NFFS, together with the American Foundry Society, North American Die Casting Association, and Steel Founders’ Society of America, has submitted formal comments calling for meaningful reform of the Cybersecurity Maturity Model Certification (CMMC) program.
The metalcasting industry strongly supports protecting Federal Contract Information (FCI), Controlled Unclassified Information (CUI), and other sensitive defense information. However, the current cost, complexity, and administrative burden of CMMC and NIST SP 800-171 can create significant barriers for small and medium-sized manufacturers seeking to participate in the defense market.
The core issue: Cybersecurity requirements should strengthen the Defense Industrial Base—not create unnecessary barriers that discourage capable domestic manufacturers from participating.
Why This Matters to NFFS Members
For smaller foundries, CMMC compliance is more than an IT issue—it can become a business decision about whether defense work is economically viable at all.
80%
Approximately 80% of U.S. metalcasters employ fewer than 100 people, and many operate with limited administrative and IT resources.
Yet these companies manufacture critical components for weapons systems, ships, aircraft, vehicles, electronics, radar systems, infrastructure, and other military applications.
Key areas of concern for smaller manufacturers include:
1
Consulting & Expertise
Third-party consulting and specialized cybersecurity expertise.
2
Technology Costs
IT infrastructure, security software, and implementation investments.
3
Certification Costs
Assessment and certification expenses that can be difficult to absorb.
4
Staff & Documentation
Management time, evidence collection, policies, and administrative requirements.
5
Lost Opportunities
Defense work that may be avoided because the cost of compliance outweighs the opportunity.
What the Metalcasting Industry Is Recommending
The comments urge policymakers to move toward a more scalable, risk-based and practical cybersecurity framework that protects sensitive information while recognizing the operational realities of small manufacturers.
1
Establish a Tiered, Risk-Based Compliance Model
Requirements should reflect the sensitivity and quantity of information a contractor actually handles.
2
Create a Simplified Pathway for Small Businesses
Focus requirements on cybersecurity controls that provide meaningful risk reduction while reducing duplicative documentation.
3
Reduce Reliance on Mandatory Third-Party Certification
Use self-attestation, targeted government verification, automated validation, or risk-based audits where appropriate.
4
Recognize Commercial Cybersecurity Solutions
Properly configured commercial technologies and managed services should be recognized when they meet defined security outcomes.
5
Allow Reasonable Remediation
Companies demonstrating substantial compliance should have opportunities to correct lower-risk deficiencies without immediately losing eligibility for defense work.
6
Create a Practical On-Ramp for New Defense Suppliers
Manufacturers should be able to progressively increase their cybersecurity capabilities as their defense participation and exposure to sensitive information grow.
Cybersecurity Should Strengthen the Industrial Base
The central message from NFFS and its industry partners is straightforward: strong cybersecurity and a strong domestic manufacturing base should go hand in hand.
CMMC reform represents an opportunity to create a framework that holds contractors accountable for protecting government information while giving small manufacturers a clear, affordable and scalable path to compliance.
The industry's recommended approach emphasizes measurable risk reduction, commercial technology, simplified requirements, appropriate self-attestation, targeted verification, reasonable remediation and continuous improvement.
Read the Full Industry Comments
NFFS will continue to advocate for policies that protect national security while ensuring that capable U.S. foundries can remain competitive and participate in the Defense Industrial Base.
READ THE FULL INDUSTRY COMMENTS
Stay Connected
If you'd like to learn more about the NFFS Government Affairs Committee and its advocacy efforts, please contact Jerrod Weaver.
Foundry Industry Comments on Reforming CMMC
Metalcasting Industry Calls for Practical CMMC Reform
NFFS and its industry partners are advocating for a cybersecurity framework that protects sensitive defense information while keeping defense participation practical for small and medium-sized manufacturers.
NFFS, together with the American Foundry Society, North American Die Casting Association, and Steel Founders’ Society of America, has submitted formal comments calling for meaningful reform of the Cybersecurity Maturity Model Certification (CMMC) program.
The metalcasting industry strongly supports protecting Federal Contract Information (FCI), Controlled Unclassified Information (CUI), and other sensitive defense information. However, the current cost, complexity, and administrative burden of CMMC and NIST SP 800-171 can create significant barriers for small and medium-sized manufacturers seeking to participate in the defense market.
Why This Matters to NFFS Members
For smaller foundries, CMMC compliance is more than an IT issue—it can become a business decision about whether defense work is economically viable at all.
Yet these companies manufacture critical components for weapons systems, ships, aircraft, vehicles, electronics, radar systems, infrastructure, and other military applications.
Key areas of concern for smaller manufacturers include:
Consulting & Expertise
Third-party consulting and specialized cybersecurity expertise.
Technology Costs
IT infrastructure, security software, and implementation investments.
Certification Costs
Assessment and certification expenses that can be difficult to absorb.
Staff & Documentation
Management time, evidence collection, policies, and administrative requirements.
Lost Opportunities
Defense work that may be avoided because the cost of compliance outweighs the opportunity.
What the Metalcasting Industry Is Recommending
The comments urge policymakers to move toward a more scalable, risk-based and practical cybersecurity framework that protects sensitive information while recognizing the operational realities of small manufacturers.
Establish a Tiered, Risk-Based Compliance Model
Requirements should reflect the sensitivity and quantity of information a contractor actually handles.
Create a Simplified Pathway for Small Businesses
Focus requirements on cybersecurity controls that provide meaningful risk reduction while reducing duplicative documentation.
Reduce Reliance on Mandatory Third-Party Certification
Use self-attestation, targeted government verification, automated validation, or risk-based audits where appropriate.
Recognize Commercial Cybersecurity Solutions
Properly configured commercial technologies and managed services should be recognized when they meet defined security outcomes.
Allow Reasonable Remediation
Companies demonstrating substantial compliance should have opportunities to correct lower-risk deficiencies without immediately losing eligibility for defense work.
Create a Practical On-Ramp for New Defense Suppliers
Manufacturers should be able to progressively increase their cybersecurity capabilities as their defense participation and exposure to sensitive information grow.
Cybersecurity Should Strengthen the Industrial Base
The central message from NFFS and its industry partners is straightforward: strong cybersecurity and a strong domestic manufacturing base should go hand in hand.
CMMC reform represents an opportunity to create a framework that holds contractors accountable for protecting government information while giving small manufacturers a clear, affordable and scalable path to compliance.
The industry's recommended approach emphasizes measurable risk reduction, commercial technology, simplified requirements, appropriate self-attestation, targeted verification, reasonable remediation and continuous improvement.
Read the Full Industry Comments
NFFS will continue to advocate for policies that protect national security while ensuring that capable U.S. foundries can remain competitive and participate in the Defense Industrial Base.
READ THE FULL INDUSTRY COMMENTSStay Connected
If you'd like to learn more about the NFFS Government Affairs Committee and its advocacy efforts, please contact Jerrod Weaver.
Jerrod@nffs.org
Categories
Most Recent Posts