Manufacturers hit a different set of CMMC problems than software companies or service providers do. The CUI usually arrives as a customer print or a CAD file, not a clean document. The equipment that touches it might be a fifteen-year-old CNC machine with no path to standard endpoint security. And the decision that shapes the rest of the compliance effort, whether to isolate that work in a secure enclave or bring the whole shop into scope, gets made too early or too late more often than it gets made well.
This guide walks through what needs to happen. How CUI and Controlled Technical Information show up on a shop floor, how the CMMC scoping rules treat production equipment, how ITAR fits in when it applies, and how to weigh an enclave against an enterprise-wide approach using your own environment instead of a generic checklist.
Quick Answer
CMMC compliance for manufacturers starts with scoping, not tooling. Identify where Controlled Technical Information and other CUI enter the business, usually through customer drawings, specifications, or CAD files, then classify every system that touches it using the DoD CIO’s five CMMC asset categories. From there, the central decision is whether to build a secure enclave around that CUI workflow or bring the broader enterprise into scope, a choice that depends on how much of the business the CUI work touches. Manufacturers that are also ITAR-registered need to treat CMMC scoping and export control technical data requirements as connected efforts, not separate projects.
Current Implementation Note
In July 2026, the Department suspended the planned CMMC Phase II requirements and pending or future implementation milestones while it reviews the program. Phase I self-assessment requirements remain in place. During the interim period, the Department is enforcing NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments, while DFARS 252.204-7012 safeguarding obligations remain in effect. The CMMC regulations still define Level 2 (Self) and Level 2 (C3PAO) statuses, so manufacturers should follow the requirements in their current solicitations and contracts together with the latest Department guidance.
Source: Department announcement, July 13, 2026; 32 CFR Part 170; DFARS 252.204-7025.
How CUI and CTI Enter a Manufacturing Environment
Most manufacturers do not generate CUI internally so much as receive it. A prime contractor sends a drawing package, a specification, or a CAD model to build a part, and that technical data is very often Controlled Technical Information, a category of CUI that covers technical data controlled under DFARS 252.227-7013, Rights in Technical Data, Noncommercial Items. It arrives by email, by a customer portal, or on a drive handed across a counter, and it does not always come labeled CUI in a way that is obvious to whoever opens it on the shop floor.
That matters because scoping starts with knowing where CUI lives, and for a manufacturer, that answer is often narrower and more specific than “the whole company.” A print for one part number, a spec for one program, a shared folder one engineer uses to prep CAM files, these are frequently the entire footprint. Finding that footprint accurately, and resisting the urge to either scope too broadly out of caution or too narrowly out of convenience, is the single highest-leverage step in the entire compliance effort.
The Five CMMC Asset Categories, Applied to a Shop Floor
The DoD CIO’s CMMC Level 2 Scoping Guide defines five categories of assets, and every system in a manufacturing environment, from the ERP server to a CNC controller, falls into one of them. Getting this classification right is what turns a vague sense of “we probably need to secure it all” into a defensible, documented scope.
| Category | What It Covers | Manufacturing Example |
|---|---|---|
| CUI Assets | Systems that process, store, or transmit CUI directly. | The engineering workstation or PLM system holding customer drawings and CAD files for a CUI program. |
| Security Protection Assets | Systems that provide security functions for the CUI environment, such as identity, logging, or endpoint protection. | The domain controller, SIEM, or endpoint detection platform protecting the CUI-scoped network segment. |
| Contractor Risk Managed Assets | Systems that can, but are not intended to, handle CUI, and are managed using the organization’s risk-based security policies. | A general-purpose office laptop that is not supposed to touch CUI files but is on the same broader network. |
| Specialized Assets | Systems that process CUI but cannot be fully secured with standard security requirements, requiring a documented risk-based plan instead. | A networked CNC machine or CAM workstation pulling a CUI-marked program file directly, or legacy OT equipment that cannot run modern endpoint tools. |
| Out-of-Scope Assets | Systems that cannot process, store, or transmit CUI and have no path to reach the CUI environment. | A stand-alone manual mill with no network connection, or a break-room device on an isolated guest network. |
Specialized Assets is usually where manufacturers get stuck, and it is also the category most generic CMMC guides skip entirely, because it is the one that does not apply cleanly to a services business. Legacy CNC controllers, programmable logic controllers, and other production equipment frequently cannot run an endpoint agent, cannot be patched on a normal cycle, and sometimes cannot be taken offline without stopping a production line. The scoping guide does not require these systems to meet every standard security requirement the way a laptop would. It requires a documented, risk-based plan for how that equipment is secured and monitored given what it is, which is a very different exercise than buying more software.
