October 4, 2026

CMMC and DFARS for Factory Teams: What Manufacturing Leaders Must Build In

By:
Dallas Bond

I start with the contract - not the machines. Before accepting defense work, I check the required CMMC status and DFARS clauses, assign owners, and confirm how the factory will protect covered information. When DFARS 252.204-7012 applies, qualifying cyber incidents must be reported within 72 hours of discovery.

My factory-readiness checklist covers five areas:

  • Contract duties: Confirm information types, assessment requirements, supplier flow-downs, and annual affirmations.
  • IT and OT scope: Map where CUI travels, classify assets, control access and vendor connections, approve changes, and test restores.
  • People and suppliers: Assign owners and backups, train staff before access, check supplier status, and remove access when roles or contracts end.
  • Incident response: Set a 24/7 reporting path, define safe shutdown authority, and preserve required incident records for at least 90 days after reporting.
  • Assessment proof: Keep approved records, track correction deadlines, and retain required assessment artifacts for six years from the CMMC Status Date.

My rule: <u>each duty needs an owner, a procedure, and proof it was done</u>. An internal checklist does not replace the required assessment - and CMMC status does not replace DFARS duties.

Define Factory Scope and IT and OT Controls

Map CUI Flows and Classify Factory Assets

Follow the information, not just the network cable. Trace CUI through controlled drawings, technical specs, bills of material, production files, inspection records, MES, cloud services, supplier portals, printers, USB transfers, backups, and paper work instructions on the factory floor. For each transfer, record the CUI owner, system owner, location, transfer method, and protective control.

Inventory CNC machines, PLCs, controllers, industrial gateways, maintenance laptops, and vendor-managed systems alongside office IT. Record each asset’s connectivity, firmware, network zone, and support provider. Use CMMC scoping guidance to classify assets - machine type alone doesn’t determine scope. At Level 2, document specialized OT assets in the SSP, including how they’re managed.[8][9] Once scope is set, assign access, remote-support, and change rules to each asset.

Asset category CUI relationship Boundary decision Owner Documented rationale
CUI asset Processes, stores, or transmits CUI Include in assessment scope System owner File inventory and data-flow map
Security-protection asset Protects the CUI environment Include under applicable scoping guidance IT/security Security dependencies and network diagram
Specialized OT asset Relationship depends on machine function and data flows Apply level-specific treatment; document in SSP OT engineering Technical limits and risk-based procedures
External service May handle CUI or provide security or remote access Assess the service and connected systems IT/OT service owner Provider responsibilities and access paths

Set Access, Remote Support, and Change Controls

Assign every access path to a named user. IT/security should manage individual identities, separate administrator accounts, and least privilege. Service-account records should cover purpose, owner, credential storage, rotation, and monitoring. Use MFA for remote access, privileged accounts, cloud services, and in-scope systems where supported.[5][10]

Require named vendor users, approved connection paths, protected remote sessions, logging, and expiration dates. Disable temporary access when its approved window closes.[4][5][10]

Segment business IT, engineering, production, safety, guest, and vendor zones. IT/security should document allowed traffic, logging, approved media transfers, and required encryption. Maintenance should enforce USB scanning and transfer procedures. For legacy equipment, document the affected requirement, technical limitation, approved isolation method, residual risk, approving authority, supporting authority, and upgrade or replacement date.[8][9][10]

OT engineering should own controller and machine configuration baselines. IT should own network and supporting-system baselines. Require production and quality signoff for changes to CNC programs, PLC logic, recipes, and inspection parameters. Each change record should include testing, the implementation window, a rollback plan, and post-change verification.

Test recovery - not just backups. Restore representative controller logic, MES data, engineering files, and network configurations. Record restore time, integrity, failures, and corrective actions. Keep these results as assessment evidence of recovery readiness.

Intro to DFARS & NIST 800-171 Compliance for Manufacturing Operations

Assign Workforce Duties and Supplier Controls

Assign a primary owner and backup for every duty. Document what the plant manager, HR, IT/OT, production supervisors, and procurement/contracts are responsible for, including incident escalation and evidence retention. Smaller manufacturers can combine roles, but they should record compensating checks - for example, having a second person approve access and review termination records. These owners should manage onboarding, shift handoffs, supplier reviews, and offboarding.

Train Staff and Manage Employment Access

Complete role-based training before granting access. Operators, engineers, supervisors, temporary workers, contractors, and maintenance staff need training on CUI handling, approved removable media, photography and video restrictions, phishing and social engineering, and incident-reporting contacts. Match the instructions to each role, and keep completion dates, course details, and acknowledgments. Repeat training on a recurring schedule[5][11]. At shift handoff, supervisors should log temporary accounts, active vendor sessions, and open security issues.

