
Introduction
A single wrong CNC program can wreck a production run. Send the outdated revision, or push a file to the wrong machine, and you're looking at scrap, rework, and a scheduling mess that ripples through the whole shop.
For defense contractors and suppliers handling controlled unclassified information (CUI), the stakes go higher. Access control, auditability, and secure system operation aren't just good practice anymore. They're CMMC considerations that show up in audits.
This article compares two ways of getting approved programs from a central system to CNC equipment: traditional push-based delivery and modern pull-based delivery.
One note on terminology: "CMMC-ready" describes design and operational capabilities that can support applicable security practices. It does not mean any DNC product or manufacturer is automatically certified.
Key Takeaways
- Push DNC is admin- or server-initiated; pull DNC lets an authenticated user request an approved program on demand.
- Centralized push control is strong, but timing, targeting, and stale-file risks remain.
- Pull-based delivery strengthens traceability and least-privilege workflows, but only with proper authentication and logging.
- CMMC readiness comes from your entire people, process, and technology environment, not from picking push or pull.
- Choose based on machine compatibility, program-control needs, and the audit evidence you must produce.
Push-Based vs Pull-Based DNC: Quick Comparison
Here’s how push and pull DNC compare on the factors that matter most for a CMMC-ready shop floor.
| Factor | Push-Based | Pull-Based |
|---|---|---|
| Delivery model | Admin, server, or scheduler sends the program to a machine | Authorized operator or machine requests an approved program at job time |
| Revision control | Earlier local copies can linger after a revision changes | Machine pulls the current approved revision at request time |
| Accountability | Who sent what, and when, depends on logging depth | Authenticated request ties user, machine, job, and revision to delivery |
| CMMC support | Needs RBAC, secure admin, and segmentation added on top | Least privilege is easier by design; still needs encryption, monitoring, and correct config |
| Best fit | Tight schedules and predictable machine assignments | High-mix, revision-sensitive, or distributed shops |
| The core difference is who initiates the transfer—not security by default. Either model can be built well or poorly. CMMC readiness still depends on the access control, logging, and revision governance wrapped around the delivery path. |
What Is Traditional Push-Based DNC Delivery?
Push-based DNC is the model most shops grew up with. A central server, programmer, or supervisor selects a file and actively sends it to a CNC controller.
Controlink's Machine Link™ works this way at its core: an operator selects the machine control, opens the file, prepares the machine, and clicks [SEND]. The software then displays session parameters and percentage-complete status while transferring.

Where Push Delivery Works Well
Push shines in environments where a central planner already knows exactly what's going where:
- Planned production runs with predictable machine assignments
- Repeat jobs, where the same file gets sent every time [CYCLE START] is pressed until [CANCEL] is selected
- Centralized coordination that eliminates carrying USB drives or floppy disks between stations
- Legacy compatibility, since most push systems (Machine Link™ included) communicate over standard RS-232 serial connections that older controls already support
Risks Worth Assessing
Push isn't inherently insecure, but it does carry operational risks that need deliberate controls:
- Wrong-machine or wrong-time delivery — a file gets pushed before the operator is ready, or to the wrong control entirely.
- Stale local copies — a program stored on a machine after delivery can drift from the engineering master if it isn't reconciled.
- Incomplete evidence trails — without detailed logging, you may not have a clear record of who approved, transmitted, or modified a program.
- Compromised admin access — a single compromised account or server could distribute an unauthorized file across many machines at once.
Ametek's experience is a real illustration of the revision-control problem. Their original DNC workflow required multiple trips to the computer, and corrected programs often weren't sent back or saved. The result: the same program had to be fixed again and again, because there was no reliable loop closing the gap between what ran at the machine and what engineering approved.
Before keeping or upgrading a push system, verify these controls:
- Machine targeting accuracy
- Revision locking and approval gates
- Delivery confirmation
- Audit-log retention
- Administrator privilege boundaries
- Offline behavior on older controls
What Is Modern Pull-Based DNC Delivery?
Pull-based delivery flips the initiation point. Instead of a server pushing a file, an authenticated operator or machine requests the approved program from a controlled source at the point of use.
Machine Link™ QUICK Serve is a working example of this pattern. The machinist opens a CNC Request Program (O1111) at the control, enters the desired filename in the Request Line, and prepares the machine to receive it.
After a short adjustable delay, QUICK Serve locates and serves the requested file directly to that machine's control. The software continuously scans connected machines for these requests and can service up to three machines simultaneously from one computer.

