In our last blog post, we talked about the importance of safeguarding the aerospace and defense supply chain. For companies working with these industries, it is also critical to have strong cybersecurity regulations and protocols set in place to ensure that any sensitive information is being handled properly.
Cybersecurity Regulations
The DoD launched the Cybersecurity Maturity Model Certification directives in 2020 due to the ever increasing need to improve the protection of controlled unclassified information (CUI) within the supply chain. The CMMC procedures incorporate five maturity levels:
CMMC Level 1
CMMC Level 2
CMMC Level 3
CMMC Level 4 and Level 5
The DoD developed the CMMC framework to assess and improve cybersecurity posture in all tiers of the supply chain. Depending on a particular business and their position in the chain is what determines which CMMC Level is appropriate for them.
To ensure the final product complies with government regulations and customer requirements, these and other standards must be closely followed across the entire supply chain and throughout the production process. As indicated above this ranges from raw materials to vendor selection and monitoring. Stringent controls, up to date documentation, and efficient oversight are essential to ensure compliance. Without adhering to these standards and regulations critical data may be misinterpreted or worse; be leaked to unauthorized personnel or countries.
As with all certifications and compliances, there are costs associated with compliance to Cybersecurity Maturity Model Certification. For SMB companies the total cost of ownership for CMMC involves:
Costs for the various levels and their annual recurring events for SMBs are shown in the table below:
**Assessment costs consist of contractor support for pre-assessment preparations, the actual assessment, and any post-assessment work. These costs also include an estimate of the potential C3PAO costs for conducting CMMC Assessment, which are comprised of labor for supporting pre-assessment preparations, actual assessment, and post-assessment work, plus travel cost. *Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)
Table courtesy of Ignyte Assurance Platform
Along with a strong supply chain and cybersecurity regulations, it's also critical for the aerospace and defense industry to be Nadcap accredited. Our next blog will cover what it means to be Nadcap compliant, and what Nadcap covers for companies working with these industries.
This blog is an excerpt from our whitepaper, The Critical Nature of Aerospace & Defense Certifications and Regulations. Click here to download your free whitepaper!
Click below to browse more of our Aerospace & Defense content.