Utah’s Defense Community and the Recent Changes to CMMC
Posted by John Pohlman in Blog, Information Security, IT Security, on
If your business supports Hill Air Force Base or the broader defense supply chain, you’ve probably heard the recent news about CMMC Level 2. Understandably, it created a lot of questions. Is CMMC certification being delayed? Does this change what contractors should be doing? Should cybersecurity projects be put on hold?
Those of us who live and work in northern Utah know that Hill Air Force Base is not just another military base but one of the economic forces that drive our communities, support thousands of families, and provide opportunities for hundreds of Utah businesses.
Nearly every part of our local economy, from aerospace manufacturers and engineering firms to machine shops, software developers, logistics companies, and technology providers, is connected in some way to Hill Air Force Base and the broader Defense Industrial Base (DIB). The success of these businesses helps communities thrive.
At Tanner, we have worked with many Utah defense industry companies. We have visited their manufacturing plants, talked with business owners who take pride in supporting the military, and helped contractors manage the increasingly complex world of cybersecurity and compliance.
The Department of War has recently put on hold the rollout of CMMC Level 2 third-party assessments as part of an overall review. This announcement does not suggest that CMMC is being abandoned or that the cybersecurity requirements for defense contractors are disappearing.
My Experience Working with Utah Defense Contractors
For many years, I have had the chance to talk with business owners and technology leaders whose companies support Hill Air Force Base and the Department of War, and I have toured the base a few times as a local elected official.
Each time, one thing is obvious.
In my experience, these companies aren’t looking for the easiest path. They’re asking practical questions: “What do we need to do?” and “How do we protect the contracts we’ve spent years earning?”
These are companies founded by hardworking individuals who prioritize quality, integrity, and safety. They are the ones who support the men and women who work to protect our country.
A number of these businesses are family-owned and have taken many years to win over the trust of major contractors. They create innovative technology that is being implemented into our nation’s defense.
What people share is a wish to do things the right way.
This also involves protecting sensitive government information.
Even though the cybersecurity requirements can at times seem overwhelming, almost all the contractors I have worked with understand the importance of protecting Controlled Unclassified Information (CUI).
Cybersecurity is not just another compliance requirement.
That is one way of protecting America’s military capabilities.
CMMC Level 2 Announcement
The Department of War has recently announced that it is pausing Phase II of CMMC, a move that would have required hundreds of contractors handling Controlled Unclassified Information to get a third-party CMMC Level 2 assessment. Contractors should, for the present, continue to use the Phase I self-assessments, and NIST SP 800-171 Revision 2 remains the baseline cybersecurity standard.
The announcement immediately raised all kinds of questions.
Naturally, contractors immediately began asking the same three questions: Is CMMC going away? Should companies stop preparing? Should companies not invest capital into cybersecurity controls?
From our perspective, the answer is absolutely not. More emphatically, NO!
The implementation schedule has been altered, but the need to protect sensitive government information has not.
What Has Not Changed
A major aspect of the Department’s announcement is the fact that it left certain things unchanged.
All defense contractors are still contractually responsible for making sure that Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are protected, and the responsibilities established by DFARS continue to apply, with NIST SP 800-171 as the cybersecurity baseline during the suspension.
With all of this being said, only the verification process is being reviewed; the importance of cybersecurity has not changed.
Why This Matters to Utah Businesses
Utah has gained a nationwide reputation for being a center of aerospace, defense, manufacturing, and technological innovation.
Many companies across the Wasatch Front provide products and services that support Hill Air Force Base, the military, or other Department of War programs.
For these businesses, good cybersecurity is now turning into a competitive advantage.
When choosing suppliers, prime contractors are becoming more concerned with a company’s cybersecurity maturity. Customers want to be sure that sensitive information will be kept safe.
Whatever changes the CMMC certification process may bring, companies that currently make investments in cybersecurity will find themselves better prepared for future contract opportunities.
Think of It Like Maintaining an Aircraft
Hill Air Force Base is world-famous for looking after some of the Air Force’s most important aircraft, and they are specifically responsible for maintaining all the landing gear for the Nation’s airplanes.
Picture delaying normal aircraft maintenance just because the inspection paperwork had been delayed.
That type of decision would not be made by a responsible maintenance team.
It is still necessary for the aircraft to fly safely.
CMMC and Cybersecurity controls function in the same way.
Whether the compliance deadline is advanced or delayed, the systems that protect sensitive information must still operate every day.
It is never smart for a business to postpone security improvements until the regulations are final.
What Utah Defense Contractors Should Do Next
Instead of seeing the latest announcement as a reason to stop cybersecurity activities, contractors should take advantage of this opportunity.
Check the way you have currently implemented NIST SP 800-171, update your System Security Plan (SSP), work on the findings still outstanding in your Plan of Action and Milestones (POA&M), carry out vulnerability assessments and penetration testing where it is appropriate, and make sure that your security controls are working as they should.
Businesses that take the time to continuously improve their cybersecurity controls will end up considerably better prepared for the final CMMC certification process.
Conclusion
Hill Air Force Base has had an excellent role in shaping the economy of Northern Utah, and the businesses which support the base are still strengthening both our local communities and the security of our nation.
The recent update to CMMC Level 2 provides an opportunity for improvement, not justification for stopping or giving up.
Compliance programs may evolve. Cyber threats will not.
For Utah defense companies, investing in cybersecurity remains one of the best long-term choices they can make for their customers, employees, and the communities they serve.
CMMC FAQ’s
Has CMMC Level 2 been canceled?
No, On the contrary, the Department of War has suspended the Phase II rollout of the mandatory third-party assessments as it reviews the certification process. The basic cybersecurity requirements remain in effect.
Do Utah defense contractors still have to comply with NIST SP 800-171?
Yes, NIST SP 800-171 remains the baseline cybersecurity standard for contractors dealing with Controlled Unclassified Information throughout the suspension.
Should companies stop preparing for CMMC?
For most businesses, NO. By continuing to improve their cybersecurity today, companies can reduce risk and prepare for future compliance, no matter how the certification process or framework changes.
Even if the compliance deadlines change, why is cybersecurity important?
Cyber threats will still exist, regardless of the regulatory schedules. Good cybersecurity helps to protect contracts, intellectual property, customer trust, and business operations.
Schedule a Call