CMMC Is Changing, But Defence Supply Chain Risk Has Not Gone Away

CMMC requirements are changing, but defence organizations still face the challenge of understanding and managing supplier cybersecurity risk across complex supply chains. This blog explores why certification alone is not enough and how continuous supplier visibility, lifecycle management, and third-party risk practices help organizations strengthen defence supply chain security.

July 2026
10 min read

Definition: What Is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) program is a cybersecurity framework designed to help protect sensitive information across the United States defence industrial base (DIB), including Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

CMMC establishes cybersecurity expectations for defence contractors and suppliers that handle sensitive government information. However, maintaining a strong security posture requires more than completing an assessment. Organizations must understand which suppliers handle sensitive information, how those suppliers connect to their environment, what risks exist across their supply chain, and how those risks are managed over time.

For defence organizations, the challenge is becoming less about preparing for a single compliance event and more about building a repeatable supplier assurance process that provides ongoing visibility across a complex ecosystem.

CMMC Requirements Are Evolving, but Supplier Security Expectations Remain

The CMMC program continues to evolve as the Department of War reviews implementation requirements and considers ways to improve adoption across the defence industrial base.

As of July 2026, Phase I self-assessment requirements remain active, while Phase II implementation requirements have been suspended pending further review. Organizations should continue monitoring official government guidance because requirements, timelines, and implementation expectations may change.

However, the underlying responsibility remains the same: defence contractors and suppliers must protect sensitive information and demonstrate effective cybersecurity practices.

For many organizations, this creates several important questions:

- Which suppliers have access to Federal Contract Information or Controlled Unclassified Information?

- Where does sensitive information flow across the supply chain?

- Which subcontractors introduce the greatest cybersecurity exposure?

- How are supplier risks identified, tracked, and remediated?

- How can leadership demonstrate that appropriate supplier due diligence has been performed?

- These challenges exist regardless of changes to certification timelines.

Traditional Approach

Prepare for certification, complete assessments, document controls, and demonstrate compliance at a specific point in time.

Modern Supplier Assurance

Maintain continuous visibility into suppliers, dependencies, access, security posture, and changing supply chain risk.

The Real Challenge Is Supplier Visibility

Defence organizations rarely operate alone.

Modern defence programs depend on extensive networks of suppliers, subcontractors, software providers, cloud platforms, engineering partners, and specialized service providers.

Each connection introduces potential risk. A supplier may handle sensitive information, connect to internal systems, support critical operations, or rely on additional third parties that create further dependencies.

Without a structured supplier assurance process, organizations can struggle to answer basic questions about their own ecosystem.

- Has a supplier’s security posture changed since the last assessment?

- Did they introduce a new subcontractor?

- Did their certifications expire?

- Did they experience a security incident?

- Did their access to systems or information increase?

Traditional approaches built around spreadsheets, email-based assessments, and periodic reviews often struggle to provide this level of visibility.

Why Defence Supply Chains Require a Modern TPRM Approach

Third-party risk management has become increasingly important because defence supply chains contain multiple layers of dependency.

A prime contractor may rely on hundreds or thousands of suppliers. Those suppliers may depend on their own technology providers, software vendors, and subcontractors.

This creates an environment where risk can move quickly through interconnected relationships.

A strong supplier assurance program should help organizations:

- Identify suppliers based on business criticality, data access, and connectivity.

- Apply appropriate levels of due diligence based on inherent risk.

- Collect and manage cybersecurity evidence.

- Track findings and remediation activities.

- Maintain visibility into supplier changes between assessments.

- Provide audit-ready reporting when customers, regulators, or leadership require evidence.

The goal is not simply completing assessments. The goal is understanding where risk exists and making informed decisions about how that risk is managed.

Risk Extends Beyond the Direct Supplier

Prime Contractor

Direct relationship with government programs and sensitive information.

Tier 1 Suppliers

Technology providers, manufacturers, and service partners supporting operations.

Subcontractors & Dependencies

Additional providers, software components, and services that expand exposure.

The Difference Between CMMC Compliance and Third-Party Security Assurance

CMMC focuses on cybersecurity requirements related to protecting sensitive information within the defence industrial base.

Third-party security assurance focuses on the broader operational challenge of managing supplier risk throughout the relationship lifecycle.

These areas overlap, but they serve different purposes.

A CMMC assessment may evaluate whether specific cybersecurity requirements are being addressed. A supplier assurance program helps organizations continuously understand:

- Who their suppliers are.

- What information those suppliers access.

- What risks those suppliers introduce.

- What actions are required when weaknesses are identified.

- How supplier risk changes over time.

This distinction matters because a point-in-time assessment does not provide ongoing visibility into changing supplier environments.

Building a Defensible Defence Supplier Assurance Program

A mature supplier security program should begin before a contract is signed and continue throughout the entire supplier relationship.

During onboarding, organizations need to understand the supplier’s role, information access, connectivity requirements, and inherent risk.

During the supplier lifecycle, organizations should monitor changes, manage reassessments, track remediation activities, and maintain accurate records of supplier security posture.

During offboarding, organizations should confirm that access has been removed, information has been returned or deleted, and supplier relationships have been properly closed.