Where ITAR Overlaps With CMMC
A meaningful share of defense manufacturers carry a second compliance obligation alongside CMMC, the International Traffic in Arms Regulations, or ITAR, administered separately from CMMC and NIST SP 800-171. ITAR governs the export of defense articles and defense services, including technical data, and that technical data is frequently the same material that qualifies as Controlled Technical Information under CMMC.
This means the same drawing, the same CAD file, the same specification, can carry both an ITAR export control obligation and a CMMC/CUI handling obligation at the same time. CMMC compliance does not satisfy ITAR requirements, and ITAR compliance does not satisfy CMMC requirements. They are separate regulatory regimes with separate enforcement, and a manufacturer that is ITAR-registered should treat scoping for both as a connected effort rather than two unrelated projects, ideally with export control counsel involved in how technical data is classified and where it is allowed to reside.
Enclave or Enterprise, How to Decide
This is the central architectural decision most manufacturers face, and it deserves a real comparison rather than a single list of “reasons to consider an enclave.” A secure enclave is a smaller, isolated environment purpose-built to handle CUI, separate from the rest of the company’s network. An enterprise-wide approach brings the organization’s broader IT environment into CMMC scope and compliance.
| Consideration | Enclave Tends to Fit When | Enterprise Tends to Fit When |
|---|---|---|
| Share of business touching CUI | CUI work is a defined slice of the business, tied to specific programs or customers. | CUI and CTI are already woven through most production workflows. |
| Upfront cost and complexity | Typically lower, since only the CUI-scoped environment needs to meet the full control set. | Typically higher, since a much larger footprint has to meet the full control set at once. |
| Ongoing operational overhead | Requires maintaining a separate environment, including duplicate tools, access management, and user workflows. | Avoids the overhead of running two parallel environments, but every future system added anywhere in the company inherits CMMC obligations. |
| Production equipment involvement | Works well when CUI-touching equipment can be logically or physically segmented from the rest of the shop floor. | Better suited when CUI-touching production equipment is integrated across multiple lines and cannot be cleanly separated. |
| Growth trajectory | Fits a company expecting CUI work to stay a defined portion of revenue. | Fits a company expecting most or all future contracts to involve CUI. |
Neither approach is inherently right. The mistake is choosing based on which one sounds simpler rather than which one matches how the business operates today and where it is headed over the next several years. A deeper side-by-side breakdown of the tradeoffs, including infrastructure and licensing considerations, is available on Sentinel Blue’s Enterprise vs Enclave Solutions comparison.
Manufacturing-Specific Challenges CMMC Guides Usually Skip
Engineering Software and VDI
CAD, CAM, and PLM tools are often licensed per workstation and can be resource-intensive, which complicates moving them into a virtual desktop environment for a CUI enclave without a performance or licensing conversation with the software vendor first.
Printed Drawings on the Floor
A printed copy of a CUI-marked drawing at a machine station is still CUI. Physical handling, marking, storage, and destruction procedures need to extend to paper, not just digital files, which is easy to overlook in a digital-first compliance plan.
