Assessment Scope Guide · MRO & Sustainment

MRO Contractors and CMMC: Why Sustainment Work Is Often the Most Complex Scope

Sustainment contractors handle technical manuals, maintenance histories, repair specifications, and configuration data for active military platforms. The data volume is high, the documentation trail is long, and the scope is harder to bound than in production environments.

Last updated: January 22, 2026

Why MRO is different Technical manuals Maintenance records Repair specifications Platform config data IT environment Assessment prep FAQ

Why Sustainment Scope Is Harder to Define Than Production Scope

Production contractors have a relatively clean model for identifying CUI: data that comes from the prime on a defense contract and describes what they are manufacturing. MRO contractors face a more complicated picture. They receive data from multiple sources — original equipment manufacturers, government technical data packages, depot-level technical orders, and accumulated maintenance histories for individual aircraft, vehicles, or weapon systems. Each source may have different CUI designations, different handling requirements, and different retention obligations.

The second complexity is continuity. A production contractor's CUI obligation for a given program ends when production ends. For an MRO contractor, the obligation continues for the service life of the platform, which may span decades. Data generated in a depot maintenance event in 2012 may still be active, may still be required by contract, and may be sitting on a network share that has never been included in a formal system boundary analysis.

The third complexity is the nature of the work itself. Maintenance and repair inherently generates documentation that captures the state of an operational military asset: component replacement histories, anomaly investigations, modification records, and inspection findings. In aggregate, this data can reveal capability gaps, maintenance patterns, and operational limitations of active platforms. That is why it is treated as sensitive, and why the CUI designation for sustainment documentation tends to be broader than for production documentation.

Technical Manuals: The CUI Problem That Sits in Plain Sight

Technical manuals for active military platforms — aircraft maintenance manuals, structural repair manuals, component maintenance manuals, illustrated parts catalogs — are among the most common CUI artifacts in an MRO environment. They are also among the most casually handled.

Military technical manuals are published by or for the government and are typically marked with distribution statements that define who can receive them and under what conditions. Distribution Statement C (distribution authorized to U.S. Government agencies and their contractors) or Distribution Statement D (distribution authorized to DoD and U.S. DoD contractors only) are common for MRO documentation on active platforms. Documents with these markings are CUI and must be handled under CMMC requirements.

The problem MRO contractors encounter is that these manuals are working documents. Technicians use them on the shop floor. Pages get printed. PDF copies get emailed to subcontractors. Revisions get downloaded and stored in multiple locations. By the time an MRO contractor sits down to identify CUI in their environment, there is often a sprawling distribution of controlled technical manuals that has never been inventoried or formally managed.

Assessor focus area
C3PAO assessors consistently ask MRO contractors how technical manuals are managed, where they are stored, who has access, and how retired or superseded versions are handled. The absence of a formal process for managing technical publication distribution is a common finding in sustainment environments.

The practical response is to build a media and information management process for technical publications. This does not mean restricting technician access to the manuals they need to do their jobs. It means knowing where those manuals are, who has them, and how they are handled when they are no longer needed. A shared drive with clear folder structure, access controls aligned with personnel roles, and a defined retention and disposal process addresses the CMMC requirement.

Maintenance Records and the Long Tail of Compliance

Maintenance records for defense platforms are CUI when they contain information about the configuration, capability, or condition of an active military system. An entry in a maintenance management system recording that a specific aircraft tail number had its hydraulic pump replaced, with the associated part number, work order, and technician sign-off, is CUI. It describes the operational state of a military asset.

For MRO contractors, the long tail problem is that maintenance records accumulate over time and are retained for extended periods. A contractor performing scheduled depot maintenance on a rotary-wing platform may generate thousands of maintenance records per aircraft per year. Those records are typically retained for the service life of the aircraft plus a contractually defined period. A 40-year-old helicopter program can have decades of accumulated maintenance history in a system that pre-dates CMMC and was never designed with CUI protection in mind.

The migration question this creates is genuinely difficult. The obligation to protect CUI does not come with an exemption for legacy data. If the records are in scope, they require the same protections as current records. The practical path forward for most MRO contractors involves mapping where legacy maintenance data lives, assessing whether the systems storing it can be brought into compliance, and in cases where they cannot, implementing a migration plan to move the data to compliant storage.

Maintenance Information Systems

Contractor logistics support information systems, computerized maintenance management systems, and government-provided maintenance information systems all potentially process CUI. If the system is government-owned and operated, it may already be under a government Authority to Operate that covers CMMC requirements. If the system is contractor-owned, it is in your CMMC boundary and must be addressed in your SSP.

The scenario that creates assessment complications is the hybrid environment: a contractor-operated maintenance management system that interfaces with a government information system. Data flowing between the two environments needs to be addressed in the system boundary description, and the access controls at the interface need to be documented.

Repair Specifications and Engineering Orders

Repair specifications are the technical documents that define how damaged or worn components can be repaired to return to airworthy or serviceable condition. For defense platforms, repair specifications may be government-furnished, OEM-furnished, or developed by the MRO contractor under government contract. All three categories can qualify as CUI.

Engineering orders and technical directives that implement depot-level modifications, service bulletins, or time compliance technical orders are similarly controlled. These documents describe changes to military system configurations and often reference performance parameters that are not publicly available.

