Cybersecurity Maturity Model Certification (CMMC) has become one of the most buzzworthy topics in the NTMA community as of late, and for good reason.
Everyone seems to have their own opinions and assumptions about the program. Some members credit their early adoption of CMMC for their success in winning bids with major OEMs they’ve been after for years. Others are more dismissive, assuming that CMMC only applies to large defense contractors.
To help separate fact from fiction, we caught up with Allison Giddens, Co-President of Win-Tech and Nominations Chair for the CMMC-AB Industry Advisory Group. Allison works closely with manufacturers navigating cybersecurity requirements, and sees many of the same misunderstandings repeated throughout the industry.
Here are some of the major takeaways:
Common Misconception: “CMMC only applies to large defense contractors.”
According to Allison, “While prime contractors often receive the most attention, CMMC requirements ultimately flow through the defense supply chain.”
If your company receives Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), you may eventually be required to meet CMMC requirements, even if you’ve never signed a contract directly with the Department of Defense. Machine shops that work with export-controlled data, ITAR-regulated programs, or engineering drawings containing distribution statements should pay close attention.
In other words, many manufacturers are already handling sensitive information without realizing that cybersecurity requirements may soon be “coming to a purchase order near you.”
Common Misconception: “CMMC doesn’t apply if I don’t have direct contracts with the DoD.”
Many manufacturers handle work for prime contractors, subcontractors, distributors, or other suppliers rather than contracting directly with the government. Cybersecurity obligations can flow through multiple tiers of the supply chain, depending on the contractual requirements and the type of information being shared.
All that is to say, the determining factor isn’t who sends your purchase order, it’s whether you’re receiving information that requires protection.
If you’re unsure whether cybersecurity clauses apply to your work, don’t guess. “I encourage you to have conversations with your customer if you believe you’re receiving CMMC-related flow-down that shouldn’t apply,” Allison says. “Ask questions in a way that shows the customer you’re paying attention, and you want to do what’s both right (for your legal compliance) and efficient for the sake of getting them what they need.”
Common Misconception: “CMMC will impact my shop, but not my supply chain at large.”
Allison explains, “A typical aerospace or defense manufacturer relies on dozens, sometimes hundreds, of external suppliers. Heat treaters, platers, painters, special processors, NDT providers, testing laboratories, calibration providers, engineering firms, and subcontract machine shops may all touch information that customers classify as CUI.”
As manufacturers achieve CMMC compliance, they begin evaluating whether their suppliers can adequately protect sensitive data. If your suppliers aren’t prepared, it could affect your ability to fulfill customer requirements.
One helpful starting point is evaluating what information you’re sharing externally. If you’re sharing FCI or CUI with your supply chain, consider surveying key suppliers about their compliance with existing DFARS cybersecurity requirements. And, as Allison puts it, “brace yourself” for your possible response.
Common Misconception: “We can wait until a customer requires it.”
Like many things in life, when you put something off until the last minute, it becomes a scramble to get it done.
“Implementing cybersecurity controls, documenting policies, establishing procedures, training employees, addressing technical gaps, and preparing for assessments takes significant time,” Allison explains. “Most organizations cannot accomplish this overnight, no matter how ‘ready’ you may think you are. This isn’t an ISO 9001 or AS9100 assessment, trust me!”
Even with the temporary suspension of CMMC Level 2, organizations that strengthen their cybersecurity now will be in a much better position regardless of how the program ultimately evolves. Because, as Allison puts it, “Cybersecurity maturity is built over months and years, not weeks.”
Common Misconception: “CMMC is something that’s happening to us.”
There’s no denying that CMMC is a major undertaking, and something that adds complexity to contract manufacturers’ place in the supply chain. Even though there’s plenty on your plate as is, Allison encourages manufacturing companies to “talk to peers and find out who they have brought on board to help them with security and compliance. Get references and don’t just jump at the first company you get an email from with promises too good to be true.”
You’re not the first person to navigate CMMC and you certainly won’t be the last. Plenty of NTMA members have successfully navigated the steps and procedures needed to achieve Level 1 and 2 compliance. We encourage you to tap into your NTMA community to find out what has worked best and what to avoid.
Common Misconception: “CMMC is just an IT project.”

CMMC implementation should involve participation across the organization.
- Leaders establish priorities.
- Operations and production teams help protect sensitive information throughout manufacturing processes.
- Quality teams help document procedures and maintain compliance.
- Purchasing evaluates supplier risk.
- Human resources supports employee training.
“Cybersecurity is ultimately a business process issue, not simply a technology issue,” Allison says.
Common Misconception: “We’re too small to be targeted.”
This is certainly not the case. According to Allison, “Threat actors often target smaller companies specifically because they tend to have fewer security resources and can serve as pathways into larger organizations.”
Common Misconception: “If it isn’t marked as CUI, it isn’t CUI.”
Marking practices aren’t always consistent throughout the defense supply chain. If you receive information you’re unsure about, don’t make assumptions; ask your customer for clarification.
Common Misconception: “Certification is the finish line.”
Is it worth celebrating achieving this milestone? Certainly! But is the work done? Absolutely not.
Cybersecurity requires continuous improvement as threats evolve, technologies advances, personnel changes, and compliance requirements continue to mature. Not only does it take effort to maintain compliance, but companies also need to affirm compliance on a regular basis. Also, Allison notes, “There is an updated revision to NIST 800-171 (what CMMC is built on), so it’s likely we’ll see a revised version of the program within a few years.”
Common Misconception: “We should treat everything like CUI to be safe.”
Manufacturers should never designate CUI based solely on assumptions. Allison advises, “When in doubt, talk to your customer. I can’t stress that enough: Communicate!”
The manufacturers that approach CMMC proactively and collaboratively will be in a much stronger position than those who wait until requirements suddenly appear in a purchase order.
Remember, CMMC may feel like a significant undertaking, but you don’t have to navigate it alone. By leveraging your network and starting the conversation today, your organization can build a stronger cybersecurity foundation for the future.