
Introduction
Open a G-code file and you'll see numbers, letters, and coordinates. Nothing that looks classified. But that same file can encode tolerances tight enough to matter to a warfighter, a tooling strategy a competitor would pay for, or geometry and notes pulled straight from a customer's controlled CAD model.
The distinction that trips up many shops is simple: a CNC program isn't automatically Controlled Unclassified Information (CUI) just because it runs on a defense job. Its status depends on the contract, where the underlying data came from, the applicable CUI category, any markings attached, and whether the file contains or was derived from covered defense information.
This guide covers the DFARS clauses that matter, the file types that carry risk, and how programs move through CNC/DNC workflows. It also flags legacy equipment gaps and the questions to ask before a file ever touches a shop-floor system.
Key Takeaways
- CNC programs trigger CUI safeguarding when they contain or derive from controlled technical information in your contract.
- Map the full data path — CAD to CAM to DNC transfer to controller to backup — not just the final G-code file.
- Match DFARS 252.204-7012 and flow-down language to your contract; "defense work" is not a compliance category.
- Segmentation, role-based access, revision control, and legacy-equipment isolation cut exposure without stopping production.
- CNC/DNC software can support controlled workflows, but the contractor owns CUI determination and compliance outcomes.
What Makes a CNC Machine File CUI?
CUI is unclassified information that a law, regulation, or government-wide policy requires an agency to protect with safeguarding or dissemination controls. Under DFARS 204.7301, Controlled Technical Information (CTI) is technical data with military or space application that carries access, use, or release restrictions. That includes engineering data, drawings, specifications, process sheets, and executable or source code.
Several file types in a typical machining workflow can carry or reveal that kind of information:
- CAD models, drawings, and GD&T data supplied directly by a customer or prime
- CAM files, toolpaths, post-processed G-code, probing routines, and setup sheets generated from that controlled design data
- Inspection programs and process validation records that reveal controlled tolerances or performance requirements
Conversion Doesn't Erase Control
Here's the part shops often miss: converting a CAD file to CAM, or CAM to G-code, doesn't strip the underlying sensitivity. DoDI 5200.48 requires a document derived from controlled material to carry the same "CUI" marking if the information still qualifies, even after it's been reshaped into a new format. A setup sheet built from a controlled drawing can be just as sensitive as the drawing itself.
Before You Classify a File as CUI
Check these factors, in this order:
- Contract clauses and markings: what does the solicitation or purchase order actually say?
- Customer or prime instructions: has anyone identified a CUI category or dissemination restriction in writing?
- Source of the data: is it government-furnished, or derived from something that was?
Then document your decision. Record:
- Who owns the file
- Who's authorized to access it
- Which systems it lives on
- How long it's retained
- How it gets disposed of
If a machinist or programmer isn't sure, that's a signal to escalate, not a judgment call for the shop floor to make informally.

Which DFARS Requirements Apply to CNC Programs?
DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," is the clause most CNC shops with defense work will run into. It requires adequate security on any nonfederal system that processes, stores, or transmits covered defense information, measured against the NIST SP 800-171 baseline in effect when the solicitation was issued, not automatically the newest revision. What the clause actually requires:
- Protecting CUI and covered defense information using the incorporated security requirements
- Maintaining documented system boundaries for anything that touches the file
- Reporting a cyber incident within 72 hours of discovery to DoD
- Preserving affected system images and monitoring data for at least 90 days
CMMC Is a Verification Layer, Not a Separate Rulebook
DFARS 252.204-7021 governs Cybersecurity Maturity Model Certification (CMMC) status requirements. Clause 7012 sets the underlying safeguarding obligation. Clause 7021, when inserted into your contract, sets the assessment level and mechanism (self-assessment or third-party) required to prove you meet it. CMMC implementation timelines have shifted more than once. Don't rely on a date from an older article; check the current DoD CIO guidance directly.
Flow-Down Doesn't Stop at the Prime
A prime contractor's DFARS obligations often reach further than people expect. A machine shop, an outside CNC programmer, an inspection vendor, or even a maintenance contractor with remote access to a controller can inherit these requirements if the subcontract involves covered defense information. Don't assume a lower-tier role means no exposure. Check the actual flow-down language in your subcontract.
How CUI Moves Through the CNC Workflow
A single controlled file typically passes through more systems than most people initially map out.
A representative lifecycle looks like this:
- Secure receipt from the customer or prime
- Engineering review and CAD/CAM preparation
- Approval and revision control
- DNC transfer to the CNC controller
- Production, inspection, and quality documentation
- Backup, archival, and eventual destruction or decontrol
Each step touches systems that may fall inside your CUI assessment boundary:
- Email, file-transfer portals, and engineering workstations
- CAM and DNC servers, shared drives, and removable media
- Machine controllers, inspection equipment, and ERP/MES platforms
- Printed setup sheets on the shop floor
Revision Control Is a Safeguarding Issue, Not Just a Quality One
If a machinist can pull up an obsolete or unapproved program, that's both a scrap risk and a data-control failure. A defensible process records who approved, released, modified, transmitted, and retired each revision, and blocks anything else from reaching the controller.
This is exactly where workflow tool integration matters most. Machine Link™ PLUS, for example, returns the latest engineering-approved file to a machine and routes field edits back to engineering for review, rather than leaving a hand-modified version on the controller indefinitely.
Legacy Controllers Change the Math
Many shop-floor controllers can't support authentication, patching, or endpoint protection. They simply weren't built for it. NIST SP 800-82 Rev. 3 addresses this directly, recommending segmentation between IT and OT networks, controlled transfer points, and data diodes or firewalls that only allow explicitly authorized communication. If a controller can't meet a requirement natively, the fix is a documented, adjudicated compensating control, not silence about the gap.

