If your shop machines parts, fabricates components, or assembles systems for a prime contractor or directly for the DoD, CMMC Level 2 is not a future problem. The requirement is written into contracts now, and the third-party assessment requirement is being enforced on a rolling basis. Understanding what NIST SP 800-171 actually demands, and where manufacturers typically fall short, is the fastest way to close the gap without wasting budget on the wrong controls.
What CMMC Level 2 Actually Is
CMMC Level 2 maps directly to the 110 security requirements in NIST SP 800-171 Revision 2. There is no separate control set to learn. If you have handled Controlled Unclassified Information (CUI) and signed a contract with a DFARS 252.204-7012 clause, you have already been contractually obligated to meet these requirements. CMMC formalizes the assessment and verification process. Level 2 requires a third-party assessment by a CMMC Third Party Assessment Organization (C3PAO) for most companies handling CUI in support of critical programs, though some lower-risk situations may qualify for self-assessment.
The 110 requirements are organized across 14 domains: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Every one of these domains has teeth for a manufacturing environment.
Where Government Manufacturers Typically Struggle
Manufacturing environments have specific friction points that office-centric compliance frameworks do not anticipate well.
OT and shop-floor systems. CNC machines, PLCs, and manufacturing execution systems often run legacy operating systems that cannot be patched, cannot run endpoint agents, and were never designed with network segmentation in mind. NIST 800-171 does not exempt them. You need a documented compensating control strategy and a network architecture that isolates these assets from systems that touch CUI.
Defining the CUI boundary. Many manufacturers have never formally identified where CUI lives. It is in engineering drawings, technical data packages, contract line item specifications, and sometimes in the ERP system. Before you can protect CUI, you need a System Security Plan (SSP) that accurately describes your CUI boundary. Assessors will test whether your controls match your documented scope.
Multi-site operations. If you have more than one facility, each location that handles CUI is in scope. Physical protection controls (PE domain) and maintenance controls (MA domain) must be implemented and documented at each site, not just at headquarters.
Third-party access. Tooling vendors, calibration services, and IT support providers who touch systems in your CUI environment are a supply chain risk. Access Control requirement 3.1.20 specifically addresses external system connections. You need agreements, access logs, and a process for terminating access when the relationship ends.
The System Security Plan Is Not Optional
The SSP is the foundation of your CMMC assessment. It is not a checkbox document. A credible SSP describes your environment accurately, maps each of the 110 requirements to how your organization meets them, and identifies any requirements that are not yet fully implemented along with a Plan of Action and Milestones (POA&M) for closing those gaps.
Assessors read SSPs carefully. An SSP that claims full implementation of every control but does not describe the actual mechanisms will fail on-site verification. Write it to reflect reality, then close the gaps.
Practical Starting Points for Manufacturers
If you are early in the process, prioritize in this order:
- Scope your environment first. Identify every system, location, and person that touches CUI. Draw the boundary. Everything inside that boundary is in scope for all 110 requirements.
- Run a gap assessment against NIST 800-171. Use the NIST SP 800-171A assessment procedures as your guide. Score each requirement honestly. The DoD’s Supplier Performance Risk System (SPRS) requires you to self-score and submit a score, and that score carries legal weight.
- Fix identity and access controls early. Multi-factor authentication, least-privilege access, and account management are among the most commonly cited deficiencies and are also among the most straightforward to implement with modern tools.
- Address audit logging. You need to be able to prove that events were logged, that logs are protected from tampering, and that someone reviews them. Many manufacturers have no centralized logging at all.
- Document everything. Policies, procedures, configurations, training records, incident response plans. If it is not documented, it did not happen from an assessor’s perspective.
Choosing a C3PAO and What to Expect
A C3PAO assessment is not a consulting engagement. The assessor’s job is to verify, not to help you pass. Choose a C3PAO that has experience with manufacturing environments, specifically with OT/IT boundary issues and multi-site scoping. Before the formal assessment, work with a Registered Practitioner Organization (RPO) or an experienced compliance partner to close your gaps and validate your SSP.
The assessment itself involves document review, interviews with personnel, and technical testing of controls. Plan for it to take time and involve your operations, IT, and leadership teams, not just your compliance lead.
The Business Case Beyond Compliance
CMMC compliance is a contract requirement, but the controls it mandates are also a reasonable baseline for protecting your intellectual property, your production systems, and your customer relationships. Technical data packages and manufacturing specifications are valuable targets. The discipline of scoping, documenting, and testing your security posture has operational value independent of the audit outcome.
Get the SSP right, close the gaps methodically, and treat the assessment as a verification of work already done, not a surprise exam.