A machine shop's CMMC problem is not really an IT problem. It is a document-flow problem that happens to end at a machine tool. The drawing arrives by email, gets opened on a CAM seat, becomes a toolpath, and lands on a control that has been running the same operating system since before CMMC existed. Every step of that is in scope, and the last one is the step no consultant's template accounts for.
Where CUI lands in a shop
- The estimator's inbox — quoting packages arrive with drawings attached, often before anyone has decided whether to bid.
- The engineering share, where the customer's model sits next to your fixture design.
- The CAM workstation, which holds both the customer geometry and the toolpath derived from it. Derived files carry the same obligation as the drawing.
- The CNC control, if the program is transferred to it and stored there.
- The QC bench, where the inspection report reproduces controlled dimensions.
- The printout taped inside the machine door, which is a real copy that no software inventory will ever find.
Notice how many of those are outside what most shops think of as "the computers". Scoping that starts from the server room misses half of them.
The legacy control problem
Nearly every shop has at least one machine whose control cannot support modern authentication, cannot be patched, and will outlive several IT refreshes. Replacing a working machine tool because of a requirement written for office computers is not a proportionate answer, and the guidance does not demand it.
The workable path is to treat those as specialized assets: isolate them on their own network segment, document what compensating measures exist, and put the honest description in the System Security Plan. What fails an assessment is not the old control — it is an SSP that pretends the old control is domain-joined and running MFA.
Move the program to the machine and delete it after the run, rather than letting the control become a file server. That single habit takes the most awkward asset in the shop mostly out of the conversation.
Scoping levers specific to job shops
Job shops have an advantage that a production plant does not: the government work is usually a minority of the jobs, and it can often be corralled. If CUI can be confined to one engineering workstation, one share, and one segment of the shop floor, the assessment boundary is small enough that a five-person operation can carry it.
- Separate quoting from production data, so a package you never bid does not drag the whole estimating PC into scope.
- Stop emailing drawings internally. Every forward is a new copy in a new mailbox.
- Give the CAM seat a defined home for controlled geometry rather than the operator's desktop.
- Decide who is allowed to print, and where those prints go at the end of a job.
What tends to score worst
Across shops of this shape, the five-point requirements that most often come back unimplemented are multifactor authentication applied only to email, encryption of CUI at rest treated as "the drive is BitLockered somewhere", audit logging that exists but is never reviewed, and incident response that lives in somebody's head. Those four account for most of the distance between a negative SPRS score and a positive one.
The free calculator walks all 110 requirements using the official DoD weights, so you can see which of those four is actually costing you points before spending anything.