CMMC for machine shops comes down to one question: what arrives with the purchase order. If the prime sends a PO, a part number and a general spec, you are handling Federal Contract Information (FCI) and you are on CMMC Level 1 (Self). If the package includes a drawing with a distribution statement, an export-controlled model, or anything with a CUI banner, you are handling Controlled Unclassified Information (CUI) and you are on CMMC Level 2 (Self), with a Supplier Performance Risk System (SPRS) score to post on top of it.
The hard part in a 5 to 50 person job shop is the second question: where does that drawing go next. Usually the general inbox, the computer-aided manufacturing (CAM) workstation, a network share, a USB stick, the controller, a traveler, the quoting system, the backup drive and the heat treater's inbox. Every one is in your assessment scope unless you deliberately move it out.
Three paths, all self-assessed. Level 1 (Self) for FCI, Level 2 (Self) for CUI, and the SPRS score under DFARS 252.204-7019 and 7020. All three matter, and since the July 2026 suspension of CMMC Phase 2 only the self-assessed levels can be required (what the suspension changed).
CMMC for machine shops: which level applies to you
FCI only: Level 1 (Self)
FAR 52.204-21 defines FCI as information not intended for public release, provided by or generated for the Government under a contract, minus public information and simple transactional data. A PO with part numbers, quantities, dates and a general spec is FCI. Level 1 (Self) is the 15 basic safeguarding requirements in paragraph (b)(1) of that clause. Under 32 CFR 170.15 you self-assess every year, post the result in SPRS and affirm it; under 32 CFR 170.24 every requirement must be fully implemented, with no plan of action. The free Level 1 checklist lists all 15.
CUI: Level 2 (Self) plus the SPRS score
Three markers on the drawings, models and specs in the request for quote (RFQ) package put a job in the CUI bucket.
- A distribution statement B through F. The CUI Registry's Controlled Technical Information category and the definition in DFARS 252.204-7012 both describe technical information with military or space application that carries distribution statements B through F under DoD Instruction 5230.24. Engineering drawings, specifications, process sheets and data sets are named examples.
- An export control notice. Items under the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR) fall in the registry's Export Controlled category, marked CUI//EXPT.
- A CUI banner. 32 CFR 2002.20 says the banner uses the word CONTROLLED or the acronym CUI, and that a missing marking does not exempt the holder when the information qualifies. The 7012 definition also covers information marked or otherwise identified in the contract. If the contract says CUI, treat the unmarked drawing as CUI. If nobody has said, ask the prime in writing.
Level 2 (Self) is defined in 32 CFR 170.16: a MET result on all 110 requirements of NIST SP 800-171 Revision 2, posted in SPRS, repeated every three years, affirmed every year. A plan of action gets you Conditional Level 2 (Self), which expires unless the open items close within 180 days. Separately, DFARS 252.204-7019 requires a NIST SP 800-171 DoD Assessment score no more than three years old in SPRS before award, and DFARS 252.204-7020(g) bars the prime from awarding you a subcontract subject to 800-171 without a Basic assessment from the last three years. DFARS 252.204-7012 still applies wherever CUI sits, including 72-hour cyber incident reporting to DoD. The free SPRS calculator gives you the number.
Where CUI actually lives in a job shop
Follow one controlled drawing. Each stop is an asset that processes, stores or transmits CUI, the scope test in 32 CFR 170.19.
The RFQ package in the general inbox. The buyer sends drawings, STEP models and specs to quotes@ or the owner's phone. Everyone who can open that mailbox is handling CUI, and the system hosting it is a CUI asset.
The CAD/CAM workstation and the network share. The estimator opens the drawing, the programmer writes the numerical control (NC) program, and the STEP, DXF, PDF and NC files land on a share. If that share sits on the accounting server, the whole server is in scope, and so is every PC that maps the drive.
The machine controllers. Older controllers cannot be patched or run endpoint protection. Table 3 in 32 CFR 170.19 classes operational technology (OT), Internet of Things devices, test equipment, government furnished equipment and restricted information systems as Specialized Assets: document them in the asset inventory, the system security plan (SSP) and the network diagram, show they are managed under your risk-based policies, and they are not assessed against the other requirements. 32 CFR 170.4 also defines an enduring exception, a system where full compliance is not feasible, with OT and test equipment as named examples: no plan of action, but it must be documented in the SSP with its mitigations.
Travelers and printed drawings. Paper is media. NIST SP 800-171 requirement 3.8.1 says protect system media containing CUI, both paper and digital, and 3.8.3 says sanitize or destroy it before disposal. The drawing clipped to the traveler and the customer touring the floor fall under 3.10.1 (limit physical access) and 3.10.3 (escort visitors).
USB sticks. Requirement 3.8.7 says control the use of removable media, which covers the sticks that carry programs to the controller; 3.8.8 prohibits portable storage with no identifiable owner; and 3.8.6 requires CUI on digital media in transport to be encrypted or physically protected.
Portal downloads. Portal files land in the Downloads folder of whichever PC was used, home laptop included.
