Skip to content

Security

CMMC on the shop floor: scope is the only lever that matters

A prime asked for your certification status and now the plant network is the problem. Almost all of the cost in a Level 2 assessment is decided before a single control is implemented — and since Phase 2 was suspended in July 2026, the person asserting your posture is you.

Updated 7 min readComputing America

In short

  • The obligation is not new, and the deadline is not current. DFARS 252.204-7012 has required NIST SP 800-171 implementation and 72-hour incident reporting for years; CMMC Phase 2 was suspended on 13 July 2026, which removed the outside assessor and left the assertion with you.
  • Scope, not controls, drives cost. A flat plant network puts every controller and every operator terminal in the assessment boundary, and segmentation is cheaper than assessing them.
  • Shared HMI logins are the most common finding on a shop floor, and the answer is an engineered enclave with documented compensating controls, not a policy that operators will ignore at 3am.
  • Legacy controllers that cannot be patched or encrypted are an expected condition in OT, not a disqualification, provided the design keeps controlled information away from them.
  • The evidence question is separate from the control question: an assessor asks who accessed this file and when, and that answer had to be designed into the system before the assessment was scheduled.

The trigger is almost always the same. A prime contractor sends a questionnaire, or a new purchase order arrives with a flow-down clause attached, and a manufacturer who has been supplying defense work for twenty years discovers that the plant network is now a compliance object. The immediate reaction is to look for a product to buy. It is the wrong first move, and it is expensive.

Start from what is actually being asked. DFARS 252.204-7012 has required contractors handling covered defense information to implement the security requirements in NIST SP 800-171 and to report cyber incidents within 72 hours of discovery for years. The CMMC program in 32 CFR Part 170 does not invent that obligation. What it changes is how the claim gets tested, and that is why a requirement many suppliers had treated as paperwork became an engineering project.

Then it changed again, and anyone selling you urgency should have to account for it. On 13 July 2026 the Department suspended CMMC Phase 2 and held the milestones after it in abeyance pending a reform review, so the third-party certified assessment that was to become the default is not currently the default. In the interim the Department has said it will enforce NIST SP 800-171 through self-assessment and selected government-led assessments. The reason given was arithmetic rather than policy: on the order of a hundred thousand contractors needed assessments and roughly a hundred authorized assessors existed to perform them.

Read carefully, that makes this article more relevant rather than less, and it is worth being explicit about why. Nothing was suspended about the underlying requirement: the DFARS clause stands, the 800-171 requirements stand, the 72-hour reporting obligation stands, and a supplier still posts a score and affirms it. What was removed is the outside party who was going to come and check. So the claim about your plant network is now made by you, under your own signature, about systems that were never built to produce evidence — and a self-attestation is not a softer instrument than an assessment. It is the same assertion with your name on it instead of an assessor’s, which is why the engineering below is worth doing on its own terms and not against a date.

The scoping decision is the whole cost

Everything in the assessment boundary must be assessed. Everything outside it does not. That single sentence accounts for most of the difference between a supplier who gets through this for a manageable number and one who spends a year on it, and the boundary is determined by where controlled information actually goes.

So trace it before doing anything else. A customer sends a drawing. It lands in an email system, gets saved to a file share, is opened by an engineer, becomes a program on a CNC controller, is printed as a traveler that sits in a bin on the floor, and is referenced in a quality record that is retained for years. Every one of those locations is a candidate for the boundary, and several of them are surprises to the people running the plant.

The engineering work that pays for itself is the work that shortens that path. If the controller receives a toolpath rather than the marked drawing, the controller may fall out of scope. If controlled work is done inside a defined enclave rather than on the general file share, the general file share falls out of scope. Scope reduction is the cheapest control available, and it is the one that requires an architect rather than a vendor.

