Thyssenkrupp Marine Systems builds submarines and surface combatants for NATO navies, the kind of contractor whose blueprints, welding schedules, and supply chain contacts are worth more to a foreign intelligence service than almost anything sitting in a typical corporate network. This week, TKMS got hit with ransomware. The same week, the Pentagon quietly suspended Phase 2 of the Cybersecurity Maturity Model Certification program, pausing the third-party audits meant to verify that defense contractors actually protect the data attackers are after. The timing is almost too on the nose. One event proves the threat is real and moving fast. The other proves the mechanism built to catch it is not.

Neither of these stories is really about TKMS or about CMMC specifically. They’re about what happens when an entire industry treats compliance frameworks as the finish line instead of the floor. Defense contractors, healthcare vendors, water utilities, whoever, they’ve spent years building cybersecurity programs shaped around passing an audit. When the audit gets paused, or delayed, or never quite shows up on schedule, the security posture underneath is what’s left standing. This week it wasn’t standing very well.

News roundup graphic representing cybersecurity incidents including the TKMS ransomware attack
A ransomware hit on a NATO submarine builder landed in the same week third-party defense contractor audits were suspended.

The Difference Between a Paused Audit and a Paused Obligation

CMMC Phase 2 was supposed to be the mechanism that forces defense industrial base contractors, thousands of them, many with no dedicated security staff, to prove they’re handling Controlled Unclassified Information properly before an independent assessor rather than just self-attesting. The Pentagon suspending it doesn’t erase the underlying requirement. Industry reaction to the pause has been consistent on this one point: the legal obligation to protect CUI didn’t go anywhere. What went away is the outside check that was supposed to catch contractors who weren’t actually meeting it.

That distinction matters more than it sounds like it should. A lot of contractors were treating the CMMC certification date as their internal deadline for finishing overdue hardening work: patching the old VPN appliance, finally segmenting the shop floor network from the corporate domain, rotating service account credentials that hadn’t changed since a system was commissioned. Pause the audit and you pause the deadline pressure, even though the risk that created the requirement in the first place is unchanged. Attackers don’t check whether your assessor showed up before they scan your exposed RDP port.

TKMS Was a Target Long Before Any Auditor Showed Up

Whatever the final scope of the TKMS incident turns out to be, the attack itself doesn’t care about certification status, national jurisdiction, or which government’s procurement office is watching. Naval shipbuilders sit at the intersection of everything ransomware crews and state-linked groups want: high-value intellectual property, deep government and subcontractor connections, and industrial control systems on production floors that are notoriously hard to patch without stopping a build schedule that’s already years behind. That combination makes defense manufacturers a persistently attractive target regardless of what compliance regime is or isn’t currently being enforced against them.

It’s also a reminder that a lot of the defense industrial base’s most sensitive exposure doesn’t sit in the country running the audit program at all. TKMS is German. CMMC is a US Department of Defense requirement. A contractor can be fully outside the CMMC pause and still be exactly as exposed, because the actual attack surface, shared design files, common vendor software, overlapping subcontractor networks, doesn’t respect national compliance boundaries. Security built to satisfy one country’s paperwork was never going to cover a genuinely global supply chain.

Cybersecurity Hardening Doesn’t Wait for a Compliance Calendar

The organizations that come out of a stretch like this in decent shape are the ones that never fully outsourced their sense of urgency to an external audit cycle in the first place. If you’re running any kind of critical infrastructure, defense-adjacent or not, treat the CMMC pause as a signal to double down, not a reason to coast.

Start with what’s cheap and immediate. Lock down remote access with strong authentication and stop exposing management interfaces directly to the internet. Put brute-force protection in front of anything that accepts login attempts, RDP, SSH, admin panels, VPN concentrators, because credential-stuffing and password-spraying bots don’t slow down while you wait on a certification date. A tool like IPBan Pro that automatically detects and blocks repeated failed-login patterns is a low-cost way to shrink that specific attack surface without buying a new platform. Segment your OT and production networks from your corporate IT environment so a phishing email in accounting can’t reach a machine that’s welding a hull.

Then build the habits that outlast any single framework. Maintain an incident response plan that gets tested on your own schedule, not your auditor’s, including who calls the FBI or CISA, who talks to customers, and who has the authority to pull a production line offline. Invest in threat detection that watches for lateral movement and unusual data flows continuously, rather than treating detection as something reviewed once a year during assessment season. Layer your defenses so that no single control failure, one missed patch, one reused password, one unsegmented VLAN, is enough to take down the whole operation. That’s defense in depth in practice, not as a slide in a compliance deck.

Frequently Asked Questions

What does the CMMC Phase 2 suspension actually change for defense contractors?
It pauses the third-party assessments that verify compliance with CUI protection requirements. It does not remove the underlying legal and contractual obligation to protect that data, so contractors that stop hardening because the audit is delayed are taking on risk with no corresponding relief from liability.
Why are shipbuilders and defense manufacturers such frequent ransomware targets?
They combine high-value intellectual property, deep government and subcontractor relationships, and industrial control systems that are hard to patch without halting production. That mix makes them attractive to both financially motivated ransomware crews and state-linked actors, independent of any single country’s compliance calendar.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.