Per-MW pricing, regional variance, and cost drivers for owners scoping hyperscale & AI builds.
Salary benchmarks across the 14 mission-critical disciplines.
I start with the contract - not the machines. Before accepting defense work, I check the required CMMC status and DFARS clauses, assign owners, and confirm how the factory will protect covered information. When DFARS 252.204-7012 applies, qualifying cyber incidents must be reported within 72 hours of discovery.
My factory-readiness checklist covers five areas:
My rule: <u>each duty needs an owner, a procedure, and proof it was done</u>. An internal checklist does not replace the required assessment - and CMMC status does not replace DFARS duties.
Follow the information, not just the network cable. Trace CUI through controlled drawings, technical specs, bills of material, production files, inspection records, MES, cloud services, supplier portals, printers, USB transfers, backups, and paper work instructions on the factory floor. For each transfer, record the CUI owner, system owner, location, transfer method, and protective control.
Inventory CNC machines, PLCs, controllers, industrial gateways, maintenance laptops, and vendor-managed systems alongside office IT. Record each asset’s connectivity, firmware, network zone, and support provider. Use CMMC scoping guidance to classify assets - machine type alone doesn’t determine scope. At Level 2, document specialized OT assets in the SSP, including how they’re managed.[8][9] Once scope is set, assign access, remote-support, and change rules to each asset.
Assign every access path to a named user. IT/security should manage individual identities, separate administrator accounts, and least privilege. Service-account records should cover purpose, owner, credential storage, rotation, and monitoring. Use MFA for remote access, privileged accounts, cloud services, and in-scope systems where supported.[5][10]
Require named vendor users, approved connection paths, protected remote sessions, logging, and expiration dates. Disable temporary access when its approved window closes.[4][5][10]
Segment business IT, engineering, production, safety, guest, and vendor zones. IT/security should document allowed traffic, logging, approved media transfers, and required encryption. Maintenance should enforce USB scanning and transfer procedures. For legacy equipment, document the affected requirement, technical limitation, approved isolation method, residual risk, approving authority, supporting authority, and upgrade or replacement date.[8][9][10]
OT engineering should own controller and machine configuration baselines. IT should own network and supporting-system baselines. Require production and quality signoff for changes to CNC programs, PLC logic, recipes, and inspection parameters. Each change record should include testing, the implementation window, a rollback plan, and post-change verification.
Test recovery - not just backups. Restore representative controller logic, MES data, engineering files, and network configurations. Record restore time, integrity, failures, and corrective actions. Keep these results as assessment evidence of recovery readiness.
Assign a primary owner and backup for every duty. Document what the plant manager, HR, IT/OT, production supervisors, and procurement/contracts are responsible for, including incident escalation and evidence retention. Smaller manufacturers can combine roles, but they should record compensating checks - for example, having a second person approve access and review termination records. These owners should manage onboarding, shift handoffs, supplier reviews, and offboarding.
Complete role-based training before granting access. Operators, engineers, supervisors, temporary workers, contractors, and maintenance staff need training on CUI handling, approved removable media, photography and video restrictions, phishing and social engineering, and incident-reporting contacts. Match the instructions to each role, and keep completion dates, course details, and acknowledgments. Repeat training on a recurring schedule[5][11]. At shift handoff, supervisors should log temporary accounts, active vendor sessions, and open security issues.
Use one HR-driven workflow for onboarding, transfers, and departures. Managers request permissions; IT/OT approve and implement them. Transfers must remove outdated access, not just add permissions. At termination or contract expiration, disable all access and recover keys, devices, badges, and media. Keep the request, approval, training acknowledgment, disablement timestamp, and manager confirmation[5][12].
Project leads should verify that subcontractor onboarding, temporary systems, and vendor access are approved, tracked, and removed at handoff. OT controls staff should document logic or firmware changes and escalate anomalies that affect safety, availability, or CUI.
Apply the same contract rules to supplier access once workforce access is under control.
Check supplier requirements before award - and before releasing protected information. Procurement and contracts should document what information will be shared, applicable flow-down clauses, the required assessment type, the approved transfer method, and the supplier’s incident contact. When DFARS 252.204-7021 applies, verify that the supplier has the required current CMMC status before subcontract award. Track annual affirmations of continuing compliance[1][15]. An SPRS assessment record under DFARS 252.204-7019 is not interchangeable with CMMC status; the obligations differ[6][14].
Keep clause reviews, access approvals, session records, terminations, and escalation contacts. Supplier compliance does not replace manufacturer accountability. The supplier protects information in its custody; the manufacturer remains responsible for sharing decisions, its own controls, and connection monitoring. Document how subcontractor incident report numbers reach each higher-tier contractor and the prime[13].
