-
- News
- Books
Featured Books
- smt007 Magazine
Latest Issues
Current IssueDo You Have X-ray Vision?
Has X-ray’s time finally come in electronics manufacturing? Join us in this issue of SMT007 Magazine, where we answer this question and others to bring more efficiency to your bottom line.
IPC APEX EXPO 2025: A Preview
It’s that time again. If you’re going to Anaheim for IPC APEX EXPO 2025, we’ll see you there. In the meantime, consider this issue of SMT007 Magazine to be your golden ticket to planning the show.
Technical Resources
Key industry organizations–all with knowledge sharing as a part of their mission–share their technical repositories in this issue of SMT007 Magazine. Where can you find information critical to your work? Odds are, right here.
- Articles
Article Highlights
- Columns
Search Console
- Links
- Media kit
||| MENU - smt007 Magazine
The Double-edged Sword of CMMC 2.0
June 6, 2022 | Divyash Patel, MX2 TechnologyEstimated reading time: 2 minutes

For the past few years, those whose SMT provider organizations supply or contract with the U.S. Department of Defense (DoD) have been hearing about—or even gearing up for—implementation of the Cybersecurity Maturity Model Certification (CMMC) program. By this, I mean that you were gearing up for CMMC 1.0. Today, we have CMMC 2.0, and there are several changes in the new version that impact both the standards for compliance and how you certify that compliance—especially if you run a small business.
Small businesses are the backbone of the defense industrial base (DIB), just as they are for the entire economy. As both patriots and businesspeople, I’m sure most contractors serving the DoD support the goals of the CMMC program: ensuring the security of sensitive data up and down the supply chain. I’m also certain that the CMMC 1.0 rules, which went into effect in November 2020, caused more than a little stress and anxiety for smaller contractors. Why? Because CMMC 1.0 required contractors to undergo an examination by a Certified Third-Party Assessment Organization (C3PAO) to become certified.
When it became clear that the burden CMMC 1.0 placed on small contractors was significant enough to potentially force some out of the DIB, the DoD hit pause on the CMMC program. In fact, the official in charge of the CMMC’s implementation came out and said one of the main goals of revising the program was to decrease the cost burden on small businesses. As a result, the DoD scrapped CMMC 1.0 and announced CMMC 2.0 in November 2021. The full 2.0 framework is expected to be released sometime next year.
But don’t make the mistake of thinking the government will kick the CMMC can down the road once again when 2023 rolls around. I fully expect CMMC 2.0 to come online when the rules are final.
At a high level, the two major changes that will likely affect you are the new tiers of security and the shift to annual self-attestation of compliance.
The original CMMC defined five levels of security. CMMC 2.0 has three:
- Foundational
- Advanced
- Expert
For most of you, the newly collapsed levels won’t change the practical compliance requirements. This is good news. Most contracts will fall into Level 1, so any work you have done to this point to achieve Level 1 compliance under CMMC 1.0 has not been wasted. The new framework relies on the same 17 baseline security controls used in the prior version—more on those controls in a moment.
The key distinction between Level 1 and Level 2 under CMMC 2.0 has to do with the type of information you handle. Level 1 focuses on securing federal contract information (FCI), for which there are no national security concerns. The bar for Level 1 is not set very high— it is essentially developing and maintaining good baseline cybersecurity policies and procedures. In my view, this is something any company should do; it’s just a good business practice.
To read this entire article, which appeared in the June 2022 issue of SMT007 Magazine, click here.
Suggested Items
TRI: Inspection Innovations at Focus on PCB Expo
04/09/2025 | TRII-Tronik, TRI's distributor, will showcase cutting-edge AI-powered inspection solutions at Focus on PCB 2025, taking place at Fiera di Vicenza, Italy, from May 21–22, 2025.
Aegis Software and Hanwha Partner to Deliver SaaS-Based SMT Programming
04/09/2025 | Aegis SoftwareAegis Software, a global provider of Manufacturing Operations Management Software (MOM/MES) software, today announced a partnership with Hanwha Semitech Americas, a leader in Surface Mount Technology (SMT) and electronics assembly solutions. Through this partnership, Hanwha SMT customers in the U.S. will have the option to leverage Aegis’ FactoryLogix® Machine Programmer solution, available as a cloud-based SaaS offering—enabling automated machine programming, faster new product introduction (NPI), and improved production efficiency without the need for on-premises infrastructure.
Zenaida Valianu, IPC, Earns IPC Excellence in Education Award at IPC APEX EXPO 2025
03/31/2025 | IPCThe IPC Excellence in Education award was presented to Zenaida (Zenny) Valianu, IPC, at IPC APEX EXPO 2025, recognizing her significant contributions to workforce development and leadership.
MVTec, Pepperl+Fuchs Enter into Technology Partnership
03/27/2025 | MVTecMVTec Software GmbH and Pepperl+Fuchs are stepping up their technological collaboration in the field of machine vision. As part of this, Pepperl+Fuchs joined the MVTec Technology Partner program at the beginning of 2025.
Datest to Highlight Flying Probe Programming and X-ray Testing Services at Upcoming SMTA Texas Expos
03/25/2025 | DatestDatest, a leading provider of integrated PCBA testing, imaging, inspection, and failure analysis services for the electronics industry, is excited to announce it will exhibit in the upcoming SMTA Dallas Expo on Tuesday, April 1st, and the SMTA Houston Expo on Thursday, April 3rd, 2025.