Naval Architecture Drawings and Ship Design Data
Naval architecture drawings for surface combatants and submarines are among the most sensitive technical documents in the defense industrial base. Hull form data, stability calculations, compartmentation drawings, and structural analyses for active and future naval platforms are CUI and frequently carry export control designations that restrict access to U.S. persons only.
For suppliers who design components or subsystems for naval platforms, receiving these drawings as part of interface definition or integration work is common. The drawing arrives in an email attachment, gets saved to a design team shared drive, and may get referenced in an internal engineering analysis document. Each of those storage locations and the systems they run on becomes part of the CMMC scope boundary.
The challenge specific to naval architecture data is that it often captures ship-wide characteristics rather than isolated component data. A hydrostatic analysis document that was shared to define installation constraints for a supplier's component contains whole-ship stability data that describes the capability of the platform at a level well beyond what the supplier needs to do their work. Naval suppliers should have a process for receiving technical data on a need-to-know basis and for returning or disposing of data that exceeds what is needed for their specific scope of work.
Combat Systems Documentation
Suppliers who develop or support combat systems, fire control systems, radar systems, sonar systems, or electronic warfare systems handle technical data that represents the most sensitive CUI category in the naval domain. Combat system interface control documents, system performance specifications, signal processing algorithms, and integration test procedures for active naval systems are typically subject to distribution restrictions that go beyond standard CUI handling requirements.
For these suppliers, CMMC Level 2 is typically a floor, not a ceiling. Many combat system programs have additional security requirements layered on top of CMMC, including cleared personnel requirements, facility clearances, and additional access controls specified in the contract or in program-specific security classification guides. CMMC compliance does not satisfy those additional requirements, but failing to meet CMMC creates a compliance deficiency that exists independently of whatever additional requirements apply.
The scoping implication is that combat system suppliers are unlikely to have clean boundaries between their defense and commercial environments. The sensitive nature of the work typically means the entire engineering environment has been built with defense program requirements in mind. The CMMC scope boundary often encompasses most or all of the engineering network.
Interface Control Documents
ICDs are a particularly common source of scope expansion in combat system environments. A supplier responsible for a single subsystem may receive ICDs from multiple other system suppliers in order to define their interfaces. Each of those ICDs describes the external behavior of a system that is not the supplier's own product, and together they can provide a fairly complete picture of the combat system architecture. Assessors ask about ICD management practices because the breadth of data these documents contain is frequently underestimated by suppliers.
Ship Repair and Availability Contractors
Ship repair contractors and contractors who support scheduled availabilities face a sustainment version of the MRO scoping problem. Repair work on active naval vessels requires access to ship drawings, system specifications, maintenance records, and in some cases operating procedures. All of those documents can be CUI.
What makes the ship repair environment distinct is the physical dimension. Repair contractors often work on the vessel itself, in spaces that may be physically controlled by the Navy. The data handling practices of personnel working aboard a vessel, where the physical environment is defined by the ship's security posture rather than the contractor's facility, create real compliance questions. The workstations and tablets that technicians carry aboard, the network connections they establish, and the documents they download to work from are all within the contractor's CMMC scope even if the physical environment is a Navy vessel.
Repair specifications developed specifically for an availability, including those that document a non-standard repair to restore a damaged or non-conforming system to specification, are CUI because they describe the condition and configuration of an operational naval asset. These documents are often generated quickly under time pressure, stored informally, and not consistently managed as controlled information. That is a recurring assessment finding in ship repair environments.
| Data Type | CUI Category | Common Storage Location | Scope Risk |
|---|---|---|---|
| Naval architecture drawings (active programs) | CTI / Export Controlled | PDM, engineering shared drive | High |
| Combat system ICDs | CTI / Export Controlled | Engineering workstations, email | High |
| Ship repair specifications (availability) | CTI | Project folders, email, tablet downloads | Medium-High |
| Propulsion plant documentation | CTI / additional restrictions possible | Engineering, operations | High |
| Configuration management records | CTI | CM system, project files | Medium |
Communications System Documentation
Suppliers who develop or support naval communications systems, including antenna systems, radio frequency equipment, satellite communications terminals, and network infrastructure installed aboard vessels, handle a specific category of CUI that warrants separate attention. Communications system documentation for naval platforms describes how the ship sends and receives information, what frequencies it uses, what signal characteristics identify it, and what redundancies it has. This information is operationally sensitive in ways that go beyond general technical data protection.
