
Removable media isn't automatically allowed, and it isn't automatically banned either. Whether a USB drive, external SSD, or memory card can touch your systems depends on the specific machine, the data involved, your organization's policy, and what your contract actually requires.
This article breaks down what counts as removable media, what the current DoD and CMMC requirements say, and how to build a shop-floor workflow that protects sensitive files without grinding production to a halt.
Key Takeaways
- Removable media use requires both an authorized operational need and an approved system.
- Personal or unknown USB devices stay off contractor systems unless a documented inspection process clears them.
- A compliant process combines policy, approved devices, scanning, encryption, custody, logging, and incident reporting.
- Controlled CNC/DNC file-transfer workflows cut down on ad hoc USB use and improve traceability.
What DoD Contractors Need to Know About Removable Media Rules
"Permitted" doesn't mean the same thing everywhere in your facility. An administrative workstation, a networked CNC controller, and a system processing CUI carry different risk profiles and different rules. Treating them identically is where most policies fall apart.
The Binding Requirements
Your obligations come from your contract, not general best practice. Two clauses matter most:
- DFARS 252.204-7012 requires adequate security—generally NIST SP 800-171—for systems that process, store, or transmit covered defense information. DFARS 252.204-7012
- DFARS 252.204-7021 requires maintaining the CMMC status specified in the contract for systems handling FCI or CUI, plus an annual affirmation in SPRS.
Under 7012, "media" explicitly includes magnetic tapes, optical disks, memory chips, and printouts.
The CMMC Assessment Guide – Level 2 lays out nine Media Protection practices (3.8.1–3.8.9), covering physical control, sanitization, marking, transport, and use restrictions.
NIST SP 800-171 Rev. 2 states the same requirements; Rev. 3 reorganizes them under a slightly different numbering scheme. Check which revision your solicitation cites before you build a program around either one.
Baseline Principles to Verify
Before you write a single procedure, confirm these against your own policy:
- Operational necessity is documented, not assumed
- The organization owns or has authorized the device
- Both the endpoint and the user are approved
- The data type and classification are known
- The transfer method and approval are recorded
A government-owned or company-issued device isn't automatically acceptable. It may still need inventory registration, encryption, malware inspection, or approval for the specific network it's touching.
When policy language is unclear, loop in your system security officer or information system security manager. This article isn't a substitute for contract-specific legal or cybersecurity advice.
What Counts as Removable Media—and Why the Shop Floor Is High Risk
NIST defines a removable media device as any system component that can be added to or removed from a network and is primarily used for data storage. That covers more ground than most people assume.
Beyond the Obvious USB Drive
Your policy should account for:
- USB flash drives, SD cards, and memory cards
- External hard drives and portable SSDs
- Writable optical discs
- Camera storage cards
- Laptops, tablets, and phones with Bluetooth or storage capability
Mobile devices and Bluetooth peripherals create the same data-transfer and wireless exposure as a thumb drive, even though nobody calls them "removable media" in casual conversation. Check your organization's formal definition before you assume something is out of scope.
Why the Shop Floor Amplifies the Risk
A machine shop floor has failure points that an office environment doesn't:
- Unknown drives left near a machine, often assumed to be a coworker's
- Personal devices used during urgent rework when the "right" process feels too slow
- Vendor-supplied media for fixture data or calibration files
- Shared USB drives with no clear owner, passed between shifts
- Legacy controllers that lack modern authentication or logging entirely
Industrial cybersecurity research underscores the risk. Honeywell's 2022 Industrial Cybersecurity USB Threat Report, based on data from hundreds of industrial facilities, found that 52% of cyber threats were specifically designed to exploit removable media, up from 32% the year before.

That figure is a threat-design statistic, not a claim about DoD-specific breach rates. It still shows where attackers are aiming their effort.
An infected drive on a production controller doesn't just risk malware. It can move engineering files outside approved custody, introduce an outdated CNC program, or make an incident nearly impossible to reconstruct after the fact.
How to Build a Compliant Removable-Media Workflow on the Shop Floor
A workable process starts before the device ever touches a machine.
Start With Written Justification
Document the machine, workstation, user, data type, destination, and transfer direction. Then answer the harder question: why can't an approved network transfer handle this instead? If there's no good answer, the removable-media request probably shouldn't be approved.
Approve and Issue the Media Itself
Each authorized device needs:
- Clear ownership — company-issued, with a unique inventory identifier
- A permitted user or role, not open access
- Approved systems it's cleared to touch
- A data classification limit and an expiration or review date
Inspect Before It Reaches Production
Every device gets scanned through an authorized inspection point before connecting to a production endpoint, whether that's an isolated scanning station or another approved process matching your environment. Document the result every time. Reject anything without a clear, identifiable owner.
Map the Transfer Sequence
From engineering release to the machine, run this sequence every time:
- Confirm the file is current
- Verify the machine and revision
- Scan and authorize the device
- Move only the file needed
- Validate it at the destination
- Log the transaction
Custody Matters as Much as the Scan
Once media is issued, it stays under the authorized user's control. Label it according to sensitivity, store it securely when idle, and prohibit informal sharing. Sanitize or return it through your designated process when the job's done.