Use one HR-driven workflow for onboarding, transfers, and departures. Managers request permissions; IT/OT approve and implement them. Transfers must remove outdated access, not just add permissions. At termination or contract expiration, disable all access and recover keys, devices, badges, and media. Keep the request, approval, training acknowledgment, disablement timestamp, and manager confirmation[5][12].

Project leads should verify that subcontractor onboarding, temporary systems, and vendor access are approved, tracked, and removed at handoff. OT controls staff should document logic or firmware changes and escalate anomalies that affect safety, availability, or CUI.

Check Supplier Clauses and Third-Party Access

Apply the same contract rules to supplier access once workforce access is under control.

Check supplier requirements before award - and before releasing protected information. Procurement and contracts should document what information will be shared, applicable flow-down clauses, the required assessment type, the approved transfer method, and the supplier’s incident contact. When DFARS 252.204-7021 applies, verify that the supplier has the required current CMMC status before subcontract award. Track annual affirmations of continuing compliance[1][15]. An SPRS assessment record under DFARS 252.204-7019 is not interchangeable with CMMC status; the obligations differ[6][14].

Keep clause reviews, access approvals, session records, terminations, and escalation contacts. Supplier compliance does not replace manufacturer accountability. The supplier protects information in its custody; the manufacturer remains responsible for sharing decisions, its own controls, and connection monitoring. Document how subcontractor incident report numbers reach each higher-tier contractor and the prime[13].

Build Incident Response and Evidence Processes

Factory Cyber Incident Response: DFARS Reporting and Evidence

Factory Cyber Incident Response: DFARS Reporting and Evidence

Detect, Report, Preserve Evidence, and Recover

The plant needs one response path when a vendor session, production device, or CUI system fails. Once access and supplier controls are in place, define how teams will handle incidents involving production equipment, vendor remote access, CUI, or OT safety.

Make that response path available 24/7. Set up one incident intake path, an on-call roster, severity levels, and escalation deadlines. Assign an incident lead, IT/security owner, OT or controls-engineering owner, plant leader, legal and contracts counsel, and communications owner. Specify who can disable accounts, suspend vendor remote access, isolate workstations or network segments, preserve images, shut down equipment, or pause production. OT and plant-safety leaders must approve any shutdown or action that could alter evidence.

Next, set clear reporting and evidence-preservation deadlines. Report covered incidents within 72 hours of discovery through the required DoD reporting channel. Do not wait for root-cause analysis. Include the discovery date and time, affected systems, CUI or covered defense information, contract and subcontract details, indicators of compromise, suspected attack method, actions taken, and contacts. Keep the submission confirmation. Legal/contracts staff should also check whether the incident affects critical support or contract performance.

Preserve affected-system images and relevant monitoring or packet-capture data for at least 90 days after report submission.[7][17] Record collectors, timestamps, hashes, storage paths, and chain of custody. Do not casually reboot, wipe, or reimage affected systems. For equipment that must stay running, OT should identify safe ways to collect evidence.[7][17]

After notification and preservation, begin controlled recovery. Recovery owners should restore production services in dependency order and get safety, production, and quality approval before restarting.

Test the incident workflow periodically with IT, OT, and plant leadership using production-safe tabletop exercises. Measure notification, decision, access-suspension, preservation, and reporting readiness times. Keep test results, recovery approvals, and assigned corrective actions. Never introduce live malware or deliberately interrupt safety-critical processes.

Keep Assessment Evidence and Check Corrective Actions

Keep evidence of work performed, not just policies. Maintain assessment-ready proof: the SSP, inventories, access reviews, configuration approvals, incident records, and recovery-test results. Use final, approved artifacts aligned with the applicable CMMC assessment procedures. Examination, interviews, and testing must support the findings.[18][19][20]

Use the evidence register below to tie each control to an owner, asset, and validation date. Owners must enter actual asset identifiers, repository paths, and validation dates.

Requirement Process owner Asset Evidence type Review frequency Storage location Last validation date
Access control IT/security owner Factory CUI enclave Privileged-access review Quarterly Restricted repository path Completed review date
Configuration management OT/controls owner Engineering workstation Signed configuration-change record Each approved change Controlled change-record path Verified implementation date
Incident response Incident lead Assessed environment Recovery-test result Documented exercise schedule Restricted incident-record path Completed test date

Manage the register with assigned ownership, restricted access, version control, and backups. Hash artifacts using a NIST-approved hashing algorithm. Retain required assessment artifacts for six years from the CMMC Status Date, and track incident-preservation deadlines separately.[16]

Track gaps, risks, owners, remediation deadlines, and closure evidence. Verify POA&M eligibility before use: Level 1 does not allow POA&Ms. Conditional status is limited and must close within 180 days through the required closeout assessment and updated plans and records.[2][3]

Conclusion: Complete the Factory Readiness Checklist

Close the checklist only when named owners can show that the required controls and evidence are current. Check each applicable contract’s cybersecurity clauses, CMMC level, information types, assessment route, and current status.[1][21]

Fill out the checklist using the scope map, evidence register, and corrective-action log.

