CMMC Level 2 for Machine Shops: A Certification Guide

Trying to figure out what CMMC Level 2 certification might take? If you search for information on CMMC Level 2 certification guide for machine shops, most of what you find was written by cybersecurity consultants. That information is accurate as far as it goes — but it describes the framework from the outside. What it doesn’t captures is what the process looks like from inside a precision machining operation that has actually gone through it. The cost, the work, the sweat equity, and more.

Borg Design is a fourth-generation, family-owned CNC machining company in Hudson, Massachusetts. We hold CMMC Level 2 certification — not as a future goal, but as a current operational reality. We went through the assessment process, understood what it meant for our business, made the operational changes it required, and came out the other side with a certification that now shapes how we engage with every defense program we support.

This guide explains what CMMC Level 2 actually is, what certification requires in a manufacturing environment, what the assessment process involves, and what defense buyers should reasonably expect from certified suppliers. It is written for two audiences: machine shops evaluating whether and how to pursue certification, and defense buyers trying to understand what a supplier’s CMMC status actually means for their program.

CMMC checklistWhat CMMC 2.0 Is — And What It Replaced

CMMC stands for Cybersecurity Maturity Model Certification. It is the Department of War’s framework for verifying that contractors and subcontractors in the defense industrial base actually protect sensitive government information — rather than simply attesting that they do.

Before CMMC, defense contractors self-reported compliance with NIST SP 800-171 cybersecurity controls with limited third-party verification. Audits were inconsistent. Documentation was often incomplete. The gap between what contractors said they did and what they actually did was well-documented and widely acknowledged.

CMMC closes that gap. It replaces self-attestation with verified assessment — either through internal self-assessment or third-party certification by an accredited C3PAO (CMMC Third-Party Assessment Organization), depending on the sensitivity of the information handled and the nature of the contract.

One important clarification: a significant amount of outdated information online still describes a five-level CMMC framework. That model was retired. The current CMMC 2.0 framework, established under 32 CFR Part 170, has three levels:

  • Level 1 — 17 basic cybersecurity practices for contractors handling Federal Contract Information (FCI). Annual self-assessment.
  • Level 2 — 110 security controls aligned to NIST SP 800-171 for contractors handling Controlled Unclassified Information (CUI). Third-party C3PAO assessment required for most contracts.
  • Level 3 — 134 practices based on NIST SP 800-172 for contractors supporting the most sensitive DoD programs. Government-led DIBCAC assessment required.

The final rule took effect November 10, 2025. CMMC requirements are now actively appearing in DoD solicitations. Phase 2 — which makes mandatory C3PAO third-party assessment a condition of award for most Level 2 contracts — begins November 10, 2026.

Why Machine Shops Are Almost Always Level 2

The most common question precision machining companies ask is which CMMC level applies to them. For shops doing defense work, the answer is almost always Level 2 — and the reason is straightforward.

Level 2 is triggered by the presence of Controlled Unclassified Information in your systems. CUI in a manufacturing environment is not abstract. It shows up every day in the form of engineering drawings, CAD and CAM files, GD&T specifications, material and process specifications, test requirements, and any technical documentation tied to a defense program.

If a defense prime sends you a drawing package, you are almost certainly handling CUI. That triggers Level 2 requirements under DFARS clause 252.204-7012, which has been in defense contracts since 2017. CMMC adds independent verification to that existing requirement.

CUI also flows down through the supply chain. If a prime contractor shares CUI with you as a subcontractor, you need the same CMMC level they hold for that information. The compliance obligation does not stop at the prime — it runs all the way through the supply chain to every shop that touches controlled technical data.

What the 110 Controls Actually Mean in a Machine Shop

CMMC Level 2’s 110 security controls come from NIST SP 800-171 and are organized across 14 domains. In a cybersecurity context, the language can sound abstract. In a machine shop context, what the controls require is more concrete.

  • Access control means documented policies governing who can access systems containing CUI — drawing servers, CAM software, email — and how that access is granted, tracked, and revoked when employees leave.
  • Configuration management means maintaining documented, controlled configurations for the systems that touch CUI. If your CNC machines connect to a network that also carries drawing files, those machines are in scope.
  • Incident response means having a documented plan for identifying, reporting, and responding to cybersecurity incidents — and being able to demonstrate that plan exists and has been tested.
  • Media protection means controlling how CUI moves in and out of your systems — USB drives, external storage, personal devices, email attachments, and file sharing platforms are all in scope.
  • System and communications protection means encrypting CUI in transit and at rest, and controlling how it moves between internal systems and external parties.

None of these requirements are designed with machine shops specifically in mind — they were developed for the broader defense industrial base. Applying them to a precision machining environment requires operational translation: mapping where CUI actually lives in your workflows, identifying which systems touch it, and building the controls, documentation, and training that the framework requires.

When we began our CMMC journey, I expected the hard part to be the technology — the IT infrastructure, the security tools, the network architecture. What I didn’t expect was how much the process would require us to examine and document how our own business actually operates, and how much work it would add to the daily roles and responsibility of our employees.

The controls that took the most work weren’t the ones that required new software. While we are an AS9100D certified organization, and are used to work instructions, and process controls, security to this level was another level. The controls required us to define, write down, and consistently follow processes we had always handled with care, but not with the stringer controls required. Drawing access controls. Visitor protocols. How we communicate program-sensitive information with customers. How we handle a personnel change that involves someone who had access to controlled technical data.

What the certification process gave us — beyond the certificate — was operational clarity. We now know exactly where CUI lives in our systems, who can access it, how it moves, and what happens if something goes wrong. That discipline has made us a better manufacturing partner, not just a more compliant one.

