Operational Leader's Guide · Issue 01

The Operational Leader's Guide to CMMC: What You Own, What You Owe, and What Happens If You Miss It

For VPs of Operations, Directors of Manufacturing, and COOs at defense contractors — CMMC is not an IT project. The production floor, the contracts it supports, and the people who run it are all in scope. This is the guide your IT department will not write for you.

Last updated: March 17, 2026

Not an IT project Contracts at stake What CMMC requires Your floor is in scope What IT cannot fix Your role in assessment Getting ready FAQ

This Is Not an IT Project.

Defense manufacturers have spent the past several years treating CMMC as a technology initiative. Buy the right software, deploy the right controls, let IT manage the process. That instinct is understandable. CMMC is framed as a cybersecurity standard, and cybersecurity is IT's domain.

The problem is that CMMC is not primarily a technology standard. It is a compliance framework that governs how your organization handles sensitive government information. That information — technical drawings, CNC programs, quality records, production travelers, ERP data tied to defense contracts — lives in your production environment, moves through your operational processes, and is touched by your people every day. IT can configure servers and enforce network policies. IT cannot decide which roles on your floor need access to engineering drawings, cannot ensure that printed travelers are handled correctly at shift change, and cannot get your quality technicians to take a security awareness training seriously. Those are operational problems, and they require operational leadership to solve.

The operational leaders who internalize this early are the ones whose companies pass assessments on the first attempt. The ones who treat CMMC as a technology project to be delegated consistently encounter a gap that doesn't close — because the gap is in operations, not in IT infrastructure.

Who this guide is for
Vice Presidents of Operations, Directors of Manufacturing, Plant Managers, Directors of Quality, and COOs at defense contractors of any size. If you run the production environment, manage the people who touch defense contract data, or are accountable for contract performance — CMMC is yours to understand, even if it is not yours to implement alone.

What Is Actually at Stake

The consequences of non-compliance are direct, they follow a predictable sequence, and the timeline is no longer theoretical. Here is what the path looks like for a defense manufacturer that does not build a credible compliance program.

New Contract Awards

Defense contracts issued under solicitations that require CMMC Level 2 certification cannot be awarded to contractors who do not hold a current, valid certification. This is not a preference — it is a condition of award. For manufacturers who depend on DoD work, inability to compete on new awards is an existential problem that compounds over time as more contracts come up for bid with CMMC requirements attached.

Subcontract Renewals

If you hold subcontracts rather than prime contracts, the renewal cycle is where CMMC becomes urgent. Prime contractors are now including compliance requirements in subcontract renewals as standard terms. Suppliers who cannot meet those terms do not get renewed. The relationships that have sustained your business for years are at risk at the next renewal cycle — which for many defense manufacturers is 12 to 18 months away.

Supply Chain Removal

Prime contractors are auditing supply chains now, independently of government enforcement timelines. Non-compliant suppliers are being placed on corrective action plans, suspended from new task orders, and in serious cases removed from approved vendor lists. This is happening based on the prime's own risk exposure — they cannot afford to have a non-compliant sub-tier supplier create liability for their government contracts.

Legal Exposure for Leadership

CMMC requires an annual affirmation — signed by a company official with authority to bind the organization — attesting that the organization's security posture is accurately represented in its SPRS score submission. This is a legal certification under penalty of the False Claims Act. If the score does not reflect the actual security posture of the production environment, the individual who signs the affirmation has personal exposure. The Department of Justice has brought FCA cases against defense contractors specifically for cybersecurity misrepresentation, and it has named individual executives, not just the company.

The affirmation is personal
The annual CMMC affirmation is not signed by IT. It is signed by a senior company official — typically a VP, COO, or CEO. Signing an affirmation for a compliance posture that includes an unaddressed production floor creates legal exposure that belongs to the person who signed it, not to the organization alone.

What CMMC Level 2 Actually Requires

CMMC Level 2 is built on 110 security requirements from NIST Special Publication 800-171, organized across 14 domains. You do not need to know each requirement by number. You do need to understand which domains require operational authority to implement — because several of them cannot be satisfied by IT alone.

