Skip to main content
GuidesBy Z Cyber TeamAugust 13, 20264 min read

The CMMC Requirements Small Manufacturers Find Hardest, and What to Do About Them

The CMMC Requirements Small Manufacturers Find Hardest, and What to Do About Them

The direct answer: the CMMC requirements that give small manufacturers the most trouble are not the ones defense contractors generally struggle with. They are the four where the 110 requirements of NIST SP 800-171 Rev 2 collide with production reality: configuration management and flaw remediation on equipment that cannot be patched, media protection for CUI that arrives as CAD files and travelers, access control on systems designed around shared accounts, and FIPS-validated cryptography on machines that cannot support it.

Every one of these is a scoping problem before it is a control problem.

The patching constraint is real, and it is not a waiver

A CNC controller running a vendor-locked operating system, a coordinate measuring machine whose software is validated as a unit, a press with an embedded controller the manufacturer will not support if modified. In each case, normal patch cadence is either impossible or commercially unacceptable.

This does not remove the requirement. It changes how the requirement is met. The workable pattern is segmentation plus compensating control: isolate the equipment onto its own network segment, tightly restrict what may reach it, monitor the boundary, and document the constraint and the compensating measures in the System Security Plan. An assessor is looking for managed and documented risk. An undocumented gap is the problem, not the constraint itself.

CUI in manufacturing does not look like CUI in an office

In most defense contractors, CUI lives in documents and email. In a machine shop it lives in the drawing package, the CAD or CAM file, the router or traveler that follows the job, the first article inspection report, and often a print taped to a machine.

That distribution is what makes media protection genuinely hard. Removable media is frequently how files reach equipment that is deliberately not networked. The requirement is not "ban USB drives," which is often impossible without stopping production. It is control, marking, and accountability over the media that carries CUI, with sanitization before reuse or disposal.

Manufacturers who handle this well usually did one thing first: they mapped where CUI physically travels through the plant, including on paper. That map is what makes the boundary decision possible.

Shared accounts on the floor

Production systems are often built around a shared operator login because shifts rotate and stopping to authenticate costs cycle time. CMMC Level 2 expects individual accountability, and the requirements around identification, authentication, and least privilege assume you can attribute action to a person.

Where individual accounts are genuinely infeasible on a machine, the path is again compensating: physical access control to the cell, logging at the network and file-transfer layer rather than the machine layer, and documented justification. Where they are feasible and merely inconvenient, assessors tend not to be sympathetic.

Segment the plant, shrink the assessment

The manufacturers who get through CMMC Level 2 without disproportionate cost are almost always the ones who stopped treating the plant network as one flat environment. A segmented design, with a defined enclave where CUI is received, processed, and staged, can take the majority of production equipment out of scope entirely.

This is the same architectural discipline that IT and OT convergence demands for other reasons, which is why it tends to pay for itself beyond the contract. For the broader OT framing, see IEC 62443 vs NERC CIP and Industrials and OT.

Where this sits today

Phase 1 of the CMMC rollout is live as of July 13, 2026, which means Level 1 or Level 2 self-assessment at award. Phases 2 through 4 are on hold, including the expansion of third-party C3PAO assessment that had been scheduled for November 10, 2026. The 110 requirements are unchanged. A manufacturer that uses this window to fix scoping and segmentation will be in materially better shape than one that waits for the phase schedule to resume.

Related reading: CMMC Level 2 Requirements for Small Business and NIST 800-171 vs CMMC.

How Z Cyber approaches this

Z Cyber works as a cybersecurity operating partner. For manufacturers that means the scoping and segmentation decision is led by a named Executive Security Advisor who has seen the tradeoff between assessment surface and production disruption, the program state lives in Glance so the SSP matches the plant as it actually runs, and remediation is delivered rather than recommended and left. We advise and implement. The manufacturer accepts the risk and owns the decision. See Defense and Government.

Frequently Asked Questions

What are the most challenging CMMC requirements for small manufacturers to implement?

Four cluster together. Configuration management and flaw remediation, because shop floor equipment often cannot be patched on a normal cycle without voiding a vendor warranty or halting production. Media protection, because CUI in manufacturing arrives as CAD files, drawings, travelers, and inspection reports that move through removable media and email. Access control, because production systems are frequently shared-account by design. And FIPS-validated cryptography, because older equipment often has no capability to support it at all. None of these are solved by buying a tool.

Does CMMC apply to shop floor equipment and OT systems?

It applies wherever Controlled Unclassified Information is stored, processed, or transmitted, which frequently includes machines that receive CAD or CAM files. Whether a given controller is in scope depends on whether CUI actually reaches it. This is why boundary definition matters more for manufacturers than for most contractors: a plant network that is flat puts production equipment in scope by default, while a segmented design can keep most of the floor out of it.

What if a machine cannot be patched without voiding the vendor warranty?

That is a common and legitimate constraint, and it is handled through compensating measures rather than by ignoring the requirement. Typical approaches include network segmentation that isolates the equipment, strict control of what may connect to it, and monitoring at the segment boundary. The requirement is that risk is managed and documented, not that every asset is patched on the same cadence. What does not work is leaving the gap undocumented and hoping it is not examined.

How does CMMC relate to IEC 62443 for a manufacturer?

They answer different questions and overlap in practice. CMMC and NIST SP 800-171 govern protection of Controlled Unclassified Information for defense work. IEC 62443 governs the security of industrial automation and control systems generally, regardless of who the customer is. A manufacturer doing defense work often needs both, and the control sets can be mapped so evidence is collected once rather than twice.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.