Review Owners, Procedures, Evidence, and Open Actions

Use this checklist during leadership reviews. Replace role titles with the owners and backups already named above, and link procedures and evidence to their assigned locations. Record completed review dates and action deadlines. Assign workforce gaps alongside technical gaps.

Checklist item Accountable owner Documented procedure Evidence Review date Open action
☐ Fund remaining gaps and close risks Executive sponsor Risk and resource review Approved staffing and funding decisions Record date Decision and deadline
☐ Verify current contract obligations and status Contracts lead Clause and assessment review Contract matrix; SPRS and affirmation records Record date Status gaps
☐ Confirm current CUI scope and next assessment date Security lead Boundary and assessment management Approved CUI-flow map; next assessment date and assessor Record date Scope or evidence gaps
☐ Validate identity, patching, logging, and backup results IT lead Identity, patching, logging, and backup procedures Access reviews; patch and restore results Record date Control gaps
☐ Control OT and remote support OT lead Segmentation and vendor-access procedure Approved rules; remote-session records Record date Unsafe access or access without approval
☐ Check daily factory practices Plant manager CUI handling and escalation procedures Supervisor checks; handling records Record date Shop-floor practice gaps
☐ Protect engineering and quality data Engineering/quality lead Technical-data and change control Approved changes; data-access records Record date Unapproved changes
☐ Train staff and manage employment access HR lead Onboarding, transfer, and termination workflow Training completions; access-removal tickets Record date Staffing or training needs
☐ Verify suppliers and flowdowns Procurement lead Supplier review and access approval Signed clauses; status checks; access expirations Record date Supplier gaps
☐ Rehearse incident response Incident lead Reporting and production-safe recovery plan Tabletop results; verified contacts and authority Record date Untested response steps

Address unresolved contract-eligibility risks first. Give every open action an owner, resources, a target date, interim protection, and a closure test. Leadership should assign staffing and training actions directly - not leave them in a general compliance backlog.

Review the checklist at least annually, after any contract, system, supplier, remote-support, or workforce change, and before the annual compliance affirmation.[1][16]

Completing the checklist marks internal readiness only. Qualified counsel must review contract-specific obligations. The required self-assessment, C3PAO assessment, or government assessment must still be completed.[21][22]

FAQs

How do I determine which CMMC level my factory needs?

Review your defense contract requirements and the controlled unclassified information (CUI) your factory processes, stores, or transmits. The information you handle determines your required CMMC level [1].

Identify where CUI, such as facility drawings, site security plans, or technical data, is viewed or stored [1][2]. Check your cybersecurity readiness against these requirements early in the proposal phase to help maintain eligibility for defense contracts [1].

Can legacy machines stay in use under CMMC?

Yes, legacy machines can stay in use if they meet cybersecurity and configuration management requirements. Include them in your cybersecurity documentation, configuration baselines, and maintenance plans [1].

To stay compliant, make sure your security controls cover legacy hardware and that you can properly monitor it. Keep records of its operating status and security configuration as evidence [1].

How do I know if a cyber incident requires DFARS reporting?

DFARS requires you to report a cyber incident when it affects a covered contractor information system or defense contract operations and involves the unauthorized release or compromise of Controlled Unclassified Information (CUI). Submit the report to the Department of Defense through the DIBNet portal.

Check with your Facility Security Officer (FSO) and review your contract’s cybersecurity provisions to confirm your reporting obligations.

Related Blog Posts

Keywords:
CMMC, DFARS, NIST SP 800-171, controlled unclassified information, factory cybersecurity, OT security, incident response, supplier flow-downs
Free Download

Data Center Construction Labor Trends in 2026

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

More mission critical construction news

DCMA, FAI and AS9102: First Article Inspection for Defense Programs
October 4, 2026

DCMA, FAI and AS9102: First Article Inspection for Defense Programs

Prepare AS9102 Forms 1–3, set full/partial FAI scope, and coordinate DCMA/QAR oversight and approvals for defense contracts.
AWS D17.1 Aerospace Welding Certification Explained
October 4, 2026

AWS D17.1 Aerospace Welding Certification Explained

Require exact-match AWS D17.1 records before assigning aerospace welds — four eligibility checks, continuity, class limits, and inspection.
Facility Clearance (FCL) and Cleared Manufacturing Explained
October 4, 2026

Facility Clearance (FCL) and Cleared Manufacturing Explained

Outlines FCL requirements and three readiness gates—company eligibility, personnel clearances, and site safeguards—before classified manufacturing.
IPC-A-610 and J-STD-001 for Defense Electronics Manufacturing Teams
October 4, 2026

IPC-A-610 and J-STD-001 for Defense Electronics Manufacturing Teams

Clarifies IPC‑A‑610 vs J‑STD‑001 roles in defense electronics: acceptance vs solder process, contract revision rules, and personnel qualification.