INDUSTRY

Korean firms still lack CMMC certification as US defense market deadline looms

by
Park Hye-won
Published : July 31, 2026 - 15:00:00
    • Copy Completed!

View Korean Original

A file photo illustrating a hacking concept. [Getty Images Bank]
A file photo illustrating a hacking concept. [Getty Images Bank]

With the United States set to require Cybersecurity Maturity Model Certification (CMMC) for all companies participating in US government defense contracts, the deadline is drawing near — yet not a single South Korean firm has obtained official certification. The South Korean government also has little visibility into where domestic companies stand, and a significant number of firms have yet to act, raising urgent calls for oversight and support.

As of Friday, no South Korean company has received final third-party CMMC Level 2 certification, according to the defense industry. CMMC is a security certification the US Department of Defense plans to mandate in phases for all companies participating in US-issued defense contracts. Industry officials expect it to apply to defense weapons and parts supply projects as well as naval vessel maintenance, repair and overhaul operations.

The US Defense Department had originally planned to make Level 2 certification mandatory starting in November this year, but has temporarily suspended the requirement while it refines its assessment criteria. The industry widely expects the mandate to take effect no later than early next year. "The US government's resolve to counter China is strong, so the timeline is just as urgent for the industry," a defense company official said.

CMMC is divided into three tiers: Level 1 (basic), Level 2 (advanced) and Level 3 (expert). Level 1 involves a relatively straightforward self-assessment process followed by registration with the US government, and some South Korean companies have already completed it. The sticking point is Level 2, which applies to contracts with stricter security requirements. Companies seeking Level 2 must satisfy 110 security controls and obtain certification from an independent third-party assessment organization, known as a C3PAO — a process that can cost up to 1 billion won ($694,000) in total.

Yet nearly a year after the US government published its final CMMC rule, only a handful of large South Korean companies are actively preparing. CMMC certification is required not only of prime contractors but also of subcontractors and suppliers throughout the supply chain. Even so, the vast majority of firms have effectively put the process on hold due to cost concerns.

A representative at a major domestic consulting firm supporting large South Korean defense and shipbuilding companies with CMMC certification said a small company with just four employees had been notified by the US government that it was subject to Level 2 certification, but could not afford the hundreds of millions of won in consulting fees. "Inquiries from small and midsize defense firms are surging, but only five companies have actually started the consulting process," the representative said.

Overseas companies, by contrast, are moving quickly. According to data published by The Cyber AB, the official CMMC accreditation body, the US Defense Department has already issued 1,666 final Level 2 certificates. Among the notable recipients, the US subsidiary of German technology company Siemens received Level 2 certification in July, and the US subsidiary of Rheinmetall, Germany's largest defense company, received it in April.

The South Korean government says it plans to support CMMC-targeted companies through consulting cost subsidies via the Export-Import Bank of Korea and local government consulting programs. However, it has no concrete picture of where domestic companies actually stand on CMMC certification. "Since this falls within the private sector, the government does not separately track the status," a Defense Acquisition Program Administration official said. An industry official called for a more systematic approach: "As South Korean companies aggressively push into the US defense market in line with the growing stature of K-defense, the government needs to provide structured support to ensure they are not tripped up by the certification hurdle."


klee@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