Depot maintenance firms, field service organizations, and parts suppliers keeping military platforms operational are sitting on maintenance records, technical manuals, and repair specifications for active systems, with no roadmap for what CMMC compliance actually requires of them.
Technical manuals for active military platforms, maintenance records referencing operational platform configurations, and repair specifications for active systems are CUI, and the obligation to protect them does not come with an exemption for age or legacy format. If it is in your environment and it describes an active military platform, it is in scope. The MRO challenge is that this data was generated continuously over years or decades, lives in systems built before compliance was a consideration, and is distributed across technical libraries, maintenance management systems, project folders, and individual technician workstations.
Aircraft maintenance manuals, structural repair manuals, and illustrated parts catalogs with Distribution C or D markings are CUI. Most are in daily use on the hangar floor with no formal access or disposal controls.
Records referencing individual tail numbers, component replacement histories, and anomaly investigations describe operational military platform status. CUI from day one of creation.
Depot-level repair specifications, time compliance technical orders, and engineering directives for active platform modifications are CUI regardless of how they were formatted or distributed.
Configuration management records that track installed components, modifications, and departures from baseline describe the operational capability of active assets, among the most sensitive CUI in the sustainment world.
The trigger is simple: if you hold technical manuals, maintenance records, or repair specifications for active military platforms under a DoD contract, you have CUI and you have obligations. Talk to us about what that means for your specific environment.
MRO environments cannot use cloud-hosted compliance platforms. The sensitivity of active platform data, maintenance records, technical manuals, and configuration data, means the compliance program must live inside your network alongside the data it governs. 1TEN deploys as an on-premises appliance with no external connectivity. All 110 requirements are covered with guidance specific to sustainment environments: maintenance system scope, technical library management, subcontractor access controls, and the legacy system compensating control documentation that assessors require.
Compensating control frameworks for maintenance systems and test equipment that cannot be patched or upgraded, documented in a format assessors accept.
Access control and retention documentation for controlled technical publications, from distribution tracking to disposal procedures for superseded revisions.
Visitor and maintenance access procedures for outside service technicians, subcontractors, and government representatives accessing your CUI environment.
Complete System Security Plan and SPRS score documentation, generated from your actual implementation, not adapted from templates that don't reflect your environment.
1TEN tracks your control implementation, calculates your live SPRS score, and organizes your evidence package. On-premises, air-gapped.
Request a Demo