Defense Manufacturing Supplier Qualification Checklist and Readiness Guide for Precision Machining Programs
Defense programs run on supplier reliability. The shops that create problems — missed deliveries, documentation gaps, compliance exposure, CUI mishandling — share predictable warning signs that show up clearly during qualification if you know what to look for.
This defense manufacturing supplier qualification checklist is built for procurement managers, supply chain directors, and quality engineers evaluating precision machining suppliers for defense and aerospace programs. It covers the certifications to verify, the operational signals that matter beyond the certificates, and the five questions that reveal how a shop actually operates under pressure.
Section 1: Certifications to Verify
A certification is a starting point, not a conclusion. Each one tells you something specific about how a shop manages its quality systems, protects sensitive data, and operates under compliance obligations.
AS9100D certification — current and active. Request the supplier’s certificate. AS9100D governs the full quality management system — documentation, revision control, inspection discipline, nonconformance management, and corrective action. An AS9100D-certified shop has had those systems independently audited, not just documented.
ISO 9001:2015 certification — current and active. The foundation quality standard underlying AS9100D. A shop holding AS9100D necessarily holds ISO 9001:2015. Verify both certificates are current with active surveillance audits.
DDTC/ITAR registration — confirmed. Request the supplier’s CAGE Code and verify registration at DDTC.state.gov. ITAR registration is required for any shop handling technical data on the U.S. Munitions List — which includes virtually all defense-program engineering drawings. An unregistered supplier receiving ITAR-controlled data creates legal exposure for the prime contractor through flow-down obligations.
CMMC Level 2 certification — verified. Request certification documentation from the supplier. When verifying, confirm two things beyond the basic certificate:
- Is this a C3PAO-assessed certification (third-party independent assessment) or a self-assessment? These are not equivalent from a program risk standpoint.
- Is the annual affirmation current? CMMC Level 2 certification requires annual affirmation of continued compliance. A shop that certified two or three years ago without submitting annual affirmations may no longer be in good standing.
- Learn all about CMMC Level 2 here.
Section 2: Documentation and Quality Signals
Certifications tell you what a shop has committed to. Documentation signals tell you whether those commitments are operational.
- Revision-controlled drawing management system — not a shared drive. A formal process governing which revision is active on the shop floor at any given moment.
- Job traveler or equivalent production tracking document — follows the part through every operation, records actuals, and creates an auditable production record.
- Nonconformance and corrective action process — documented, active, and closed in a defined timeframe. Ask to see a recent corrective action. How quickly it was identified and closed tells you more than the certificate.
- Material traceability from raw stock certificate to finished part — the chain from MTR to shipment should be unbroken.
- First Article Inspection (FAIR) capability in AS9102 format — not just dimensional inspection, but a structured report with ballooned drawing, actual measurements, material certifications, and sign-off traceable to the drawing revision level.
Section 3: CUI Handling and Operational Signals
For defense programs, how a supplier handles controlled technical data is as important as how they machine the parts. These signals are harder to observe than certifications but more predictive of program risk.
- Documented CUI handling procedures — who can access drawings, how files are stored and transmitted, what happens when an employee leaves. Vague answers are a red flag regardless of CMMC status.
- Personnel training on ITAR obligations — ITAR awareness should be documented and regular, not a one-time onboarding item.
- Outside processor controls — when a shop sends work to a plater, heat treater, or coating vendor, how is controlled documentation handled? The compliance obligation follows the data, not just the part.
- Defined communication and escalation standards — does the shop have a defined threshold for proactive contact? Ask specifically: “What triggers an escalation call and who makes it?”
- First-order monitoring process — ask how a shop manages the first production run on a new program. The answer tells you whether new business receives dedicated attention or gets treated like existing work from day one.
Section 4: Five Questions to Ask
These questions are designed to reveal operational reality, not documentation. A supplier that answers them specifically and without hesitation is operating at a different level than one that answers in generalities.
How do you handle revision changes to drawings mid-production?
✓ Strong: Documented traveler update process, customer notification protocol, version control. A named owner responsible for the change.
