CMMC for engineering services firms

When the deliverable is a document rather than a part, nearly everything you produce is potentially CUI — and a laptop-and-cloud firm scopes very differently from a shop with a building.

Written for Machine Shops, Other Aircraft Parts and Auxiliary Equipment Manufacturing.

A manufacturer receives controlled data and turns it into hardware. An engineering services firm receives controlled data and produces more of it — analysis reports, models, drawing packages, test plans. The obligation attaches to your output as much as your input, and that changes how the problem looks.

There is no natural boundary

A shop's scope has physical edges: the building, the network in it, the machines on the floor. A services firm's work happens on laptops, in cloud tooling, in personal home offices, and increasingly on whatever device an engineer had with them. Nothing about that arrangement draws its own boundary, so you have to impose one deliberately.

  • Company-issued and managed devices, or a documented and enforced arrangement for anything else. "Everyone uses their own laptop" is the most expensive sentence in this business model.
  • One defined place where project data lives, with the cloud service named in the SSP.
  • Remote access that is described and controlled rather than assumed.
  • A rule about local copies — because analysis work generates them constantly and they are invisible in any central inventory.

Your people are the boundary

Access control in a services firm is mostly about staffing rather than technology. Subcontracted engineers, part-time specialists and overseas contractors all touch controlled data, and each is a scoping and — where export control applies — a legal question before it is an IT one.

The hardest CMMC conversations in this sector are about the contractor who has done excellent work for six years from another country. The requirement will not bend around that relationship, and discovering it during an assessment is the worst possible time.

Multiple clients, multiple obligations

Serving several primes means holding several bodies of controlled data with different markings and, sometimes, contradictory handling instructions. Segregation by client is worth building early: it limits what any one incident exposes, and it makes an assessor's questions easy to answer.

Your deliverable is somebody else's CUI

One asymmetry catches services firms out. A manufacturer's output is a part, and parts do not need safeguarding. Your output is a document, and the moment it describes a controlled design it is controlled itself — which means the analysis report sitting in your project folder, the revision you emailed for comment, and the copy in the client's inbox are all in scope somewhere.

Practically, that puts version control and retention inside the CMMC conversation rather than beside it. Firms that keep every draft forever, in the belief that it is good engineering practice, are also keeping every draft of somebody else's controlled data — and each one is a copy an assessor can ask about and an incident could expose.

The advantage you do have

Services firms are usually smaller, more technical, and less encumbered by legacy equipment than manufacturers. There is no thirty-year-old machine control to isolate and no shop floor to segment. If the practice is already run on modern managed devices and a single cloud platform, a Level 2 readiness project here can be shorter than for a comparable manufacturer — provided the staffing questions are faced honestly rather than deferred.

See where you actually stand

The free calculator scores all 110 NIST SP 800-171 requirements with the official DoD Assessment Methodology weights — the same arithmetic your prime sees in SPRS. Twenty minutes, no cost, nothing stored unless you ask for the report.

Related questions