Remain Vigilant
A warning for defense contractors and subcontractors from a top cyber security expert.
While this might seem like an IT issue, company leaders, especially those among the estimated 400+ defense contractors across the state, need to hear this. In late July, the Department of War announced that it would pause the third-party certification aspect of its cyber security program for contractors and subcontractors. But Grant Burns, the founder of Bound Planet, a Twin Cities-based cyber security consulting and services firm, says even though that portion of the program is on hold, it’s critical that companies serving as contractors or subcontractors continue to take all the steps needed to safeguard federal information.
In a recent discussion with Enterprise Minnesota, Burns explained the origin of the Cyber Maturity Model Certification (CMMC) program and the obligations of manufacturers who operate as contractors. CMMC exists, Burns says, to protect two categories of sensitive government information shared with contractors during the procurement process. The requirements trace back to breaches in which adversaries obtained U.S. military technology, including China’s J-31 fighter jet bearing a striking resemblance to the F-35. In response, the government adopted safeguarding standards and built a certification ecosystem so contractors could be independently verified against it.
Only the third-party certification assessment piece, which had been scheduled to expand this November, has been paused, Burns says. The underlying obligation to protect information remains. “It doesn’t remove any of the actual requirements of safeguarding the information,” he says.
Company leaders who aren’t sure whether any of this applies to them have an easy way to check, Burns says: search your contracts for a clause called DFARS 252.204-7012. If that clause shows up, it means the government has determined you’ll be handling protected information, and the safeguarding requirements apply to you, pause or no pause.
While it would be tempting to pass this off to the IT experts, owners and presidents are often the ones on the hook for compliance, Burns says. Someone at the company, often the president or owner acting as the “affirming official,” attests that safeguards are in place, and that attestation carries real legal weight under the False Claims Act. He points to an Alabama company that claimed a perfect implementation score and was later found to fall short. The resulting fine topped $500,000. “Nobody should say they’re 100% when they know they have gaps,” Burns says.
His advice for contractors already pursuing CMMC is to keep building toward full implementation, even if it makes sense to hold off on hiring a third-party assessor until the Department of War signals its next move. Companies that stay ready can often satisfy a customer’s security questionnaire simply by producing a certificate rather than answering item by item.
Burns says that mindset is good business, not just good compliance. He’s seen clients outside the defense world lean on their certification the same way, satisfying a customer’s third-party risk review by handing over a certificate instead of filling out a lengthy questionnaire.
He also says it gives companies a strategic advantage, much like ISO certification, even when no one requires it, because it signals quality processes across markets. Companies that treat CMMC as a growth strategy, rather than a box to check, often find it gives them an edge when competing for new business, both in the defense arena and beyond.
Burns adds that the discipline required by CMMC tends to pay off beyond a specific contract. His clients who expanded employee training, for instance, report far more phishing emails being caught and reported–rather than clicked.
The bottom line for manufacturers, Burns says, is that the pause is not a signal to relax. It’s a chance to keep strengthening cyber practices.
Industry News
Tilt-A-Whirl! The Minnesota invention and State Fair staple turns 100
August 15, Mesabi Tribune
Cirrus expands Grand Forks manufacturing facility, adding 30,000 SF
August 15, Business North
Bongards invests $135m in Minnesota cheese plant
August 14, Food & Drink International
Winnebago Industries moving B-Van production from Lake Mills to Forest City
August 14, KIMT3
As layoffs strike a Minnesota solar company, U.S. industrial policy needs sunlight
August 12, Minnesota Star Tribune

