- Sponsored
Security involves more than checking boxes; it’s about accelerating defense innovation
Pentagon leaders are intensifying efforts to encourage current and prospective defense suppliers to bring next-generation technologies into the military’s mission-critical environments. However, their push for innovation is colliding with concurrent pressures to meet rigorous security requirements, such as Cybersecurity Maturity Model Certification (CMMC).
Those pressures received a reprieve earlier this month when Defense Department CIO Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey announced the department was suspending Phase 2 of its CMMC requirements, set to take effect Nov. 10. The suspension reflected mounting concerns about the cost burden and complexity of the requirements, especially on new entrants into the defense industry.
Ensuring defense contractors properly store and transmit Pentagon data and prevent adversaries from exploiting it remains a critical Pentagon objective. But SAP NS2 Chief Executive Officer Harish Luthra, in a new interview with Scoop News Group, argues that defense suppliers need to view the CMMC framework as more than a compliance checklist relegated to the IT department to satisfy auditors.
This fundamental shift in perspective is critical, he adds, because siloing security creates severe operational bottlenecks. When compliance is treated as an isolated IT function or a final milestone inserted at the end of a project, it actively delays the rollout of vital military capabilities and threatens mission readiness, he says.
Instead, Luthra suggests that defense suppliers need to weave CMMC standards into every facet of their business, from research and development to cloud operations, procurement, and legal departments. Security ceases to be a speed bump. It becomes a continuous, strategic enabler that allows organizations not only to protect warfighter data but also to innovate at scale and ultimately win more defense contracts.
Responding to industry concerns that heavy compliance stifles agility, Luthra stressed that a “protect what matters, but drive what’s next” approach is the only way forward. To safely deploy next-generation tools without exposing classified government data to adversaries, organizations must view rigorous, localized security controls not as a cost of doing business but as the very foundation that makes innovation possible.
Luthra detailed three distinct structural, technical, and programmatic approaches that defense contractors must adopt to ensure compliance accelerates innovation rather than stifling it, especially as the defense industry rolls out AI-enabled capabilities.
- Conduct unvarnished vulnerability assessments: Organizations must honestly evaluate their current security posture by bringing in outside experts to rigorously test their systems. “Make it part of your DNA… we have to make sure we do a proper assessment of where we are today,” Luthra advised, noting that leaders should actively invite third-party assessors to introduce vulnerabilities to expose blind spots.
- Establish direct executive ownership: Cybersecurity accountability cannot be pushed down to middle management or siloed in IT; it requires active, top-level sponsorship. “I have personally taken on the securities executive sponsorship within the organization,” Luthra said, explaining that this ensures he has direct oversight of enterprise risks across R&D, operations, and procurement across SAP NS2.
- Unify internal and external security controls: As companies modernize with new technologies like AI, their internal security posture must perfectly mirror the strict compliance standards they provide to their defense clients. “[W]e have to make sure both the internal corporate controls and the customer controls are both exactly the same, and we protect both our internal organization and the customer organizations,” he explained.
This operating model is particularly vital not only for defense organizations working to bridge the gap between global commercial technology and classified government systems, but also for a new generation of companies seeking to bring innovation to the defense sector.
Watch the entire interview. And learn more about SAP NS2 — an independent proxy wholly owned by SAP, and governed through the Defense Counterintelligence Security Agency — is helping defense and civilian agencies protect national security data.
This video interview and article were produced by Scoop News Group for DefenseScoop and underwritten by SAP NS2.