2026-07-17OPINION · SUPPLYCHAINSECURITY · CYBERGOVERNANCE · CMMCPAUSE · THIRDPARTYRISK · BOARDROOMCYBER5 MIN READ READ
FILED UNDER

Certification Is Not Posture: What the CMMC Pause Reveals

The gap between passing a certification review and actually being harder to compromise is wide, costly, and almost never discussed at board level. The CMMC pause is a chance to close it.

When Compliance Kills the Supply Chain It Was Meant to Protect

The Pentagon has paused the next phase of its Cybersecurity Maturity Model Certification program — and the reason is instructive. Smaller defence suppliers were exiting the market rather than absorbing the cost and complexity of third-party audits. As iTnews reports, the certification program designed to harden the defence industrial base was instead shrinking it.

Our position is this: that pause may be the most strategically sound cyber security decision the Pentagon has made in years. Not because the underlying security requirements are wrong, but because a compliance framework that drives suppliers out of the market doesn’t improve security — it consolidates risk into fewer, larger vendors who are paradoxically harder to scrutinise and too embedded to penalise.

The Paperwork Hardens. The Posture Doesn’t.

Those of us who have sat inside CMMC-style certification processes — not as consultants selling them, but as executives responsible for the security outcomes they were supposed to produce — know what trade press rarely says plainly: these frameworks are exceptionally good at generating documentation and exceptionally poor at generating resilience.

The audit validates that controls exist and are described correctly. It does not validate that they work under pressure, that the people operating them understand why they exist, or that the organisation would detect a sophisticated intrusion rather than simply pass a checklist review. A supplier can satisfy every CMMC control and still be comprehensively compromised. We’ve seen it.

What certification frameworks do well is create a market for auditors and consultants. What they do poorly is distinguish between organisations that are genuinely harder to attack and those that are genuinely better at writing policies. When the cost of compliance is high and the security return is marginal, rational suppliers do the rational thing — they leave.

The Consolidation Problem Boards Miss

When smaller suppliers exit, the work doesn’t disappear. It migrates to larger prime contractors and tier-one suppliers who are already certified, already embedded, and already carrying the bulk of systemic risk in that supply chain.

This is the second-order consequence that audit-focused frameworks almost never account for. You began with a diversified supplier base where risk was distributed across many smaller entities. You end with a concentrated supplier base where a smaller number of large vendors hold more critical capability, more sensitive data, and more systemic leverage — and where the customer (government or prime) has less practical ability to exit or discipline them.

Concentration is not a security improvement. In supply chain risk terms, it is a regression. The compliance program produced the opposite of its intended effect.

The Australian Parallel Is Not Hypothetical

Australian boards with defence-adjacent exposure, or with supply chain obligations under the Security of Critical Infrastructure Act, should read the CMMC situation as a direct warning — not a distant American curiosity.

Australia is building its own uplift requirements. DISP (Defence Industry Security Program) membership requirements are tightening. SOCI Act obligations are expanding across more sectors and more entities within those sectors. APRA CPS 234 already imposes third-party security expectations on regulated entities. The direction of travel is consistent: mandatory frameworks, third-party verification, and escalating compliance costs.

If those frameworks are designed with the same structural incentives as CMMC — where the audit becomes the product and the auditor ecosystem grows faster than actual security capability — Australian supply chains will face the same exit dynamic. Smaller suppliers, often the ones carrying specialist capability that large primes depend on, will make the same rational calculation: the cost of compliance exceeds the value of the contract.

The government’s response, like the Pentagon’s, will likely be to pause or adjust the framework. But by then, some of those suppliers will have already left. Capability, once lost from an industrial base, is slow to rebuild.

What a Better Framework Looks Like

The goal of supply chain security is not supplier certification. It is supplier visibility, supplier resilience, and the practical ability to identify and respond when a supplier is compromised.

That requires a different set of questions at board level. Not “are our suppliers certified?” but “do we know what our suppliers actually have access to, and what the blast radius is if they’re compromised?” Not “does our CISO manage third-party risk?” but “have we ever tested what happens operationally when a critical supplier fails?”

Certification answers the first question in each pair. It rarely answers the second. Boards that confuse certification status with security posture are making a governance error, and that error becomes expensive when a supplier fails in the way the certification was supposed to prevent.

The Contrarian Takeaway

The CMMC pause is being reported as a setback for cyber security policy. It isn’t. It’s an opportunity to ask whether the framework was measuring what actually matters — and to redesign it before the compliance infrastructure becomes too entrenched to reform.

For Australian boards: use this moment to examine whether your supply chain security program is producing genuine visibility and resilience, or producing audit artefacts and false assurance. If your third-party risk program is primarily a documentation exercise, it is not a security program. It is a liability management exercise dressed up as one.

The distinction matters, because when something goes wrong in that supply chain — and it will — the board will be asked whether it exercised genuine oversight or simply confirmed that the paperwork was in order. Those are not the same defence.

Next dossier
AI Agents Are Now Your Most Privileged Users →
Engage the author
Stephen Betros is currently taking on briefs for FY26.
Brief Stephen
Share