come in, examine your environment, and certify that you had implemented the controls you claimed to have implemented — was set aside while the Department convened a task force to review the whole program. A lot of the frantic energy around resourcing and preparation slowed down. More than a few owners we work with told us, with understandable relief, that the pressure was off. 

We would like to offer a less comfortable reading of the same event, because we think the relief is misplaced, and because the reasoning behind it is worth walking through carefully rather than dismissing. 

What actually paused, and what did not 

The suspension applies to the certification step. Contracting officers have been directed to include only self-assessment requirements in new solicitations while the review is underway, which means that the third-party assessment organizations everyone had been preparing for are, for the moment, out of the contract path. 

Almost nothing else changed. The underlying contract clause that obligates you to safeguard controlled unclassified information is still in force, and it always operated independently of the certification program. You are still expected to implement the security controls described in the federal standard. You are still expected to assess yourself against those controls, post the resulting score to the government's supplier portal, and affirm annually that the score is accurate. That affirmation is still signed by a named senior official at your company, who is personally attesting to its truth. The obligation to flow these requirements down to your own suppliers has not moved either, and neither have the expectations your primes have already written into their supplier agreements. 

So the process changed, but the expectations around controlled unclassified information did not. 

The part that makes this more dangerous rather than less 

Here is the shift that we think deserves more attention than it has received. Under the model everyone was preparing for, the assessor was, among other things, a safety net. If your documentation described a configuration you had never actually deployed, or if your score reflected optimism rather than measurement, an assessor was going to find that in a conference room, tell you about it, and give you a chance to fix it before it became a problem with legal consequences. 

Take that step away and the self-assessment stands entirely on its own. The score you post is a representation to the federal government made in connection with a contract you are being paid to perform, and the only party in a position to check your arithmetic is now the Department of Justice. 

That is not a hypothetical concern. In July, a defense contractor called LOGZONE settled with the Justice Department for a little over half a million dollars. The company had reported a perfect score of 110 to the government's supplier portal, indicating full implementation of every required control. When the Defense Contract Management Agency looked at the actual environment, it calculated the real score at negative 170, on a scale where negative 203 is the floor. There was no breach and no customer was harmed in any way that anyone has described publicly. The entire matter came down to the distance between a number the company had reported and the reality of the systems behind it, sustained over several years of invoices. 

For a company that has been treating its self-assessment as a formality, that is a genuinely uncomfortable precedent, and the suspension of Phase II does nothing to soften it. If anything, it removes the one checkpoint that might have caught the discrepancy while it was still an operational problem rather than a legal one. 

Where this gets specific for manufacturers 

The reason we keep returning to this with our own clients is that the gap between the paperwork and the reality tends to open up in places that are easy to overlook, and manufacturing environments have more of those places than most. 

If you run a job shop of any complexity, the sensitive information you have committed to protect is rarely confined to email and a file server, which is where most compliance conversations begin and end. It has a way of living in the systems where the work actually happens: in drawings attached to a job, in the routings and travelers that move through the shop, in engineering revisions, in inspection records and quality documents, in the part numbers and specifications that appear on a work order. Which is to say that a meaningful share of it tends to live in the ERP, and in everything connected to it. 

For the manufacturers we support who run Global Shop Solutions, this is a conversation we have been having for some time, and it is more interesting than it first appears. The question of whether the ERP sits inside or outside your protected boundary is not a small architectural detail to be settled later. It shapes almost everything downstream. Bring the ERP inside and you have also brought in the shop floor terminals, the barcode scanners, the label printers, the data collection devices, and every report that reads from the database. Leave it outside and you have taken on the obligation to demonstrate, in a way that would survive scrutiny, that sensitive information never lands there in the first place — which is a harder thing to prove than most people expect when they first consider it. 

Neither answer is wrong. Plenty of shops are well served by keeping the ERP outside a tightly drawn boundary, and plenty of others find that the operational friction of doing so costs more than the alternative. What tends to go badly is when the decision is made implicitly, by whoever happened to be scoping the project, without anyone tracing where the information actually flows on an ordinary Tuesday. 

What we would do with the time 

The most useful way to think about the current moment is that the Department has handed the industry an unscheduled and (probably) temporary window. The review is underway, the comment period has closed, and something will come out the other side. Whatever that something turns out to be, it is difficult to imagine a version of it that does not still expect you to know where your sensitive information lives and to control who can reach it. Those requirements have survived every revision of this program so far, and they are the expensive part anyway. The C3PAO-validated certificate was always just the wrapper. 

So the companies we think are handling this well are the ones who never took their feet off the gas, on the theory that the work is the same either way and it is considerably cheaper to do it deliberately over eighteen months than urgently over three. They are also, not incidentally, the companies that can answer a prime's supplier questionnaire this quarter without a scramble, because primes have their own timelines and have shown no particular interest in waiting for the Pentagon to sort this out. 

If it has been a while since anyone traced where sensitive information actually travels through your business — through the ERP, through the shop floor, through the systems your team touches every day without thinking about it — that is the exercise worth doing while the pressure is low. It is a far better conversation to have now, with time to make thoughtful decisions, than in response to a letter. 

 

Upward Technology supports manufacturers across the country, with Certified CMMC Professionals on staff and secure enclave deployments currently in progress. We are also the only Preferred IT Services partner of Global Shop Solutions. If you would like a second set of eyes on where your compliance scope actually begins and ends, we would welcome the conversation. 

www.upward-technology.com

 

 
 
 

Related Posts