An Executive Guide to CMMC, NIST 800-171, CUI, and Preparing Your Manufacturing Business for Defense Cybersecurity Requirements
For manufacturers in the Defense Industrial Base, CMMC establishes a framework for assessing whether contractors have implemented required cybersecurity protections for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The current CMMC model includes three levels. Level 1 addresses basic safeguarding requirements for FCI, while Level 2 is based on the 110 security requirements of NIST SP 800-171 Revision 2 for protecting CUI. Level 3 adds enhanced requirements for higher-priority programs.
CMMC implementation is also evolving. As of August 2026, implementation remains in Phase 1, and the Department of Defense has suspended the planned Phase 2 requirements while it reviews the program. Current contractual cybersecurity obligations have not disappeared, however. Manufacturers in the defense supply chain should continue strengthening their cybersecurity programs and preparing for applicable requirements.
A practical CMMC strategy starts with five areas: applicability, required CMMC level, FCI/CUI scope, security and documentation gaps, and ongoing compliance.
1. Determine Whether CMMC Applies to Your Manufacturing Company
Manufacturers working directly or indirectly in the defense supply chain may be required to protect FCI or CUI. The specific requirements depend on the company’s contracts, the information it handles, and how that information is processed, stored, and transmitted.
Federal Contract Information (FCI) generally includes information provided by or generated for the federal government under a contract that is not intended for public release.
Controlled Unclassified Information (CUI) is government information that requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policies.
For manufacturers, covered information may appear in engineering documentation, technical specifications, drawings, files, email, collaboration platforms, or other systems used to perform defense-related work.
Contract requirements and information flows therefore need to be evaluated together. A company should understand which contractual clauses apply, what types of information it receives or creates, and where that information moves throughout the organization.
2. Identify the CMMC Level Required by Your Contract
The current CMMC model includes three levels, with requirements determined by the contract and the type of information being protected.
CMMC Level 1: Foundational
Level 1 focuses on safeguarding FCI and includes 15 security requirements derived from FAR 52.204-21.
Under the current Phase 1 implementation, Level 1 requires an annual self-assessment and annual affirmation of compliance.
CMMC Level 2: Advanced
Level 2 focuses on protecting CUI and incorporates the 110 security requirements of NIST SP 800-171 Revision 2.
During the current Phase 1 implementation, Level 2 requirements are being enforced through self-assessments, with applicable results entered into the Supplier Performance Risk System (SPRS). Level 2 self-assessment status is generally valid for three years, subject to annual affirmation requirements.
CMMC Level 3: Expert
Level 3 is intended for higher-priority programs requiring cybersecurity protections beyond Level 2.
Because CMMC implementation continues to evolve, manufacturers should rely on their current contractual requirements and official DoD guidance rather than older CMMC charts or implementation schedules.
CMMC Levels at a Glance
| CMMC Level | Primary Focus | Security Requirements | Information |
|---|---|---|---|
| Level 1 | Basic safeguarding | 15 requirements from FAR 52.204-21 | FCI |
| Level 2 | Protection of CUI | 110 requirements from NIST SP 800-171 Rev. 2 | CUI |
| Level 3 | Enhanced protection for higher-priority programs | Level 2 plus additional enhanced requirements | CUI in higher-risk programs |
For many small and midsize manufacturers, determining whether the company handles FCI only or CUI is a critical early step because it directly affects the cybersecurity requirements that need to be addressed.
3. Identify Where FCI and CUI Exist in Your Environment
CMMC requirements apply to more than servers and cybersecurity software. Manufacturers need visibility into how covered information moves through the business.
A controlled document may arrive through email, be stored on a file server, used by an engineering application, accessed from a workstation, discussed through a collaboration platform, or shared with an authorized subcontractor.
Those activities can bring additional people, devices, applications, networks, and service providers into the compliance environment.
Manufacturers should document:
- Where FCI and CUI enter the organization
- Where the information is stored
- Who can access it
- Which computers, servers, applications, and cloud platforms interact with it
- Which networks transmit it
- Whether suppliers or subcontractors receive it
Reducing unnecessary access can also reduce compliance complexity. When sensitive information can be handled within a clearly defined environment, fewer systems and users may need to be included within the compliance boundary.
