CybertronIT Blog

Cybertron Blog

Cybertron has been serving the Wichita area since 1997, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

10 Questions Every Machine Shop Should Ask Before Buying a CMMC Solution

Before you read

You run a machine shop that supplies the defense sector. A prime asked about CMMC, or you saw the clause in a contract, and now your inbox is full of vendors promising to make it painless. Every one of them sounds confident. Every proposal has a number on it. And you're stuck nodding along to words like "enclave" and "GCC High" and "FIPS boundary," hoping the person across the table actually knows what they mean for a shop that runs Mastercam and pushes G-code to the floor every day.

One thing just shifted in your favor. On July 13, 2026, the Department of War (DoW) suspended the mandatory third-party certification step (CMMC Phase II) pending a review aimed at cutting cost and burden for shops like yours. The clock that vendors have been using to rush you is gone for now. You still have to meet the controls and stand behind your own score, but the pressure to buy a big, expensive, C3PAO-ready package this year just eased. That makes this the right moment to slow down and ask hard questions, not to get talked into the biggest solution on the shelf.

Here's the truth. A confident answer isn't the same as a correct one. The gap between the two is where shops lose money, overbuy, and end up with a score they can't defend.

So we wrote this down. Not a teaser, the real thing. First we decode the jargon and lay out what CMMC Level 2 actually asks for, in plain English, including what the July suspension did and didn't change. Then we give you a ten-minute exercise to map your own CUI so you walk into vendor calls already knowing your rough scope. Then the ten questions we'd ask if we were sitting in your chair, each one with what a strong answer sounds like, what a weak one sounds like, and a real number or requirement to hold the vendor to.

Ask these of every vendor you're talking to, including us. The right partner welcomes them and answers straight. The wrong one gets vague, changes the subject, or waves it off as "we'll sort that out later." How a vendor handles these ten tells you more than any proposal ever will.

One note on us, so you know where this is coming from. We're a CyberAB-authorized Registered Practitioner Organization, so we do CMMC readiness work: a gap analysis, a roadmap, standing up the controls, building the documentation, and getting your self-assessment to a place you can defend. We deliver that as an add-on to our managed IT, on one agreement, with the readiness labor included rather than billed by the hour. We also build our own PCs and servers on our own line in Wichita, and we've done that since 1997. That's why this guide is written from the shop floor, not a whiteboard. Use it, keep it, and bring it to every sales call you take.


CMMC Level 2 in plain English

Before the questions, here's the lay of the land. If you already live this every day, skip ahead. If you're newer to it, ten minutes here saves you from getting talked in circles later.

What CMMC is. CMMC stands for Cybersecurity Maturity Model Certification. It's the DoW's way of checking that the companies in its supply chain actually protect the sensitive information they handle. It isn't a new set of security rules. It's a verification layer on top of rules that have existed for years.

The three levels. Level 1 covers Federal Contract Information (FCI) and is a yearly self-assessment against 15 basic safeguards. Level 2 covers Controlled Unclassified Information (CUI) and is the one most defense machine shops are heading for. Level 3 is for the highest-sensitivity programs and is assessed by the government directly. This guide is about Level 2, because that's where the cost and the work live.

What Level 2 actually requires. Level 2 is built on a security standard called NIST SP 800-171, which has 110 individual controls spread across 14 families (things like access control, physical protection, and incident response). To meet it, you need three things working together. First, the 110 controls in place in your actual environment. Second, a System Security Plan (SSP), which is the written document describing exactly how each control is met at your shop. Third, a Plan of Action and Milestones (POA&M) for anything that isn't fully done yet, because a plan for the gaps is normal and expected.

How you're scored. You self-score against NIST 800-171 on a scale that tops out at 110. Each control is worth 1, 3, or 5 points, and missing a control subtracts its weight, so you can end up well below zero. That score gets posted in a DoW system called SPRS, along with a senior official's affirmation that it's accurate. Until the July 2026 suspension, contracts involving CUI were headed toward a mandatory check of that score by an accredited third-party assessor called a C3PAO. That third-party step is the part that's now paused (more just below).

Where things stand now, and why the pressure just eased. Here's the important update. On July 13, 2026, the DoW suspended CMMC Phase II, the mandatory third-party (C3PAO) certification that was set to become a condition of contract award on November 10, 2026. It's suspended pending a top-to-bottom review meant to lower cost and burden for small and mid-size contractors, not cancelled, so the third-party requirement could return or change. Two things did not change. Phase I self-assessment requirements, in force since November 2025, still apply. And Level 2 itself still stands, with all 110 NIST 800-171 controls. For now, you demonstrate Level 2 by doing the self-assessment and having a senior official affirm your score in SPRS, instead of hiring an accredited third-party assessor. That affirmation is a legally binding statement, so a score you can't back up carries real exposure, including under the False Claims Act. And the duty to protect CUI under DFARS 252.204-7012 has applied since 2017 regardless of any of this. The takeaway: you still have to meet the same controls and stand behind your number, but the pressure to buy a rushed, expensive C3PAO-ready enclave this year just eased. That's room to do it right, not a reason to do nothing. (Verify the current status at build time against the DoW CMMC page, since this is under active review.)

