New York's small aerospace and defense suppliers take protecting sensitive defense information seriously. Nobody has more at stake in the security of the defense industrial base than the companies whose livelihoods depend on it. But cybersecurity mandates written for prime contractors with dedicated IT and compliance departments land very differently on a 15-person machine shop — and when compliance costs exceed what a small supplier can bear, the result is not better security. It is fewer suppliers.
Defense suppliers that handle controlled unclassified information are subject to the cybersecurity requirements of NIST SP 800-171 — 110 security controls — and, with the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) program now phasing into contracts, many will need formal third-party assessment to keep the work they already do. For a small shop, the price tag includes gap assessments, new hardware and software, consultants, documentation, ongoing monitoring, and assessment fees — costs that routinely run well into six figures before the first certified part ships. Primes flow these requirements down the supply chain regardless of a supplier's size, the sensitivity of the data it actually touches, or its ability to pay.
Long Island's aerospace ecosystem is built on small, specialized, family-owned manufacturers. If disproportionate compliance costs push even a fraction of them out of defense work — or out of business — the capability does not come back. The supply chain consolidates, prices rise, and New York loses exactly the high-value manufacturing base that national defense readiness depends on.
Our headline proposal, submitted formally to the Department of War's CMMC Reform Task Force in August 2026, is design-based certification: let a small manufacturer demonstrate compliance by adopting a pre-approved reference design that meets or exceeds NIST SP 800-171, and verify conformance to the design — exactly the way the flight-critical parts we machine are already certified. Approve good designs once; adopt them many times. The six-figure one-off assessment disappears, the barrier to entering the defense industrial base drops, and security improves because sound designs spread instead of unique ones being improvised shop by shop.
Read the full proposal » — the burden in the Department's own numbers, the boundary-protection architecture, the fixed-function hardware principle, and the reforms deployable inside the Task Force's 60-day window, with LIFT's complete RFI response as a downloadable PDF.
Around that centerpiece: requirements proportionate to the sensitivity of the information a supplier actually handles; ground-based, on-premises designs on equal footing with cloud subscriptions; shared services and state-supported resources that let small suppliers meet real standards affordably; realistic phase-in timelines that recognize assessor capacity; a good-faith safe harbor for honest self-assessment; and clear, stable guidance — a small shop cannot re-architect its network every time the rules change.
Our position in one sentence: protect the defense industrial base's information and its suppliers — because a security regime that bankrupts the supply chain defends nothing.