Four conditions that fail on a plant floor

A flat network

The plants we are asked to look at usually have one broadcast domain, or close to it. The MES, the historian, the cell controllers, the badge system and the office file share can all reach each other, often because a machine vendor once needed remote support and the quickest path was the flat one. In that topology there is no defensible boundary, so the boundary becomes the plant, and the assessment cost scales with the number of devices on the floor.

Segmentation here is not the same exercise as on a corporate network. NIST SP 800-82 exists precisely because operational technology cannot absorb the controls that enterprise IT takes for granted: availability and safety constraints come first, and a scanner that probes a PLC can stop a line. Segment with that in mind, at the cell and process level, with an inventory built from passive observation rather than active scanning.

Shared logins on the HMI

This is the finding we see most often and the one with the least honest answer available. The requirement is unique identification of users. The plant reality is that a machine must not be locked behind a credential prompt when something is going wrong at 3am, and that gloves and shift changes make per-person login on a panel genuinely impractical.

The resolution is architectural, not disciplinary. Keep controlled information off the shared-account systems so the identification requirement applies where it can be met, use badge or token identification where the interaction can support it, and where a shared account is genuinely necessary, document the compensating controls: physical access control to the cell, video, logging at the network layer, and a named owner. A policy that says operators will each log in individually, on a panel where they demonstrably will not, is worse than no policy. It is a control you have claimed and cannot evidence.

Machines that cannot be patched

A controller running an operating system that has been unsupported for a decade, attached to a machine with fifteen years of service life left, is a normal condition in manufacturing rather than an aberration. It cannot be patched without the machine builder’s approval, and the machine builder may not exist any more.

This is expected, and it is handled by containment: the device sits in a segment that cannot reach the internet or the controlled enclave, its network behavior is monitored, and access to it is mediated. What does not work is pretending the device is current, because a serious assessor will ask, and the plant’s own inventory will contradict you.

Evidence that was never generated

The control question and the evidence question are different, and the second one is the one that runs out of road. An assessor does not only ask whether access is restricted, they ask you to show who accessed a specific file, when, and from where, over a period. On a file share configured in 2014 that answer frequently does not exist, and it cannot be produced retroactively.

This is the same decision we make on every system we build: what a system can prove later is fixed by design choices made long before anyone needs the proof. Audit logging on the systems that touch controlled information, retention long enough to cover an assessment period, and a mechanism to actually query those logs are three specific line items, and they are cheap in a design and expensive in a retrofit.

Sequence it like a project, because it is one

  1. 1.Trace the information flow end to end, including paper, email and the copy someone keeps on a laptop for convenience. This produces the boundary.
  2. 2.Reduce the boundary by design before implementing controls: an enclave for controlled work, derived files rather than source files on the floor, and a mediated path between the two.
  3. 3.Only then assess the requirements against the reduced boundary, and be specific about what is met, what is not, and what is met by a compensating control you can evidence.
  4. 4.Build the evidence layer at the same time as the controls, not after. Logging, retention, and the ability to answer a question about a specific file on a specific day.
  5. 5.Rehearse. Have someone outside the team ask the questions an assessor will ask, and watch how long each answer takes to produce. The slow answers are the real gaps.

The reason we treat this as an engineering engagement rather than a compliance one is that the controls outlive whatever the program is called this year. A plant with a segmented network, a defined enclave for controlled work, an accurate device inventory and logs that answer questions is a plant that is measurably harder to disrupt, whoever is asking — and it is the only version of this work that a suspension, a reform review or a new phase schedule cannot invalidate. If a firm is selling you this against a date, note that the last date moved, and ask what happens to their argument when the next one does.

Sources

  1. 1.DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting, Defense Federal Acquisition Regulation Supplement
  2. 2.SP 800-171 Rev. 3: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, NIST
  3. 3.32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program, Electronic Code of Federal Regulations
  4. 4.DOD halts cybersecurity requirements for CMMC Phase 2: ‘The math just simply doesn’t math’, DefenseScoop,
  5. 5.SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security, NIST

Next step

Tell us what’s breaking.

Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.