
Introduction
A CNC controller doesn't know the difference between an approved file and an outdated one. It just runs what it receives. If that file arrived through a personal USB drive, an untracked email, or a shared login nobody remembers creating, the part might still come out correct. That same delivery path is still a security failure waiting to be found.
A C3PAO (CMMC Third-Party Assessment Organization) is the independent body that evaluates whether a contractor's security practices are actually implemented, not just written down.
This article is for U.S. CNC machine shops and defense manufacturers handling Controlled Unclassified Information (CUI). It shows what that evaluation looks like on the shop floor.
We'll walk through how assessors trace a CNC program from approval to execution, covering storage, transfer, machine access, operator behavior, logging, and incident response along the way.
Key Takeaways
- A C3PAO reviews the full CNC program lifecycle, not just the DNC server or controller screen.
- Assessments map CMMC and NIST SP 800-171 to evidence: access logs, revision history, transfers, and interviews.
- Shops must prove machinists get the approved file while unauthorized users and transfer paths stay locked out.
- Legacy controllers, removable media, and vendor access need documented, tested safeguards, not informal workarounds.
What a C3PAO Evaluates in a CNC Manufacturing Environment
Assessors look at whether CUI is identified, scoped, and handled consistently across every system that touches it: engineering workstations, CAD/CAM systems, DNC servers, shop-floor terminals, CNC controllers, inspection systems, backups, and removable media.
This is a different exercise from a quality audit. Verifying a part meets its tolerance tells you the program worked correctly. It tells you nothing about whether that program was protected from unauthorized access or alteration before it ever reached the spindle.
Assessment Themes Mapped to Shop-Floor Systems
The DoD CMMC Assessment Guide Level 2 directs assessors to use NIST SP 800-171A procedures across 14 domains. On a shop floor, the most relevant ones include:
- Access Control — who can view, send, edit, or delete a CNC program
- Identification and Authentication — how users, machines, and service accounts prove who they are
- Audit and Accountability — whether actions on a program are traceable to a specific person
- Configuration Management — whether the delivered file matches an approved baseline
- Media Protection — how removable drives and backups holding CUI are controlled
- System and Communications Protection — how DNC traffic and network boundaries are secured
- System Integrity — whether files are scanned and monitored for unauthorized changes
Not every CNC workflow gets assessed identically. The guide gives assessors flexibility to select methods and evidence based on the specific objective in question — there's no single universal checklist applied line for line.
To confirm implementation, assessors combine document review, technical examination, direct observation, personnel interviews, and sampling of systems or records. A written policy alone rarely satisfies an objective; they want to see it working.

Why CNC Program Delivery Matters to CMMC and Shop-Floor Security
A CNC program can carry more sensitive information than most people assume. Geometry, dimensions, tolerances, tooling instructions, and material specifications can qualify as Controlled Technical Information under the NARA CUI Registry, which covers engineering data, drawings, specifications, and process sheets tied to military or space applications.
Whether a specific file counts as CUI depends on the contract and the information itself. Not every G-code file automatically qualifies, and shops shouldn't assume otherwise without checking with the contracting organization.
A program is exposed at multiple points, and each one is a potential gap:
- Receipt from the customer
- CAM post-processing
- Engineering approval
- Storage on a file server or DNC system
- Transfer to the machine
- Local storage on the controller
- Backup
- Disposal
Informal practices multiply the risk at nearly every one of these points:
- Shared network folders with no access restrictions
- Personal USB drives moving files machine to machine
- Untracked email attachments
- Generic "operator1" logins shared across a shift
- Files renamed by hand instead of a formal revision process
None of these leave the kind of evidence trail an assessor needs to see.
Because these systems store, process, or transmit CUI, they fall inside the CMMC assessment boundary. They must appear in the organization's asset inventory and System Security Plan. That scoping requirement catches many shops off guard when their DNC server was never treated as an in-scope asset.
How a C3PAO Traces CNC Program Delivery
Rather than reviewing policies in isolation, assessors often pick one representative job and trace it end to end: find the approved source file, follow its revision history, watch how it's released, and confirm how the machine actually receives and runs it.
Step 1: Identify the Data and Define the Boundary
The organization needs to know which systems store, process, transmit, or protect the CNC file in question: engineering workstations, CAM software, DNC infrastructure, controllers, backups, and supporting systems. Evidence here includes:
- Data-flow diagrams
- Asset inventories
- Network diagrams
- The System Security Plan (SSP)
If the SSP doesn't mention the DNC server, that's a scoping gap before the assessor even gets to a technical control.
Step 2: Verify Approval, Version Control, and Change Management
The assessor may pull the engineering-approved revision and compare it directly against what's sitting on the machine. This means checking release permissions, revision identifiers, change orders, and protections against unauthorized edits.
Emergency changes and rework programs need attention too. A shop that allows "just this once" edits outside the normal approval path creates an undocumented route around every other control it built. Keep emergency changes available, and document a formal, expedited approval path so those edits stay inside the control system.
Step 3: Examine Delivery and Machine Access
This step covers how the file physically gets from the server to the spindle: DNC transfer methods, authenticated user accounts, machine-level access, network segmentation, and removable-media restrictions.
Controls that prevent unauthorized delivery differ from controls that only document it after the fact. A transfer log tells you a file moved. It doesn't tell you whether the person who sent it was allowed to.
Step 4: Test Evidence and Employee Understanding
Assessors request records: transfer logs, access logs, approvals, backup records, exception documentation, and controller configuration data. They also talk to people.
Machinists, programmers, supervisors, IT staff, and vendors may all get interviewed about how they obtain programs, how they recognize an approved revision, and what they do if something looks wrong.
A control that exists on paper but no operator can explain isn't functioning. That gap shows up fast in an interview.
Step 5: Review Response and Recovery
Finally, assessors look at how the shop detects and handles a wrong, altered, missing, or suspicious program: containment, notification, investigation, restoration from a trusted backup, and lessons-learned documentation.
Restoring the correct file gets production running again. It doesn't answer the harder questions: how did the wrong file get there in the first place, and is that path still open?

