When the Government Stops Checking
As the US government stresses the importance of quality and cybersecurity, changes to independent certification and auditing requirements raise questions about whether its actions match its warnings.
Sometimes I just shake my head and say, “Really?” In recent years, I seem to be doing that a lot more often.
Product quality, particularly in high-reliability products, has long ranked among the most important goals for manufacturing companies. W. Edwards Deming helped establish modern thinking about manufacturing quality by emphasizing statistical methods, process improvement and the use of data to improve manufacturing outcomes.
That thinking helped drive the concept of certifying processes, products and quality systems so customers could have confidence that manufacturers had verified and validated the products they delivered.
Today, virtually every industry uses certification programs to verify product quality and demonstrate that products will consistently perform their intended functions. Manufacturing companies encounter many of these programs, including ISO, AS, IATF and Nadcap certifications.
The defense electronics industry has also historically relied on military specifications and qualification programs to demonstrate that products supplied to the US military meet demanding requirements. Standards tailored to specific industries, manufacturing processes and end markets underpin all these programs.
More recently, growing concerns about data security in an increasingly competitive world have driven additional requirements. In the United States, the NIST SP 800 series has played an important role in establishing cybersecurity requirements and guidance. Companies and governments understandably do not want their intellectual property to end up in the hands of competitors, whether those competitors are businesses or foreign governments.
Certification programs certainly create challenges, particularly for smaller companies. Compliance costs money, consumes resources and creates plenty of complaints. But the benefits can justify that effort and expense. Strong certification systems can provide assurance that manufacturers maintain product quality, manage processes properly, improve safety, protect the environment and secure sensitive data.
One of the strongest proponents of quality and security requirements has historically been the US government.
Over decades, the government has established requirements including the FAR, DFARS, military specifications and, more recently, the Cybersecurity Maturity Model Certification (CMMC). These requirements seek to address product quality, business practices, supply chain integrity and data security.
Some rely on companies to assess and attest to their own compliance. Others require independent audits, which provide a much stronger level of assurance. Historically, government qualification programs have included outside oversight, while CMMC introduced independent assessments for companies handling certain sensitive Department of Defense information.
For the past decade, and particularly during the past several years, the US government has repeatedly emphasized the critical importance of ensuring that military equipment and supplies come from reliable sources and meet demanding standards.
At the same time, federal officials have repeatedly warned businesses about the threat of cyberattacks and stressed the need for stronger cybersecurity and demonstrable compliance with requirements such as NIST SP 800-171.
All of which leads me to another moment when I shake my head and ask, “Really?”
Recent changes to longstanding military qualification programs have reduced some of the government’s direct auditing and qualification activities, shifting more responsibility toward manufacturers. That represents a significant change from a system in which independent oversight provided additional assurance that suppliers met the government’s requirements.
If independent verification mattered enough to require it before, why should self-assessment provide the same confidence now?
That question becomes even more important when we look at cybersecurity.
CMMC has already gone through multiple rounds of revision, review and delayed implementation as the government has tried to balance cybersecurity requirements against the compliance burden placed on the defense industrial base. Each additional review may have legitimate reasons behind it, particularly when smaller manufacturers face significant costs. But every delay also pushes back the day when the government can consistently verify whether contractors have implemented the protections it says are critical.
That creates a contradiction that the government needs to address.
On one hand, federal officials tell the defense industrial base that product quality, supply chain integrity and cybersecurity have never mattered more. On the other, changes that reduce independent verification or delay certification requirements can send the opposite message.
Manufacturers notice that contradiction.
I understand the argument for reducing unnecessary compliance burdens. No company wants to spend money satisfying requirements that add paperwork without improving products or security. Small manufacturers in particular cannot absorb endless compliance costs without consequences.
But if a requirement protects something important enough to mandate in the first place, the government should think carefully before weakening the mechanism that verifies compliance.
Otherwise, I find myself shaking my head again and asking, “Really?”
If government rhetoric continually warns industry about serious quality and cybersecurity threats while government actions appear to reduce the mechanisms intended to address those threats, companies may eventually stop treating the warnings with the urgency they deserve.
That is what worries me most.
We all know the story of the boy who cried wolf. If we hear the warning often enough without seeing actions that match it, eventually people stop responding. And when the wolf finally does show up, we may discover that no one prepared for it.End of article content
Peter Bigelow has more than 30 years’ experience as a PCB executive, most recently as president of FTG Circuits Haverhill; peterbigelow@msn.com.

