2026-07-17OPINION · SUPPLYCHAINSECURITY · CYBERGOVERNANCE · CMMCPAUSE · THIRDPARTYRISK · BOARDROOMCYBER5 MIN READ READ
FILED UNDER

Certification Is Not Posture: What the CMMC Pause Reveals

The gap between passing a certification review and actually being harder to compromise is wide, costly, and almost never discussed at board level. The CMMC pause is a chance to close it.

When Compliance Kills the Supply Chain It Was Meant to Protect

The Pentagon has paused the next phase of its Cybersecurity Maturity Model Certification program, and the reason it gave is the interesting part. Smaller defence suppliers were leaving the market rather than absorbing the cost and complexity of third-party audits. As iTnews reports, a certification program built to harden the defence industrial base was shrinking it instead.

That pause may be the most sensible cyber security decision the Pentagon has made in some years. The underlying security requirements are largely sound. The problem is what a high-cost compliance regime does to the shape of a supply chain: it pushes risk upward into fewer and larger vendors, who are harder to scrutinise and too embedded to discipline.

The Paperwork Hardens. The Posture Doesn’t.

Some of us have sat inside CMMC-style certification processes, not as consultants selling them but as the executives accountable for the security outcomes they were meant to produce. These frameworks are exceptionally good at generating documentation and quite poor at generating resilience, which the trade press rarely puts in those words.

An audit confirms that controls exist and are described correctly. It says nothing about whether they hold under pressure, whether the people running them understand why they are there, or whether anyone would notice a patient intruder who was not making noise. A supplier can satisfy every CMMC control and be comprehensively compromised at the same time. We have seen exactly that.

What these frameworks reliably create is a market for auditors and consultants. What they do not do is separate the organisations that are genuinely hard to attack from the ones that are simply good at writing policy. Put the compliance cost high enough and the security return low enough, and suppliers do the rational thing: they leave.

The Consolidation Problem Boards Miss

When smaller suppliers exit, the work doesn’t disappear. It migrates to larger prime contractors and tier-one suppliers who are already certified, already embedded, and already carrying the bulk of systemic risk in that supply chain.

This is the second-order effect audit-focused frameworks almost never model. You start with a diversified supplier base and risk distributed across many small entities. You finish with a concentrated one, where fewer large vendors hold more critical capability, more sensitive data and more leverage, and where the customer — government or prime — has correspondingly less ability to walk away or apply pressure. In supply chain terms that is a regression, delivered by a program designed to do the opposite.

The Australian Parallel Is Not Hypothetical

Australian boards with defence-adjacent exposure, or with supply chain obligations under the Security of Critical Infrastructure Act, should read the CMMC situation as a direct warning — not a distant American curiosity.

Australia is building its own uplift requirements. DISP (Defence Industry Security Program) membership requirements are tightening. SOCI Act obligations are expanding across more sectors and more entities within those sectors. APRA CPS 234 already imposes third-party security expectations on regulated entities. The direction of travel is consistent: mandatory frameworks, third-party verification, and escalating compliance costs.

If those frameworks are designed with the same structural incentives as CMMC — where the audit becomes the product and the auditor ecosystem grows faster than actual security capability — Australian supply chains will face the same exit dynamic. Smaller suppliers, often the ones carrying specialist capability that large primes depend on, will make the same rational calculation: the cost of compliance exceeds the value of the contract.

The government’s response, like the Pentagon’s, will likely be to pause or adjust the framework. But by then, some of those suppliers will have already left. Capability, once lost from an industrial base, is slow to rebuild.

What a Better Framework Looks Like

The point of supply chain security is knowing who has access to what, keeping the chain standing when one link fails, and being able to act when a supplier is compromised. Certification is at best a proxy for the first of those.

That implies a different set of questions in the boardroom. “Are our suppliers certified?” is answerable from a spreadsheet. “Do we know what our suppliers can reach, and what the blast radius is if one of them is breached?” is not. Nor is “have we ever tested what actually happens operationally when a critical supplier goes dark?” — a question we have asked in a good number of committee meetings and rarely had answered.

Boards that read certification status as security posture are making a governance error, and the error becomes expensive at precisely the moment a supplier fails in the way the certificate implied it would not.

The Contrarian Read

The pause is being written up as a setback for cyber security policy. It is closer to an opening: a chance to ask whether the framework was measuring anything that matters, while the compliance industry around it is still young enough to reform.

Australian boards can use the same moment domestically. Is your supply chain program producing visibility and resilience, or artefacts and assurance? A third-party risk program that consists mostly of collected documentation is liability management with a security budget.

The distinction gets tested eventually, because something in that supply chain will go wrong. At that point the board will be asked whether it exercised genuine oversight or confirmed the paperwork was in order, and only one of those answers is a defence.

Next dossier
AI Agents Are Now Your Most Privileged Users →
Engage the author
Stephen Betros is currently taking on briefs.
Brief Stephen
Share