Aerospace and space suppliers
What security rules apply to aerospace and space suppliers?
Aerospace and space suppliers on defense programs usually face DFARS 252.204-7012 and NIST SP 800-171 for CUI, a CMMC level in their contracts, and ITAR for technical data on the United States Munitions List. The work is to design one environment that satisfies the security requirements and the export access rules together.
NIST SP 800-171, CMMC Level 2 and ITAR technical data programs for aerospace and space suppliers on defense programs, designed as one environment.
Book a 30 minute callWhich regulations apply?
DFARS 252.204-7012
Requires adequate security for covered defense information by implementing NIST SP 800-171, reporting cyber incidents to DoD within 72 hours, meeting cloud security requirements equivalent to FedRAMP Moderate, and flowing the clause down to subcontractors.
DFARS 252.204-7019
Requires a current NIST SP 800-171 assessment score, no more than three years old, posted in the Supplier Performance Risk System.
DFARS 252.204-7020
Gives DoD access to assess your NIST SP 800-171 implementation and requires you to confirm your subcontractors' assessments before flowing work to them.
DFARS 252.204-7021
The contract clause that puts a CMMC level into a contract and requires the matching CMMC status and annual affirmation.
CMMC, 32 CFR part 170
The program rule that defines CMMC Levels 1, 2 and 3, how each is assessed, the scoping rules and the annual affirmation. Level 2 maps to the 110 requirements of NIST SP 800-171 Rev 2.
NIST SP 800-171 Rev 2
The 110 security requirements for protecting Controlled Unclassified Information in contractor systems, organized into 14 families and assessed with NIST SP 800-171A.
ITAR, 22 CFR parts 120 to 130
Controls the export of defense articles and technical data on the United States Munitions List, including release to foreign persons inside the United States. 22 CFR 120.54 sets the conditions under which encrypted technical data is not an export.
Which clauses apply to you depends on your contracts. Read them, and take legal advice where the answer matters.
Where does the work usually get hard?
- Engineering data moves between CAD, PLM, simulation and test systems, and each one may hold controlled technical data.
- Foreign national engineers, offshore partners and visiting customers create export questions that a compliant cloud platform does not answer by itself.
- Test benches, ground support equipment and lab instruments behave like operational technology and rarely fit standard IT controls.
- Supply chains are deep, so a supplier may receive flow down clauses from several primes with different expectations and timelines.
- Commercial and defense programs often share people and systems, which makes drawing a clean CUI boundary harder.
Which engagements fit?
ITAR cybersecurity program
Cybersecurity programs for ITAR controlled technical data, built on NIST SP 800-171 and DFARS 252.204-7012, from Capital Cyber.
CUI enclave design
CUI enclave design in Microsoft Azure and M365 GCC High, with a defined authorization boundary, for defense contractors.
CMMC Level 2 program leadership
Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.
C3PAO readiness and mock assessment
CMMC Level 2 mock assessment and C3PAO readiness, including C3PAO selection, for defense contractors preparing for certification.
No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.
What do companies in this industry ask?
Can commercial and defense work share the same systems?
They can, but everything that touches CUI is then in scope. Many suppliers keep defense data in an enclave so commercial systems stay outside the boundary.
Does GCC High solve our ITAR obligations?
No platform does by itself. A platform built for export controlled data supports the obligations, but access decisions, classification and procedures stay with the company.
How are test benches and lab instruments handled?
They are often scoped as Specialized Assets, segmented from the rest of the network, and documented in the SSP with the controls that apply to them.
Ready to talk it through?
BOOK A CALLPick a time for a 30 minute call with the practice.
What happens in 30 minutes
- We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
- We talk through where you stand and which engagement fits, if any does.
- If there is a fit, we follow up with a written scope. No slides.