Issue link: https://iconnect007.uberflip.com/i/1546025
26 SMT007 MAGAZINE I AUGUST 2026 F E AT U R E A RT I C L E BY DA N I E L P O RTO N A N D A L E X DA N OV I C H When the U.S. Department of Defense began signaling that cybersecurity self-attestation would eventually give way to mandatory third-party certification, San Francisco Circuits decided to get ahead of it. That decision, made in 2019, shaped everything that followed: the systems we imple- mented, the partners we engaged, and the audit we ultimately passed. This is the story of that process, including what worked, what added complexity, and what we'd tell other EMS companies and defense suppliers that are now facing the same path. Defense contractors that handle Controlled Unclassified Information (CUI) are now required to hold CMMC Level 2 certification to win new DoD work, and self-attestation is no longer accepted. Level 2 requires full implementation of all 110 security practices aligned to NIST SP 800-171, covering every organization in the Defense Indus- trial Base supply chain that processes, stores, or transmits CUI. Why It Matters for Defense Programs For our customers working on defense and govern- ment programs, it's not whether their PCB supplier can build the board, but whether that supplier can be trusted with the data surrounding it. Design files, program specifications, and contract infor- mation flowing through a supplier's systems are part of the same security perimeter that CMMC is designed to protect. How San Francisco Circuits Achieved CMMC Certification While CMMC certification requirements have been paused by the U.S. DoW for further consideration and a new timeline, what follows is still relevant and applicable information.

