This week we sit down with Supply Chain Director Bo Birdwell to discuss Elbit America’s latest open letter to suppliers regarding CMMC. Elbit’s letter doesn’t mince words: CMMC is here and the time to act is now. Bo not only walks us through the perspective of a major prime contractor on cost, timelines, outsourced services, CMMC Level 3, and more – he also drops a ton of helpful tips for current and prospective suppliers.
Transcript
[Music] All right, folks. It is January of 2026, and if you don’t know, Elbit Systems of America is the billion-dollar subsidiary of global defense tech giant Elbit Systems. Elbit America, as it’s known, has over 3,300 employees. They operate in 16 locations across 12 states. They partner with more than 70 different research labs, and they maintain a massive supply chain chock full of controlled unclassified information related to every warfighter and weapon system you can possibly imagine. When they speak, people listen. And on January 9th of 2026, they released a second open letter to their suppliers regarding CMMC. And they don’t mince words. According to the letter, CMMC is no longer an impending requirement. It is actively being enforced and flowed down. And according to Elbit, our buyers will not issue purchase orders to suppliers who fail to meet contractual CMMC flowdown requirements. Today we’re joined by Elbit America’s supply chain director, former deputy CISO, and lead CCA, the great and powerful Bo Birdwell, to walk us through what’s happening. Everybody give it up for Bo. Yeah. What’s up?
Hey, Jacob. Thank you for having me on. And Jason, thank you as well. I’m really excited. I’ve been listening to your podcast since it started back when it was three hours. Oh, man. You remember the three-hour days. I do remember. Amazing.
All right. Well, let’s just jump into it. Bo, maybe tell us about yourself, your role at Elbit, and what’s going on with these open letters. You are not your average supply chain director by any stretch of the imagination. You’ve been around this space for a long time. You walk the walk, you talk the talk. Tell us about yourself.
I will. And I hope one of the things you all see is that this ain’t my first rodeo. I’m not all hat and no cattle. I’ve been there, done that, and I have the t-shirts to show it. I’ve been through three DIBCAC assessments and two CMMC assessments because of a subsidiary. We’ve actually been there and done that, and I’m really hoping we can help people. First, I have three big points I’m going to circle around all day long. One, I’m not here to sell anything. I’m here so I can buy stuff. I hope people listening believe that I am reaching out today to help build my rolodex, and yes, I’m old enough to know what that is. It’s about knowing who I can work with. That’s message number one. Message number two is that a rising tide lifts all ships. We have the ability to share our experiences so that, as a friend of mine at Boeing says, we’re all competitive friends. We all want to protect government data. Many of us are veterans. We take this personally. We want to protect our technical advantage. There are a lot of industries and companies willing to share lessons learned. That’s a huge point. The last one is that we owe a big thanks to the Department of War. They’ve given us transparency, warning, and time. Now that the mountains are coming into focus and we can feel the incline, this is not out of the blue. Most big primes took years to solve this. We didn’t have to do massive budget increases. We did low double digits each year over three to four years to address requirements. When you compress that into 12 months or less, the numbers get hard to swallow. They did everything possible not to surprise us. Now we’re addressing the mountain of getting our supply chain in line. It’s a giant mountain. We’re not all climbing the same face. Some things are universal, some are company-specific depending on size. Those are the bottom-line things I hope everyone takes from this.
Getting to the open letters, your supplier cybersecurity page is one of the most concise I’ve seen from a major prime. Props to you for putting that information out there. My big takeaway is that CMMC is real. Your second letter opens by saying Elbit America got a requirement for CMMC Level 2 certification just 32 days into the phased rollout. This is not theoretical. How are suppliers reacting?
Over two weeks, I was in one-on-one communication with over 600 suppliers. Many are now dealing with the consequences of deferment decisions. Some are taking a very capitalistic view: if you want us to get there, you should help us. That’s a business decision every higher-tier contractor has to address. If key suppliers aren’t certified, you either help them or requalify someone else. Requalifying is not free and takes time. Most big companies are already looking at Level 3. It’s not aspirational. Many are heading there in the next 12 to 18 months because we can read the tea leaves.
