Skip to content
CMMC Guidance
← Industries
Manufacturing

CMMC has to work on the shop floor, not just on the assessor’s checklist.

In a manufacturer, Controlled Unclassified Information (CUI) does not stay in the office. It becomes a toolpath on a machine controller, an inspection record at a quality station and a file on a shop-floor computer that operations would prefer nobody touched. The program has to account for that or it will be worked around within a week.

CMMC has to work on the shop floor, not just on the assessor's checklist.

01 · What CUI Looks Like in Your Industry

What CUI may look like here.

Examples of information that may constitute CUI when appropriately designated or contractually identified include:

  • Computer-aided design (CAD) drawings
  • Computer-aided manufacturing (CAM) and computer numerical control (CNC) files
  • Technical specifications
  • Bills of materials
  • Manufacturing instructions
  • Inspection documentation
  • Test results
  • Quality documentation
  • Engineering changes
02 · Where Your CUI Typically Travels

The path a file takes.

  1. Prime Contractor
  2. Engineer
  3. SharePoint
  4. CAD Workstation
  5. Shop Floor/CNC
  6. Quality Control
  7. Prime
A drawing arrives from the prime and reaches an engineer, who files it to SharePoint and opens it on a CAD workstation. From there it is programmed and carried to a machine on the shop floor, the finished part is inspected and documented at quality control, and the records go back to the prime. The last three stops are the ones the office network never sees, and they are where most manufacturers are surprised.
03 · Where Organizations Like Yours Commonly Get Into Trouble

Where it goes wrong.

01

Shared production accounts

A single login for the whole shift, or one account per machine that everyone knows, is the norm on many floors because it keeps the line moving. It also means no one can say who opened a controlled file, and a control that requires individual accountability cannot be evidenced. Fixing it is less about the software and more about designing a login pattern operators will actually use.

02

Legacy systems and specialized equipment

Machine controllers and their attached PCs are often on an operating system the vendor no longer supports, and operations believes they cannot be patched or modified without voiding a warranty or stopping production. Sometimes that is true. The program then has to treat those systems as specialized assets with documented, compensating protection rather than pretending they are ordinary workstations.

03

Unmanaged shop-floor computers and removable media

The computer beside the machine was set up by whoever installed the equipment and has never joined the domain, never received an agent and never had its USB ports thought about. Files reach it on a thumb drive because that is the only path that works. Each of those facts is a finding, and together they are the usual reason a manufacturer’s first gap assessment is longer than expected.

04

Vendor remote access

Equipment vendors need to service their machines and often hold a standing remote connection to do it. That connection is a path into the production network that the manufacturer did not build, does not monitor and frequently cannot describe. It has to be brokered, logged and switched on for the session rather than left open.

05

Engineers moving files between corporate and production

The gap between the office network and the floor is bridged every day by an engineer with a laptop and a cable, or a personal cloud folder, or the same thumb drive as above. The transfer itself is legitimate work. What is missing is a managed way to do it, so the legitimate path and the uncontrolled path are the same path.

04 · "But We..."

"We can't implement security controls that interfere with production."

That statement is correct, and it is where the design should start rather than where it stops. CMMC has to work on the shop floor and not just on the assessor’s checklist. A program that treats every manufacturing system like a standard office workstation will be rejected by operations, worked around by the people who have parts to ship, and end up as paperwork that describes a floor that does not exist.

The workable approach accounts for operational requirements up front. Production systems are inventoried and classified for what they are; the ones that cannot take an agent or a patch are documented as specialized assets with compensating protection around them, such as network segmentation, restricted physical access and controlled transfer paths. Individual accounts are introduced in a form operators can live with. Removable media becomes a controlled exception with a log, not a ban that is ignored. None of that stops the line. All of it produces evidence.

05 · What a Practical CMMC Environment Looks Like

An environment that holds.

01
A segmented production networkThe shop floor sits on its own network segment, separated from corporate systems by a firewall with rules someone can explain. Machine controllers and their PCs talk to what they need and nothing else. The segment boundary is also the assessment boundary for those systems, which keeps the scope honest.
02
Shop-floor systems as specialized assets, with documented compensating controlsEach controller, legacy PC and instrument is listed in the asset inventory with its category, and the System Security Plan (SSP) says what protects it when a standard control cannot apply: isolation, physical access limits, monitoring at the segment edge, a documented patch exception. The assessor sees a decision, not an omission.
03
No shared production accountsEvery person who touches a system that holds CUI has their own credential, including on the floor. Where a machine interface genuinely cannot support that, the workstation in front of it does, and the record of who was logged in there is the accountability trail.
04
A managed transfer path between corporate and productionOne sanctioned way for programs and drawings to cross from engineering to the machine, with the transfer logged and the files scanned. It is faster than the thumb drive because it is on the network, and once it exists the informal routes can be closed without a fight.
05
Controlled removable mediaUSB is disabled by default on in-scope systems and enabled by exception on devices the company owns, issues and tracks. The list of exceptions is short, current and reviewed.
06
Brokered vendor remote accessVendors reach their equipment through a gateway the manufacturer controls, using their own named accounts, for a session that is requested, approved, recorded and closed. The standing tunnel goes away and the maintenance still happens.
06 · How CMMCg Approaches It

The order we do it in.

  1. 01

    Discover CUI

  2. 02

    Define Scope

  3. 03

    Identify Gaps

  4. 04

    Design Controls

  5. 05

    Implement

  6. 06

    Collect Evidence

  7. 07

    Prepare for Assessment

  8. 08

    Maintain Compliance

This is the CMMCg Method applied to your environment. Read the Method →

Does this look like your environment?

The readiness call starts from where your information actually goes, not from a template. An engineer runs it.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.