Domain Primary Owner Why Operations Is Involved
Access Control (AC) IT with operations input Defining who on the floor needs access to which systems requires operational knowledge — IT cannot make those decisions unilaterally
Awareness and Training (AT) Operations and HR Every person who handles CUI must complete security training. Delivering it to floor personnel requires operational authority and visible leadership commitment
Maintenance (MA) Operations Controls on how outside service technicians access in-scope systems. Escort requirements, access logging, equipment checks — all operational
Media Protection (MP) Operations with IT Printed travelers, USB drives on the floor, physical handling and disposal of CUI — entirely in the operational domain
Personnel Security (PS) HR and operations Screening before CUI access is granted; access termination when personnel leave. Operational and HR process, not IT configuration
Physical Protection (PE) Operations and facilities Physical access to in-scope systems; visitor escort; facility controls. Operational and facilities function
Incident Response (IR) IT with operations Operations must understand the incident response plan, know their role in it, and be able to execute during a real event

The remaining domains — System and Communications Protection, Configuration Management, Identification and Authentication, Audit and Accountability, Risk Assessment, Security Assessment, and System and Information Integrity — are primarily IT work. But even in those domains, operational leadership plays a role: approving the resources needed, ensuring cooperation from floor supervisors when IT needs access to production systems, and making the organizational decisions that IT cannot make on its own.

Your Floor Is in Scope

In CMMC assessment terms, "in scope" means a system, component, or location will be examined by the assessor. If it is in scope and a requirement is not met, it generates a finding. If findings accumulate above certain thresholds, certification is denied.

For a defense manufacturer, the production environment is almost always in scope — because Controlled Unclassified Information flows through it. The engineering drawings your operators reference, the travelers and work instructions that describe how defense parts are made, the inspection records your quality team generates, and the systems that create, display, and store any of those things are in your CMMC boundary.

Shop Floor Workstations

A workstation on the production floor that displays engineering drawings, loads CNC programs, or records inspection results is processing CUI. CMMC requires that it run an authorized operating system, have endpoint protection in place, be included in a configuration baseline, and have individual user authentication — not shared or generic accounts. Most shop floor workstations at defense manufacturers fail at least two of those requirements. Many fail all four, because they were never considered part of a security inventory.

Printed Materials

CMMC media protection requirements apply to physical media as well as electronic media. A printed engineering drawing left on a work surface at end of shift is a media protection issue. A traveler with inspection data dropped in the recycling bin rather than a shred receptacle is a media protection issue. These findings come as a genuine surprise to manufacturers who have focused compliance attention entirely on IT systems — and they are unambiguously in the operational leader's domain to correct.

Outside Service Access

CMMC requires that maintenance performed on in-scope systems by outside personnel is controlled. The vendor who services the coordinate measuring machine, the machine tool manufacturer's calibration team, the controls engineer troubleshooting the DNC server — each of them requires escort, logged access, and equipment accountability. If your current practice is to let vendor representatives work independently on the production floor, that practice is a finding under the Maintenance domain.

What assessors do on your floor
C3PAO assessors walk the facility. They look at workstation authentication, printed material handling, visitor access controls, and vendor access logs. They interview floor supervisors and technicians — not just IT staff. The picture your production environment presents on assessment day determines a significant portion of the outcome.

What IT Cannot Fix Without You

IT can deploy sophisticated endpoint management across every workstation in the plant. They cannot tell that software which employees should have access to which systems — that requires someone who understands production roles and responsibilities. Here are the domains where IT is blocked without active operational leadership involvement.

Access Role Definition

CMMC requires that access to CUI is limited to the individuals who need it for their specific job function. Defining that requires operational knowledge: what does a CNC operator actually need access to, versus what does a quality technician need, versus what does a floor supervisor need? IT can enforce role-based access once roles are defined. Defining the roles requires someone who runs the floor and understands the work.

Security Awareness Training for Floor Personnel

Every person in the organization who handles CUI — including operators, quality technicians, and floor supervisors — requires security awareness training that is specific to their responsibilities. This training must cover what CUI is and how to identify it, how to handle printed materials that contain it, what to do when something suspicious happens, and who to contact when a potential incident occurs. Delivering effective training to production personnel requires operational authority and credibility. An IT-generated online module that no one takes seriously does not satisfy the requirement — and assessors will conduct personnel interviews that surface it.

