CMMC Level 1 for Manufacturers: When Your Work Stays Below the CUI Line

Contributors

Shantanoo Govilkar
Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions

The biggest question is often not how to implement cybersecurity controls, but which level actually applies. If your organization handles Federal Contract Information (FCI) but does not handle Controlled Unclassified Information (CUI), you may fall under CMMC Level 1 rather than the more demanding Level 2 requirements. That distinction matters because it can significantly change the scope of your compliance effort.

The challenge is figuring out exactly where that line sits. A manufacturer can support defense programs, work with prime contractors, produce military components, and still operate in an environment that does not handle CUI. This guide breaks down what CMMC Level 1 means for manufacturers, how to tell whether your environment stays below the CUI line, what the 17 required practices look like in a manufacturing setting, and when it may be time to prepare for Level 2.

Also Read: CMMC Level 1 vs Level 2, Which Applies to You?

Understanding the CUI Line in Manufacturing

The first step is to understand the difference between FCI and CUI. They are not interchangeable, and the distinction directly affects CMMC requirements. Federal Contract Information generally refers to information provided by or generated by the government under a contract that is not intended for public release.

CUI is more sensitive to information that requires specific safeguarding or dissemination of controls under applicable laws, regulations, or government-wide policies. For manufacturers, this distinction can get complicated quickly. A company might produce components for a defense contractor, communicate with government customers, and manage contract documentation without ever handling CUI.

Another manufacturer might work with controlled technical information, engineering drawings, or other CUI as part of the same broader defense supply chain. That is why simply being a defense contractor does not automatically mean every system in your organization falls under CMMC Level 2.

When CMMC Level 1 Applies to a Manufacturer

CMMC Level 1 is intended for organizations that handle FCI but do not handle CUI within the relevant environment. For a manufacturer, this could include organizations involved in fabrication, assembly, production, maintenance, logistics, or other defense-related activities where the information they receive or create qualifies as FCI rather than CUI.

Consider a manufacturer producing a standard component for a defense program. The company may receive purchase orders, delivery requirements, contract details, or other nonpublic information related to the work. If that information qualifies as FCI and no CUI enters the environment, Level 1 may be the applicable CMMC level.

However, manufacturers should not make this determination based on assumptions. The contract, applicable clauses, information markings, customer requirements, and actual data flows all matter.

Also Read: Why CHIPS Act Manufacturers Can't Rely on CMMC Pen Testing Alone

The 17 Practices Behind CMMC Level 1

CMMC Level 1 focuses on 17 basic safeguarding practices that help organizations protect Federal Contract Information (FCI). For manufacturers, these practices should translate into everyday protections across office systems, production environments, workstations, and the people who access contract information.

  • Limit system access to authorized users: Make sure only approved employees, contractors, and other authorized individuals can access systems containing FCI.
  • Limit access to the types of transactions and functions users can perform: Give users only the system capabilities they need to perform their assigned responsibilities.
  • Verify and control connections to external systems: Know which external systems connect to your environment and ensure those connections are authorized.
  • Control connections to publicly accessible systems: Prevent unauthorized individuals from gaining access to internal systems through publicly accessible services.
  • Identify system users, processes, and devices: Maintain a clear understanding of who and what connects to systems that handle FCI.
  • Authenticate users, processes, and devices: Use appropriate authentication methods before allowing access to relevant systems and resources.
  • Sanitize or destroy information system media before disposal or reuse: Properly remove FCI from equipment and storage media before they are discarded, transferred, or reused.
  • Restrict physical access to systems: Prevent unauthorized individuals from physically accessing computers, equipment, and other systems that handle FCI.
  • Escort visitors and monitor visitor activity: Maintain appropriate oversight when visitors enter areas containing systems or equipment used to handle FCI.
  • Maintain audit logs: Keep records of relevant system activity so the organization can understand and review events occurring within its environment.
  • Monitor and control remote access sessions: Manage remote connections to systems and ensure remote access is authorized and appropriately controlled.
  • Protect the confidentiality of remote access sessions: Use appropriate safeguards to protect FCI when employees, contractors, or other authorized users connect remotely.
  • Route remote access through managed access control points: Ensure remote connections pass through controlled and managed access mechanisms.
  • Control wireless access: Identify and manage wireless connections to systems that handle FCI.
  • Protect systems from malicious code: Use appropriate protections against malware and other malicious software that could compromise systems or information.
  • Perform periodic and real-time scans for malicious code: Scan systems for malicious software and respond appropriately when threats are identified.
  • Update malicious code protection mechanisms: Keep antivirus and other malicious-code protection mechanisms current so they can address emerging threats.