Structural repair manuals for military aircraft are a specific category worth calling out. They contain material specifications, damage limits, and repair procedures that are directly derived from the original airframe design. The design data in those manuals is CUI even if the repair manual itself is not individually marked, because the underlying design data is controlled.

Document Type Typical Distribution Statement CUI Status Where Found in MRO
Aircraft Maintenance Manuals (active platforms) C or D CUI Technical library, shop floor workstations
Structural Repair Manuals C or D CUI Engineering, structural repair shop
Engineering Orders / Technical Directives C CUI Engineering, planning
Maintenance records (individual tail numbers) Often unmarked CUI when referencing operational status CMMS, shared drives
Illustrated parts catalogs (active military) B or C CUI Parts control, shop floor

Platform Configuration Data and Modification Records

MRO contractors who perform depot-level modifications or manage configuration control for active platforms handle some of the most sensitive CUI in the sustainment world. Configuration data for a military aircraft, ship system, or ground vehicle describes the exact installed configuration of an operational asset, including all modifications, installed avionics or electronics, and departures from baseline configuration. This data can reveal capabilities, limitations, and installed countermeasures that are operationally sensitive.

Configuration management systems that track this data, and the databases behind them, are in CMMC scope. The personnel who have access to them, the processes for updating them, and the controls that prevent unauthorized modification are all subjects of CMMC assessment.

For contractors who serve as the configuration control authority for a platform, there is an additional dimension: the integrity of the data is itself a security requirement. CMMC system and information integrity requirements apply directly to the accuracy and protection of configuration data, not just to the systems that contain it.

The MRO IT Environment and Its Unique Challenges

The IT environment at an MRO facility often reflects the history of the work, not a deliberate architecture. Systems were added as programs were won, networks were expanded to accommodate new hangar space or new customers, and legacy software that controls special test equipment or ground support equipment has been running for years without updates.

Three specific challenges appear consistently in MRO environments during CMMC gap assessments.

The first is government-furnished equipment and systems. Many MRO contractors operate government-owned diagnostic equipment, special test equipment, and maintenance information systems. The question of who is responsible for CMMC compliance on government-furnished equipment is not always clear, and contractors sometimes assume that because the equipment is government-owned, it is not their responsibility. The correct analysis is whether that equipment is within the contractor's operational system boundary, meaning the contractor has operational control over it. If it is, it is in scope.

The second challenge is subcontractor access. MRO work frequently involves specialized subcontractors: NDT providers, engine overhaul shops, avionics repair facilities. When those subcontractors access the prime MRO contractor's maintenance information systems or receive CUI from the prime, the flow-down obligation applies. The prime MRO contractor is responsible for ensuring its subcontractors protect CUI appropriately.

The third challenge is the network boundary between the hangar floor and the administrative environment. Test equipment, ground support equipment, and maintenance information terminals on the hangar floor are often connected to the same network as administrative workstations, with little or no segmentation. In a CMMC assessment, this means the administrative environment and the hangar floor environment are typically in the same scope boundary, which increases the complexity and cost of compliance.

What C3PAO Assessors Focus On in MRO Environments

Assessors who have evaluated MRO contractors consistently highlight access control for technical library systems as the highest-priority area. Who can access controlled technical publications? How is that access provisioned and revoked? Are there any shared accounts used to access technical data systems? These questions are asked early and the answers set the tone for the rest of the assessment.

The second focus area is the handling of physical and electronic media containing CUI. Technical manuals that have been printed, configuration records that have been exported to portable media for field use, and maintenance records that have been archived to external drives are all media management issues. Assessors look for evidence of a formal media management program, physical controls over portable media, and a defined process for media sanitization and disposal.

Audit logging on maintenance information systems receives specific attention because of the sensitivity of the data. CMMC requires that audit records capture who accessed what system, when, and what actions were taken. For a maintenance management system that tracks the configuration of active military platforms, the absence of detailed audit logging is a significant finding.

Frequently Asked Questions

We work exclusively on commercial derivative aircraft that also have military variants. Are the manuals we use CUI?

It depends on the source of the manuals and the nature of the work. If the manuals were provided under a government contract for work on a military variant, they are likely CUI regardless of whether they also apply to commercial variants. If the manuals are commercially available publications obtained from the OEM for commercial work, they are not CUI. The relevant question is whether the data was provided under a government contract for the purpose of performing work on a defense article. If yes, it is CUI.

We use a government-provided maintenance information system (GCSS-MC, ALIS, similar). Is that system in our CMMC scope?

Government-operated systems that the contractor accesses but does not own or operate are typically considered external systems under CMMC scoping guidance. The contractor's obligation is to manage the interface with that external system, including controlling which users can access it, logging access, and ensuring that data extracted from it is handled appropriately in the contractor's own environment. The government system itself is not typically included in the contractor's assessment boundary, but the workstations and network used to access it are.

Our maintenance records go back 20 years and are on legacy systems. Do we need to bring all of that into compliance?

Yes, if the records qualify as CUI and the systems containing them are within your assessment boundary. The age of the data does not change its CUI status. The practical question is how to address legacy systems that may not support current security controls. The options are to migrate the data to compliant storage, implement compensating controls for the legacy systems, or demonstrate that the legacy systems are isolated from your current network and CUI environment in a way that effectively removes them from scope. Each approach has tradeoffs, and the right choice depends on the volume of data, the systems involved, and your operational requirements.

Know your posture.

1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.

Request a Demo