Maintenance Access Procedures

The Maintenance domain requires documented procedures governing how outside service personnel access in-scope systems. Writing the procedure is straightforward. Getting floor supervisors to follow it consistently, logging every vendor access, and ensuring that accounts created for service visits are removed after the visit — these are operational execution problems that live outside IT's authority.

Physical Access and Visitor Controls

CMMC Physical Protection requirements are largely satisfied by controls that operations and facilities already operate: badge access to production areas, visitor sign-in, escorting guests on the floor. The gap is almost never the controls themselves — it is documentation. The physical access controls exist, but they have not been formally connected to the CMMC framework in the System Security Plan, and the records that demonstrate they are functioning have not been maintained with assessment in mind.

Your Role When the Assessor Arrives

A CMMC Level 2 assessment typically runs three to five days on site. The C3PAO assessor team uses three methods: examining documentation, interviewing personnel, and testing controls. All three methods will involve people and spaces under operational leadership's authority.

The Facility Walkthrough

Assessors walk the facility. They observe the production floor, the quality lab, engineering areas, and any space where CUI is created or used. They note whether workstations are locked when unattended, whether printed materials are left in the open, whether vendor access to in-scope areas appears to be controlled, and whether the physical environment matches the System Security Plan. The operations leader — or a designated representative — will accompany the assessor. What the assessor observes in your environment reflects directly on your organization's compliance posture.

Personnel Interviews

Assessors interview floor personnel. This is not optional and it is not limited to IT staff. Supervisors, quality technicians, and production operators may be asked how they handle printed drawings, what they would do if they found a USB drive on a workstation, whether they have received security awareness training, and who they would contact if they suspected a security incident. The answers must be consistent with the policies and procedures your organization has documented and trained to. If your personnel have not been trained, the interviews will surface that within the first day.

Access Control Review

Assessors pull user account lists from systems that contain CUI and verify that every account corresponds to a current, authorized person with a legitimate need for that access. Former employees with active accounts, shared or generic accounts, and accounts with permissions beyond what the role requires are all findings. In a manufacturing environment, this review consistently surfaces terminated employees still active in quality management systems, generic operator accounts on floor terminals, and vendor service accounts that were never removed after a maintenance visit.

Maintenance and Visitor Records

Assessors review maintenance logs and visitor access records for the period under assessment. They verify that outside access to in-scope systems and production areas has been controlled and documented. A binder of maintenance records that has not been consistently maintained, or a visitor log that does not capture which areas were accessed and who provided escort, produces findings. These records are entirely within operations' control to maintain correctly.

A Practical Readiness Plan for Operational Leaders

Getting ready for a CMMC assessment does not require technical expertise. It requires operational authority and follow-through. The following six actions belong in the operational leader's workplan — not the IT project plan.

1. Walk Your Environment with CUI in Mind

Before anyone else conducts a formal gap assessment, do your own walk. Go through the production floor, quality lab, and engineering areas with one question: where does government contract data touch this environment? Look at what is displayed on workstations. Look at what is printed and where it ends up. Look at how CNC programs reach machines. Look at what happens to quality records after they are completed. You will see things that a pure IT assessment misses because you understand how the work actually happens. Write down what you find and bring it to your compliance team.

2. Get an Honest Answer on Your SPRS Score

Your organization has submitted or is required to submit an SPRS score representing compliance with NIST 800-171. Ask what that score is, how it was calculated, and whether the production environment was included in the assessment that produced it. If the answer is that IT calculated it based on network and endpoint controls, ask specifically whether shop floor workstations, DNC systems, quality management systems, and physical media handling were evaluated. If they were not, the score does not reflect your actual posture — and you are now aware of that, which matters for the affirmation you or your CEO will sign.

3. Assign Operational Ownership for Each CMMC Domain

Using the domain table earlier in this guide, identify a specific person responsible for each domain. Some are IT. Several are yours or belong to someone on your team. Awareness and Training, Maintenance, Media Protection, Personnel Security, and Physical Protection all need an operational owner — not an IT owner. Make those assignments explicit, put them in writing, and hold the owners accountable for the same rigor you would apply to any other operational program.