What Level 1 Looks Like on the Manufacturing Floor

Cybersecurity can look very different on a manufacturing floor than it does in a corporate office.

An employee may need access to a production workstation to complete a job. A supervisor may need access to contract information from another location. A maintenance vendor may require remote access to equipment. Files may move between engineering, procurement, production, and shipping teams throughout the day. Each of these activities creates potential access points that manufacturers need to understand.

For example, organizations should know who can access systems containing FCI and whether those users actually need that access. They should also review physical access to relevant workstations and equipment, manage credentials appropriately, and understand how external or remote connections operate.

The important thing is to connect cybersecurity requirements to real workflows. A policy saying that only authorized personnel can access FCI does little if employees routinely share passwords or vendors have unrestricted remote access.

cmmc-level-1-on-the-manufacturing-floor

 

Scoping a Level 1 Environment Without Overextending It

One of the biggest challenges for manufacturers is determining what belongs inside the CMMC assessment scope. It can be tempting to put every corporate system, production device, application, and employee into scope just to be safe. That approach can make compliance far more complicated than necessary.

Instead, start with the information.

Identify where FCI enters the organization, where it is stored, which systems process it, and which users need access to it. Then map the systems and connections supporting those activities. This exercise may reveal that some systems have no relationship to FCI and do not need to be treated in the same way as systems that directly support the contract.

External service providers deserve attention. Cloud platforms, managed IT services, remote support tools, and vendor connections can influence the security of an in-scope environment. The objective is to establish a scope that is both accurate and defensible. An overly broad scope wastes resources, while an incomplete scope can leave relevant systems outside the assessment.

Common CMMC Level 1 Mistakes Manufacturers Make

Manufacturers often make the same few mistakes when preparing for CMMC Level 1. The first is treating documentation as the same thing as implementation. Having a cybersecurity policy on paper does not automatically demonstrate that the corresponding practice works in the real environment.

Another common mistake is assuming that every manufacturing system is automatically in scope because the company has a defense contract. The opposite assumption can be just as problematic. A system may need to be considered because of the way it stores, processes, transmits, or supports access to FCI.

Shared accounts can also create problems, particularly when multiple employees use the same workstation or application credentials. Remote access, removable media, physical security, and third-party connections are other areas that can easily receive less attention than traditional IT systems.

Finally, some manufacturers determine their CMMC level once and never revisit it. That can become a problem when the business takes on a new defense contract or begins handling a different type of information.

cta-banners

Building a Practical Level 1 Readiness Program

A practical Level 1 program does not need to start with an expensive technology overhaul.

Start by understanding the contracts and information involved. Identify the FCI your organization handles, map the systems and users associated with that information, and establish the boundaries of the environment.

Next, evaluate the 17 Level 1 practices against what is already in place. Look for gaps, assign responsibility for addressing them, and document the changes.

Evidence matters, too. Depending on the practice, useful evidence may include policies, system configurations, access records, procedures, training records, or other documentation showing that the required safeguards are actually operating. Most importantly, build the program around the way your manufacturing operation works.

A security control that looks good on paper but disrupts production or gets bypassed by employees will not provide much protection. The strongest Level 1 programs make cybersecurity part of normal operations rather than treating compliance as a separate project.

Moving Ahead

For manufacturers, CMMC Level 1 can provide an appropriate cybersecurity baseline when defense-related work involves FCI but not CUI. The difficult part is often not understanding the 17 practices. It is accurately determining what information the organization handles and where that information moves.

A strong approach starts with the contract and works outward. Understand the information requirements, identify the systems and users involved, establish a clear assessment boundary, and make sure the required safeguards operate consistently in the real manufacturing environment.

Also Read: The October 2026 CMMC Deadline: What Happens If You Miss It

Frequently Asked Questions

Back
to Top