If you run a machine shop, a metal finishing operation, a job shop, or any production facility that makes parts for the defense supply chain, here is the question that decides your next two years: where does your customer’s technical data actually live in your building?
Because that data the drawings, the models, the specifications, the CNC programs derived from them — is almost certainly Controlled Unclassified Information (CUI). And the moment a system in your shop processes, stores, or transmits it, you are in scope for CMMC Level 2. Not “might be.” Are. The only contractors carved out of CMMC entirely are those selling commercial off-the-shelf (COTS) commodities on the open market. A shop machining to a customer’s print is not selling a commodity. It is handling covered defense information.
Most CMMC guidance online is written for a generic office environment laptops, email, a file server, maybe a cloud tenant. That guidance misses the problem that makes manufacturing the hardest environment in the entire Defense Industrial Base to certify: in a shop, CUI does not sit politely in one place. It moves from your customer’s portal to an engineering workstation, into your CAM software, onto your ERP or MES, and frequently down to a controller bolted to a machine that has been running since before the iPhone existed. This is written for that reality.
Yes, CMMC Applies to Manufacturers and the Trigger Is the Data, Not Your Size
Let’s settle the most common misconception we hear from shop owners: “We’re a small manufacturer, we just make parts, surely this is for the big IT companies.”
It is not. There is no small-business exemption, no revenue threshold, and no headcount carve-out in the rule. The level you need is determined by one thing: the sensitivity of the data your customer flows down to you.
If a customer shares only Federal Contract Information (FCI) — basic contract information that isn’t public but isn’t sensitive — your minimum is Level 1, an annual self-assessment against 15 requirements. But manufacturers rarely live at Level 1. The instant a customer sends you an engineering drawing, a 3D model, a performance specification, a technical data package, or anything marked CUI or export-controlled under ITAR, you are at Level 2: full implementation of all 110 NIST SP 800-171 Rev 2 controls. Starting in Phase 2 on November 10, 2026, most Level 2 contracts require an independent assessment by an authorized C3PAO — not a self-assessment.
Here is the trap that catches manufacturers specifically: technical drawings and specifications routinely qualify as CUI even when they arrive without an obvious CUI banner. A shop that self-categorizes as “FCI only” because nothing looked marked is making exactly the assumption the Department of Justice has started prosecuting. (More on that below.)
Where CUI Actually Lives in a Manufacturing Environment
This is the section no generic CMMC article will give you, and it is the one that determines your cost. Walk the path a single defense drawing takes through your shop:
It arrives — through your customer’s secure portal, Exostar, or email. Now it’s on a workstation and in an inbox.
It goes to engineering or programming — opened in your CAD viewer, imported into your CAM software to generate toolpaths. Now it’s on an engineering workstation and probably a file server.
It gets quoted and scheduled — referenced in your ERP or MES, attached to a job traveler, maybe printed for the floor. Now it’s in your business system and potentially on paper at a machine.
It drives production — the CNC program derived from that controlled drawing is loaded to a machine controller. That program is derivative of CUI, and depending on its content, may itself be CUI.
It gets inspected — measured on a CMM, with results tied back to the controlled specification. Now it’s in your quality system.
Every one of those systems is a candidate for your CMMC scope. A manufacturer who never maps this flow ends up trying to certify the entire shop — every workstation, every server, every machine, the whole network — against 110 controls. A manufacturer who maps it can often isolate CUI to a tight enclave and certify a handful of systems instead. Same 110 controls. A fraction of the cost and timeline. This single decision is worth more than any tool you will buy.
The Legacy Equipment Problem Nobody Warns You About
Office environments don’t have this problem. Shops do.
A large share of production equipment — CNC controllers, CMMs, PLCs, test stands — runs on operating systems that are years or decades past end-of-life. Windows XP and Windows 7 are still everywhere on the floor because the machines around them cost six and seven figures and “if it cuts good parts, why touch it?” The difficulty is that these systems frequently cannot accept the controls CMMC requires: multi-factor authentication, modern encryption, endpoint protection, current patching. The machine builder may not even support it.
You cannot simply rip out a $400,000 machine to satisfy a security control. And you don’t have to — but you do have to deal with it deliberately. The correct approach is almost always architectural: segment operational technology (OT) away from the systems that hold CUI, isolate or air-gap legacy controllers, and control the CUI upstream — at the engineering and file-transfer layer — so the derivative program reaches the machine through a managed path rather than a flat network where everything can see everything.
This is engineering work. It is network segmentation, identity and access management, secure file transfer, and boundary design. It is precisely the work a gap report alone will never do for you — and it is exactly where most manufacturers stall.
Special-Process Suppliers Are Squarely in Scope, Too
If you do plating, anodizing, coating, heat treating, passivation, welding, or any other special process for aerospace and defense customers — the kind of work that runs through NADCAP accreditation — do not assume CMMC is someone else’s problem upstream.
Special-process shops handle the same controlled artifacts as machine shops: technical drawings, process specifications, material requirements, and covered defense information tied to the parts you treat. NADCAP tells your customer your process is sound; it says nothing about whether your IT environment protects their CUI. Those are two different audits, and your primes are now asking about both. The metal finisher who assumed “we just coat the parts, we don’t design anything” is in scope the moment a controlled spec or drawing lands in the building.
