The CMMC Scoping Gaps Most Defense Manufacturers Don’t Know They Have
The hardest part of a CMMC scoping conversation with a defense manufacturer is not finding what is in scope. It is convincing them that the systems they never thought to mention are.
Most manufacturers approach scoping thinking about their servers, their network, their email, and the shared drive where controlled drawings live. That covers part of the picture. The rest lives on the shop floor, in the quality room, and in business systems that engineers and operations staff use every day without thinking of them as assets that carry controlled information.
After working through these assessments in manufacturing environments, the same gaps keep showing up. These are the systems that show up in every assessment but never come up until the conversation is already underway.
The First Person to Touch the Drawing Is Rarely an Engineer
A controlled engineering drawing arrives from a customer. It comes through a portal, by email, or on physical media. Someone downloads it and saves it before any engineering work begins.
That person is almost never an engineer.
Estimators review drawings for quoting. Operations managers triage incoming work. Sales staff open controlled drawings to answer customer questions. In most shops these users are working on general-purpose computers with no data loss prevention controls, no hardening, and sometimes a personal device. They are the first to interact with Controlled Unclassified Information and nobody includes them in the scoping conversation.
The drawing is CUI from the moment it is downloaded. Not from the moment engineering opens it. Not from the moment it is assigned a job number. Every machine that touches it before it reaches an engineering workstation is potentially in scope. Most scoping conversations start in the engineering department and never ask about the steps that happened before it got there.
Your ERP System Is Probably In Scope
Once a job is created in the ERP system, controlled information is embedded in your business platform. The customer name tied to a defense program. The controlled part number. The bill of materials. The delivery schedule. These carry CUI exposure because they describe controlled work tied to a defense contract.
ERP is an afterthought in most manufacturing CMMC conversations. It shouldn’t be. Access is typically broad: accounting, purchasing, sales, and production scheduling staff all have accounts. The system is thought of as a business tool rather than a defense system, and it rarely surfaces in the initial scoping discussion.
There is a more serious issue for shops running cloud-based ERP platforms. Many widely-used cloud ERP systems are not authorized to store government-controlled information. If your ERP is hosted in a cloud environment without the appropriate government authorization, the controlled part numbers, customer names, and contract data stored there may represent a compliance exposure your IT provider has never raised with you.
Predator Protects Less Than You Think
For shops running CNC equipment, a DNC platform like Predator manages the distribution of G-code programs to machines. Most manufacturers treat this as adequate protection for their machine programs. The reality is more complicated.
Predator has its own access controls: user roles, machine definitions, program permissions. But Predator sits on top of a Windows file server. The G-code files are stored in a directory on that server. If the underlying Windows folder is accessible as a network share (and in most shops it is), any device on the network can reach those files directly, bypassing Predator’s controls entirely.
The software-level controls exist. The file-system-level exposure often makes them irrelevant. A well-configured Predator installation is only as secure as the folder it sits on.
G-Code Is Derivative CUI. Almost Nobody Knows That.
This is the one that stops manufacturers cold.
A G-code program is derived directly from a controlled drawing. It encodes the geometry, dimensions, tolerances, and manufacturing process of a controlled part in machine-readable form. Under the regulatory framework governing the CUI program, information created using CUI as its source inherits the same obligations. G-code is derivative CUI.
The programs in your DNC library, stored on machine controllers, on USB drives used to transfer programs to older equipment: all of it is controlled information. The fact that it looks like plain text and carries no visible markings does not change what it is or what protections it requires. Most manufacturers have never been told this, and most scoping conversations have never asked about it.
The CMM at the End of Your Line
At the end of the production process sits a Coordinate Measuring Machine. The CMM measures a finished part against the specifications in the original controlled drawing. The program driving the measurement was written directly from that drawing. The inspection report it generates contains actual measured dimensions of a controlled part.
The CMM workstation is what gets missed. Every time.
It sits in the quality room, operated by quality staff rather than IT staff. It has almost certainly never been patched or hardened. It was not mentioned in the initial scoping conversation. And the inspection reports it generates are frequently exported to spreadsheets and emailed to customers, engineers, and quality managers with no controls on distribution.
Every one of those emails is a potential uncontrolled CUI disclosure. The part has been measured, the job is done, and the controlled information is on its way to an inbox that nobody included in scope.
The Question That Changes the Scoping Conversation
Generic CMMC scoping starts with the IT environment: servers, workstations, network, cloud services. That is the right starting point for an office environment. It is the wrong starting point for a defense manufacturer.
The question that produces accurate scope in a manufacturing environment is different: where does a controlled drawing go from the moment it arrives?
Follow that question through your facility. The estimator who opens it for quoting. The ERP system that creates the job. The engineering workstation that builds the CAD model. The DNC server that holds the G-code. The machine controllers that store the programs. The CMM that measures the finished part and sends the results by email.
That path is your scope. For most defense manufacturers, it is longer than expected. The gaps it reveals are exactly what assessors are trained to find.
Jason Vanzin is the CEO of Right Hand Technology Group, a CMMC Level 2 certified managed service provider serving defense manufacturers and SMBs across the defense industrial base. RHTG achieved CMMC Level 2 certification in its production environment in December 2025, one of a small number of MSPs in the country to do so. Jason works directly with defense subcontractors navigating CMMC readiness, compliance, and ongoing risk management.
Featured Product
