Cybersecurity Maturity Model Certification (CMMC) has become one of the most buzzworthy topics in the NTMA community as of late, and for good reason.
Everyone seems to have their own opinions and assumptions about the program. Some members credit their early adoption of CMMC for their success in winning bids with major OEMs they’ve been after for years. Others are more dismissive, assuming that CMMC only applies to large defense contractors.
To help separate fact from fiction, we caught up with Allison Giddens, Co-President of Win-Tech. Allison works closely with manufacturers navigating cybersecurity requirements and sees many of the same misunderstandings repeated throughout the industry.
Here are some of the major takeaways:
Common Misconception: “CMMC only applies to large defense contractors.”
According to Allison, “While prime contractors often receive the most attention, CMMC requirements ultimately flow through the defense supply chain.”
If your company receives Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), you may eventually be required to meet CMMC requirements, even if you’ve never signed a contract directly with the Department of Defense. Machine shops that work with export-controlled data, ITAR-regulated programs, or engineering drawings containing distribution statements should pay close attention.
In other words, many manufacturers are already handling sensitive information without realizing that cybersecurity requirements may soon be “coming to a purchase order near you.”
Common Misconception: “CMMC doesn’t apply if I don’t have direct contracts with the DoD.”
Many manufacturers handle work for prime contractors, subcontractors, distributors, or other suppliers rather than contracting directly with the government. Cybersecurity obligations can flow through multiple tiers of the supply chain, depending on the contractual requirements and the type of information being shared.
All that is to say, the determining factor isn’t who sends your purchase order, it’s whether you’re receiving information that requires protection.
If you’re unsure whether cybersecurity clauses apply to your work, don’t guess. “I encourage you to have conversations with your customer if you believe you’re receiving CMMC-related flow-down that shouldn’t apply,” Allison says. “Ask questions in a way that shows the customer you’re paying attention, and you want to do what’s both right (for your legal compliance) and efficient for the sake of getting them what they need.”
Common Misconception: “CMMC will impact my shop, but not my supply chain at large.”
Allison explains, “A typical aerospace or defense manufacturer relies on dozens, sometimes hundreds, of external suppliers. Heat treaters, platers, painters, special processors, NDT providers, testing laboratories, calibration providers, engineering firms, and subcontract machine shops may all touch information that customers classify as CUI.”
As manufacturers achieve CMMC compliance, they begin evaluating whether their suppliers can adequately protect sensitive data. If your suppliers aren’t prepared, it could affect your ability to fulfill customer requirements.
One helpful starting point is evaluating what information you’re sharing externally. If you’re sharing FCI or CUI with your supply chain, consider surveying key suppliers about their compliance with existing DFARS cybersecurity requirements. And, as Allison puts it, “brace yourself” for your possible response.
Common Misconception: “We can wait until a customer requires it.”
Like many things in life, when you put something off until the last minute, it becomes a scramble to get it done.
“Implementing cybersecurity controls, documenting policies, establishing procedures, training employees, addressing technical gaps, and preparing for assessments takes significant time,” Allison explains. “Most organizations cannot accomplish this overnight, no matter how ‘ready’ you may think you are. This isn’t an ISO 9001 or AS9100 assessment, trust me!”
Even with the temporary pause to mandatory CMMC Level 2 implementation, the underlying cybersecurity obligations haven’t disappeared. Existing DFARS requirements, NIST SP 800-171, and the responsibility to adequately safeguard sensitive information remain in place for many defense contractors.
“The pause shouldn’t be interpreted as a reason to stop progress,” Allison says. “If anything, it gives manufacturers an opportunity to prepare without the pressure of an immediate assessment. Keep moving forward as if you were getting an assessment. Organizations that continue improving their cybersecurity today will be in a much stronger position regardless of how the program ultimately evolves.”
Common Misconception: “CMMC is something that’s happening to us.”
There’s no denying that CMMC is a major undertaking, and something that adds complexity to contract manufacturers’ place in the supply chain. Even though there’s plenty on your plate as is, Allison encourages manufacturing companies to “talk to peers and find out who they have brought on board to help them with security and compliance. Get references and don’t just jump at the first company you get an email from with promises too good to be true.”
