-
- News
- Books
Featured Books
- smt007 Magazine
Latest Issues
Current IssueIntelligent Test and Inspection
Are you ready to explore the cutting-edge advancements shaping the electronics manufacturing industry? The May 2025 issue of SMT007 Magazine is packed with insights, innovations, and expert perspectives that you won’t want to miss.
Do You Have X-ray Vision?
Has X-ray’s time finally come in electronics manufacturing? Join us in this issue of SMT007 Magazine, where we answer this question and others to bring more efficiency to your bottom line.
IPC APEX EXPO 2025: A Preview
It’s that time again. If you’re going to Anaheim for IPC APEX EXPO 2025, we’ll see you there. In the meantime, consider this issue of SMT007 Magazine to be your golden ticket to planning the show.
- Articles
- Columns
Search Console
- Links
- Media kit
||| MENU - smt007 Magazine
CMMC 2.0: Are You Ready?
July 6, 2022 | Nolan Johnson, I-Connect007Estimated reading time: 3 minutes

Nolan Johnson discusses with Ryan Bonner of DEFCERT exactly where and how EMS companies should aim for CMMC certification. Organizations, he says, “need to avoid false dichotomies where they assume that either CMMC is a go or it’s not happening at all. All the government mandated reviews to keep CMMC moving forward, resulting in new contract clauses, are already underway. The rule making is scheduled; it will happen.
Nolan Johnson: Ryan, what’s the status of CMMC 2.0?
Ryan Bonner: The aspects of CMMC 2.0 that those contractors can act on now, even while we wait on other components, are the model itself and the assessment guide. Those are the two documents that are most appropriate for contractors. Because those two items are in place, there is a path forward for CMMC, even while secondary aspects of CMMC, like the C3PAOs assessment process or the eventual contract clauses that will drive adoption, are under the surface, if you will, and are going through rule making.
Johnson: There is something tangible that we can proceed with in anticipation of everything else coming into place.
Bonner: Absolutely. Many organizations don’t realize that the shift to CMMC 2.0 was the outcome of a review by the Government Accountability Office. I believe it was congressionally mandated as well under the National Defense Authorization Act. That process has already been completed.
The big change coming out of that review process was to shrink the model back to only the requirements described in the original parent document, NIST 800-171. That creates a situation where now the CMMC model under 2.0 is identical to the requirements and assessment content that’s in both NIST 800-171 and NIST 800-171A (the document used to assess 800-171). Those are identical. They’re in lockstep. There’s no appreciable difference between the two.
Johnson: If my company has already completed NIST 800-171, what does this mean regarding CMMC?
Bonner: You should be aware of two ways you might be assessed or graded against what you’ve already done. If you have already worked on 800-171, or even completed your implementation, you have two pathways. The first is being assessed by the government or the defense contract management agency that’s done through their DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) teams. But the DIBCAC teams, at no cost to you, schedule either a moderate confidence or high confidence assessment and, because of that, assign you a completion score using their assessment methodology. That’s one way to be assessed against NIST 800-171.
The other pathway is a proactive approach where you seek CMMC certification. This involves the accreditation body and their authorized assessing organizations, which are the C3PAOs coming in and, at your cost, you are assessed and then certified. That certification is expected to be good for three years. The difference there is that contracting officers are allowed to request your CMMC certification as a source selection criterion for awards. That’s the big shift. Organizations that want to skip many of the government audited steps can go straight to private sector certification, and then have that on file to show you’ve completed everything in NIST 800-171.
They’re not mutually exclusive, so if organizations haven’t completed NIST 800-171 implementations, there is an additional change to rule making that we expect next March. It will involve setting either certain minimum threshold scores or specifying which of the 800-171 requirements must be done as a prerequisite for contract awards while other, perhaps less vital implementations, can be saved until a 180-day window after-contract award.
Johnson: Sounds like there’s room there to transition without being completely locked out.
Bonner: Correct. Organizations should be aware of how compressed a 180-day window is for completing your implementations. It’s not a lot of time based on how long it seems to take most contractors to implement.
Continue reading the rest of this interview in the July 2022 issue of SMT007 Magazine.
Suggested Items
Designing Through the Noise: April 2025 Design007 Magazine
04/08/2025 | I-Connect007 Editorial TeamIn the April 2025 issue of Design007 Magazine, our experts discuss the constantly evolving world of RF design, including the many tradeoffs, material considerations, and design tips and techniques that designers and design engineers need to know to succeed in this high-frequency realm.
It’s Only Common Sense: 7 Tips to Focus on What Works
03/31/2025 | Dan Beaulieu -- Column: It's Only Common SenseIn business, there’s always the temptation to be all things to all people, whether it’s expanding product lines, chasing every lead, or trying to keep up with competitors. The fear of missing out can lead to spreading our time, resources, and energy too thin. However, success doesn’t come from doing everything; it comes from doing the right things well.
It’s Only Common Sense: The Danger of Overthinking
03/24/2025 | Dan Beaulieu -- Column: It's Only Common SenseWe’ve all had those moments when we find ourselves endlessly analyzing a decision, cycling through every possible outcome, and trying to anticipate every potential obstacle. It’s not just frustrating; it’s paralyzing. Overthinking is a timewaster, a progress-stopper, and a productivity killer. For many of us, it’s become a habit that keeps us from reaching our full potential.
It’s Only Common Sense: Why Building a Strong Personal Brand Is Critical
03/17/2025 | Dan Beaulieu -- Column: It's Only Common Sense“Your reputation precedes you.” This is one of those clichés that happens to be entirely true. Whether you’re stepping into a room full of potential clients, meeting a new colleague for the first time, or connecting online, people often know something about you before you say a word. That “something” is your personal brand—your reputation, your promise, and your legacy all rolled into one. In today’s competitive world, your personal brand is one of the most powerful assets you can cultivate.
It’s Only Common Sense: Be the Solution, Not the Problem
03/10/2025 | Dan Beaulieu -- Column: It's Only Common SenseIn life and business, you’re either contributing to the problem or the solution. Customers come to you because they have a challenge, a pain point, or a problem that needs solving. The businesses that customers rave about consistently prove themselves to be problem solvers. Adopting a problem-solving mindset isn’t just good for your customers; it’s the key to building loyalty, standing out in the marketplace, and growing your business.