CMMC for machine shops comes down to one question: what arrives with the purchase order. If the prime sends a PO, a part number and a general spec, you are handling Federal Contract Information (FCI) and you are on CMMC Level 1 (Self). If the package includes a drawing with a distribution statement, an export-controlled model, or anything with a CUI banner, you are handling Controlled Unclassified Information (CUI) and you are on CMMC Level 2 (Self), with a Supplier Performance Risk System (SPRS) score to post on top of it.

The hard part in a 5 to 50 person job shop is the second question: where does that drawing go next. Usually the general inbox, the computer-aided manufacturing (CAM) workstation, a network share, a USB stick, the controller, a traveler, the quoting system, the backup drive and the heat treater's inbox. Every one is in your assessment scope unless you deliberately move it out.

Three paths, all self-assessed. Level 1 (Self) for FCI, Level 2 (Self) for CUI, and the SPRS score under DFARS 252.204-7019 and 7020. All three matter, and since the July 2026 suspension of CMMC Phase 2 only the self-assessed levels can be required (what the suspension changed).

CMMC for machine shops: which level applies to you

FCI only: Level 1 (Self)

FAR 52.204-21 defines FCI as information not intended for public release, provided by or generated for the Government under a contract, minus public information and simple transactional data. A PO with part numbers, quantities, dates and a general spec is FCI. Level 1 (Self) is the 15 basic safeguarding requirements in paragraph (b)(1) of that clause. Under 32 CFR 170.15 you self-assess every year, post the result in SPRS and affirm it; under 32 CFR 170.24 every requirement must be fully implemented, with no plan of action. The free Level 1 checklist lists all 15.

CUI: Level 2 (Self) plus the SPRS score

Three markers on the drawings, models and specs in the request for quote (RFQ) package put a job in the CUI bucket.

Level 2 (Self) is defined in 32 CFR 170.16: a MET result on all 110 requirements of NIST SP 800-171 Revision 2, posted in SPRS, repeated every three years, affirmed every year. A plan of action gets you Conditional Level 2 (Self), which expires unless the open items close within 180 days. Separately, DFARS 252.204-7019 requires a NIST SP 800-171 DoD Assessment score no more than three years old in SPRS before award, and DFARS 252.204-7020(g) bars the prime from awarding you a subcontract subject to 800-171 without a Basic assessment from the last three years. DFARS 252.204-7012 still applies wherever CUI sits, including 72-hour cyber incident reporting to DoD. The free SPRS calculator gives you the number.

Where CUI actually lives in a job shop

Follow one controlled drawing. Each stop is an asset that processes, stores or transmits CUI, the scope test in 32 CFR 170.19.

The RFQ package in the general inbox. The buyer sends drawings, STEP models and specs to quotes@ or the owner's phone. Everyone who can open that mailbox is handling CUI, and the system hosting it is a CUI asset.

The CAD/CAM workstation and the network share. The estimator opens the drawing, the programmer writes the numerical control (NC) program, and the STEP, DXF, PDF and NC files land on a share. If that share sits on the accounting server, the whole server is in scope, and so is every PC that maps the drive.

The machine controllers. Older controllers cannot be patched or run endpoint protection. Table 3 in 32 CFR 170.19 classes operational technology (OT), Internet of Things devices, test equipment, government furnished equipment and restricted information systems as Specialized Assets: document them in the asset inventory, the system security plan (SSP) and the network diagram, show they are managed under your risk-based policies, and they are not assessed against the other requirements. 32 CFR 170.4 also defines an enduring exception, a system where full compliance is not feasible, with OT and test equipment as named examples: no plan of action, but it must be documented in the SSP with its mitigations.

Travelers and printed drawings. Paper is media. NIST SP 800-171 requirement 3.8.1 says protect system media containing CUI, both paper and digital, and 3.8.3 says sanitize or destroy it before disposal. The drawing clipped to the traveler and the customer touring the floor fall under 3.10.1 (limit physical access) and 3.10.3 (escort visitors).

USB sticks. Requirement 3.8.7 says control the use of removable media, which covers the sticks that carry programs to the controller; 3.8.8 prohibits portable storage with no identifiable owner; and 3.8.6 requires CUI on digital media in transport to be encrypted or physically protected.

Portal downloads. Portal files land in the Downloads folder of whichever PC was used, home laptop included.