You’re not the first person to navigate CMMC and you certainly won’t be the last. Plenty of NTMA members have successfully navigated the steps and procedures needed to achieve Level 1 and 2 compliance. We encourage you to tap into your NTMA community to find out what has worked best and what to avoid.
Common Misconception: “CMMC is just an IT project.”

CMMC implementation should involve participation across the organization.
- Leaders establish priorities.
- Operations and production teams help protect sensitive information throughout manufacturing processes.
- Quality teams help document procedures and maintain compliance.
- Purchasing evaluates supplier risk.
- Human resources supports employee training.
“Cybersecurity is ultimately a business process issue, not simply a technology issue,” Allison says.
Common Misconception: “We’re too small to be targeted.”
This is certainly not the case. According to Allison, “Threat actors often target smaller companies specifically because they tend to have fewer security resources and can serve as pathways into larger organizations.”
Common Misconception: “If it isn’t marked as CUI, it isn’t CUI.”
Marking practices aren’t always consistent throughout the defense supply chain. If you receive information you’re unsure about, don’t make assumptions; ask your customer for clarification.
Common Misconception: “Certification is the finish line.”
Is it worth celebrating achieving this milestone? Certainly! But is the work done? Absolutely not.
Cybersecurity requires continuous improvement as threats evolve, technologies advances, personnel changes, and compliance requirements continue to mature. Not only does it take effort to maintain compliance, but companies also need to affirm compliance on a regular basis. Also, Allison notes, “There is an updated revision to NIST 800-171 (what CMMC is built on), so it’s likely we’ll see a revised version of the program within a few years.”
Common Misconception: “The CMMC pause means we should stop preparing.”
The recent pause to mandatory CMMC Level 2 implementation has caused some manufacturers to question whether they should continue investing in cybersecurity.
Allison cautions against viewing the pause as a signal that cybersecurity expectations are going away. “The Department of War has repeatedly stated that protecting Federal Contract Information and Controlled Unclassified Information remains a priority,” she explains. “Whether the timeline changes or the program is refined, manufacturers that continue improving their security posture won’t regret the investment. You don’t want to be the slowest person running from the grizzly bear.”
Others in the industry also expect that a third-party assessment, or something very similar, will ultimately become the standard for companies handling CUI. Organizations that stay the course are likely to be better positioned than those who wait until requirements reappear.
Common Misconception: “We should treat everything like CUI to be safe.”
Manufacturers should never designate CUI based solely on assumptions. Allison advises, “When in doubt, talk to your customer. I can’t stress that enough: Communicate!”
The manufacturers that approach CMMC proactively and collaboratively will be in a much stronger position than those who wait until requirements suddenly appear in a purchase order.
Looking Ahead at What’s Next
While the implementation timeline for CMMC continues to evolve, manufacturers shouldn’t lose sight of the larger picture.
An independent cybersecurity assessment can provide valuable evidence that your organization took reasonable steps to protect sensitive information. In an era of increasing cybersecurity enforcement, False Claims Act investigations, and whistleblower actions, demonstrating due diligence may prove just as valuable as earning a certification.
“Think of it like insurance,” Allison says. “None of us hope we’ll ever need to defend the cybersecurity decisions we’ve made, but having an independent assessment demonstrates that you took your obligations seriously. It’s a lot easier to focus on manufacturing if the threat of someone coming to make sure you’re not lying about compliance is not a risk.”
Even if CMMC Level 2 is temporarily paused, many in the defense industrial base still expect independent assessments to become the long-term baseline for organizations handling Controlled Unclassified Information. Companies that continue building mature cybersecurity programs today will likely find themselves ahead of the curve when the next phase of implementation arrives.
Remember, CMMC may feel like a significant undertaking, but you don’t have to navigate it alone. By leveraging your network and starting the conversation today, your organization can build a stronger cybersecurity foundation for the future.