The DOJ Already Made the Example Out of a Shop Like Yours
In December 2025, the Department of Justice announced a settlement with a precision machining subcontractor that allegedly failed to provide adequate cybersecurity for technical drawings it received from prime contractors, as required under DFARS 252.204-7012. The supplier agreed to pay roughly $421,000. The case was initiated by a qui tam action filed by a former quality control manager — an insider who knew the controls weren’t actually in place.
Read that again, because every detail is a warning aimed at manufacturers. It was a machine shop. The CUI in question was technical drawings — the most ordinary artifact in your shop. The company’s size did not protect it. The enforcement mechanism was the False Claims Act, which carries treble damages plus per-claim penalties, and it was triggered by a whistleblower who stood to collect up to 30% of the recovery.
The lesson is not “be afraid.” The lesson is that your SPRS score and your annual affirmation are representations to the federal government. If they say you’re compliant and your shop floor says otherwise, that gap is the liability — whether or not anyone ever breaches you.
The Realistic Timeline for a Manufacturer Starting Now
If you handle CUI, your prime requires Level 2, and you’re starting today, here’s the honest shape of it:
Weeks 1–4 — scoping and gap assessment. Map the CUI flow described above, define your enclave boundary, and score your environment against the 110 controls. Get a real SPRS number, not a guess.
Months 2–6 — remediation. Segment OT from your CUI systems, deploy MFA on everything that touches CUI (not just the VPN), implement validated encryption, and build a System Security Plan that maps each control to your actual environment. For a shop, this is where the architectural work lives.
Months 6–9 — documentation and evidence. Assessors evaluate evidence, not policies. A binder written the week before the assessment does not pass. You need running operational history — log reviews, scan remediation, training records.
Months 9–18 — C3PAO scheduling and assessment. With fewer than 100 authorized C3PAOs serving tens of thousands of organizations, wait times already run six to twelve months and are getting longer. The shops getting certified now started in 2024 or early 2025.
The math is blunt. If you start now and move efficiently, you can be demonstrably in process — scoped enclave, defensible SPRS score, active remediation, a C3PAO conversation initiated — which is what your prime will accept as evidence that you belong in the supplier pool. If you wait, your prime is already evaluating your replacement.
Why a Manufacturer Needs an RP Who Can Actually Touch the Floor
Here is the distinction that matters most for a shop. Plenty of consultants will scope your environment, hand you a gap report, and leave. For an office, that gets you maybe halfway. For a manufacturer, it gets you about 20% of the way — because the other 80% is segmenting your OT network, redesigning data flow between engineering and the floor, deploying encryption and access controls, and building documentation that survives an assessor reading it line by line. That is engineering, not advice.
A CMMC Registered Practitioner (RP) is the partner who prepares you before certification — scoping, gap assessment, SSP, remediation roadmap. A C3PAO is the independent body that certifies you afterward and is explicitly there not to fix anything. The order is not optional, and skipping the preparation step is the most expensive mistake a manufacturer can make. But the question to ask any RP is the one that separates a report-writer from a partner: can you fix what you find?
That is the difference at Rudram. Our Registered Practitioner is backed by a systems engineering firm with 18+ years in the Defense Industrial Base and federal clients including NASA, Raytheon, and the U.S. Air Force Academy. We understand production environments — OT, legacy controllers, ERP/MES, the path a controlled drawing takes from portal to part. When your gap assessment surfaces architectural work on your floor, our engineers execute it. One team, from your first scoping call through C3PAO readiness — not a report and a handoff.
Frequently Asked Questions
Q. Does CMMC apply to small manufacturers and machine shops?
Yes. There is no small-business, revenue, or headcount exemption. If any system in your shop processes, stores, or transmits FCI or CUI for a DoD contract, CMMC applies. The only carve-out is for commercial off-the-shelf products — which machining or finishing to a customer’s specification is not.
Q. Are technical drawings considered CUI?
In most defense work, yes. Engineering drawings, 3D models, specifications, and export-controlled (ITAR) technical data routinely qualify as CUI even when they arrive without an obvious marking. If you’re unsure, ask your customer in writing for the data’s CUI status before you do anything else.
Q. Do my CNC machines and shop-floor systems have to meet all 110 controls?
Only the systems inside your CUI boundary do. That’s why scoping is the highest-leverage decision a manufacturer makes — isolating CUI to a tight enclave and segmenting legacy OT away from it can dramatically reduce how many systems must be certified.
Q. Does NADCAP accreditation cover CMMC?
No. NADCAP accredits your special process; CMMC governs how your IT environment protects your customer’s CUI. They are separate requirements, and primes increasingly ask for both.
Q. Where should a manufacturer start?
With a scoping and gap assessment from a Registered Practitioner — before buying any security tools or changing any configurations. Map where CUI lives, define your enclave, and score your real SPRS position first.
Rudram Engineering, Inc. | Rockledge, FL | Serving the Defense Industrial Base for 18+ years | Trusted by NASA, the U.S. Air Force Academy, and Raytheon