WASHINGTON – The costs and burdens of compliance with the Cybersecurity Maturity Model Certification (CMMC) may force some US electronics suppliers out of the Department of Defense’s supply chain, a new survey says.
The report from IPC also finds that for many small- to medium-size businesses (SMB), the costs and burdens of CMMC compliance may outweigh the benefits of doing business with the DoD.
Some 24% of responding companies said they may leave the DoD vendor lists, according to the survey, which was conducted between Feb. 25 and Mar. 5 and garnered 108 responses from contract manufacturers, printed circuit board fabricators, original equipment manufacturers and suppliers who self-reported they are planning to undergo a CMMC assessment in the next five years. In addition, 33% of respondents say the CMMC will weaken the US defense electronics industrial base, while 18% are unsure, highlighting the uncertainties involved. And 41% believe applying the CMMC clause to their suppliers will create other problems in the supply chain.
“Cybersecurity is a must for U.S. national security, but the costs and burdens of achieving CMMC compliance under the current approach will likely force many small and medium-sized manufacturers out of the DoD supply chain, negatively impacting national security,” said John Mitchell, president and CEO, IPC. “The objectives of CMMC are well-intentioned, but they must not be achieved at the expense of other key aspects of supply chain health.”
Most suppliers expect and are willing to spend upwards of $50,000 on CMMC readiness, and nearly one-third (32%) report that it will take them one to two years to prepare to undergo CMMC assessment. However, more than half of the suppliers say implementation costs of more than $100,000 would make CMMC readiness too expensive. DoD’s own cost analysis estimated the cost of a CMMC Maturity Level 3 (ML3) certification to be more than $118,000 in the first year. This means DoD’s own estimate of CMMC compliance costs is too high for 77% of the IPC survey respondents.
“The Pentagon needs to take into consideration that most SMBs do not have dedicated cybersecurity personnel to achieve the prerequisites, and while many commercial electronics manufacturers have considerable business with the defense community, they themselves do not consider themselves a defense contractor,” added Mitchell.
The study’s author, cyber security expert Leslie Weinstein, says the DoD can reduce the costs and uncertainties of CMMC compliance by leveraging existing industry standards and certifications, such as IPC-1791, the electronics industry’s “Trusted Supplier” standard, which was designed in collaboration with the DoD; or the certifications offered by HITRUST or the International Standards Organization.
“The DoD recognizes a variety of respected, industry-driven certifications when it comes to hiring cybersecurity professionals,” says Weinstein. “Taking the same approach to certifying suppliers would allow companies to invest more in security than in redundant audits, and it would quickly create a pool of companies who are able to bid on DoD solicitations containing the CMMC DFARS clause. And importantly, it would prevent further erosion of the US defense industrial base.”
See related article on the Defense supply base here.