Designing a hybrid physical and digital CUI workflow for a full-scope manufacturer.
When CUI flows through paper travelers, machinist toolboxes, contract workers, and a NADCAP cage at the same time as it flows through an ERP system, an email server, and a customer drawing repository, neither a pure digital enclave strategy nor a pure paper-control strategy is sufficient. The defensible answer is a hybrid CUI boundary - and it is built one workflow at a time.
A full-scope metal finishing workshop has more CUI handling events than an office-only contractor sees in a year.
The organization at the center of this case study is a full-scope metal finishing workshop operating in Southern California, supplying parts to the aerospace and defense supply chain. "Full-scope" means the shop receives raw or partially completed parts from customers, performs one or more special processes - anodizing, conversion coating, plating, passivation, heat treatment, non-destructive testing - and ships finished work back to the customer. It is the kind of operation NADCAP was created to accredit, and the kind of operation that does not exist in a clean, digital-only form.
CUI enters this shop in many ways. Customer-supplied technical drawings come in through email, customer portals, and occasionally as printed packages alongside delivered parts. Job travelers - the paper or hybrid documents that move physically with parts through every operation - frequently carry CUI markings or reference CUI-marked customer drawings. Process specifications taped to walls near anodizing tanks reproduce excerpts of customer documents. Quality records and certificates of conformance generated during inspection reference the CUI-bearing customer specifications. The CUI footprint is genuinely hybrid: digital where it can be, physical where it must be, and frequently both at once.
The workforce reality is also hybrid. The shop employs its own full-time workforce of operators, inspectors, and quality engineers, but - like virtually every metal finishing shop in California - it also brings in temporary contract workers through staffing agencies during peak demand. Those temporary workers, although employed by a third-party staffing firm rather than by the shop directly, work on CUI-bearing parts on the production floor. The CMMC framework, NIST SP 800-171, and 32 CFR Part 2002 (which governs the CUI program more broadly) all expect that any individual handling CUI is appropriately controlled - regardless of who issues their W-2.
Digital-first CMMC guidance does not survive contact with a real shop floor.
The dominant published guidance on CMMC for manufacturers tilts hard toward two recommendations: minimize the CUI footprint by going paperless wherever possible, and isolate CUI in a digital enclave such as Microsoft GCC High or a PreVeil-secured environment. Both recommendations are sound - for environments where they apply. For a full-scope metal finishing workshop, neither one fully solves the problem.
Paper does not always go away in a real shop. A job traveler that moves physically with the part across ten production stations cannot be replaced with a tablet without rebuilding shop-floor IT around connected devices, retraining the entire operator workforce, and convincing your customer base - much of which still requires paper documentation for receiving inspection - that the change is acceptable. Some shops can make that conversion. Many cannot, at least not on the CMMC timeline they are working against.
A digital enclave does not control the physical world. A CUI-marked drawing that exists only inside a PreVeil enclave is well-protected against digital threats. The same drawing, printed for use on the production floor, exits the enclave the moment ink hits paper. From that point, CMMC's Physical Protection family (PE.L2-3.10.1 through 3.10.6) takes over - visitor escort, area access controls, device protection, monitoring of physical access, and authorized handling of CUI in physical form. Those controls have no digital equivalent. They have to be implemented on the floor.
Contract workers complicate everything. Industry forums and practitioner communities consistently raise temporary workforce CUI exposure as one of the harder unresolved questions in manufacturer CMMC implementations. The staffing agency may not perform the kind of background checks that customer flow-down clauses sometimes require. The contract worker may be ITAR-eligible (a U.S. person, as the regulation defines that term) but not subject to the same nondisclosure and CUI awareness training as a direct-hire employee. The shop is on the hook for whatever they handle.
NADCAP cages, restricted areas, and shop layouts add physical complexity. A NADCAP-accredited chemical processing line often has restricted physical zones for chemical safety and process integrity reasons that pre-date any CUI consideration. Those zones already have access logs, training requirements, and personnel restrictions for reasons unrelated to information security. The CMMC question is not whether to invent new physical access controls - it is how to extend the controls that already exist to also satisfy the cyber framework.