Factory Cyber Incident Response: DFARS Reporting and Evidence
The plant needs one response path when a vendor session, production device, or CUI system fails. Once access and supplier controls are in place, define how teams will handle incidents involving production equipment, vendor remote access, CUI, or OT safety.
Make that response path available 24/7. Set up one incident intake path, an on-call roster, severity levels, and escalation deadlines. Assign an incident lead, IT/security owner, OT or controls-engineering owner, plant leader, legal and contracts counsel, and communications owner. Specify who can disable accounts, suspend vendor remote access, isolate workstations or network segments, preserve images, shut down equipment, or pause production. OT and plant-safety leaders must approve any shutdown or action that could alter evidence.
Next, set clear reporting and evidence-preservation deadlines. Report covered incidents within 72 hours of discovery through the required DoD reporting channel. Do not wait for root-cause analysis. Include the discovery date and time, affected systems, CUI or covered defense information, contract and subcontract details, indicators of compromise, suspected attack method, actions taken, and contacts. Keep the submission confirmation. Legal/contracts staff should also check whether the incident affects critical support or contract performance.
Preserve affected-system images and relevant monitoring or packet-capture data for at least 90 days after report submission.[7][17] Record collectors, timestamps, hashes, storage paths, and chain of custody. Do not casually reboot, wipe, or reimage affected systems. For equipment that must stay running, OT should identify safe ways to collect evidence.[7][17]
After notification and preservation, begin controlled recovery. Recovery owners should restore production services in dependency order and get safety, production, and quality approval before restarting.
Test the incident workflow periodically with IT, OT, and plant leadership using production-safe tabletop exercises. Measure notification, decision, access-suspension, preservation, and reporting readiness times. Keep test results, recovery approvals, and assigned corrective actions. Never introduce live malware or deliberately interrupt safety-critical processes.
Keep evidence of work performed, not just policies. Maintain assessment-ready proof: the SSP, inventories, access reviews, configuration approvals, incident records, and recovery-test results. Use final, approved artifacts aligned with the applicable CMMC assessment procedures. Examination, interviews, and testing must support the findings.[18][19][20]
Use the evidence register below to tie each control to an owner, asset, and validation date. Owners must enter actual asset identifiers, repository paths, and validation dates.
Manage the register with assigned ownership, restricted access, version control, and backups. Hash artifacts using a NIST-approved hashing algorithm. Retain required assessment artifacts for six years from the CMMC Status Date, and track incident-preservation deadlines separately.[16]
Track gaps, risks, owners, remediation deadlines, and closure evidence. Verify POA&M eligibility before use: Level 1 does not allow POA&Ms. Conditional status is limited and must close within 180 days through the required closeout assessment and updated plans and records.[2][3]
Close the checklist only when named owners can show that the required controls and evidence are current. Check each applicable contract’s cybersecurity clauses, CMMC level, information types, assessment route, and current status.[1][21]
Fill out the checklist using the scope map, evidence register, and corrective-action log.
Use this checklist during leadership reviews. Replace role titles with the owners and backups already named above, and link procedures and evidence to their assigned locations. Record completed review dates and action deadlines. Assign workforce gaps alongside technical gaps.
Address unresolved contract-eligibility risks first. Give every open action an owner, resources, a target date, interim protection, and a closure test. Leadership should assign staffing and training actions directly - not leave them in a general compliance backlog.
Review the checklist at least annually, after any contract, system, supplier, remote-support, or workforce change, and before the annual compliance affirmation.[1][16]
Completing the checklist marks internal readiness only. Qualified counsel must review contract-specific obligations. The required self-assessment, C3PAO assessment, or government assessment must still be completed.[21][22]
Review your defense contract requirements and the controlled unclassified information (CUI) your factory processes, stores, or transmits. The information you handle determines your required CMMC level [1].
Identify where CUI, such as facility drawings, site security plans, or technical data, is viewed or stored [1][2]. Check your cybersecurity readiness against these requirements early in the proposal phase to help maintain eligibility for defense contracts [1].
Yes, legacy machines can stay in use if they meet cybersecurity and configuration management requirements. Include them in your cybersecurity documentation, configuration baselines, and maintenance plans [1].
To stay compliant, make sure your security controls cover legacy hardware and that you can properly monitor it. Keep records of its operating status and security configuration as evidence [1].
DFARS requires you to report a cyber incident when it affects a covered contractor information system or defense contract operations and involves the unauthorized release or compromise of Controlled Unclassified Information (CUI). Submit the report to the Department of Defense through the DIBNet portal.
Check with your Facility Security Officer (FSO) and review your contract’s cybersecurity provisions to confirm your reporting obligations.