Where CybertronIT sits in that. We're an RPO, a Registered Practitioner Organization. We do the readiness work that gets you to the point where you'd meet the controls and could defend your score. We are not the C3PAO, and by design the same firm can't both prepare you and run the third-party assessment on the same engagement. That line matters even with the third-party step paused, because it could come back. Any vendor who blurs it is worth a second look.


The jargon, decoded

Vendors hide behind these words. Here's what each one means, so nobody can fog you with it.

  • CUI (Controlled Unclassified Information). Government information that isn't classified but still has to be protected, like a defense drawing, a spec, or a technical data package marked for control. If your contract involves CUI, you're in Level 2 territory. Your everyday financial records aren't automatically CUI, so part of the job is figuring out what actually counts.
  • FCI (Federal Contract Information). A lower tier of sensitive information tied to a federal contract that isn't meant for public release. FCI alone puts you at Level 1. Handling CUI moves you up to Level 2.
  • NIST SP 800-171. The security standard Level 2 is built on. It's the list of 110 controls across 14 families that you have to meet. When a vendor says "the controls," this is what they mean. The July 2026 suspension didn't touch these controls, they still apply.
  • Enclave. A walled-off, secured part of your network (or a separate cloud environment) where CUI is allowed to live, kept apart from the rest of your systems. The idea is to shrink the area that has to meet all the controls. It's a common approach, not the only one, and it only works if the walls actually hold when data has to move in and out.
  • GCC High. Microsoft 365 Government Community Cloud High, a version of Microsoft's cloud built to meet the requirements for storing CUI. It's often part of a compliant setup, and it costs more than regular Microsoft 365. Roughly $60 per user per month all-in for a Level 2-capable Business Premium seat as of 2026, more on higher tiers, with a government price increase landing mid-2026 (verify current pricing for your seat count). Whether you need it at all depends on your CUI and your scope, which is a reason not to get rushed into buying it.
  • C3PAO. Certified Third-Party Assessment Organization. The accredited outside firm that runs an official Level 2 assessment and certifies you. Not your IT provider, not your readiness partner, by design. As of July 13, 2026, the mandatory third-party assessment is suspended pending review, so for now Level 2 is shown by self-assessment and a senior-official affirmation instead. The distinction still matters, because the requirement could return.
  • RPO. Registered Practitioner Organization. A firm authorized to do CMMC readiness and advisory work, the prep that gets you ready. CybertronIT is an RPO.
  • SSP (System Security Plan). The written master document that describes how each of the 110 controls is met in your specific environment. It's the backbone of your compliance, and the thing a prime or an auditor asks to see behind your score. NIST 800-171 requires it (control 3.12.4). A generic template with your name on it is not the same as an SSP built for your shop.
  • POA&M (Plan of Action and Milestones). The written plan for closing the gaps you haven't finished yet, with dates. A POA&M is normal. It shows a realistic path from where you are to full compliance, and it's part of what makes your self-assessment score defensible rather than a guess.
  • SPRS (Supplier Performance Risk System). The DoW system where your NIST 800-171 self-assessment score gets posted, along with a senior official's affirmation that it's accurate. Primes and contracting officers can see it. That affirmation is a legally binding statement, so a number you can't back up with evidence is a liability, not a checkmark.
  • FIPS 140 validated. A specific government certification for encryption. NIST 800-171 (control 3.13.11) requires that the cryptography protecting CUI be FIPS-validated, meaning the encryption module was tested and certified by a NIST-approved lab, not just "uses strong encryption." This is the toggle that famously breaks some business software, including QuickBooks Desktop and some CAD tools, when it's turned on the wrong way.

The 10 questions

Here are the ten questions, with why each one matters on a real shop floor. Ask all ten, and watch the reactions as closely as the answers. The full checklist below adds, for every question, exactly what a strong answer sounds like, what a weak one sounds like, and the specific number or requirement to hold each vendor to.

1. How will my CAM software actually run in the environment you're proposing?

Mastercam, GibbsCAM, Fusion, Esprit. These aren't email. They're graphics-heavy applications that lean on a real GPU and a real workstation to run without dragging. When a vendor proposes to move you into a secured cloud or a virtual desktop to protect CUI, ask exactly how your CAM seat performs in that setup, who tested it, and what it costs. With the third-party deadline paused, you have time to get this right instead of accepting whatever design a vendor can stand up fastest.