The quoting and ERP (enterprise resource planning) system. Drawings attached to the job record. If the system is cloud-hosted and holds CUI, DFARS 252.204-7012(b)(2)(ii)(D) requires the provider to meet security equivalent to the FedRAMP (Federal Risk and Authorization Management Program) Moderate baseline, and 32 CFR 170.16(c)(2) keeps your on-premises side in scope.

Backups. Requirement 3.8.9 says protect the confidentiality of backup CUI at storage locations, including the drive in the desk drawer and the cloud backup.

Outside vendors. Heat treat, plating, outside grinding and inspection all get the drawing re-sent, and two things follow. The flowdown: DFARS 252.204-7012(m) requires the clause in subcontracts involving covered defense information, and FAR 52.204-21(c) flows the FCI requirements the same way. The transmission: requirement 3.13.8 requires cryptographic protection of CUI in transit unless physical safeguards protect it, and 3.13.11 requires that cryptography to be FIPS validated. Ordinary email does not meet that on its own; our guide to FIPS-validated encryption covers what does.

Each location, the control, and the 800-171 family

Where CUI shows upWhat to do800-171 family
General inboxDedicated CUI mailbox, named users, multifactor authenticationAccess Control (3.1), Identification and Authentication (3.5)
CAD/CAM workstationThe CUI workstation: named logins, encrypted disk, patched, loggedConfiguration Management (3.4), System and Information Integrity (3.14)
Network shareSeparate CUI share, short access list, access loggingAccess Control (3.1), Audit and Accountability (3.3)
Machine controllersSpecialized Assets: own network segment, mitigations in the SSPSystem and Communications Protection (3.13)
Travelers, printed drawingsLocked cabinet, shred bin, visitors escortedMedia Protection (3.8), Physical Protection (3.10)
USB sticksCompany-owned, encrypted, signed out; unknown devices blockedMedia Protection (3.8)
Portal downloadsOnly on the CUI workstation, into the CUI shareAccess Control (3.1)
Quoting and ERPKeep drawings out of the job record, or put the ERP in scopeAccess Control (3.1)
BackupsEncrypt, restrict restores, test oneMedia Protection (3.8)
Outside vendorsFlowdown in the PO, FIPS-validated encrypted transfer, listed in the SSPSystem and Communications Protection (3.13), Security Assessment (3.12)

Shrink the scope before you assess it

32 CFR 170.19 sorts every asset into five categories: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope Assets. An out-of-scope asset cannot process, store or transmit CUI because it is physically or logically separated from those that do, and you must be prepared to justify that. Make the list of places CUI can be as short as you can defend.

Then write it down: requirement 3.12.4 asks for an SSP describing system boundaries, the environment of operation, how each requirement is implemented and connections to other systems. Our scoping guide goes deeper.

Scope is what touched CUI, not what you wish had. If the quoting laptop opened one controlled drawing, it is a CUI asset until wiped, rebuilt and separated. 32 CFR 170.19 says an asset in any in-scope category cannot be called out of scope.

What to do this week

  1. Pull the last ten RFQ packages and POs. Look for distribution statements, CUI banners and ITAR or EAR notices, then sort the jobs into FCI-only and CUI. That decides your level.
  2. Trace one controlled drawing. Inbox, workstation, share, USB, controller, traveler, vendor, backup. Every stop goes on the asset list.
  3. Pick the CUI workstation and the CUI share. Move the drawings there and delete every other copy.
  4. Inventory the controllers. Make, model, operating system, what reaches them and how, plus the mitigations for the SSP.
  5. Fix the vendor transfer. Choose a FIPS-validated encrypted method for heat treat, plating and inspection, and put flowdown language in your POs.
  6. Run the assessment. The Level 1 checklist if you are FCI-only, all 110 requirements if you hold CUI, then post or refresh your SPRS score.

CMMC Map, CMMC compliance software for small defense contractors, starts with scoping questions written for this kind of shop, then walks the 110 requirements (or the Level 1 safeguards) with a live SPRS score, free forever, no credit card. The generated SSP, plan of action, 14 policies and readiness report are the one paid plan at $149 a month.

This is explanatory content about contractual requirements, not legal advice. Your contract clauses and your prime's flowdown letter govern.

Find out which level your shop is actually on

The free CMMC Map assessment starts with scoping questions written for a job shop, then walks every requirement with a live SPRS score. No credit card, no trial clock.

Start free in CMMC Map
Free to assess · Documents $149/mo · No credit card