How CUI moves through a metal finishing shop
Reading this diagram: the top lane (green) is the digital domain. The bottom lane (gray) is the physical environment. Dashed bridge events mark every point where CUI changes media. Each event lists the NIST 800-171 control families that govern it. Sources: NIST SP 800-171 Rev 2, NARA / ISOO CUI Registry, 32 CFR Part 2002.
Map every CUI handling event in the production process, then layer controls per event.
We built the boundary the way an industrial engineer maps a process - handling event by handling event, with the appropriate control set for each. The result is a CUI flow diagram that an assessor can walk, end to end, and that the production team can actually execute against under daily pressure.
Build a complete CUI handling event inventory
We catalogued every point in the shop's workflow where CUI is created, received, transformed, stored, transmitted, or destroyed. The inventory ran longer than the team expected - over forty distinct handling events from initial customer drawing receipt through final certificate of conformance issuance. Each event was tagged with the system or location involved (email, drawing repository, ERP, printer, shop-floor traveler, inspection workstation, file cabinet, shredder bin), the personnel role authorized to handle it, and the format (digital, paper, hybrid). This inventory becomes the source of truth for the CUI boundary diagram in the System Security Plan.
Apply the right control set per event class
Digital CUI events get the digital control set - access control, encryption in transit and at rest, audit logging, multi-factor authentication, FIPS-validated cryptography where required. Physical CUI events get the physical control set - marking, area access, escort, secure storage, sanctioned destruction. Hybrid events (a CUI drawing printed for shop-floor use, for example) get both. The framework supports this exactly: NIST 800-171's Access Control, Audit and Accountability, and System and Communications Protection families cover the digital side; the Physical Protection family covers the physical side. Most CMMC implementations under-invest in the second.
Mark CUI at every transformation, in both forms
Per the NARA / ISOO CUI Registry and 32 CFR Part 2002, CUI must carry its marking throughout its lifecycle - including derivative work. A printed drawing must carry the customer's CUI marking. A job traveler that references that drawing must reference the marking. A quality inspection report that includes excerpted dimensions from a CUI drawing inherits the marking. We documented the marking SOP across all forms - print headers, traveler templates, inspection report templates, and the document-control numbering scheme that ties physical artifacts back to their digital source of truth.
Implement zone-based physical access controls aligned to existing chemical-safety zones
Rather than creating new physical access zones for CMMC, we extended the existing zones the shop already operated for chemical safety, NADCAP process integrity, and ITAR export control reasons. The chemical processing area was already restricted to trained, qualified personnel. We layered CUI-aware access logging onto that existing zone, documented the personnel roles authorized to enter, integrated the entry log with the cyber incident response process, and built escort procedures for visitors and unbadged personnel. The result satisfies PE.L2-3.10.3 (escort visitors and monitor visitor activity) and PE.L2-3.10.4 (maintain audit logs of physical access) without requiring the shop to build a parallel access control system.
Build a contract-worker controls module
Contract workers handling CUI received a documented control set: an updated staffing agency master service agreement requiring background screening at the level the customer flow-down demands, role-specific CUI awareness training delivered before first shift, a documented authorization record kept by HR that maps every contract worker to the specific authorized zones and roles, and a defined escalation procedure for incidents involving contract workers. The agreement language was extended to cover the staffing agency's flow-down responsibility under DFARS 252.204-7012(m) - the requirement that primes and subs pass cybersecurity requirements down to their own subcontractors, including labor providers when those providers' personnel handle CUI.
Design a destruction and disposition workflow that an assessor can verify
Paper CUI must be destroyed in a manner that prevents recovery. NIST SP 800-88 and the NIST 800-171 Media Protection family govern this. We documented the destruction SOP - cross-cut or higher-grade shredders at defined locations, logged destruction events for traveler-class documents, secure disposal of damaged or superseded customer drawings, and a quarterly internal audit reconciling the destruction log against issued-and-returned document counts. Digital CUI sanitization, including hard drives, removable media, and printer/MFP memory, follows the same framework with the appropriate digital methods.