This lifecycle approach creates stronger defence supply chain resilience because it moves beyond isolated compliance activities and establishes continuous governance.

Onboard

Understand supplier role, access, and inherent risk.

Assess

Collect evidence and evaluate security requirements.

Monitor

Track changes, exposure, and supplier posture.

Offboard

Remove access and close relationships securely.

How TPSaaS Supports Defence Supply Chain Security

TPSaaS helps organizations build a structured third-party security assurance program by bringing supplier governance, assessments, evidence management, remediation tracking, and monitoring into a single platform.

Instead of relying on disconnected spreadsheets and manual processes, organizations can create a centralized view of supplier risk across the entire lifecycle.

TPSaaS supports defence organizations by helping teams:

- Streamline supplier intake and risk tiering.

- Manage security assessments and evidence collection.

- Track findings and remediation activities.

- Maintain supplier records and audit trails.

- Monitor changes in supplier security posture.

- Improve collaboration between procurement, cybersecurity, compliance, and governance teams.

TPSaaS is designed around a practitioner-led operating model that combines structured workflows with human expertise. Technology improves visibility and efficiency, but effective third-party risk management still requires experienced professionals who understand business context, security requirements, and organizational risk tolerance.

Building Defence Supply Chain Confidence

Strong supplier security requires more than collecting documentation. Organizations need visibility into supplier relationships, evidence, changes in security posture, and remediation activities throughout the entire lifecycle.

Supplier Risk Visibility
Evidence Management
Continuous Monitoring
Lifecycle Governance

Conclusion

CMMC requirements may continue to change, but the need for strong defence supply chain security will remain.

The organizations best positioned for the future will be those that move beyond preparing for individual assessments and build continuous supplier assurance capabilities.

Understanding supplier relationships, monitoring cybersecurity posture, managing remediation, and maintaining evidence of due diligence are becoming essential parts of modern defence operations.

CMMC may define specific cybersecurity expectations, but visibility and governance are what allow organizations to manage third-party risk effectively.

Compliance Defines Expectations. Visibility Enables Action.

CMMC provides cybersecurity expectations for protecting sensitive information across the defence industrial base. However, organizations need continuous supplier visibility to understand how risk changes across their ecosystem.

Strong supplier assurance comes from understanding relationships, monitoring changes, and maintaining evidence throughout the supplier lifecycle.

Frequently Asked Questions

What is CMMC and why does it matter for defence contractors?

The Cybersecurity Maturity Model Certification (CMMC) program establishes cybersecurity requirements designed to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) within the defence industrial base. It helps ensure contractors and suppliers have appropriate security practices when handling sensitive government information.

Does the CMMC Phase II suspension remove the need for supplier cybersecurity controls?

No. While CMMC timelines and implementation requirements may continue to evolve, defence contractors and suppliers are still responsible for protecting sensitive information and managing cybersecurity risks across their supply chain.

What is the difference between CMMC compliance and third-party risk management?

CMMC focuses on meeting cybersecurity requirements related to protecting sensitive information. Third-party risk management is the broader process of identifying, assessing, monitoring, and managing risks introduced by suppliers, subcontractors, and service providers throughout the relationship lifecycle.

Why is third-party risk management important for defence contractors?

Defence contractors often depend on complex networks of suppliers and subcontractors that may access sensitive information, connect to internal systems, or support critical operations. Without effective third-party risk management, organizations may have limited visibility into supplier cybersecurity risks.

How should defence contractors manage supplier cybersecurity risk?

A strong supplier cybersecurity program should include supplier identification, risk-based tiering, security assessments, evidence collection, remediation tracking, ongoing monitoring, and reporting. The goal is to maintain visibility into supplier risk before, during, and after a contract relationship.

How does NIST SP 800-171 relate to supplier risk management?

NIST SP 800-171 provides cybersecurity requirements for protecting Controlled Unclassified Information in non-federal systems and organizations. For defence contractors, supplier risk management helps ensure that third parties handling CUI maintain appropriate security practices.

Can CMMC certification alone eliminate third-party risk?

No. Certification and assessments provide an important view of cybersecurity practices, but supplier risk can change over time. Organizations still need processes to monitor changes, manage remediation activities, and maintain ongoing supplier oversight.

How can organizations improve visibility across their defence supply chain?

Organizations can improve visibility by maintaining accurate supplier inventories, understanding which vendors access sensitive information, applying risk-based assessments, tracking remediation activities, and implementing continuous monitoring processes.

About TPSaaS

TPSaaS helps organizations identify, assess, monitor, and manage third-party risk across the entire vendor lifecycle.

By combining automated vendor onboarding, continuous monitoring, dependency awareness, and centralized visibility, TPSaaS enables security, risk, compliance, and procurement teams to move beyond periodic assessments and gain a clearer understanding of their evolving supplier ecosystem.

Instead of reacting to third-party incidents after they occur, organizations can maintain continuous visibility into vendor relationships and make more informed risk decisions as their ecosystems change.

About the author

Founder & CEO of TPSaaS.io with 25+ years in cybersecurity, compliance, and third-party risk management. Vic built TPSaaS to make enterprise-grade third-party security smarter, faster, and accessible to all.

Vic du Toit

Founder & CEO
Book a demo