Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Small manufacturers warned to prepare for incoming cybersecurity standards; Connex supply‑chain mapping expanded

2135778 · January 21, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Beatriz Gutierrez of Comstead (Connecticut’s NIST MEP center) told lawmakers small manufacturers face an imminent DoD cybersecurity standard and that state-supported Connex profiling and MEP services can help with readiness and supply‑chain mapping.

Beatriz Gutierrez, president and CEO of Comstead (Connecticut’s NIST Manufacturing Extension Partnership center), told the Commerce Committee that cybersecurity readiness and supply‑chain visibility are urgent issues for small and medium manufacturers that supply the defense and medical sectors.

Nut graf: Gutierrez said a new round of DoD and federal cybersecurity standards — commonly described as CMMC 2.0 — is expected to become a practical requirement for suppliers and that many small firms lack the technical resources or funding to meet certification without assistance.

Gutierrez told legislators Comstead has used federal matching funds and state Manufactured Innovation Fund support to provide assessments, training and project management to help suppliers upgrade cybersecurity, adopt Industry 4.0 capabilities and move toward certifications. “The standard is coming down in February,” she said, and “some of our companies do not have the resources to do so.”

She described Connex, the supplier‑matching platform funded through MIF and administered with partners, as a work‑in‑progress that now hosts hundreds of Connecticut manufacturer profiles and has produced dozens of supplier matches. Gutierrez said Connex has recorded more than 8,844 customer engagements and that, in the most recent MIF report, the platform had created or matched 513 manufacturer profiles and reported 199 effective matches.

Gutierrez urged state officials and the federal delegation to consider funding or contract requirements that include resources to help smaller suppliers achieve cybersecurity certification. She said certification costs could reach six figures for a single small firm, while Comstead can provide assessment and technical assistance but not ongoing certification funding.

The testimony highlighted two policy implications for the committee: (1) prioritize funding and outreach so that critical defense and medical suppliers can meet new federal cybersecurity rules without leaving the Connecticut supply base, and (2) continue support for Connex and MEP technical assistance to map and stabilize the state’s supplier network.

Ending: Committee members discussed whether Connecticut could develop shared or outsourced cybersecurity back‑office services to help tiered suppliers meet certification requirements; Gutierrez and lawmakers agreed this idea merited further study.