COMSEC-related technical data, even at the unclassified level, carries strict handling requirements. Not all communications system documentation that a contractor handles will be COMSEC material, but the line between general communications system technical data and COMSEC-related information is not always obvious. Contractors in this space should work with their program security officers to understand what documentation in their environment requires special handling beyond standard CUI protection.
For CMMC purposes, communications system technical documentation received under DoD contracts is CUI and brings the systems containing it into scope. The question of whether additional requirements apply beyond CMMC is a program-specific question that does not change the baseline CMMC obligation.
Defining the Scope Boundary in a Naval Supplier Environment
The system boundary for a naval supplier's CMMC assessment will typically encompass the engineering environment where ship system data is created and used, the CAD and PDM systems that store design data, the collaboration tools used to exchange data with primes and the government, and the administrative systems that have access to the same network segments as those technical environments.
The segmentation challenge in naval supplier environments often involves commercial maritime work. Many suppliers who work on naval systems also work on commercial vessels: commercial shipping, offshore energy, or passenger vessels. The commercial work is not subject to CMMC, but if the technical environments are not segmented, the entire environment ends up in scope. Naval suppliers who want to limit their CMMC boundary need to make the segmentation real and demonstrable, not just organizational.
A specific boundary definition question that arises frequently: when a supplier's engineers use personal laptops or home workstations to access company systems that contain CUI, those devices are within scope. The BYOD policy, or the absence of one, is an assessment subject. If personal devices have ever been used to access CUI, the scope boundary has extended to those devices and the controls on them must be addressed.
Assessment Preparation for Naval Suppliers
C3PAO assessors who have evaluated naval and maritime suppliers consistently identify data classification and handling practices as the first area of focus. Can the organization demonstrate that it knows what CUI it holds, where it is stored, and who has access? The answer to this question determines how the rest of the assessment proceeds. Organizations that have done the work of inventorying their CUI and building processes around its handling start from a position of credibility. Organizations that cannot answer basic questions about where their ship system data lives create an immediate credibility gap that follows them through the entire assessment.
The second area is system and communications protection. Naval suppliers are a target. Assessors verify that network boundaries are real, that communications are encrypted in transit, that boundary protection controls are configured and tested, and that the organization has a defined incident response process that includes notification to the appropriate government contacts when a CUI-related incident occurs.
Personnel security and access control receive particular attention because of the sensitivity of the data. Assessors look for evidence that access to CUI is granted based on documented need-to-know, that access is reviewed periodically, and that terminated personnel lose access promptly. The citizenship and person of interest screening requirements that apply to access to export-controlled technical data may also be relevant depending on the specific programs involved.
Frequently Asked Questions
We hold a facility clearance for classified work. Does that satisfy CMMC requirements for our unclassified CUI?
No. A facility clearance and its associated security program covers classified National Security Information. CUI is unclassified information that does not require a security clearance to access but does require protection under CMMC and NIST 800-171. The programs operate in parallel under different legal authorities. Maintaining a facility clearance does not satisfy CMMC requirements, and CMMC compliance does not satisfy the requirements of your facility clearance. Both must be maintained independently.
We receive ship drawings but only for specific subsystems, not the whole ship. Are we still in scope?
Yes. The CUI obligation attaches to the data you receive, not to whether you hold a complete picture of the platform. If the subsystem drawings you receive are marked for restricted distribution or were provided under a DoD contract that includes DFARS 252.204-7012, the data is CUI and the systems where it lives are in scope. The fact that you hold only a subset of the ship's technical data package does not change the obligation to protect what you do hold.
We do on-site work aboard Navy vessels. Do we need to comply with CMMC for work performed physically on the ship?
The CMMC obligation follows the data, not the physical location where work is performed. If you bring devices aboard that contain CUI, or if you generate documents aboard the vessel that qualify as CUI, those devices and documents are subject to your CMMC requirements. The physical environment provided by the Navy does not substitute for your organization's own CMMC compliance. Devices used for shipboard work should be enrolled in your endpoint management program and should meet the same configuration requirements as devices used in your facility.