Legacy OT and CNC Equipment
Controllers running unsupported operating systems or proprietary firmware often cannot run standard endpoint security. These typically fall under Specialized Assets and need a documented, risk-based compensating plan rather than a standard fix.
Physical Site Boundaries
A shop floor is a physical space as much as a network. Badge access, visitor logs, and physical segmentation between a CUI work cell and the rest of the floor are part of scope, not an afterthought layered on top of IT controls.
Supplier and Subcontractor Flow-Down
Manufacturers that subcontract operations such as heat treating, plating, or specialty machining need CUI handling requirements to flow down contractually to those suppliers, and need visibility into whether those suppliers can meet them.
Multiple Facilities, One Assessment Boundary
A company with more than one production site needs a single, clearly defined assessment boundary that accounts for every facility touching CUI, not a boundary drawn around whichever site is easiest to document.
What Cost and Timeline Depend On
There is no universal price tag or calendar for CMMC compliance, and any guide that gives you a single number without asking about your environment first is guessing. What drives cost and timeline for a manufacturer is a short list of variables worth walking through honestly before budgeting anything.
How much of the business, and how many facilities, touch CUI or CTI.
How much production and IT equipment needs replacement, isolation, or a documented compensating plan.
Whether an enclave or enterprise approach is chosen, and the ongoing overhead that choice carries.
A tightly scoped enclave covering a single CUI workflow generally costs less to stand up than bringing an entire manufacturing enterprise into compliance at once, but an enclave also introduces its own ongoing operational cost, including maintaining a separate environment and managing which employees and workflows sit inside it versus outside it. Timeline follows the same logic. A manufacturer with clean scope, modern infrastructure, and an existing NIST SP 800-171 foundation moves faster than one starting from legacy OT equipment and loosely defined CUI boundaries. A CMMC readiness assessment is the fastest way to turn these variables into a real estimate for your environment rather than a generic range.
Common Mistakes Manufacturers Make
- Assuming CMMC does not apply because the company is small or is a subcontractor rather than a prime.
- Treating every printed drawing or shared folder as automatically out of scope because it feels informal.
- Choosing an enclave or enterprise approach based on which sounds simpler rather than how CUI flows through the business.
- Overlooking production equipment entirely during scoping, then discovering CNC or OT systems touch CUI after the environment is already built.
- Assuming ITAR registration and CMMC compliance are handled by the same process, when they are separate obligations that need to be scoped together.
- Failing to flow CUI handling requirements down to subcontractors performing outside processing on CUI parts.
- Treating certification as a finish line instead of a point-in-time result that needs ongoing maintenance.
Staying Compliant After Certification
Passing an assessment is not the end of the work. Production environments change constantly, new equipment gets added, new suppliers come on board, and CAD or ERP systems get upgraded, any of which can move a system in or out of scope without anyone updating the System Security Plan to reflect it. Sentinel Blue’s post on managed CMMC compliance covers what it takes to keep a program operating correctly after the initial assessment work is done, and the best practices for CMMC assessment preparation post is a useful reference if a reassessment or a new contract requirement is coming up.
GCC vs. GCC High for CMMCChoosing an enclave often means choosing a cloud environment to build it in. This comparison walks through where GCC is sufficient and where GCC High is required.
Frequently Asked Questions
Does CMMC apply to small manufacturers, not just large defense primes?
What is Controlled Technical Information and why does it matter for manufacturers?
Should a manufacturer build a secure enclave or go enterprise-wide for CMMC?
Are CNC machines and shop floor equipment in scope for CMMC?
How does ITAR affect CMMC compliance for manufacturers?
How long does CMMC compliance take for a manufacturer?
What does CMMC compliance typically cost a manufacturer?
What happens after a manufacturer achieves CMMC certification?
Not sure whether your shop needs an enclave or an enterprise approach?
Sentinel Blue works with defense manufacturers to scope CUI accurately, classify production equipment against the CMMC asset categories, and build a plan that fits how the business runs.