The quoting and ERP (enterprise resource planning) system. Drawings attached to the job record. If the system is cloud-hosted and holds CUI, DFARS 252.204-7012(b)(2)(ii)(D) requires the provider to meet security equivalent to the FedRAMP (Federal Risk and Authorization Management Program) Moderate baseline, and 32 CFR 170.16(c)(2) keeps your on-premises side in scope.
Backups. Requirement 3.8.9 says protect the confidentiality of backup CUI at storage locations, including the drive in the desk drawer and the cloud backup.
Outside vendors. Heat treat, plating, outside grinding and inspection all get the drawing re-sent, and two things follow. The flowdown: DFARS 252.204-7012(m) requires the clause in subcontracts involving covered defense information, and FAR 52.204-21(c) flows the FCI requirements the same way. The transmission: requirement 3.13.8 requires cryptographic protection of CUI in transit unless physical safeguards protect it, and 3.13.11 requires that cryptography to be FIPS validated. Ordinary email does not meet that on its own; our guide to FIPS-validated encryption covers what does.
Each location, the control, and the 800-171 family
| Where CUI shows up | What to do | 800-171 family |
|---|---|---|
| General inbox | Dedicated CUI mailbox, named users, multifactor authentication | Access Control (3.1), Identification and Authentication (3.5) |
| CAD/CAM workstation | The CUI workstation: named logins, encrypted disk, patched, logged | Configuration Management (3.4), System and Information Integrity (3.14) |
| Network share | Separate CUI share, short access list, access logging | Access Control (3.1), Audit and Accountability (3.3) |
| Machine controllers | Specialized Assets: own network segment, mitigations in the SSP | System and Communications Protection (3.13) |
| Travelers, printed drawings | Locked cabinet, shred bin, visitors escorted | Media Protection (3.8), Physical Protection (3.10) |
| USB sticks | Company-owned, encrypted, signed out; unknown devices blocked | Media Protection (3.8) |
| Portal downloads | Only on the CUI workstation, into the CUI share | Access Control (3.1) |
| Quoting and ERP | Keep drawings out of the job record, or put the ERP in scope | Access Control (3.1) |
| Backups | Encrypt, restrict restores, test one | Media Protection (3.8) |
| Outside vendors | Flowdown in the PO, FIPS-validated encrypted transfer, listed in the SSP | System and Communications Protection (3.13), Security Assessment (3.12) |
Shrink the scope before you assess it
32 CFR 170.19 sorts every asset into five categories: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope Assets. An out-of-scope asset cannot process, store or transmit CUI because it is physically or logically separated from those that do, and you must be prepared to justify that. Make the list of places CUI can be as short as you can defend.
- One CUI workstation. Drawings are opened and programs written there, nowhere else.
- One CUI share, or a small enclave. A separate share with its own access list is the minimum; a segmented network with its own share, logins and controllers is cleaner.
- A CUI mailbox instead of the general inbox. Ask the buyer to send controlled packages there.
- Front office out. Accounting and payroll PCs are out of scope only if they truly cannot reach the CUI share or mailbox; write down why.
- Shop floor as Specialized Assets. The program was cut from the drawing, so keep the transfer path, USB or drop folder, inside the enclave.
- Cloud with care. 32 CFR 170.16(c)(2) allows CUI in a cloud service that is FedRAMP Moderate authorized or equivalent, with the provider's customer responsibility matrix documented in your SSP.
Then write it down: requirement 3.12.4 asks for an SSP describing system boundaries, the environment of operation, how each requirement is implemented and connections to other systems. Our scoping guide goes deeper.
Scope is what touched CUI, not what you wish had. If the quoting laptop opened one controlled drawing, it is a CUI asset until wiped, rebuilt and separated. 32 CFR 170.19 says an asset in any in-scope category cannot be called out of scope.
What to do this week
- Pull the last ten RFQ packages and POs. Look for distribution statements, CUI banners and ITAR or EAR notices, then sort the jobs into FCI-only and CUI. That decides your level.
- Trace one controlled drawing. Inbox, workstation, share, USB, controller, traveler, vendor, backup. Every stop goes on the asset list.
- Pick the CUI workstation and the CUI share. Move the drawings there and delete every other copy.
- Inventory the controllers. Make, model, operating system, what reaches them and how, plus the mitigations for the SSP.
- Fix the vendor transfer. Choose a FIPS-validated encrypted method for heat treat, plating and inspection, and put flowdown language in your POs.
- Run the assessment. The Level 1 checklist if you are FCI-only, all 110 requirements if you hold CUI, then post or refresh your SPRS score.
CMMC Map, CMMC compliance software for small defense contractors, starts with scoping questions written for this kind of shop, then walks the 110 requirements (or the Level 1 safeguards) with a live SPRS score, free forever, no credit card. The generated SSP, plan of action, 14 policies and readiness report are the one paid plan at $149 a month.
This is explanatory content about contractual requirements, not legal advice. Your contract clauses and your prime's flowdown letter govern.
Find out which level your shop is actually on
The free CMMC Map assessment starts with scoping questions written for a job shop, then walks every requirement with a live SPRS score. No credit card, no trial clock.
Start free in CMMC Map