That cost is the part that quietly wrecks budgets. A regular office user in a compliant cloud is cheap by comparison. A GPU-backed virtual workstation that can actually run CAM is a different animal. A GPU-capable virtual machine in a government cloud can run from several hundred dollars a month per seat into four figures per seat per month depending on the GPU size and how many hours it runs, and Azure Government carries roughly a 15 percent premium over commercial Azure on top of that. Those are ballpark figures to frame the question, not a quote. Make the vendor price your seats, your way.

2. Does the price include the CAM licensing this move actually requires?

Moving a CAM seat into a virtual or cloud environment isn't always a clean lift. Some CAM licenses are tied to a physical dongle or a specific machine. Some vendors' license terms treat a virtual desktop as a different kind of install, which can mean a different license, an added cost, or a call to your CAM reseller before anything activates. Find this out before you sign, not the week you go live.

3. How does a program get from the secure environment to the machine, and stay compliant the whole way?

This is the question that separates people who understand shops from people who understand servers. It's one thing to lock CUI inside a secure enclave. It's another to get a program out to a machine that has no idea what CMMC is, and do it without breaking your compliance.

How does the post get to the control? USB stick? Network share? A DNC box in the corner running Windows 7? Every one of those is a real answer with real consequences. NIST 800-171 has a whole media protection family, and control 3.8.7 is specifically about controlling removable media like USB drives. So "we'll just sneakernet it on a thumb drive" isn't a shrug, it's a control you now have to account for.

4. Once a file leaves the secure environment, what becomes part of my CMMC scope?

Follow the part. The moment CUI leaves the protected boundary, whatever it touches can get pulled into scope. The workstation at the machine. The USB drive. The shared printer. The traveler printed on paper and clipped to the job. The old PC nobody's logged into since 2019 that still has a network cable in it.

This isn't guesswork. The official CMMC Level 2 scoping guidance sorts every asset into categories, including assets that handle CUI, assets that protect the environment, and specialized assets like the machine controls themselves. A vendor who knows the work talks in those terms and sorts your gear honestly. Scope also drives cost, so a vendor who oversizes your scope is oversizing your bill.

5. Can you walk my whole workflow, customer portal to CAM to G-code to the machine, and show me it stays compliant end to end?

Your CUI doesn't sit still. A print lands from a customer portal. An engineer opens it in CAM. That becomes a program. The program becomes G-code. The G-code goes to a machine, and the finished part ships. Compliance has to hold at every handoff, not just where the data sits at rest.

There's a trap here worth knowing. Information derived from CUI is usually still CUI. So the toolpath and the G-code your team generates from a controlled drawing can carry the same protection requirement as the drawing itself. A vendor who thinks only the original PDF is sensitive, and treats the G-code as just machine data, has a hole in their plan.

6. What assumptions are baked into this proposal that could bite me later?

Every proposal rests on assumptions. You use these machines. Your data flows this way. You have this many CUI users. Your CAM works like this. When an assumption is wrong, the fix costs money, and it usually surfaces after you've signed.

Here's a concrete one. Compliant cloud seats are priced per user, so the headcount in the proposal drives the bill. At roughly $60 per user per month for a Level 2-capable GCC High seat, guessing 10 users when the real number is 25 isn't a rounding error, it's about $900 a month the proposal didn't show. Ask what their user count is and where it came from. And ask how the labor is billed, because a low headline price with hourly remediation on top is a different deal than one with the work included.

7. How are you handling the controls that aren't technical, the people and building side?

CMMC Level 2 is built on 110 controls, and a large share of them have nothing to do with software. Whole families are about people and buildings: physical protection, personnel security, awareness and training, media handling. Who's screened before they touch CUI. Who can walk up to a machine or a server. What happens to accounts when someone quits. How visitors are logged. How you dispose of a drive or a stack of printed travelers.

Here's where you want an honest vendor, not a flattering one. A good partner will tell you plainly which of these they handle and which stay with you. The technical and administrative controls, the policies, the procedures, the account and access side, those are things a readiness partner should stand up and document. But the physical safeguards themselves, the locks on the door, the alarm, the fireproofing, the camera at the dock, those live with you, the building owner. No IT vendor installs your deadbolts. The right answer is a clear division of labor, in writing, so nothing falls in the crack between "we assumed you had it" and "we thought you did that."

8. Who documents those people-and-building controls, and how?

Doing a control isn't enough. You have to prove it. Whoever asks, a prime, an auditor, or a future assessor, wants to see the written policy, the training records, the visitor log, the screening process, the media disposal procedure. Talk without documentation is a weak spot in your self-assessment. Your score runs on evidence, and evidence means documents that match reality.