Where Shop-Floor Security Is Tested
Security gets tested at every handoff point, not just at the server. Engineering-to-production handoff: CAD/CAM and post-processing systems, file servers, DNC applications, and the interfaces that push programs to machines all fall under scrutiny for how changes are reviewed and released. The physical shop floor: Unattended terminals, shared workstations, visible technical data on a screen or printout, locked cabinets, and visitor access all matter. A program left open on an unlocked terminal can be photographed in seconds. Legacy and disconnected equipment: Older controllers often can't run modern authentication or endpoint protection. Assessors expect compensating controls instead: network isolation, restricted physical access, and documented exceptions explaining why the standard control isn't feasible and what replaces it. Removable media and manual transfer: Where USB drives or other portable media are used, expect scrutiny of:
- Malware scanning before use
- Chain of custody
- Labeling and tracking
- Return or destruction procedures
- Restrictions against personal devices Third-party and maintenance access: Vendor remote connections, service laptops, and temporary credentials need approval, monitoring, and prompt termination once the work is done. An open vendor account from six months ago is exactly the kind of finding that shows up in an assessment. Purpose-built CNC/DNC communication platforms can help structure this whole process. They control who can send a file, track what version reached which machine, and connect shop-floor systems in a way that's easier to document than a patchwork of shared drives and USB sticks. Controlink Systems LLC has built CNC/DNC communication and shop-floor automation software since 1998, including tools that manage program requests directly from the machine control and route corrected programs back through engineering review before they re-enter the file library. That structured workflow can support a compliance program. The technology still has to be configured, documented, and governed by the organization—the software doesn't create compliance on its own.

Key Factors, Common Issues, and Misconceptions
These factors determine how well a shop's program-delivery process holds up under C3PAO review:
- Data classification and scope — is the file, work instruction, or inspection record actually CUI under this contract?
- Identity and authorization — does each person, machine, and vendor account have only the access their job requires?
- Integrity and revision control — can the delivered file be tied to an approved revision, and would an unauthorized change be noticed?
- Logging and evidence retention — can the shop reconstruct who accessed, changed, or approved a program?
- Availability and recovery — do security controls protect production without creating an untested single point of failure?
- Physical and operational realities — do controls actually hold up across shifts, shared terminals, and urgent production changes?
Weakness in any of these areas drives most assessment findings. Two misconceptions make that worse.
First, a password on the DNC server doesn't secure the whole workflow. Assessors will still look at what happens downstream: local copies on the controller, removable media, backup files, and what operators actually do day to day.
Second, a compliant quality management system doesn't automatically satisfy cybersecurity requirements. Revision control and approval processes overlap between the two, but authentication, monitoring, incident response, and system protection are security-specific requirements a QMS was never built to address.
The core question an assessor asks goes beyond whether the file reached the machine. They need proof that delivery was authorized, traceable, protected, repeatable, and backed by evidence.

Before a formal assessment, a shop can get ahead of most findings by:
- Mapping the full CNC data flow from receipt to disposal
- Documenting every approved delivery path
- Removing shared or generic accounts
- Testing whether logging actually captures what it's supposed to
- Reviewing removable-media practices against written policy
- Validating that backups actually restore correctly
- Interviewing a few operators to see if their answers match the documentation
Conclusion
A C3PAO evaluates CNC program delivery as one connected security workflow: spanning classification, approval, transfer, machine access, physical safeguards, evidence, and recovery. No single control carries the whole burden.
Protecting CUI and keeping production running can work together when controls are documented and tested—not patched together for convenience. A shop that treats security as an afterthought to production usually finds out the hard way during an assessment.
Before the formal assessment date:
- Run a scoped readiness review early
- Bring in qualified support to close real gaps
- Confirm current requirements through the DoD's CMMC resources and Cyber AB
Rely on those primary sources rather than secondhand summaries — including this one.
Frequently Asked Questions
Is a CNC program considered CUI?
It depends on the specific information, the contract, and applicable safeguarding requirements. Not every G-code file automatically qualifies. Confirm the determination with the contracting organization or a qualified compliance professional rather than guessing.
What evidence might a C3PAO request for CNC program delivery?
Expect data-flow diagrams, approval and revision history, access and transfer logs, configuration records, media-handling procedures, training records, and incident or recovery documentation.
Can a machine shop use USB drives to transfer CNC programs during a CMMC assessment?
Removable media isn't automatically prohibited, but its use needs to be authorized, controlled, scanned or managed per policy, and traceable. Undocumented, unrestricted USB use is what draws scrutiny.
How does a C3PAO assess legacy CNC machines?
Assessors examine how older equipment is scoped, isolated, accessed, and maintained. They look for compensating controls such as network isolation when the controller lacks modern security features.
What happens if a machinist uses the wrong CNC program revision?
Contain the issue immediately, assess production and security impact, notify stakeholders, and investigate the delivery and approval trail. Restore a trusted version and document corrective action.
Can a C3PAO help a manufacturer fix CNC security gaps?
No. An independent assessment is separate from preparation or remediation work, and Cyber AB conflict-of-interest rules restrict assessors from doing both. Verify any provider's actual authorized role before engaging them.


