Part of our work on aerospace and defense
Aerospace and Defense
The Certification Question Most Defense Subcontractors Answer Too Late
Big Sky Consulting Group · September 21, 2026 · 7 min read

The question is not which certifications. It is whose calendar.
A shop owner asks us which certifications they should pursue, and the question is almost always framed as a shopping list. AS9100, Nadcap, CMMC Level 2, maybe ISO 13485 if there is a medical side of the business. They want to know which ones open the most doors.
That is the wrong axis. The certifications you need are already determined by the work you have quoted and the customers you have. What is not determined, and what almost nobody tracks, is when each one has to be in hand. That date does not come from a standard or a regulator. It comes from a contract clause in a purchase order you signed, or from a supplier portal questionnaire that arrives one Tuesday with a hard deadline on it.
By the time the questionnaire arrives, the decision has already been made for you. The only remaining question is whether the lead time fits, and usually it does not.
Certification is a lead time, not a purchase
Every certification in this space is a calendar item measured in quarters. That is the single fact that turns a checklist into a sequencing problem.
Nadcap is the clearest example. The Performance Review Institute describes a typical first-time accreditation as roughly six to twelve months end to end: registration, two to four months of preparation and self-audit, a scheduling window, the on-site audit itself, then one to three months closing nonconformances before a Task Group reviews the file. Audits are commonly booked months out. PRI's own guidance is to start planning as much as a year ahead.
CMMC Level 2 is worse right now, for a different reason. The certified assessor market is too small for the demand. As of the February 2026 Cyber AB town hall there were 98 authorized C3PAOs and 748 credentialed assessors against a DoD projection of more than 80,000 contractors eventually needing third-party assessment. Practitioners are reporting booking windows past a year. You cannot solve that with budget. There is no premium freight on an audit schedule.
So the honest shape of the answer is not "which certifications" but "count backward from the earliest date a customer can bind you, and see what still fits." Most shops have never run that arithmetic, because the certifications live with the quality manager and the contract dates live with whoever handles the customer portal, and those two people talk when something goes wrong.
AS9100 is company-wide. Nadcap is not. That difference costs jobs.
The most expensive misunderstanding we see is treating these as two tiers of the same thing.
AS9100 certifies a quality management system, and it covers the company. Nadcap accredits a specific special process at a specific facility: heat treat, nondestructive testing, chemical processing, welding, each one audited on its own. Accreditation in one commodity does not extend to another. It does not extend to the same process at your second building.
The practical consequence is that a shop can be fully certified and still unqualified for the exact job it just quoted. You hold AS9100. You hold Nadcap for NDT. The print calls for a heat treat you do in-house and have never had accredited. You are not a little bit short. You are out, unless you can outsource that operation to an accredited source, which changes your cost and your flow time and frequently your margin on a job you already priced.
This is the version of the problem that shows up at quote review, and it is worth building the check there rather than at first article. A print-level check on special processes against your actual accreditation scope is a small piece of process discipline that prevents a category of surprise nothing downstream can fix. We see the same pattern in AS9100 document control: the rule-driven, checkable parts of quality are the last ones anyone systematizes, because the person who owns the risk owns it personally rather than procedurally.
This is the general shape of the problem. Which parts apply to your process depends on answers only your systems can give.
Put us on it, from $5,000Flowdown means your deadline belongs to your customer
CMMC has made this point impossible to miss, and it is worth understanding as a general principle rather than a cybersecurity story.
Primes are responsible for flowing requirements down to their subcontractors. That means the date that governs a small shop is set in its customer's contract, not by the government's own phase-in schedule. In April 2026, L3Harris Missile Solutions told suppliers it wanted proof of Level 2 certification by July 30, 2026. That was the company acting as a customer, on its own authority, on a timeline it chose.
Then in July 2026 the Department of War suspended CMMC Phase 2 and opened a sixty-day review. A lot of shops read the headline and stood down.
Watch what actually happened to the obligations. DFARS 252.204-7012 still applies. Self-assessment scores still have to be posted to SPRS with an annual executive affirmation. L3Harris did not withdraw its July date. Elbit America issued a notice days after the pause telling suppliers to confirm the applicable requirement with their buyer before canceling a C3PAO assessment. In other words, the regulator paused and the customers did not, because the customers were never operating on the regulator's calendar in the first place.
That is the whole lesson, and it generalizes past CMMC. A regulatory delay relieves nothing that is already written into a purchase order. If you are tracking your obligations against Federal Register dates instead of against your own contract clauses and portal notices, you are tracking the wrong document.
What we tell shops to do about it, and what we do not
We are usually arguing people out of something here rather than into it.
The instinct after a scare like this is to buy a compliance platform, or to hire a compliance manager, or both. Sometimes that is right. Often it is premature, because the failure that just happened was not a failure of evidence management. It was a failure of visibility: nobody in the building could answer, on demand, which certifications each active customer contract obliges you to hold and by when. That is a question about where your obligations are written down, and it is usually answerable with a list rather than a system.
The list is unglamorous. Customer, contract or PO, the certification clauses it contains, the date each bites, and who confirmed it. Fifteen rows for most small subcontractors. Until that exists, a platform is automating a question you have not asked yet, and every vendor on page one of your search will be happy to sell you one anyway. The same buy-side caution applies here that applies to evaluating any automation vendor: a product that assumes you already know your requirements cannot supply them.
Once the list exists, the sequencing decisions become obvious and mostly boring. The certification with the longest lead time and the nearest contractual date goes first. Anything with no contractual date behind it goes into the marketing column, where it belongs, and gets funded out of business development rather than out of the quality budget. Shops routinely discover here that one accreditation they have been putting off for two years is the only one actually binding, and two they were planning to pursue are aspirational.
The recurring cost of holding certifications is a separate question, and a real one. We have written about what DFARS and CMMC compliance actually consume in hours at a 200-person shop, which is the part that never appears on a quote. Sequencing tells you what to start. That article tells you what you are signing up to carry.
The failure mode is quiet until it is not
None of this announces itself. A shop does not get a letter saying it sequenced its certifications badly. It gets a portal questionnaire with a date, discovers the audit calendar is longer than the runway, and then spends a quarter managing a customer relationship instead of shipping parts. Or it quotes a job, wins it, and finds the special process it needs is not in its accreditation scope.
Both of those look like compliance problems in the postmortem. Both of them were scheduling problems that were visible six months earlier to anyone who had put the contract dates and the audit lead times on the same page.
If you are looking at a supplier notice with a date on it and trying to work out whether your certification path fits inside it, or whether a customer's requirement is genuinely binding or a preference written in strong language, that is the conversation to have before you commit budget. Talk to us. Working out which of your obligations are real, and in what order they bite, takes a week of looking at your actual contracts, and it is the cheapest week in the whole program.
