Reading time ( words)
In a new IPC industry survey and report, one-quarter (24 percent) of electronic manufacturers say the costs and burdens of compliance with the Cybersecurity Maturity Model Certification (CMMC) may force them out of the U.S. Department of Defense’s (DoD) supply chain.
The survey conducted by IPC, the global electronics manufacturing association, also finds that for many small- to medium-size businesses (SMB), the costs and burdens of CMMC compliance may outweigh the benefits of doing business with the DoD.
In addition, 33 percent of respondents say the CMMC will weaken the U.S. defense electronics industrial base, while 18 percent are unsure, highlighting the uncertainties involved. And 41 percent believe applying the CMMC clause to their suppliers will create other problems in the supply chain.
“Cybersecurity is a must for U.S. national security, but the costs and burdens of achieving CMMC compliance under the current approach will likely force many small and medium-sized manufacturers out of the DoD supply chain, negatively impacting national security,” said John Mitchell, IPC president and CEO. “The objectives of CMMC are well-intentioned, but they must not be achieved at the expense of other key aspects of supply chain health.”
Most suppliers expect and are willing to spend upwards of $50,000 on CMMC readiness, and nearly one-third (32 percent) report that it will take them one to two years to prepare to undergo CMMC assessment. However, more than half of the suppliers say implementation costs of more than $100,000 would make CMMC readiness too expensive. DoD’s own cost analysis estimated the cost of a CMMC Maturity Level 3 (ML3) certification to be more than $118,000 in the first year. This means DoD’s own estimate of CMMC compliance costs is too high for 77 percent of the IPC survey respondents.
“The Pentagon needs to take into consideration that most SMBs do not have dedicated cybersecurity personnel to achieve the prerequisites, and while many commercial electronics manufacturers have considerable business with the defense community, they themselves do not consider themselves a defense contractor,” added Mitchell.
The study’s author, cyber security expert Leslie Weinstein, says the DoD can reduce the costs and uncertainties of CMMC compliance by leveraging existing industry standards and certifications, such as IPC-1791, the electronics industry’s “Trusted Supplier” standard, which was designed in collaboration with the DoD; or the certifications offered by HITRUST or the International Standards Organization.
“The DoD recognizes a variety of respected, industry-driven certifications when it comes to hiring cybersecurity professionals,” says Weinstein. “Taking the same approach to certifying suppliers would allow companies to invest more in security than in redundant audits, and it would quickly create a pool of companies who are able to bid on DoD solicitations containing the CMMC DFARS clause. And importantly, it would prevent further erosion of the U.S. defense industrial base.”
IPC fielded the survey between February 25 and March 5, 2021 and garnered 108 responses from contract manufacturers, printed circuit board fabricators, original equipment manufacturers and suppliers who self-reported they are planning to undergo a CMMC assessment in the next five years.