For specialty manufacturers
The cyber clause in your supplier quality agreement
It did not arrive as a regulation. It arrived as a revision. Your customer's supplier quality agreement came through for signature — Rev C replacing Rev B — and around section 9 there are three paragraphs that were not there before. Safeguarding covered defense information. NIST SP 800-171. Possibly a CMMC level. A sentence about export-controlled technical data, and another requiring you to flow the same terms down to your own suppliers. Purchasing wants it back Friday. It landed on your desk because you own the QMS and a supplier quality agreement is a QMS document — not IT's, not the owner's, yours. You already run the machinery this needs. What you do not want is to sign a representation you cannot evidence.
Why this is happening to you and not to IT
The quality standards and the security standards are converging, and it is happening through the supply chain rather than through a rulemaking. Quality Magazine reported in 2026 that AS9100, IATF 16949, NIST 800-171 and CMMC are converging; that the IA9100 and IATF 16949 revision committees are exploring formal references to ISO/IEC 27001-style information security controls; and that OEM customers are embedding cyber and export-control clauses directly into supplier quality agreements (Quality Magazine, 2026 — "ISO 9001 in 2026: what's changing, and how AS9100, IA9100, IATF 16949, NIST and CMMC fit together").
Read that with an auditor's eye. If information security controls get referenced in your quality standard, information security becomes auditable in your quality system — objective evidence, corrective action, management review. That is your apparatus. The practical version is simpler: your customer has an obligation and their contract requires them to push it down, and the cheapest way to push anything down is to put it in the document the supplier already signs.
You have one advantage worth naming. You already run a system of documented requirements, controlled documents, defined responsibilities, records, internal audits and corrective action. The subject matter is unfamiliar. The structure is not.
What is actually required right now — get this exactly right
CMMC Phase 2 was suspended. The DoD CIO suspended Phase 2 requirements on July 13, 2026 (memo 26-P-1023), citing prohibitive cost for smaller companies and insufficient C3PAO assessor capacity. A Reform Task Force review is running sixty days with recommendations due mid-September 2026 (Federal News Network, July 2026).
Everything below is still fully in force today.
- DFARS 252.204-7012. If it is in your contract it binds: implement NIST SP 800-171 — Rev 2
remains the operative revision — and report a cyber incident within 72 hours.
- Phase 1 self-assessment. You assess yourself against the 800-171 controls and produce a score.
- SPRS. That score is posted in the Supplier Performance Risk System, visible to your customers
and to the government.
- The annual affirmation. A senior official affirms, annually, that the score is accurate.
Sit with that last one. Somebody at your company signs a statement to the federal government about the state of your security controls. That is not a quality record — it is a representation, and inaccurate cybersecurity representations carry False Claims Act exposure. Not theoretical: Aerojet Rocketdyne settled for $9 million and Penn State for $1.25 million. Suspending Phase 2 changed the assessment regime. It changed none of that.
Do not panic-buy a Level 2 assessment
Advice against our own short-term interest, and we mean it.
Phase 2 is suspended, the reform review is unfinished, and assessor capacity is one of the stated reasons for the suspension — so you would be queuing for a scarce resource against requirements that may change. The cost is real. DoD's own estimates: Level 2 with C3PAO certification, $105,000 to $118,000 triennially. Level 2 self-assessment, $37,000 to $49,000. Level 1, $4,000 to $6,000. Spending six figures before the review lands in September is a bad trade.
If a vendor is calling this month telling you CMMC is an emergency and you need a certification assessment booked before quarter end, they are selling into a suspension. Ask them the date Phase 2 was suspended and see whether they know.
Make the SPRS score accurate, not higher
Those are two different pieces of work and only one of them is urgent.
Most shops here have a score produced once, in a hurry, by somebody who no longer works there, against a spreadsheet template, and never revisited. Since then you moved to Microsoft 365, added a remote user, changed how the ERP is backed up, and took on a customer whose prints are export-controlled. The score on file describes a company that no longer exists.
Three things, in order. Find your current SPRS score and the date it was posted — if nobody knows who can look it up, that is the finding. Re-run the self-assessment honestly: every control implemented, partially implemented, or not, with the gaps in a plan of action with dates. A lower honest score with a credible plan is defensible; a high score you cannot evidence is the Aerojet problem. Make sure whoever signs the annual affirmation has read what they are signing, with a record of what it was based on — a controlled document with a revision level and an approval.
Answering the clause in front of you
- Mark the verbs. "Shall implement," "shall maintain," "shall notify within," "shall flow down."
Each verb is a requirement with an owner and a record.
- Scope it. Which customers send controlled information, and where does it live — email, the ERP,
a shared drive, an engineering workstation, the machine at cell four with a USB port. Prints do not need to be everywhere.
- Check the flow-down. Your outside heat treat, your plating house, your calibration lab. Some
are two-person shops. Start that conversation before you sign, not after.
- Do not sign a representation you cannot evidence. You would not sign a C of C for a lot you had
not inspected. Same signature, same instinct. Give your customer a date instead.
- Put the whole thing through contract review like any other supplier requirement.
Close
Security Policies, $4,900 — a written program describing your shop as it actually operates, mapped to NIST CSF 2.0 and CIS Controls v8.1, read line by line by a vCISO who signs an attestation. Full Program (Compliance Ready), $8,900 adds the crosswalk across NIST CSF 2.0, CIS v8.1 and NIST SP 800-171. GRC Platform, $495/month, keeps it published and current.
What we refuse: we are not a C3PAO and we do not certify anyone; we do not sell the crosswalk without the policies underneath it; we do not deliver a policy the vCISO has not read; and no agent we build prices a job, commits a lead time, accepts a change order, or touches the shop floor or any quality disposition — no nonconformance, no deviation, no MRB decision, no C of C, no first article result. Those carry your signature.
Signet — AI that holds up. A division of Circle Square Consulting, Radnor, PA.