CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

Defense manufacturing and machine shops

How do defense manufacturers and machine shops meet CMMC and ITAR?

By scoping CUI tightly around the people and machines that actually touch controlled drawings, implementing the 110 NIST SP 800-171 requirements inside that boundary, and treating shop floor equipment as Specialized Assets that are isolated and documented. Where drawings are ITAR technical data, access rules also have to account for who is a U.S. person.

CMMC Level 2, NIST SP 800-171 and ITAR programs for defense manufacturers and machine shops, from enclave scoping to shop floor equipment and evidence.

Book a 30 minute call

Which regulations apply?

DFARS 252.204-7012

Requires adequate security for covered defense information by implementing NIST SP 800-171, reporting cyber incidents to DoD within 72 hours, meeting cloud security requirements equivalent to FedRAMP Moderate, and flowing the clause down to subcontractors.

DFARS 252.204-7019

Requires a current NIST SP 800-171 assessment score, no more than three years old, posted in the Supplier Performance Risk System.

DFARS 252.204-7020

Gives DoD access to assess your NIST SP 800-171 implementation and requires you to confirm your subcontractors' assessments before flowing work to them.

DFARS 252.204-7021

The contract clause that puts a CMMC level into a contract and requires the matching CMMC status and annual affirmation.

CMMC, 32 CFR part 170

The program rule that defines CMMC Levels 1, 2 and 3, how each is assessed, the scoping rules and the annual affirmation. Level 2 maps to the 110 requirements of NIST SP 800-171 Rev 2.

NIST SP 800-171 Rev 2

The 110 security requirements for protecting Controlled Unclassified Information in contractor systems, organized into 14 families and assessed with NIST SP 800-171A.

ITAR, 22 CFR parts 120 to 130

Controls the export of defense articles and technical data on the United States Munitions List, including release to foreign persons inside the United States. 22 CFR 120.54 sets the conditions under which encrypted technical data is not an export.

FAR 52.204-21

Basic safeguarding of covered contractor information systems that hold Federal Contract Information. It lists fifteen basic safeguarding requirements and is the basis of CMMC Level 1.

Which clauses apply to you depends on your contracts. Read them, and take legal advice where the answer matters.

Where does the work usually get hard?

  • Controlled drawings arrive by email, portal and USB, and end up on engineering workstations, file shares, printers and machine controllers that nobody mapped.
  • CNC controllers and the computers that feed them programs often run old operating systems that cannot be patched or fitted with modern controls.
  • Small shops rarely have a security leader, so the SPRS score and the annual affirmation are signed on the word of an IT provider.
  • Primes flow down DFARS clauses with short deadlines, and losing a supplier approval can mean losing the work.
  • Printed travelers and drawings on the floor are media under NIST SP 800-171 and, for ITAR data, a potential export if a visitor sees them.

Which engagements fit?

CUI enclave design

CUI enclave design in Microsoft Azure and M365 GCC High, with a defined authorization boundary, for defense contractors.

ITAR cybersecurity program

Cybersecurity programs for ITAR controlled technical data, built on NIST SP 800-171 and DFARS 252.204-7012, from Capital Cyber.

SSP and POA&M review and assessor readiness

Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.

CMMC Level 2 program leadership

Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.

No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.

What do companies in this industry ask?

Do our CNC machines have to meet all 110 requirements?

Usually not directly. Machines that cannot be fully configured are commonly treated as Specialized Assets, isolated on their own network segment and documented in the SSP with the controls that contain the risk.

Is a shop that only receives FCI subject to CMMC Level 2?

No. A company that handles only Federal Contract Information falls under FAR 52.204-21 and CMMC Level 1. Level 2 applies when the contract involves CUI.

Who decides whether our drawings are ITAR controlled?

Your customer's markings and your export compliance function, using the ITAR definitions and the United States Munitions List. The security program then protects whatever is controlled.

See all the industries we work with.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.