✗ Weak: “We update the file and let the machinists know.” Informal, verbal, no documented chain.
Where does our controlled technical data live in your systems, and who has access to it?
✓ Strong: A defined CUI enclave — specific systems, documented access controls, a named list of authorized personnel. They can answer this without hesitation.
✗ Weak: “On our server” or “in our ERP.” Vague systems, no access controls described.
What triggers an escalation call to us, and who makes that call?
✓ Strong: A defined threshold — for example, any delivery risk exceeding 48 hours triggers proactive contact from a named account owner before the customer needs to ask.
✗ Weak: “We call you when we know something is wrong.” No protocol, reactive by default.
Walk me through your first article inspection process.
✓ Strong: AS9102 format, CMM-generated dimensional data, actual measurements recorded against every ballooned characteristic, traceable to drawing revision level.
✗ Weak: “We check it and sign off.” No standard format, no CMM data, no traceability.
What outside processors do you use, and how do you manage their access to our documentation?
✓ Strong: An approved vendor list, documented flow-down obligations, a controlled process for transmitting technical data to processors. They can name the vendors and describe the controls.
✗ Weak: “We send them what they need.” Unstructured, no documented controls.
Compliance Reference
A brief overview of the three certifications that matter most when qualifying precision machining suppliers for defense programs.
CMMC Level 2 — Cybersecurity Maturity Model Certification
What it is: 110 security controls aligned to NIST SP 800-171, governing how defense suppliers protect Controlled Unclassified Information (CUI) — including engineering drawings, technical specifications, and program documentation.
Who needs it: Any supplier whose systems process, store, or transmit CUI. In a machine shop environment, this includes nearly all defense work involving customer-supplied drawings or program-specific technical data.
How to verify: Request certification documentation from the supplier. Confirm the certification is C3PAO-assessed (third-party), not self-assessed, and that annual affirmation is current.
Phase 2 note: Mandatory third-party C3PAO assessment becomes a condition of award for most Level 2 contracts beginning November 10, 2026. Some FY2026 contracts already include this requirement.
ITAR — International Traffic in Arms Regulations
What it is: Federal regulations administered by the State Department’s DDTC governing the manufacture, export, and handling of defense articles and technical data listed on the U.S. Munitions List (USML).
Who needs it: Any company that manufactures, exports, brokers, or receives technical data related to items on the USML — including most precision machining shops supporting defense programs.
How to verify: Request the supplier’s CAGE Code and verify registration at DDTC.state.gov. ITAR-registered companies appear in the DDTC registrant database.
Why it matters: An unregistered supplier receiving ITAR-controlled technical data creates legal exposure for the prime contractor through flow-down obligations in the defense contract.
AS9100D — Aerospace and Defense Quality Management System
What it is: The quality management standard for aviation, space, and defense manufacturing. Built on ISO 9001:2015 with additional requirements for risk management, configuration management, and counterfeit part prevention.
Who needs it: Required by most aerospace and defense primes as a qualification criterion for Tier 2 suppliers. Governs documentation, revision control, inspection, nonconformance, and corrective action processes.
How to verify: Request the certificate and verify through the issuing registrar. Cross-reference using the IAQG OASIS database at iaqg.org.
What it signals: An AS9100D-certified shop has documented, independently audited quality systems covering the full production cycle. Certification is maintained through ongoing surveillance audits — not a one-time achievement.
Who is Borg Design? We are a CNC machining and engineering business which holds AS9100D, ISO 9001:2015, DDTC/ITAR registration, and CMMC Level 2 certification. We operate from a 58,000 sq. ft. facility in Hudson, Massachusetts with 50+ precision machines, including large-format CNC capability to 120″ X-axis travel. We are a fourth generation family ownership since 1945. CAGE Code: 1V3P1.
Related resources:
CMMC Level 2 for Machine Shops: What Certification Actually Requires →
ITAR vs CMMC: What Defense Buyers Need from Suppliers →
Defense Industry CNC Machining →
Download this checklist as a PDF →

Ready to Talk?
WHAT BIG IDEA WE CAN HELP YOU WITH?