The appropriate scope depends on the manufacturer’s contracts, workflows, technology environment, and operational requirements.
4. Assess Security and Documentation Gaps
CMMC preparation includes technology, policies, procedures, documentation, responsibilities, and evidence.
For organizations working toward Level 2 requirements, NIST SP 800-171 addresses areas including access control, identification and authentication, incident response, configuration management, media protection, risk assessment, security assessment, and system and communications protection.
Many manufacturers already have some of these controls in place. The compliance work involves determining whether the controls satisfy applicable requirements, whether they are consistently implemented, and whether the organization can demonstrate that implementation.
Several components are particularly important.
System Security Plan (SSP)
The System Security Plan documents the organization’s system environment and describes how applicable security requirements are implemented.
The SSP should reflect the actual environment. Changes to systems, users, locations, vendors, networks, or security controls may require corresponding updates to the documentation.
Plan of Action and Milestones (POA&M)
A POA&M documents specific security requirements that have not yet been fully satisfied and establishes a plan for remediation.
The current CMMC program allows limited use of POA&Ms in certain Level 2 circumstances. Level 1 does not permit POA&Ms.
Not every missing requirement can therefore be deferred for future remediation.
Supplier Performance Risk System (SPRS)
SPRS is used to report applicable assessment information associated with defense cybersecurity requirements.
Manufacturers should know what information must be reported, who is responsible for submitting it, and whether the organization’s reported status accurately reflects its current cybersecurity environment.
Accurate documentation matters because CMMC requires more than having security products installed. Organizations need evidence showing how applicable requirements are implemented and maintained.
5. Build CMMC Compliance Into an Ongoing Process
CMMC readiness should continue after the initial assessment or remediation project.
Manufacturing environments change constantly. Employees join and leave, equipment is installed, cloud applications are adopted, facilities expand, vendors change, and cybersecurity threats evolve. These changes can affect the environment used to process, store, or transmit covered information.
A sustainable CMMC program can be organized around six stages:
Understand → Scope → Assess → Remediate → Document → Maintain
Understand
Identify applicable contractual requirements and determine what federal information the organization handles.
Scope
Define the people, systems, applications, networks, facilities, and service providers involved in processing, storing, or transmitting that information.
Assess
Compare the current environment with applicable cybersecurity requirements and document gaps.
Remediate
Prioritize identified gaps and implement appropriate technical, administrative, and operational improvements.
Document
Maintain the SSP, assessment information, policies, procedures, and supporting evidence that demonstrate how requirements are implemented.
Maintain
Review the environment as technology, personnel, contracts, and requirements change.
This ongoing process helps keep the compliance program aligned with the actual manufacturing environment rather than the environment that existed at the time of the last assessment.
CMMC Requires More Than IT
CMMC involves cybersecurity technology, but responsibility extends beyond the IT department.
Leadership decisions, employee behavior, physical security, documentation, vendor relationships, contracts, HR processes, and operational procedures can all affect compliance.
Access control is a good example. Technology can enforce MFA and account permissions, but the organization still needs processes for determining who should receive access, approving that access, removing it when an employee leaves, and periodically reviewing permissions.
The same principle applies throughout a CMMC program. Technical controls support compliance, while organizational processes determine how those controls are governed and maintained.
For manufacturers, CMMC preparation may require collaboration among leadership, IT, cybersecurity, operations, HR, compliance resources, and outside technology partners.
From the Field: Modernizing Compliance at a Precision Machine Shop
A precision machine shop working in the government procurement space needed to strengthen its IT infrastructure while modernizing its approach to security and compliance. The company was also building a new facility, creating an opportunity to address infrastructure and compliance requirements together.
AT-NET evaluated the manufacturer’s existing environment and developed a plan based on its compliance needs. AT-NET also specified and wired the technology infrastructure for the new facility and continues to support the organization as its security and compliance requirements evolve.
The company’s general manager described the importance of having technical guidance in practical terms:
“I’m a machinist, not an IT specialist.”