A CUI boundary that survives contact with the shop floor - and a C3PAO assessor walking it.
The shop's CUI boundary is now visible. There is a documented inventory of every place CUI exists, in any form, and a documented control set for each. The System Security Plan's boundary diagram reflects the actual production environment, not an idealized digital-only version of it. When a C3PAO assessor begins the Examine phase, the inventory document is the entry point - and every artifact referenced in the inventory exists, in its claimed location, in its claimed form.
Day-to-day operations on the shop floor are essentially unchanged. Operators still see their job travelers. Inspectors still produce their reports. The contract workers from the staffing agency still come in for peak demand. What changed is that every one of those handling events now has a documented procedure behind it, the procedure is being followed because it was designed to fit how the shop actually works, and the evidence to prove the procedure is being followed is being collected automatically as part of normal operations.
The reduction in scope, achieved by classifying assets correctly rather than by force-fitting every system into a single CUI environment, materially reduced the size of the engagement footprint. Specialized Assets - older shop-floor systems that cannot be fully patched or monitored under standard IT controls - were documented as such, with the compensating procedural controls that the CMMC framework explicitly permits for that asset category. The shop did not have to replace working production equipment to achieve compliance. It had to document, control, and evidence the equipment it already had.
The published controls and authorities behind this work.
Every Consilien engagement maps to specific, citeable controls and publications. This is the regulatory and standards footprint of the work described above.
PE.L2-3.10.1PE.L2-3.10.3PE.L2-3.10.4PE.L2-3.10.5 / 3.10.6MP.L2-3.8.1 through 3.8.9PS.L2-3.9.1 / 3.9.232 CFR Part 2002NARA / ISOO CUI RegistryMost published CMMC guidance was written for office-only environments. Manufacturers need something else.
If your shop receives parts, performs work on them, and ships them back, you are operating in a hybrid CUI world. There is no published shortcut that lets you treat your environment as digital-only. The framework recognizes this - the Physical Protection family exists for a reason, and the Specialized Asset category exists for a reason. Most published CMMC guidance under-invests in both, because most published CMMC guidance was written by IT-focused consultancies for office-environment clients.
The Reddit and practitioner-community signal on this is clear and consistent. The single most-discussed manufacturer-specific CMMC pain point in active practitioner forums is over-marking and over-scoping CUI - shops marking too much information as CUI because they are not confident in their classification methodology, then paying for security controls on the over-scoped footprint. A correctly scoped CUI inventory, mapped to actual handling events on the production floor, is the cheapest single intervention available in a manufacturer CMMC program. It precedes every tooling decision.
The work involved in mapping a hybrid CUI boundary is not glamorous. It looks more like industrial engineering than like cybersecurity. But the outputs - the inventory, the boundary diagram, the per-event control mapping, the contract-worker module, the destruction procedure - are exactly what a C3PAO assessor needs to see during the Examine and Test phases. If your shop is in this position, this is the work to do first.
Sources & references
Does your CUI flow through paper, people, and the shop floor?
If your CMMC scope cannot be solved by a digital-only enclave, we can map your CUI handling events against your real production workflow in a 30-minute call.
More from the series
Aligning Shop-Floor and IT Processes to CMMC Level 2
How a NADCAP-accredited aerospace metal finishing supplier bridged its AS9100 quality culture with the cyber controls that CMMC Level 2 demands - without disrupting production.
Read case study Case Study 03Building a Complete CMMC Policy and Procedure Architecture from Scratch
Templates do not survive a C3PAO assessment. We built an Information Security Policies and Standards document, a five-playbook Incident Response chain, an Operations Security Procedures Manual, and Shared Responsibility Matrices - all in one engagement.
Read case study Case Study 04PreVeil Enclave Design Instead of a Full GCC High Rollout
Industry data shows GCC High deployments can run to six figures and require an organization-wide rip-and-replace. For a mid-sized aerospace supplier with a narrow CUI footprint, an enclave architecture was the smarter path.
Read case study