For defense buyers evaluating suppliers, my suggestion is this: don’t just ask whether a shop has CMMC certification. Ask whether the certification changed how they operate. A shop that went through the process and came out the other side with stronger internal discipline is a fundamentally different supply chain partner than one that checked a box.

— K. Andrew Borg, President, Borg Design, Inc.

What the C3PAO Assessment Process Involves

For most Level 2 defense contracts, certification requires an independent assessment by an accredited C3PAO — an organization authorized by the Cyber AB to conduct official CMMC assessments. C3PAOs can be found and verified in the Cyber AB Marketplace.

The assessment process typically involves:

  • Scoping. Before the formal assessment begins, you and the C3PAO define the assessment boundary — the systems, people, and locations that touch CUI. Scope definition is one of the most consequential decisions in the process. A well-defined CUI enclave can reduce the cost and complexity of compliance significantly.
  • Documentation review. Assessors review your System Security Plan (SSP), policies, procedures, and supporting documentation against all 110 practices. Strong documentation before the assessment begins reduces assessment time and the risk of findings.
  • On-site assessment. A team of typically two to four assessors spends three to five days on-site, reviewing documentation, interviewing personnel, and testing controls. Each of the 110 practices receives a determination of MET, NOT MET, or NOT APPLICABLE.
  • Findings and POA&M. If deficiencies are identified, a Plan of Action and Milestones (POA&M) may be submitted for certain practices, allowing conditional certification while remediation is completed.
  • Certification. The C3PAO submits results to the DoD’s eMASS system. Certification is issued by the Cyber AB and is valid for three years, with annual affirmation of continued compliance required.

On cost: It’s not cheap. On cost: It’s not cheap. And might not be the right investment for your organization. The C3PAO assessment fee itself typically runs $35,000–$75,000 depending on scope and complexity. Total time investment to get to the assessment, including salaries, hardware, software can take well over a year. This includes gap assessment, remediation, technology implementation, documentation, and then the assessment. Costs can range from $105,000 to $285,000 or more for manufacturers starting from a low baseline. Shops that have maintained strong NIST SP 800-171 compliance prior to assessment face substantially lower remediation costs. Certification is valid for three years; ongoing annual compliance costs are typically $40,000–$100,000.

One practical note: C3PAO assessment capacity is constrained. Many C3PAOs are booked months in advance. Shops targeting contracts that will require Phase 2 certification by November 2026 should be initiating gap assessments now, not waiting until the deadline is imminent.

The Phase Rollout: Where We Are Now

Understanding the current enforcement landscape matters for both suppliers preparing for certification and buyers managing supply chain compliance risk. We’re currently in Phase 1, with Phase 2 coming at us like a freight train.

  • Phase 1 (Active since November 10, 2025): CMMC requirements are appearing in new DoD solicitations. Level 1 and Level 2 self-assessments are required where specified. The DoD may include mandatory C3PAO requirements in prioritized contracts even during Phase 1.
  • Phase 2 (Beginning November 10, 2026): Mandatory third-party C3PAO certification becomes a condition of award for the broad majority of Level 2 contracts. This is the critical inflection point for most defense manufacturing suppliers.
  • Phase 3 (Beginning November 2027): Level 2 and Level 3 assessments required for all new and renewing contracts. Option exercises on existing contracts also require certification.
  • Phase 4 (Beginning November 2028): Full CMMC implementation across all applicable DoD contracts. No waivers, no exceptions.
  • The practical deadline for any given supplier is not 2027 — it is the moment a contract they want to bid on requires it. Those solicitations are active today.

What Defense Buyers Should Ask Certified Suppliers

CMMC certification is a threshold — it tells you a supplier has met the minimum bar for Level 2 compliance. It doesn’t tell you everything about the operational quality of that compliance. Procurement and quality teams evaluating defense machining suppliers should go beyond the certificate.

  • Verify the certification. Certification should be publicly verifiable. If a supplier claims CMMC Level 2 but cannot provide a verifiable listing or assessment record, treat that claim with appropriate skepticism. Click here to see Borg Design CMMC L2 C3PAO certification (.pdf)
  • Ask about CUI handling in the manufacturing workflow. Where does controlled technical data — drawings, specs, CAM files — live in their systems? How is access controlled? What happens when a drawing is revised and the old version needs to be removed from circulation?
  • Ask about annual affirmation. CMMC Level 2 certification requires annual affirmation of continued compliance. A shop that certified two years ago and has not submitted annual affirmations may no longer be in good standing.
  • Ask what the certification process changed. As noted above: a supplier who can describe specific operational changes driven by the certification process has internalized what compliance actually means. A supplier who answers with a list of tools they purchased probably hasn’t.
  • Understand the difference between C3PAO certification and self-assessment. Until Phase 2 begins, some Level 2 contracts allow self-assessment. A self-assessed Level 2 supplier and a C3PAO-certified Level 2 supplier are not equivalent from a program risk standpoint. Know which one you’re working with.

What Borg Design’s CMMC Certification Means in Practice

Borg Design holds CMMC Level 2 certification through a completed C3PAO assessment. Our CAGE code is 1V3P1 and our CMMC Unique Identifier is L200001374. Download a copy of our certification here(.pdf). In practical terms, that means:

  • CUI handling is documented, controlled, and enforced across our systems and workflows
  • Drawing access, revision control, and technical data transmission follow documented processes with defined accountability
  • Incident response procedures are in place, documented, and tested
  • Our certification is verifiable in the Cyber AB Marketplace and maintained through annual affirmation

For defense industry programs that require a manufacturing partner who can receive, process, and protect controlled technical data — and demonstrate that protection to an independent assessor — Borg Design is built for that requirement.

For defense-specific machining inquiries, including programs requiring ITAR registration alongside CMMC Level 2, contact Borg Design here → or review our defense manufacturing capabilities →.