Manufacturing leaders don’t need to become cybersecurity engineers or NIST specialists. They do need clear visibility into contractual requirements, sensitive information, cybersecurity gaps, remediation priorities, and organizational responsibilities.
Effective CMMC guidance translates technical and compliance requirements into a roadmap the business can execute.
How Long Does CMMC Preparation Take?
There is no universal CMMC preparation timeline.
A manufacturer with a mature cybersecurity program, accurate documentation, clearly defined CUI boundaries, and many NIST SP 800-171 requirements already implemented will require a different level of effort than a company beginning with significant security and documentation gaps.
Based on AT-NET’s experience, implementing the 110 NIST SP 800-171 requirements and associated assessment objectives can commonly require approximately 9–15 months for small and midsize contractors.
This is an AT-NET planning estimate, not a government-mandated timeline or guarantee.
Actual preparation time depends on factors including the organization’s starting point, compliance scope, number of locations and systems, documentation maturity, available resources, remediation requirements, and speed of internal decision-making.
Organizations pursuing defense work should allow sufficient time to assess the environment, remediate gaps, develop documentation, and verify that controls are operating as intended.
7 CMMC Questions Manufacturing Leaders Should Be Able to Answer
Manufacturing leadership should have clear answers to seven fundamental questions:
- Which contracts contain cybersecurity requirements related to FCI or CUI?
- Where are FCI and CUI processed, stored, and transmitted?
- Which employees, systems, applications, and vendors have access to that information?
- Which CMMC level or assessment requirement applies to current contracts?
- Has the environment been assessed against the applicable security requirements?
- Do the SSP, POA&M, SPRS information, and supporting documentation accurately reflect the environment?
- Who is responsible for maintaining compliance as the organization changes?
Unclear answers identify areas that should be investigated as part of the organization’s compliance planning.
What Does the Current CMMC Phase 1 Status Mean for Manufacturers?
CMMC contractual implementation began with Phase 1 on November 10, 2025. In July 2026, the Department of Defense suspended the planned Phase 2 requirements while conducting a broader review of the program.
As of August 2026, implementation remains in Phase 1. Current official guidance indicates that Phase 1 self-assessment requirements remain in place while the Department reviews future implementation.
The pause does not eliminate existing contractual obligations to protect covered information.
Manufacturers can continue strengthening the underlying cybersecurity program by identifying CUI, addressing NIST SP 800-171 requirements, improving documentation, managing access, remediating known gaps, and maintaining accurate assessment information.
Progress in those areas strengthens the organization’s security posture regardless of how future CMMC implementation details evolve.
Final Thoughts
CMMC brings together contract requirements, cybersecurity controls, sensitive information, documentation, assessments, and ongoing business processes.
Manufacturers can make the process more manageable by focusing on five areas:
- Determine whether CMMC requirements apply.
- Identify the applicable CMMC level.
- Define where FCI and CUI exist.
- Assess and remediate security and documentation gaps.
- Maintain the compliance program as the business changes.
AT-NET has served businesses since 1999 and currently supports more than 75 manufacturing clients. As a CMMC Registered Provider Organization (RPO), AT-NET assists organizations with CMMC and NIST SP 800-171 preparation, including assessments, SSPs, POA&Ms, SPRS scores, DFARS reporting, remediation planning, cybersecurity, and ongoing security strategy.
Effective CMMC preparation should do more than support an assessment. It should strengthen the cybersecurity practices used to protect sensitive information and support the manufacturer’s defense-industry requirements over time.
About AT-NET
AT-NET helps manufacturers strengthen cybersecurity and prepare for requirements associated with NIST SP 800-171, CMMC, DFARS, and defense-industry contracts.
AT-NET can help assess the current environment, identify security and documentation gaps, develop SSPs and POA&Ms, prioritize remediation, support SPRS and DFARS requirements, and establish an ongoing cybersecurity and compliance strategy.
Assess Your CMMC Readiness
Manufacturers preparing for CMMC need a clear understanding of their contractual requirements, CUI environment, cybersecurity controls, and remaining gaps.
AT-NET can evaluate your current environment and develop a practical roadmap for addressing applicable requirements.