Assurance does not travel
THREE ALLIED REGIMES, NO MUTUAL RECOGNITION, AND NOW NO COMMON DIRECTION EITHER.
A company building a component for a joint programme across the UK, the US and Australia will be asked to demonstrate its security posture three times.
Three regimes. Three evidence formats. Three assessment clocks. Three sets of consultants.
The controls underneath are largely the same. Access control, asset management, incident response, patch and vulnerability handling, personnel screening, flow-down to subcontractors. Any competent security engineer moving between the three documents would recognise the same content rearranged.
The evidence is not portable. And as of this week, the three regimes are no longer even moving in the same direction.
Three regimes, one supplier
In the UK, Secure by Design has been mandated across Defence since July 2023 and sits within JSP 440. It covers the definition, acquisition, development, maintenance and disposal of information-based capability, explicitly including capability delivered by suppliers, and it displaces the older model of one-off accreditation in favour of continuous risk management.
Running alongside it, the Defence Cyber Protection Partnership's Cyber Security Model flows specific requirements into contracts and down the supply chain. CSMv4 arrived on 3 December 2025, replacing five risk profiles with four levels and re-anchoring on Defence Standard 05-138 Issue 4. Existing CSMv3 assessments do not transfer. A subsequent clarification extended scope from a project's data to the supplier as a legal entity and its business-critical operations, which is a considerably larger claim on a small company than a segregated project enclave ever was.
In Australia, the Defence Industry Security Programme operates as entity-level membership under the Defence Security Principles Framework, assessed across four domains covering governance, personnel, physical and information security. Members select a level per domain from Entry through to Level 3, mapped to the classification of information handled, with the governance level required to match or exceed the highest held elsewhere. Since November 2025, all members have been required to reach and maintain the ASD Essential Eight at Maturity Level 2 across the corporate environment used for Defence business.
In the US, the CMMC acquisition rule took effect on 10 November 2025, giving contracting officers the DFARS clause needed to make certification a condition of award. Level 2 requires evidencing all 110 NIST SP 800-171 controls.
Read those dates together. Three allied nations independently tightened entity-level supply chain security requirements within roughly three weeks of each other in late 2025, using three different control catalogues, with no mechanism between them for recognising each other's work.
Then one of them stopped
On 13 July the Department of War suspended Phase 2 of the CMMC rollout, the stage that would have required third-party certification by an authorised assessor from 10 November 2026. Later phases are frozen with it. Phase 1 self-assessment obligations remain in place, as do the underlying DFARS safeguarding requirements, and a reform task force has been given sixty days to recommend a way forward.
The stated reasons were assessor capacity and the burden the programme was placing on small and non-traditional suppliers.
Both are real, and the capacity problem in particular was arithmetic rather than opinion. As of the March 2026 Cyber AB town hall, roughly 103 organisations were authorised to conduct assessments, and around 178 new Level 2 certifications were issued that month, against a population the Department estimated at 76,000 to 80,000 organisations requiring them. At that run rate the queue clears in something on the order of three decades. Capacity was always going to have to rise by close to an order of magnitude, and assessor capacity does not scale quickly, because assessors have to be trained, authorised and kept honest.
It is worth being precise about what this is. It is not a retreat from the security baseline, which is unchanged, and the obligation to protect the data has not moved. It is an admission that the verification mechanism was costing more than it was returning at the small end of the supplier base.
Which is the correct diagnosis, arrived at three years late, and it fixes the problem for exactly one of the three regimes.
Relief is national, burden is international
A supplier working only in the American market has just had a planning problem removed.
A supplier on a trilateral programme has had one added.
Nothing about the suspension touches CSMv4, which did not pause. Nothing about it touches DISP, which did not pause. The company that had sequenced its compliance investment across three regimes now holds one that is frozen mid-implementation and under review, and two that are proceeding on their original timelines.
That is worse than three regimes moving in parallel, because parallel at least permits planning. A regime under review cannot be planned against at all. Investment made now against a programme whose structure is being reconsidered may be evidence in nine months or may be sunk cost, and no supplier can tell which from the outside.
The tension this exposes runs through all three countries. The UK, while tightening, has committed to increasing SME spend by £2.5 billion by May 2028 from a base of roughly four per cent of direct MOD spend. Australia has raised its floor to Essential Eight Maturity Level 2 for every member regardless of size. The US has just concluded that its verification burden was pushing exactly those suppliers out.
Every increment of assurance adds fixed cost to entry. Fixed costs are close to irrelevant for a prime with a compliance function and material for a company of thirty people, which is the profile of supplier all three governments say they want more of.
None of which is an argument for weaker requirements. Supply chain compromise is a demonstrated attack path and the case for raising the floor is sound. It is an argument about duplication, which is a different thing. A supplier that has evidenced access control once has not become more secure by evidencing it twice in a different template.
Where it concentrates
Joint development is where this lands hardest.
When two or three nations co-develop a capability, security requirements are among the last things harmonised and frequently are never harmonised at all. Each side flows down its own regime through its own contracting chain. The supplier in the middle holds all of them, reconciles them and pays for them. No government obtains more assurance from the second copy than it obtained from the first.
Interoperability discussion in this space is dominated by the technical layer. Data formats, interfaces, waveforms, standards for exchange between systems. That work matters and it is difficult.
For a small supplier with something a programme actually needs, the binding constraint is more often administrative. It is not that the technology cannot interoperate. It is that the company cannot afford to be assured three times, and so does not bid.
That is a capability outcome arrived at through a procurement mechanism, which is the least visible way to lose something.
The open door
Recognition does not mean harmonisation. The three regimes rest on different legal bases, different definitions of protected information and different national risk appetites. They will not merge, and proposals assuming they might are not serious.
What is achievable is evidence reuse. A published control mapping between the regimes. A defined mechanism for one to accept another's assessment artefacts as partial evidence, with an explicit delta covering what remains to be shown. An agreed treatment of assessment currency, so a recent assessment under one scheme is not simply discarded by the next.
This is dull administrative work that costs no reduction in rigour and removes a large fraction of the duplicated effort. Mutual recognition of conformity assessment is well established in other regulated domains and there is no structural reason it cannot be adapted here.
What has been missing is not a method but an owner, because the problem sits between departments, between nations and between the security and procurement functions inside each. That is a reliable formula for something remaining everybody's concern and nobody's responsibility.
A sixty-day review is the rare moment when that changes. Structural questions get asked of programmes under reconsideration and almost never of programmes running to plan. If mutual recognition is ever going to be put on the table, it is put there now, into an open review, by the allies who would benefit from it.
The frameworks had already converged on substance and diverged on process.
They have now diverged on direction as well.
For a prime, that is a line in the overhead.
For the supplier the programme most wants to reach, it is a decision about whether to bid at all.