Controlled CNC/DNC file distribution addresses the same risk: getting the correct, current program to the correct machine without walking a drive across the floor. Controlink Systems LLC has built CNC/DNC communication software for shop floors since 1998.
Its Machine Link™ QUICK Serve tool returns the latest engineering-approved file directly to the machine control and routes program edits back to engineering for review, cutting out the manual USB step. That does not satisfy DFARS or CMMC on its own, but fewer ad hoc USB transfers remove a major source of untraceable file movement.
Technical and Administrative Controls That Make the Policy Enforceable
A written policy is only as good as the controls behind it.
Technical Restrictions
Apply these technical controls where feasible:
- Disable unauthorized USB storage at the endpoint level
- Allow only approved device identifiers
- Separate charging ports from data-transfer ports where hardware supports it
- Restrict Bluetooth and other wireless connections on production systems
- Apply endpoint or network controls appropriate to the system's authorization boundary
NIST SP 800-53 MP-7 offers a menu of options here, including physical port restrictions and device allow-listing. None of these are mandated by name; you choose what fits your environment and document the choice.
Data Protection and Logging
Validate against your contract and system policy:
- Encryption for CUI in transit, and at rest where the contract requires it
- Least privilege access controls tied to role, not blanket permissions
- Data-classification labels on files and media alike
- Restrictions on approved file formats for copying to portable devices
Log every device connection, user, workstation, file movement, scan result, and exception. Those records are what you hand an assessor, and what lets you reconstruct an incident instead of guessing.
When Something Goes Wrong
For a lost, stolen, infected, or unauthorized device:
- Stop using it immediately to limit further exposure
- Preserve evidence where it is safe to do so
- Disconnect or isolate affected equipment if directed by your incident process
- Notify your designated security contact without delay
- Meet the contractual reporting timelines that apply to your environment
Under DFARS 252.204-7012, a qualifying cyber incident must be reported within 72 hours of discovery through DIBNet, with relevant system images and monitoring data preserved for at least 90 days. Not every failed scan or blocked device triggers this clause. Knowing the threshold matters more than guessing at it during an actual incident.

Audit-Ready Implementation Checklist for a DoD Contractor
Assessors want evidence, not intentions. Build a one-page checklist that covers:
- Current removable-media policy and applicable contract/system requirements
- Approved-device inventory with unique identifiers
- Authorization records and user training documentation
- Scan logs, transfer logs, and exception approvals
- Incident records and sanitization/destruction logs
- Policy review dates Run a role-based walk-through with security, IT, engineering, quality, production supervision, and operators in the same room. That session usually surfaces the undocumented workaround — often on legacy CNC equipment, or during a rush job when the normal process felt too slow. Test the process against real scenarios:
- An unknown USB device shows up near a machine
- An authorized device has expired
- A vendor hands over a file on their own drive
- A device goes missing
- A scan flags malware
- The DNC network goes down mid-shift and a current program still needs to move One shop we've worked with, Snavely's Machine, ran 30+ CNC machines across 10 control types with 40 operators. Getting the right program to the right machine was already hard before media-control rules entered the picture. An integrated CNC/DNC setup, such as those from Controlink Systems LLC, can cut that ad hoc USB dependence by making repeatable, traceable file distribution part of normal production. Map where your workflow still relies on manual transfers and replace those paths with a documented alternative before the auditor asks.
Frequently Asked Questions
Is removable media permitted for DoD use?
It may be permitted for an authorized, mission-essential purpose, but permission depends on the applicable DoD or customer policy, the system involved, data classification, and device approval status. There's no blanket yes or no.
What counts as removable media?
USB drives, memory cards, external hard drives or SSDs, writable optical media, and portable devices with storage or data-transfer capability all qualify. Your organization's formal policy definition controls what applies in your environment.
Are personal USB drives allowed on a DoD contractor's systems?
No, not by default. Personal or unknown removable media should be treated as prohibited unless an authorized policy and inspection process expressly allows a specific, documented exception.
What should a contractor do if an unknown USB drive is found on the shop floor?
Don't connect it. Preserve it as found if it's safe to do so, and notify your designated security or IT contact according to your incident procedure. Guessing at its origin isn't worth the risk.
What if a CNC job requires a file transfer and the approved network is unavailable?
Production urgency doesn't override authorization requirements. Use your documented exception or contingency process, and transfer files only through an approved, inspected, and traceable method — even if it takes longer than plugging in a drive would.


