Here's what happened in the last 18 months.
CMMC's final rule went into effect. Self-attestation for Level 2 is functionally over. If you handle CUI in the defense electronics supply chain, you need 110 NIST SP 800-171 controls implemented, documented, and evidence-ready for a third-party assessment. The DOJ has already fined companies for overstating their compliance posture. This is real enforcement now.
SEMI E187 moved from "awareness" to "procurement requirement." In 2025, SEMI Taiwan launched the E187 certification program. OEMs and fabs are asking equipment suppliers and component manufacturers to demonstrate E187 alignment. If you supply into semiconductor manufacturing, this standard is showing up in your customer questionnaires.
ITAR enforcement hasn't softened. The Department of State continues to issue penalties for violations, with fines up to $1M per incident, criminal prosecution, and debarment from government contracts. For electronics manufacturers handling defense-related technical data, the IT controls around access, encryption, and audit logging aren't optional.

