Resources Aerospace and defence

CMMC compliance starts with finding every copy of your data

The scope of a CMMC assessment is set by the systems that store, process, or transmit controlled information, so map those first.

CMMC compliance is scoped by the systems your controlled data reaches. The requirement applies to every system that stores, processes, or transmits the government’s controlled information, so the first real question is not which tool to buy, it is which of your mailboxes, drives, workstations, machines, and vendors already hold a copy of it. Until you can draw that on one page, every remediation quote you get is a guess.

The shop that made this concrete for me had eleven people. A drawing came in on a Tuesday as an email attachment marked by the prime. The estimator opened it on the office laptop, saved it to the shared drive, and forwarded it to two outside vendors for quotes on heat treat and plating. Programming pulled it onto the CAM workstation. Somebody printed the tolerance page and taped it to the machine. The inspector photographed the finished part next to the print, on his own phone, because that is how the shop had always sent proof to customers. The office backup ran that night to a consumer cloud account the owner set up in 2019 and never thought about again. Nobody did anything careless. By Friday that one file had reached nine places, and only four of them were on anybody’s list.

What does CMMC compliance actually cover?

CMMC, the Cybersecurity Maturity Model Certification, is the US Department of Defense program for verifying that suppliers protect the contract information they handle. Two kinds of government data show up in a supplier’s business. Federal contract information is the ordinary material generated for or under a contract that is not meant for public release. Controlled unclassified information is the narrower, marked category: the drawings, specifications, test data, and technical detail the government protects. The level of requirement that applies to you, and how it gets verified, come from the clause in your contract. Read the clause. Then ask your prime, in writing, exactly what they will send you, how it will be marked, and through which channel.

The scope rule is the part worth memorizing. Assessment covers the assets that store, process, or transmit the controlled data, plus the assets that provide security protection to those. That is why CMMC compliance is a data question before it is a technology question. Your network diagram does not set your scope. The path your data takes through that network sets it. The rule text and a qualified professional govern what your organization actually has to do.

Where do copies of controlled information end up?

In every shop I have walked through, the same handoffs show up, and they look ordinary precisely because nobody thinks of them as data handling.

  • Email, which is where most controlled files arrive and where most of them stay
  • The quoting path, because a drawing sent to three outside vendors is now in three other companies
  • Engineering and programming workstations, plus whatever USB stick walks a program to a machine
  • The machines themselves, and the inspection equipment holding programs and results
  • Printed travelers, prints on the floor, and the photo somebody took of them
  • Backups, file sync, and the personal device that still holds a copy of the shared drive
  • The ERP or job system, if part numbers and specifications live in the notes field

None of this is a scandal. It is how work gets done in a small shop that has been serving primes for thirty years. It only becomes a problem when you are asked to describe your boundary and the honest answer is that you have never drawn one.

How to map your CMMC data flow in an afternoon

This is CMMC scoping done by hand, before anyone sells you a tool for it. The exercise costs less than a day.

Take one live defence contract. Take one file from it, ideally the drawing package. Then trace it, in writing, from the moment it arrived to right now.

For each stop, put down four things: what arrived, how it arrived, who touched it, and where a copy still sits today. Do not explain anything away. Do not fix anything yet. Just follow the file.

When you have the list, sort every stop into three piles. Keep means the copy has to live there for the work to happen, so it gets protected. Move means the work is real but the location is wrong, so it belongs somewhere you control. Kill means the copy exists only because nobody stopped it, so it goes away and the habit that created it changes.

Then do it once more with a different contract and a different type of file, an inspection report or a supplier purchase order. The second pass finds the paths the first one missed, because the first pass follows the way you think work flows and the second follows the way it actually does.

You now have the input every assessor, consultant, and vendor is going to ask for, and you built it before anyone quoted you a price for it.

Can you make the scope smaller?

Yes, and it is usually the cheapest thing available to you. Fewer places the controlled data can land means fewer systems to protect, fewer people to train, less evidence to produce, and a smaller bill. Some shops carve out a defined environment where all of that work happens and keep everything else out of it. Some take email out of the path entirely and receive files one defined way.

Two cautions from watching shops get this wrong. If people route around that environment because it is slow, it stops being a boundary and becomes a diagram nobody follows. And a smaller scope is only smaller if the copies outside it genuinely stopped, which is why the map of what actually happened matters more than the plan.

What to ask a vendor

Any system you put in the path of controlled data becomes part of your assessment scope. Ask all of this in writing, of every vendor.

  1. Can this system hold controlled information, and where does it run?
  2. Can it run inside an environment I control, and what do I give up if it does?
  3. Which of your people can reach my data, from where, and do I see the log?
  4. What evidence does the system produce on its own: access logs, change history, retention?
  5. Every subprocessor by name, and what each one touches.
  6. What exactly is certified, and who assessed it?

That last one matters. Certification applies to organizations that get assessed, so “CMMC certified software” is a claim worth questioning before you accept it. A vendor can make your scope smaller and your evidence easier. No vendor makes you compliant.

The day you need this map is the day somebody else is asking for it. A prime’s supplier questionnaire. A flow-down clause in a renewal. An assessment date on a calendar. You can spend an afternoon now following one file through your own shop, or you can build the same map later, under a deadline, with a contract depending on it.

Questions people ask

CMMC compliance is the set of cybersecurity requirements the US Department of Defense attaches to its contracts, flowed down to suppliers through contract clauses. What applies to you, at what level, and how it is verified come from the clause in your contract and the rule text, read with a qualified professional.