4. Run a Production-Specific Training Campaign

Security awareness training must reach every person who handles CUI, and for production personnel, it must be practical and specific to their environment. Generic cybersecurity modules designed for office workers do not satisfy the requirement in a manufacturing context, and they will not survive assessor scrutiny. Build or commission training that addresses what CUI looks like on the production floor, how to handle printed materials correctly, what to do when something unexpected happens, and why it matters for the contracts that employ them. Track attendance. Attendance records are part of your evidence package.

5. Review and Tighten Access to CUI Systems

Sit down with IT and pull a current list of every person with access to systems that contain defense contract data — engineering drawing servers, quality management systems, ERP modules with defense program data, DNC servers. Review it yourself. Remove former employees. Challenge any account whose current role does not clearly require that access. Document the review. This exercise is the single highest-value action most manufacturers can take before an assessment, because it consistently surfaces findings that would otherwise appear on assessment day.

6. Establish and Document Maintenance Access Procedures

Write a procedure governing outside service technician access to production systems. It does not need to be long. It needs to require that access is escorted, that the technician's equipment is verified before connection to any in-scope system, that access is logged, and that accounts or credentials created for service visits are removed when the visit ends. Communicate it to the supervisors responsible for production floor access. Keep records showing that it is being followed. This is the maintenance domain finding that most easily prevented — and most commonly appears — in manufacturing assessments.

Frequently Asked Questions

Our leadership team views CMMC as IT's responsibility. How do we change that framing?

Frame it in contract revenue. Calculate the DoD subcontract revenue at risk if your organization cannot pass a CMMC assessment when the next renewal arrives. Then walk through the specific domains that require operational input and show what cannot be satisfied without operational authority and cooperation. The argument is not about who should care about cybersecurity in principle — it is about who is accountable for the contracts and what those contracts now require. When the conversation is about contract survival rather than compliance framework, operational leaders engage differently.

We have been making defense parts for decades without compliance requirements like this. Why is this being imposed now?

The threat environment changed materially over the past 15 years. Nation-state adversaries — specifically China and Russia — have systematically targeted the defense industrial base for controlled technical data, and they have been successful at scale. The loss of sensitive manufacturing data, design information, and production processes has had documented effects on defense program security and the country's technological advantage. CMMC is the government's response to a real and demonstrated threat. The contractors who have been in the defense supply chain the longest often have the most accumulated sensitive data and the least mature security culture around it — which is exactly why the requirement exists.

How involved does an operations leader actually need to be, day to day, in the compliance program?

Active involvement is highest during the initial program build — walking the environment, assigning domain ownership, driving training, and reviewing access lists. Once those foundations are established, the ongoing operational requirement is primarily about maintaining what you built: keeping access lists current when personnel change, ensuring maintenance access procedures are actually followed, and conducting periodic reviews of the physical environment. The compliance program should not require the operations leader to become a cybersecurity expert. It should require them to apply the same operational discipline to security practices that they apply to quality, safety, and production performance.

What is a realistic timeline to get from where most manufacturers are to assessment-ready?

For a defense manufacturer starting from a typical baseline — some IT controls in place, no formal operational compliance program, production floor largely unaddressed — a realistic preparation timeline is nine to eighteen months. Organizations with material gaps in physical protection, access control, or training, or with significant legacy equipment requiring compensating control documentation, are toward the longer end of that range. The variable that compresses the timeline most reliably is operational leadership engagement from the start. Organizations where operations and IT work together from day one consistently move faster than those where compliance is treated as an IT-only effort until an assessment forces the conversation.

What is the difference between the SPRS score we submitted and the C3PAO assessment we need to pass?

The SPRS score is self-assessed — your organization evaluates its own implementation against the 110 requirements and submits the number. A C3PAO assessment is conducted by an independent, government-authorized organization that verifies your implementation through documentation review, personnel interviews, and control testing. The SPRS score is what you say your posture is. The C3PAO assessment verifies whether that is accurate. Many organizations that have submitted confident SPRS scores discover significant gaps when an independent assessor examines the production environment — particularly in operational domains that were not part of the IT-focused self-assessment.

Your SSP. Not a template.

1TEN generates your System Security Plan from your actual documented control implementations. C3PAO-ready.

Request a Demo