CMMC reaches defense contracts: the factory’s first task is to map its information
Cybersecurity is becoming a more explicit condition of doing business in the US defense supply chain. The acquisition rule effective from 10 November connects CMMC status with applicable contract requirements, making information handling a commercial issue for manufacturers as well as a technical one.
As of November 24, 2025. For a machine shop or component producer, the first useful step is to understand what information it receives and where that information travels. Buying security software before answering those questions can leave the real exposure untouched. A drawing may move through estimating, production planning, inspection and an outside processor, crossing several systems and organisations along the way.
The contract determines the requirement
The September 2025 final DFARS rule incorporates contractual requirements associated with the Cybersecurity Maturity Model Certification programme. It requires the relevant current status for information systems used to process, store or transmit covered information where the solicitation calls for it. Awards exclusively for commercially available off-the-shelf items are excluded from this rule’s application.
That scope matters. CMMC is not a universal certification requirement for every factory, nor does a manufacturer’s size alone determine the required assessment. Federal Contract Information and Controlled Unclassified Information have different implications, and the applicable contract and information must be understood together.
A supplier evaluating an opportunity should therefore resolve the required level, relevant systems and evidence before treating compliance as a routine box in the quotation. A commercial product used by a defense customer does not automatically make every associated transaction identical. Conversely, describing a business as a small subcontractor does not remove obligations that apply through its actual work and information handling.
Phase one is a beginning, not a blanket exemption
The 2024 programme rule sets out a phased implementation approach beginning with Level 1 and Level 2 self-assessment requirements for applicable work. It also allows the department to require a Level 2 third-party assessment in place of self-assessment at its discretion. Suppliers should read the actual requirement rather than assume that the first phase makes external assessment irrelevant.
The programme also distinguishes asset categories and their treatment. Operational technology can involve specialised assets with particular scoping provisions. A production machine should not be classified casually simply because it sits on the factory floor. Its information handling, connections and role in the assessed environment need examination.
For management, the practical lesson is to make scope a documented decision involving contracts, engineering, operations and security. An IT provider may understand the network but need help understanding how a controlled drawing becomes a machine programme or inspection record. Production staff may understand the process while being unaware of how a remote support tool exposes it.
Follow one job from quotation to shipment
An illustrative mapping exercise starts with a single representative defense job. Identify who receives the customer’s files, where they are stored and how estimating uses them. Continue through programming, work instructions, quality records and shipment documentation. Include any transfer to heat treatment, coating, testing or other outside processing.
The purpose is to reveal the actual route, including ordinary workarounds. A file copied to a personal folder, an obsolete shared account or a service laptop can matter more than the neat diagram in a policy document. The exercise should be conducted with the people doing the work, using an authorised sample and avoiding unnecessary duplication of sensitive material.
This mapping also helps separate a business need from a habit. A subcontractor may need a specific manufacturing instruction rather than a complete package of customer information. Reducing unnecessary distribution can simplify handling, provided the remaining information still supports correct production and contractual obligations. The decision should be agreed with the appropriate customer and compliance personnel rather than improvised on the shop floor.
Factory security must respect physical processes
NIST’s Guide to Operational Technology Security explains why industrial environments require care beyond ordinary office IT practice. Its patch-management section recommends testing and an accountable process that considers operational effects. A software change that removes one vulnerability can still disrupt a control application, and some older systems lack supported patches.
That is not an argument for leaving equipment unmanaged. It is an argument for coordinated decisions about testing, deployment and compensating controls when changes must be delayed. Engineering and maintenance need a place in the security process because they understand the machine’s operating constraints.
A practical planning discussion can identify maintenance windows, vendor support, recovery information and the person authorised to approve a change. The factory should know how a failed update would be reversed or how production would be restored. Treating that preparation as part of reliability makes the discussion more useful than presenting cybersecurity as a separate activity that competes with output.
Remote support deserves its own review
CISA and partner agencies’ 2023 guide describes both the legitimate value and malicious use of remote access software. Its recommendations include auditing tools, reviewing activity, controlling which software can run and restricting access. The guidance is broader than CMMC and does not itself certify a manufacturing environment.
For a factory, the commercial question is who can reach which equipment and for what purpose. A machine supplier, internal technician and external IT provider may have different needs. Those differences should be reflected in authorisation, access duration and accountability rather than one enduring shared route into the plant.
An illustrative service arrangement could require a named contact to approve a support session and confirm its completion. The exact technical controls must fit the system and its safety requirements, but the operational ownership should be clear. A valuable remote diagnostic capability becomes harder to manage when nobody can explain whether an old account is still needed or who is responsible for closing it.
Demonstration guidance is useful, but it is not a purchase order
NIST’s manufacturing integrity project offers example solutions for industrial control environments. It connects the protection of systems and data with manufacturing operations, showing how multiple capabilities can work together. Its value is as a reference architecture and implementation resource, not a finding that one product automatically satisfies every manufacturer’s obligations.
That distinction helps suppliers evaluate proposals. A vendor should explain how its service addresses the company’s actual information flows, who operates it, what evidence it produces and what remains the customer’s responsibility. A list of familiar product names is not enough to establish those answers.
Manufacturers should also distinguish a technical installation from an operating process. Logs that nobody reviews, alerts without an escalation owner and backups that have never been tested may create the appearance of coverage without resolving the underlying business risk. These are issues to investigate and demonstrate, not assumptions to make from a dashboard screenshot.
Make readiness part of the bid decision
A quotation review can bring the work together. Alongside capacity, tooling and delivery, the business should identify the information requirement, assessment status, unresolved dependencies and the time needed to address them. This creates an opportunity to resolve gaps before accepting a delivery commitment that depends on eligibility the supplier cannot yet demonstrate.
Responsibilities across the supply chain should be explicit. If an outside processor receives covered information, the prime supplier needs a reliable way to determine what requirements flow down and how they will be met. Purchasing, engineering and security should share the same understanding of the intended exchange.
The November milestone makes that coordination more urgent. A manufacturer’s strongest response is a defensible account of what it handles, where it goes, how the relevant environment is protected and who keeps the evidence current. That account supports both contract readiness and more reliable factory operations. It is also a better basis for investment than assuming that compliance can be purchased as a single software package.