Safeguarding CNC Files and Shop-Floor Systems
Practical safeguards break down into four control groups.
| Control Area | What It Covers |
|---|---|
| Access | Least privilege, role-based permissions, unique accounts, prompt removal after a project or role change |
| Transfer | Encrypted channels, approved DNC pathways, controlled removable media, no personal email or consumer file-sharing |
| Integrity | Revision identifiers, release workflows, digital approval, backups, change records |
| Visibility | Audit logs for access, downloads, edits, transfers, and failed attempts |
Physical and human safeguards matter just as much on the shop floor:
- Visitor controls and screen-visibility rules near active terminals
- Secure handling and disposal of printed setup sheets
- Operator training on what not to photograph, copy, or email
- Clean-desk practices for anything with controlled data printed on it
Where a CNC/DNC Platform Fits — and Where It Doesn't
Controlink Systems LLC has built DNC communication tools since 1998, including:
- Machine Link™ for standard serial file transfer
- Machine Link™ QUICK Serve for automated file delivery to machine controls
- PDADNC™ for mobile transfer
These tools cover the integration manufacturers need for controlled revision delivery, transfer logging, and legacy-controller support in one place. A Timken newsletter case study from 2000 credited Controlink's technology with improving data security by eliminating floppy-disk transfers.
That said, no software platform is automatically DFARS- or CMMC-compliant simply because it moves files reliably. Before deploying any CNC/DNC tool into a controlled environment, verify its access control, logging, revision management, secure transfer, and evidence-capture capabilities against your actual security boundary and contract requirements.

A Practical Compliance Review for CNC Programs
Run this checklist before a controlled file goes anywhere near a machine.
Pre-production checks:
- Identify the contract, prime, CUI category, and any markings or handling instructions
- Inventory every system and person who will touch the file
- Confirm the approved revision and who has release authority
- Verify the transfer path and receiving machine sit inside your documented security boundary
- Confirm subcontractor and vendor flow-down obligations
Evidence to have ready for a customer inquiry or internal review:
- Data-flow diagram and asset inventory
- Access approvals and training records
- System security documentation
- Transfer logs and revision history
- Incident procedures and supplier agreements
When to Pause and Ask
Stop production and get clarification if you see:
- Missing or conflicting markings
- Two revisions in circulation with no clear authority
- A request to load a file onto a system outside the documented boundary
- Suspected exposure or an unapproved transfer method
This article is educational guidance, not legal advice. Confirm specific obligations with your contracting officer, prime contractor, and a qualified compliance adviser using current official DFARS and CMMC sources.
Frequently Asked Questions
What are the requirements for DFARS compliance?
Requirements depend on your contract and the clauses it incorporates. They typically cover safeguarding covered defense information, cybersecurity controls, incident response, subcontractor flow-down, documentation, and any CMMC level stated in the solicitation.
Is CMMC required for CUI?
CUI contracts may require CMMC at a specific level and assessment type, but only if the solicitation or contract states it. DFARS safeguarding obligations under 252.204-7012 apply separately and should be reviewed on their own.
What is the DFARS clause for CUI?
DFARS 252.204-7012 is the central safeguarding and cyber incident reporting clause commonly tied to covered defense information. Always confirm the full set of clauses actually incorporated into your contract.
Are CNC program files automatically considered CUI?
No. A CNC file isn't CUI just because it's used for defense manufacturing. Its status depends on the information it contains or derives from, the contract terms, applicable CUI category, and any handling instructions from the government or prime.
How should a machine shop protect CUI on legacy CNC equipment?
Scope and segment the system, then move files through controlled transfer stations with restricted removable media. If the controller can't support modern security features, document compensating controls and physical safeguards.