How Pull Delivery Strengthens Program Governance
- Reduces stale-file exposure by pulling the current approved revision at request time instead of a copy saved days earlier
- Captures context together: user, machine, job, and revision tie to one request event
- Keeps revision control with engineering by routing machine-edited programs to a review folder before they re-enter the CNC library
- Prevents unapproved requests when the workflow gates access to approved files only
Connecting Pull Delivery to CMMC Considerations
NIST SP 800-171 Rev. 2 maps the control families that matter for this workflow: access control, identification and authentication, audit and accountability, media protection, configuration management, and incident response. A pull-based system generates useful evidence for several of these, including access events, delivery records, revision history, and failed requests.
That evidence is only useful if it's protected, time-synchronized, reviewed regularly, and retained according to policy. A pull request log sitting unmonitored on an unsecured server doesn't help you during an assessment.
Implementation Challenges to Plan For
- Reliable identity management and network availability are prerequisites, not afterthoughts
- Legacy CNC controls may need gateways or serial-to-Ethernet adapters. Test compatibility before rolling out broadly
- Security controls need to extend to endpoints, repositories, and backups, not just the DNC application itself
- You need a documented fallback procedure for when the network goes down mid-shift
Push vs Pull: What Is Better for CMMC-Ready Manufacturing?
Neither model wins outright. CMMC readiness depends on how the system is configured, operated, and documented, not on whether files get pushed or pulled.
When to Choose Each Model
- Stick with push when production is highly scheduled, machine assignments are predictable, and you can enforce strong approval, targeting, and logging controls around it.
- Move toward pull when you need point-of-use access, tighter operator accountability, less stale-file risk, or better linkage between job identity and program revision.
- Consider a hybrid when engineering stages the job centrally and the operator authenticates to request the final approved program at the machine. Shops often run Machine Link™ alongside QUICK Serve across different machine groups this way.
A CMMC-Readiness Evaluation Process
- Inventory your CNC programs and metadata to identify which files or work instructions may touch CUI.
- Map your system boundary: connected assets, users, service accounts, network paths, and removable media.
- Compare current DNC capabilities to applicable practices, then document gaps in policies, configurations, and monitoring.
- Bring in a qualified cybersecurity professional or authorized assessor to validate your interpretation. This article is not a compliance determination.
What Real-World Evidence Shows
CIMCO's documented case with M-1 Tool Works is a useful reference point. The shop had been hand-delivering increasingly large programs on flash drives. Moving to a central server with versioning and quarantine controls let them track and revert changes rather than chase down which copy was current.
The case doesn't quantify scrap avoided. It does show the revision-governance gap that both push and pull systems need to close.
Snavely's Machine faced a similar shop-floor problem. With 30+ CNC machines, 10 control types, and 40 operators, Scott Cooper described picking the right program for the right machine as "quite an ordeal" before the workflow was standardized.

CMMC-adjacent controls exist for that operational certainty: knowing which file ran where, not only for an audit trail.
Practical Evaluation Checklist
Before selecting or replacing a DNC system, verify:
- Machine and protocol compatibility (RS-232, Ethernet, USB)
- Authentication and role-based authorization
- Revision control and approval workflows
- Audit trail generation and retention policy
- Encryption and network segmentation
- Backup and offline-recovery procedures
- Vendor support and total cost of ownership
- Documentation sufficient for CMMC evidence requests
Where Controlink fits: Controlink Systems LLC has built CNC/DNC communication software since 1998, including push-style tools like Machine Link™ and request-driven tools like Machine Link™ QUICK Serve. If you need legacy-machine connectivity or shop-floor automation support, that is worth discussing.
Any CMMC assessment or certification still depends on your full security environment and qualified compliance support. No single software vendor can make that determination.
Conclusion
Push-based DNC can still be the right call when centralized dispatch and controls are genuinely strong. Pull-based delivery tends to win when point-of-use authorization, revision accuracy, and traceability matter more. That edge shows up most in complex or security-sensitive shops.
Either way, CMMC-ready delivery comes from a complete control framework spanning people, processes, software, machines, networks, identities, and logs. No single delivery model gets you there alone.
Before you commit, pressure-test the model against your shop:
- Document the current workflow and flag program-control and security gaps
- Check real CNC compatibility and how operators actually request or receive files
- Validate recovery scenarios and audit requirements under realistic conditions
Frequently Asked Questions
Does DNC software replace CNC simulation or CAM?
CNC simulation software validates toolpaths, machine motion, and collision risks before a program runs. DNC software manages secure storage, control, and delivery of that program. Many shops need both — they solve different problems.
What is the difference between push-based and pull-based DNC software?
Push systems have a central admin or server initiate delivery to a machine. Pull systems let an authorized operator or machine request the approved program when it's actually needed.
Is pull-based DNC software automatically CMMC compliant?
No. Pull delivery can support access control and traceability goals, but CMMC compliance depends on your full technical, administrative, and organizational environment — not on the delivery model alone.
Can pull-based DNC software work with legacy CNC machines?
Often, yes, but it depends on the controller, interface, and available adapters. Test each machine's compatibility before deploying pull-based workflows shop-wide.
What security features should a CMMC-ready DNC system include?
Look for authentication, role-based authorization, protected repositories, audit logging, revision control, network segmentation, backups, and documented procedures for incident response.
Should a manufacturer replace push-based DNC with pull-based delivery?
Assess your job routing, machine count, revision risk, CUI scope, and existing controls first. Many shops land on a hybrid approach rather than a full replacement.