9. Is the System Security Plan built for my shop, or a template with my name pasted in?

The SSP is the backbone document of your Level 2 compliance. NIST 800-171 requires it (control 3.12.4), and it has to describe exactly how each of the 110 controls is met in your environment. A real SSP names your systems, your CAM setup, your network, your machines, your data flow. A template SSP describes a generic company that doesn't exist, and anyone who reads it against your floor spots the difference fast, because the document won't match what they see. That's true whether the reader is a prime today or a third-party assessor if that requirement comes back.

10. How do you make sure I can stand behind my score, whoever ends up checking it?

Here's what the July 2026 change means for this question. The mandatory third-party assessment (the C3PAO step) is suspended pending the DoW's review, so for now you're not hiring an outside assessor. You demonstrate Level 2 by self-assessing against the 110 controls and having a senior official affirm your score in SPRS. A single-site third-party assessment commonly ran $30,000 to $60,000 in fees for a small shop, and that expense is off your plate for now. That's real money the suspension just saved you this year.

But self-certifying is not a free pass, and any vendor who sells it that way is setting you up. The SPRS affirmation is a legally binding statement, and a score you can't back up with evidence carries False Claims Act exposure. Primes can still ask to see your number and your SSP before they hand you work. And the duty to protect CUI under DFARS 252.204-7012 has applied since 2017 no matter what CMMC does. The review could also bring the third-party step back in some form, so a defensible self-assessment now is also insurance against a rushed scramble later.

Red flags to listen for

You're not just collecting answers. You're watching how a vendor reacts to hard questions. These are the patterns that should give you pause. One on its own might be a vendor having an off day. A cluster of them is a vendor who'll leave you exposed or oversold.

  • Manufactured urgency. A vendor still pounding the November 2026 deadline to rush you. That third-party deadline is suspended as of July 13, 2026. Anyone using it to close you fast either isn't current or is counting on you not being.
  • Hidden infrastructure cost. No straight answer on what compliant, GPU-backed workstations for CAM actually cost. The horsepower your software needs in a compliant cloud is expensive, and a vendor who hides it now will invoice it later. Make them price your CAM seats separately from your office seats.
  • Hidden CAM licensing. The proposal never mentions what happens to your CAM licenses in the new environment. That silence becomes a bill, or a seat that won't activate the week you go live.
  • Vague on data flow. Confident about the cloud, fuzzy the moment CUI has to reach a machine. They've solved the easy half and are hoping you don't notice the hard half.
  • Hand-waving on scope. They can't tell you what gets pulled into scope once a file leaves the boundary. Printers, USB drives, paper travelers, and old PCs all count. Oversizing your scope also oversizes your bill.
  • Enclave tunnel vision. They talk only about the secure container and stop at the shop floor, as if production isn't part of compliance. Your parts get made out there, and so does the risk.
  • "We handle all 110 controls." Nobody installs your locks or guards your dock. A vendor who claims to own your physical premises security either doesn't understand the controls or is telling you what you want to hear. You want a clear split of who does what, in writing.
  • "Self-cert means you barely have to do anything." The opposite of urgency, and just as dangerous. A self-assessment you can't defend is a legal exposure, not a box checked. The controls and the evidence still matter.
  • Template documentation. An SSP or policy set that describes a generic company instead of your shop. Anyone reading it against your floor sees through it, and so should you.
  • Incomplete workflow. They cover where data rests but can't trace it from customer portal to CAM to G-code to machine. Compliance breaks at the handoffs they skipped.
  • The RPO and C3PAO blur. A vendor who implies they can both get you ready and run your third-party assessment. Those can't be the same firm on the same engagement, and that line still matters if the requirement returns.
  • Hourly surprises. A low headline price with the remediation labor billed by the hour on top. Ask whether the work to reach readiness is included or whether the meter runs every time a gap turns up.

Get the full playbook (free)

Everything above is the map. The full checklist is the tool you bring into the room.

The free PDF adds, for every one of the ten questions, exactly what a strong answer sounds like, what a weak one sounds like, and the specific number or requirement to hold each vendor to. It also includes a ten-minute exercise to map your own CUI before you take a single sales call, so you walk in already knowing your rough scope. It is built to print and carry.

Give us an email and it is yours. We will send the PDF to your inbox and start it downloading right away. No cost, no obligation.

  • Company Name *
  • First Name *
  • Last Name *
  • Comments:
  • Yes, I'd like to subscribe to:
      10 Questions Every Defense Contractor Should Ask B...
      CMMC Phase II Is Suspended. What To Do Now.
      Comment for this post has been locked by admin.
       

      Comments

      Already Registered? Login Here
      No comments made yet. Be the first to submit a comment