-
- News
- Books
Featured Books
- smt007 Magazine
Latest Issues
Current IssueProduction Software Integration
EMS companies need advanced software systems to thrive and compete. But these systems require significant effort to integrate and deploy. What is the reality, and how can we make it easier for everyone?
Spotlight on India
We invite you on a virtual tour of India’s thriving ecosystem, guided by the Global Electronics Association’s India office staff, who share their insights into the region’s growth and opportunities.
Supply Chain Strategies
A successful brand is built on strong customer relationships—anchored by a well-orchestrated supply chain at its core. This month, we look at how managing your supply chain directly influences customer perception.
- Articles
- Columns
- Links
- Media kit
||| MENU - smt007 Magazine
The Double-edged Sword of CMMC 2.0
June 6, 2022 | Divyash Patel, MX2 TechnologyEstimated reading time: 2 minutes

For the past few years, those whose SMT provider organizations supply or contract with the U.S. Department of Defense (DoD) have been hearing about—or even gearing up for—implementation of the Cybersecurity Maturity Model Certification (CMMC) program. By this, I mean that you were gearing up for CMMC 1.0. Today, we have CMMC 2.0, and there are several changes in the new version that impact both the standards for compliance and how you certify that compliance—especially if you run a small business.
Small businesses are the backbone of the defense industrial base (DIB), just as they are for the entire economy. As both patriots and businesspeople, I’m sure most contractors serving the DoD support the goals of the CMMC program: ensuring the security of sensitive data up and down the supply chain. I’m also certain that the CMMC 1.0 rules, which went into effect in November 2020, caused more than a little stress and anxiety for smaller contractors. Why? Because CMMC 1.0 required contractors to undergo an examination by a Certified Third-Party Assessment Organization (C3PAO) to become certified.
When it became clear that the burden CMMC 1.0 placed on small contractors was significant enough to potentially force some out of the DIB, the DoD hit pause on the CMMC program. In fact, the official in charge of the CMMC’s implementation came out and said one of the main goals of revising the program was to decrease the cost burden on small businesses. As a result, the DoD scrapped CMMC 1.0 and announced CMMC 2.0 in November 2021. The full 2.0 framework is expected to be released sometime next year.
But don’t make the mistake of thinking the government will kick the CMMC can down the road once again when 2023 rolls around. I fully expect CMMC 2.0 to come online when the rules are final.
At a high level, the two major changes that will likely affect you are the new tiers of security and the shift to annual self-attestation of compliance.
The original CMMC defined five levels of security. CMMC 2.0 has three:
- Foundational
- Advanced
- Expert
For most of you, the newly collapsed levels won’t change the practical compliance requirements. This is good news. Most contracts will fall into Level 1, so any work you have done to this point to achieve Level 1 compliance under CMMC 1.0 has not been wasted. The new framework relies on the same 17 baseline security controls used in the prior version—more on those controls in a moment.
The key distinction between Level 1 and Level 2 under CMMC 2.0 has to do with the type of information you handle. Level 1 focuses on securing federal contract information (FCI), for which there are no national security concerns. The bar for Level 1 is not set very high— it is essentially developing and maintaining good baseline cybersecurity policies and procedures. In my view, this is something any company should do; it’s just a good business practice.
To read this entire article, which appeared in the June 2022 issue of SMT007 Magazine, click here.
Testimonial
"Our marketing partnership with I-Connect007 is already delivering. Just a day after our press release went live, we received a direct inquiry about our updated products!"
Rachael Temple - AlltematedSuggested Items
The Training Connection, LLC Welcomes Industry Veteran Jack Harris to Lead Training Partnerships
10/07/2025 | The Training Connection LLCThe Training Connection, LLC (TTC-LLC), a premier provider of test engineering and development training, is proud to announce that Jack Harris, one of the most recognized names in electronics manufacturing training and technical development, has joined the company as Relationship Lead, Training.
Alpha Insights, Performance by Design: The Future of PCB Manufacturing in the Midwest
10/07/2025 | Team Alpha -- Column: Alpha Insights: Performance by DesignFor years, Midwest PCB manufacturing was often viewed as a low-cost, high-volume business—good for standard builds but not for the high-reliability programs that demand tight process control. Defense primes and medical OEMs frequently turned to coastal or overseas suppliers for advanced work.
Schweizer Ends Staff Restructuring Measures and Short-Time Working at the Schramberg Site
10/01/2025 | Schweizer Electronic AGSchweizer Electronic AG has implemented comprehensive measures to adjust its cost and personnel structure at its Schramberg site due to strong market fluctuations in the automotive and industrial electronics sector. Thanks to the successful restructuring, short-time working can now be ended with immediate effect. A stable order situation is expected for the fourth quarter, with signs of growth momentum returning in 2026.
HyRel Technologies Showcases Summer Intern Success Through Hands-On Innovation
09/16/2025 | HyRel TechnologiesHyRel Technologies, a global provider of quick turn semiconductor modification solutions, proudly highlights the accomplishments of its two recent summer interns, Danny Hoang and Nisarg Jadav.
Beyond the Board: What Companies Need to Know Before Entering the MilAero PCB Market
09/16/2025 | Jesse Vaughan -- Column: Beyond the BoardThe MilAero electronics supply chain offers opportunities for manufacturers that are both prestigious and strategically important. Serving prime contractors and Tier-1 suppliers can mean long-term program stability and the satisfaction of contributing to national security. At the same time, this sector is unlike commercial electronics in almost every respect. Success requires more than technical capabilities, it requires patience, preparation, attention to detail, and a clear understanding of how the business model differs.