
CMMC Level 2 readiness doesn't stop at the office server. It touches CNC controllers, DNC file transfers, USB drives, printed travelers, shop-floor tablets, and the people who handle all of it. This playbook walks through determining whether Level 2 applies, mapping your CUI, defining your assessment boundary, translating requirements into real shop-floor controls, fixing gaps, and preparing evidence for assessment.
Program rules, contract clauses, and implementation dates change. Confirm current requirements with the DoD CIO CMMC office, the CMMC Program Management Office, NIST, and the Cyber AB before making compliance decisions.
Key Takeaways
- Your contract and CUI determine whether Level 2 applies, not your industry label.
- Assessment scope covers every system touching CUI, including email, drives, and printers.
- A documented enclave shrinks scope only when separation is real and enforced.
- Certification needs technical controls plus evidence: policies, training logs, and access reviews.
What CMMC Level 2 Means for a CNC Manufacturer
Not everything that flows through your shop is CUI. Federal Contract Information (FCI) is government-provided or government-generated information tied to contract performance that isn't intended for public release: think a basic purchase order. CUI is a narrower, more sensitive category requiring specific safeguarding under law or government policy. The distinction matters because it drives which security level applies to your systems.
CMMC Level 2 aligns with the 110 security requirements in NIST SP 800-171 Rev. 2, organized into 14 control families such as access control, incident response, and media protection. NIST has published Rev. 3, but current CMMC materials still reference Rev. 2—confirm which version applies before you build your program.
Where the Obligation Actually Comes From
Your obligation traces back to contract clauses, not your shop's SIC code. Specific triggers include:
- DFARS clauses flowed down from a prime contractor
- Subcontract terms requiring a specific CMMC status before award
- Direct instructions from a customer identifying what they're sending you as CUI
If your prime hasn't told you what's CUI, ask. Don't guess.
What Counts as CUI on a Shop Floor
Typical CUI candidates on a shop floor include:
- Defense-related drawings and CAD/CAM files (including revisions)
- Material specs, process sheets, and inspection data
- Travelers, setup photos, and tooling details
- Customer portal access and manufacturing programs
G-code and part numbers aren't automatically CUI or automatically exempt. Classification depends on their connection to a controlled defense program.
Quick scope check. Ask yourself:
- Does any contract reference CUI, DFARS 252.204-7012, or a required CMMC level?
- Do you receive or create drawings, specs, or programs tied to defense work?
- Do outside vendors, IT providers, or remote users touch those systems?
- How long do you retain that data, and where does it live once the job's done?
Map the CUI Boundary Before Buying Technology
Buying security tools before you know your boundary is how shops overspend and still fail an assessment. Start with a data-flow map tracing CUI from receipt through quoting, engineering, programming, production, inspection, shipping, archiving, backup, and disposal.

Pair that map with an inventory of everything that touches or could touch CUI:
- Users, endpoints, and servers
- Cloud applications and file shares
- CNC controllers and DNC systems
- Removable media, printers, phones, and cameras
- Third parties with remote access
Enclave vs. All-In
A bounded enclave is a defined set of systems that handle only CUI and stay separated from the rest of your network. Used well, it can shrink your assessment scope in a meaningful way. Going all-in—treating the entire shop network as in-scope—is simpler to operate day to day, but every control applies everywhere.
According to DoD's CMMC Level 2 Scoping Guide, an asset is only out of scope if it cannot process, store, or transmit CUI and is physically or logically separated from assets that do. A firewall rule you forgot about doesn't count as separation.
Common ways shops accidentally blow up their scope:
- Shared Microsoft 365 or email accounts used for both CUI and general business
- General-purpose file shares mixing job types
- Personal USB drives plugged into shop-floor terminals
- Unmanaged laptops or shop tablets with network access
- Collaboration platforms and common printers reachable from both environments
Those gaps are why boundary documentation matters. Include a diagram of what's in scope, what's out, the interfaces between them, and the safeguards on each connection. A consultant, managed service provider, or assessor can review the boundary, but the manufacturer stays accountable for how it runs day to day.
Translate Level 2 Requirements Into CNC Shop Controls
Generic security checklists don't mean much until they're translated into shop-floor language. Here's how the major control families show up in a machining environment. Access control means engineering files, NC programs, inspection records, and job travelers are only reachable by people who need them, not the whole shop. Apply role-based access, review permissions periodically, and don't forget temporary personnel and remote support accounts. Identification and authentication gets harder with legacy CNC equipment that predates modern login requirements. Multi-factor authentication (MFA) should cover office systems, remote connections, and service accounts at minimum, with compensating measures documented for machines that can't support it. System and communications protection covers network segmentation, firewalls, encrypted file transfer, and secure remote access. This is where CNC/DNC transfers matter most: files moving between an engineering system and a machine controller need a controlled, auditable path, not a USB stick passed hand to hand. Media and physical protection applies to USB devices, printed drawings, backup media, tool carts, and locked cabinets. Visitor access to shop-floor areas handling CUI needs the same scrutiny as server room access.
Handling the Scenarios That Actually Happen
- A workstation gets compromised — do you have monitoring and an incident procedure?
- G-code gets altered without authorization — would you catch it?
- An unknown USB device shows up on the floor — is there a policy, and does anyone follow it? Every control area needs evidence an assessor can review:
- Policies and network diagrams
- Asset inventories and access-review logs
- Training records and vulnerability scans
- Backup tests and incident records An assessor doesn't take your word for it. A note on legacy equipment: older CNC machines may need segmentation, supervised operation, or exclusion from the boundary entirely rather than a technical fix. No single workaround guarantees assessor acceptance without a documented risk analysis. This is also where CNC/DNC infrastructure earns its keep. Controlink Systems LLC has built CNC/DNC communications and shop-floor automation tools since 1998, including Machine Link™ for program transfer over standard serial communications and Machine Link™ QUICK Serve for engineering-approved delivery to multiple machines. Tools like these help enforce that machinists run the correct, current file rather than a stray copy on a thumb drive. A DNC or automation product is still one piece of a much larger program. It doesn't establish CMMC compliance by itself.
CMMC Level 2 Readiness Roadmap: From Gap Assessment to Certification
Certification readiness happens in stages, not all at once.
- Confirm the obligation and scope. Collect contract clauses, ask your prime what's CUI, and identify suppliers and service providers touching your systems.
- Build the current-state record. Inventory assets, document users and roles, review existing policies, and record how CUI moves, gets backed up, printed, and destroyed.
- Run a control-by-control gap assessment. Map each requirement to an owner, current evidence, the gap, a remediation action, and a target date. Separate missing technology from missing process.
- Remediate in risk order. Start with identity and access, MFA, endpoint protection, and patching. Then address segmentation, encryption, logging, backups, incident response, and training.
- Build the System Security Plan (SSP). Describe your environment, boundary, implemented controls, and known deficiencies. Confirm Plan of Action and Milestones (POA&M) rules before you rely on one; current rules allow only specific, limited uses.
- Validate readiness. Test restores, sample access permissions, review logs, run an incident exercise, and confirm your evidence traces back to the SSP.
Choosing outside help? Ask for machine-shop or defense-supply-chain experience, request references and sample deliverables, and get clear on where their responsibility ends and yours begins. Be wary of anyone claiming to make you "CMMC-ready" without showing technical evidence.

