Nolan’s Notes: The CMMC Certification Question Mark
About a year ago, the Global Electronics Association published a report, “Interconnected: Global Electronics Trade in an Age of Disruption,” which made a convincing case that the electronics industry is the most globally interconnected industry on the planet. But those digital connections come with a warning label: Storing and transferring large amounts of intellectual property means facing data security challenges we’ve never seen before.
Cybersecurity is no longer a nice-to-have proposition. You can’t just say, “We’re a little company; the hackers don’t even know who we are.” That’s simply no longer valid. In fact, cybersecurity experts will tell you that hackers tend to break into value chains more often at small- to medium-sized companies, where security is weakest. Claiming anonymity and obscurity is no longer a choice for these companies.
Recently, I came across a blog post claiming that hackers had stolen schematics for the Apple iPhone 18 from Tata, an Indian supplier in the Apple value chain. I traced the story back to Appleinsider.com, which broke the news. Other mainstream channels picked up the story and added their own reporting (so some details may be suspect), but the overall story has merit. Tata is a mega-corporation you would expect to have robust cybersecurity, yet it still suffered a breach. Not to be alarmist, but if Tata is vulnerable, so are you, and it’s exactly why we’re devoting this issue to the U.S. Cybersecurity Maturity Model Certification (CMMC) program.
CMMC is the government’s system to ensure that if you’re handling sensitive information, you’re also protecting it. It began as a response to cybersecurity breaches in the U.S. defense industry ecosystem. The U.S. Department of Defense set a Nov. 10, 2026, deadline to comply with its CMMC Phase II requirements, then recently pulled back on that date, and called for a 60-day evaluation. It was a big deadline, to be sure, and many companies of all sizes in the supply chain have been steadily working toward compliance.
That’s key to the success of the CMMC program. Even if you don’t do direct defense work, you might still need to increase your data security. The Tata iPhone example confirms the value in that. Each of your customers is a separate, distinct value chain. Do you know the full extent of each? How many of those value chains lead to a military application? The military drone teardown videos so popular on YouTube these days show that some surprisingly consumer-level components are now key systems in military assets. One could argue that CMMC is a good idea, no matter where you fit in the EMS value chain.
In this issue, we begin by exploring CMMC’s history and implications. Then we talk to three EMS companies pursuing CMMC Level 2 certification: one that has achieved its certs and two that were on track to do so before the November deadline. Each company shares its perspective on the process and the implications for its business going forward into 2027. We also include a cybersecurity roundtable from APEX EXPO 2026 in Anaheim, where I moderated a compelling panel discussion on the reasons and practicalities of CMMC certification.
With such important steps in motion, the recent DoD news about the CMMC suspension came as a bit of a surprise. We asked our sources how this news would change their plans, and you’ll find those updates in this issue, as well as a reaction piece from recurring CMMC contributor Divyash Patel.
To round out this August issue, tariff expert James Kim continues his discussion of the USMCA, and Nash Bell's column compares hot-air and infrared device removal methods for rework.
Cybersecurity always carries some controversy. Opinions vary on how much money and time must be invested to be the most effective. In this case, however, even the U.S. government is having second thoughts about whether this protocol is appropriate for supporting sensitive military and government work in a sustainable way. Is this our new de facto standard? Perhaps it’s too soon to tell, but how will CMMC affect your business? Are you seeking certification? Is CMMC too much, or not nearly enough? Drop me an email at editorial@iconnect007.com.
This column originally appeared in the August 2026 issue of SMT007 Magazine.