Yes, a company that’s ready is valuable, but it’s nuanced. This isn’t Lego pieces. You can’t just swap suppliers with a control-F. Requalifying a supplier is a multimonth process. Some primes may focus on acquisitions of critical suppliers. Others may invest in helping them get compliant. But no one is doing that lightly. And there’s a chicken-and-egg dilemma. You can’t guarantee work until you win a contract, and you can’t win the contract without the supply chain.
Later this year, we’ll start requiring Level 1 of suppliers that aren’t handling CUI. The muscle movements are similar. The supplier actions are easier for Level 1, but from our side, the processes are similar. We’re implementing incrementally, like we did internally, instead of flipping everything at once and breaking things. We had one control take over 12 months to implement because we didn’t want to break stuff. FIPS is a great example. You can either fix apps over time or break a lot of things turning it on overnight.
Some suppliers say they’ll wait until business decreases before acting. That amplifies risk. So we’re building a bench. We’re opening the floodgates and talking to new companies. We’re not ready to promise work, but we’re onboarding conversations. We’re preparing for adult decisions. There’s a perception the Department of War will blink. I don’t think that’s wise. Many primes are now actively looking at alternatives.
Regarding government conversations, maturity varies. One contracting officer told us, “I don’t know what this CMMC thing is, but I need you to have it.” There’s variation in understanding, but broadly, they know it’s coming and expect compliance.
On cost, if you spread it over years, you’re looking at low double-digit increases. Compress it, and those numbers climb. SaaS providers not being FedRAMP creates friction. FedRAMP equivalency every 12 months is expensive. But if you’re putting CUI in the cloud, FedRAMP or equivalent is table stakes.
Small entities might implement for modest cost, especially engineering firms or consultants using VDI solutions. But manufacturers integrating ERP, MES, SolidWorks, and enterprise tools face more complexity. Pushback often targets CMMC as the visible object, even though it’s about implementing the controls. If you seek assistance, ensure your RPO has certified CMMC professionals. Many C3PAOs also provide advisory services, but not both for the same client due to ethics rules.
With MSPs, shared responsibility means almost everything is shared. Don’t assume you can punt responsibility. I recommend MSPs that are CMMC certified. Start by sending someone in your organization through CCP training. Evaluate your MSP’s knowledge. Build a roadmap. Talk to leadership in business terms: cost, time, capital versus opex.
Assessment lessons learned: documentation is as important as implementation. Most determination statements require both. Don’t outsource documentation and insource implementation without alignment. We provided over 10,000 pages of documentation, structured clearly with references. We wrote security plans to be shareable without disclosing tool names. We conducted annual self-assessments as required by DFARS 7012 and documented all 320 determination statements with screenshots and references. Auditors aren’t out to get you. Show you’re meeting the intent. Know the assessment guide.
On minimizing CUI flowdown, no prime wants to flow CUI unnecessarily. If we say you need Level 2, there’s a reason. We cannot issue a PO without validating compliance. Enlightened self-interest drives this. We’re not going to accept liability for the entire supply chain. Mailing hard copy to avoid compliance isn’t viable for us as a manufacturing company.
Level 3 will be a compelling conversation by 2027. No one wants to flow it down unless absolutely required. Some companies are pursuing enterprise approaches; others enclaves. It’s program-specific and risk-based.
Practical guidance: if you haven’t started, start. Invest in training. Evaluate your MSP. Build a roadmap. Speak business language. Critical suppliers may warrant closer partnership, but not every supplier is critical.
Closing thoughts: this is the real deal. We’re in phased rollout. It’s happening quickly. My request is simple. If you haven’t started, start. The longest journey still requires the same amount of work. Please start.
All right, everybody. Thanks for tuning in. Make sure you like and subscribe, and we’ll see you next week. [Music]
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.