Phase-gate checklist. Don't move forward until:
- Scoping → Remediation: Boundary is documented and confirmed with the prime
- Remediation → Readiness Review: All high-priority gaps are closed and evidenced
- Readiness Review → Assessment: SSP is current and every control has traceable proof
Assessment, Cost, Timeline, and Ongoing Compliance
Internal readiness work and an official assessment are not the same. A self-assessment is your own evaluation. A certification assessment requires a Certified Third-Party Assessment Organization (C3PAO) under the Cyber AB ecosystem.
Confirm which pathway your contract requires before you commit resources.
What Drives Cost
CMMC Level 2 costs usually land in these buckets:
- Scoping and consulting to define the CUI boundary
- Managed IT or security services for day-to-day controls
- Hardware, software, and network changes on the shop floor
- Employee training and policy documentation
- C3PAO assessment fees plus remediation
- Ongoing monitoring and maintenance
A March 2026 GAO report put DoD's own assessment cost estimates between $4,042 and $117,768. That range covers the assessment only—not full readiness spend for a machine shop. Get a scoped estimate instead of relying on a flat quote.

What Drives Timeline
Timelines move with factors like:
- CUI boundary complexity and multi-site operations
- Legacy CNC gear that needs compensating controls
- Subcontractor and supplier dependencies
- Strength of existing evidence and documentation
- Size of the remediation backlog
- C3PAO assessor availability
Staying Compliant Isn't a One-Time Event
Certification is the start of the operating rhythm, not the finish line. After you pass, keep the program alive with work such as:
- Monitoring configuration and environment changes
- Reviewing access rights on a set schedule
- Patching systems and testing backups
- Training staff and refreshing awareness
- Updating the SSP and asset inventory
- Vetting new software and suppliers before they touch CUI
- Preserving evidence so you can show what you did and when
Costs, timelines, assessment rules, and certification validity periods change. This article is educational only—it is not a System Security Plan, legal advice, or a formal readiness assessment, and it does not guarantee certification. Confirm current requirements with official sources, your contracting parties, and a qualified CMMC professional before you make business decisions.
Frequently Asked Questions
How much does CMMC Level 2 certification cost for a machine shop?
Cost depends on scope, existing systems, legacy equipment, remediation needs, consulting, and assessment fees. There's no universal figure. Get a scoped estimate based on your actual environment.
Can a machine shop self-assess for CMMC Level 2?
Internal gap assessments and preparation work differ from the official Level 2 pathway, which may require a C3PAO assessment depending on your contract. Verify current DoD rules before assuming self-assessment is enough.
How long does it take for a machine shop to achieve CMMC Level 2 certification?
Timeline varies with boundary complexity, existing controls, documentation maturity, legacy equipment, and assessor availability. Start with a gap assessment to get a realistic estimate for your shop.
Is CMMC Level 2 required for a machine shop?
It depends on your contract, the CUI you handle, and flow-down terms from your prime, not simply on being a machine shop. Confirm directly with your prime or contracting authority.
What counts as CUI in a CNC machine shop?
Possible examples include defense-related drawings, revisions, process data, inspection records, travelers, setup images, and manufacturing programs. Actual classification depends on contract context, so confirm with your prime and contract markings.
Do legacy CNC machines and DNC systems need to be replaced for CMMC Level 2?
Not automatically. Options include segmentation, physical safeguards, supervised transfers, and documented risk treatment, but any approach needs assessor review before you rely on it.


