When the U.S. Department of Defense began signaling that cybersecurity self-attestation would eventually give way to mandatory third-party certification, San Francisco Circuits decided to get ahead of it. That decision, made in 2019, shaped everything that followed: the systems we implemented, the partners we engaged, and the audit we ultimately passed. This is the story of that process, including what worked, what added complexity, and what we'd tell other EMS companies and defense suppliers that are now facing the same path.
Defense contractors that handle Controlled Unclassified Information (CUI) are now required to hold CMMC Level 2 certification to win new DoD work, and self-attestation is no longer accepted. Level 2 requires full implementation of all 110 security practices aligned to NIST SP 800-171, covering every organization in the Defense Industrial Base supply chain that processes, stores, or transmits CUI.
Why It Matters for Defense Programs
For our customers working on defense and government programs, it’s not whether their PCB supplier can build the board, but whether that supplier can be trusted with the data surrounding it. Design files, program specifications, and contract information flowing through a supplier's systems are part of the same security perimeter that CMMC is designed to protect.
CMMC 2.0 Level 2 certification provides customers with verified assurance that suppliers meet the cybersecurity standards required to handle government and defense program data, and that this assurance is ongoing. As part of the certification, we conduct annual cybersecurity evaluations and must undergo full recertification every three years.
The certification also strengthens supply chain security beyond our own walls. We hold our vendors and manufacturing partners to the same standards, creating consistent security expectations across every link in the chain rather than only at the prime contractor level. For customers working on programs where data protection is a contractual requirement, consistency matters.
To continue reading this article, which appeared in the August 2026 SMT007 Magazine, click here.