The operational reality

What Makes Industrial Manufacturing Different

Nobody owns the boundary. Plant engineers own operational technology. IT owns the corporate network. The seam between them - where a compromised business workstation reaches a controller - is where incidents happen and where accountability is vacant.

Patching can void certification. CNC machines, PLCs, and embedded HMIs have fifteen to twenty-five year lives, and the controller vendor certifies specific configurations. "Just patch it" is not a plan; segmentation and compensating controls are.

Active scanning is dangerous here. Standard IT vulnerability scanning against industrial devices can disrupt them. Operational environments need passive monitoring and carefully scoped assessment.

Downtime is the loss, not the fine. Ransomware on ERP or MES stops the line, and the cost is measured in hours of production and missed delivery dates. That is the number that motivates the plant manager, and it is a real one - you can calculate yours.

Your compliance contact is your operations director. Named on the contract, with no bandwidth and no security background. The artifacts that gate contracts - the System Security Plan, the plan of action, the score in the supplier performance system - are documents, and someone has to write them.

Failure patterns

What Usually Goes Wrong

  • An IT vulnerability scan is run against the plant network and a controller faults. This is not hypothetical and it is why OT assessment is a different discipline.
  • CMMC is assumed to be a prime contractor problem. The flow-down clause in your purchase order says otherwise.
  • CUI is never identified. Without knowing which drawings, specifications, and process documents are covered, scope is guesswork and the assessment cannot be passed.
  • A security stack gets bought and the contract artifacts never get written - no System Security Plan, no plan of action and milestones, no current score submitted.
  • The corporate network reaches the plant network flat. One phished office account and the line is exposed.
  • A remote support tunnel from an equipment vendor stays open long after the commissioning visit.
  • Backups cover the file server and not the historian, the HMI images, or the controller programs. Recovery time is what matters, and those are what you need.
  • Segmentation is drawn on a diagram that no longer matches the plant.

Questions people ask

Frequently Asked Questions

Am I required to have CMMC certification?
It depends on whether your contracts include the requirement and what information you handle. CMMC applies through the Defense Federal Acquisition Regulation Supplement to contractors and subcontractors handling covered information, phased into solicitations over time. The program rule is at 32 CFR Part 170 and the official source is dodcio.defense.gov/cmmc - check the current phase-in language rather than a secondary summary.
Does CMMC apply if I am only a sub-tier supplier?
Requirements flow down through the supply chain. If your purchase order or your customer's prime contract passes the clause to you and you handle covered information, the obligation is yours. Many small shops discover this when a customer sends a flow-down notice rather than when they read a regulation.
What is the difference between CMMC Level 1 and Level 2?
Broadly, Level 1 addresses basic safeguarding of federal contract information with self-assessment, while Level 2 addresses protection of controlled unclassified information against the NIST SP 800-171 control set, with third-party assessment required for certain contracts. The authoritative breakdown is in 32 CFR Part 170.
Is our SCADA or historian data considered CUI?
Not by default. CUI is defined by category and by how the information was generated or provided under a federal contract - not by which system it sits in. The CUI Registry maintained by the National Archives is the reference, and this determination should be documented rather than assumed.
Do I need to segment my OT network from IT?
Segmentation is the single highest-value control in an industrial environment, because it is what stops an ordinary office compromise from reaching production. ISA/IEC 62443 provides the zone and conduit model, and NIST SP 800-82 provides guidance for operational technology security - both are public.
Can our PLCs be attacked over the internet?
Directly exposed industrial devices are routinely discoverable, and vendor remote access tunnels left open after commissioning are a common path. The question worth answering is not whether it is possible but whether anything in your plant currently has a route to the internet that nobody inventoried.
Are Windows XP machines on the plant floor a security risk?
Yes, and often they cannot be replaced without re-certifying the machine tool. The answer is not to pretend otherwise - it is isolation, strict access control, and monitoring around them, documented as a compensating control rather than an accepted unknown.
What is a DFARS clause and why is my customer asking about it?
DFARS 252.204-7012 requires safeguarding of covered defense information and rapid reporting of cyber incidents to the Department of Defense. Your customer is asking because their contract obligates them to flow it down to you. The clause text is public at acquisition.gov.
Do I need ITAR registration if I make parts for defense primes?
ITAR registration turns on whether you manufacture defense articles or furnish defense services as defined in the International Traffic in Arms Regulations, not on contract size. Since it also restricts who may access technical data, it has direct consequences for your file permissions and your hiring. Get a determination from export counsel.
Can I get cyber insurance if our SCADA is not patched?
Underwriters increasingly ask about segmentation, remote access controls, backup and recovery testing, and multi-factor authentication rather than universal patching. Unpatchable equipment is answerable if you can describe the compensating controls. It is unanswerable if you cannot.