Foundry Industry Comments on Reforming CMMC

Posted By: Jerrod Weaver Government Affairs, NFFS,
NFFS Government Affairs

Metalcasting Industry Calls for Practical CMMC Reform

NFFS and its industry partners are advocating for a cybersecurity framework that protects sensitive defense information while keeping defense participation practical for small and medium-sized manufacturers.

NFFS, together with the American Foundry Society, North American Die Casting Association, and Steel Founders’ Society of America, has submitted formal comments calling for meaningful reform of the Cybersecurity Maturity Model Certification (CMMC) program.

The metalcasting industry strongly supports protecting Federal Contract Information (FCI), Controlled Unclassified Information (CUI), and other sensitive defense information. However, the current cost, complexity, and administrative burden of CMMC and NIST SP 800-171 can create significant barriers for small and medium-sized manufacturers seeking to participate in the defense market.

The core issue: Cybersecurity requirements should strengthen the Defense Industrial Base—not create unnecessary barriers that discourage capable domestic manufacturers from participating.

Why This Matters to NFFS Members

For smaller foundries, CMMC compliance is more than an IT issue—it can become a business decision about whether defense work is economically viable at all.

80%
Approximately 80% of U.S. metalcasters employ fewer than 100 people, and many operate with limited administrative and IT resources.

Yet these companies manufacture critical components for weapons systems, ships, aircraft, vehicles, electronics, radar systems, infrastructure, and other military applications.

Key areas of concern for smaller manufacturers include:

1

Consulting & Expertise

Third-party consulting and specialized cybersecurity expertise.

2

Technology Costs

IT infrastructure, security software, and implementation investments.

3

Certification Costs

Assessment and certification expenses that can be difficult to absorb.

4

Staff & Documentation

Management time, evidence collection, policies, and administrative requirements.

5

Lost Opportunities

Defense work that may be avoided because the cost of compliance outweighs the opportunity.

What the Metalcasting Industry Is Recommending

The comments urge policymakers to move toward a more scalable, risk-based and practical cybersecurity framework that protects sensitive information while recognizing the operational realities of small manufacturers.

1

Establish a Tiered, Risk-Based Compliance Model

Requirements should reflect the sensitivity and quantity of information a contractor actually handles.

2

Create a Simplified Pathway for Small Businesses

Focus requirements on cybersecurity controls that provide meaningful risk reduction while reducing duplicative documentation.

3

Reduce Reliance on Mandatory Third-Party Certification

Use self-attestation, targeted government verification, automated validation, or risk-based audits where appropriate.

4

Recognize Commercial Cybersecurity Solutions

Properly configured commercial technologies and managed services should be recognized when they meet defined security outcomes.

5

Allow Reasonable Remediation

Companies demonstrating substantial compliance should have opportunities to correct lower-risk deficiencies without immediately losing eligibility for defense work.

6

Create a Practical On-Ramp for New Defense Suppliers

Manufacturers should be able to progressively increase their cybersecurity capabilities as their defense participation and exposure to sensitive information grow.

Cybersecurity Should Strengthen the Industrial Base

The central message from NFFS and its industry partners is straightforward: strong cybersecurity and a strong domestic manufacturing base should go hand in hand.

CMMC reform represents an opportunity to create a framework that holds contractors accountable for protecting government information while giving small manufacturers a clear, affordable and scalable path to compliance.

The industry's recommended approach emphasizes measurable risk reduction, commercial technology, simplified requirements, appropriate self-attestation, targeted verification, reasonable remediation and continuous improvement.

Read the Full Industry Comments

NFFS will continue to advocate for policies that protect national security while ensuring that capable U.S. foundries can remain competitive and participate in the Defense Industrial Base.

READ THE FULL INDUSTRY COMMENTS

Stay Connected

If you'd like to learn more about the NFFS Government Affairs Committee and its advocacy efforts, please contact Jerrod Weaver.

Jerrod Weaver NFFS Executive Director
Jerrod@nffs.org