Aligning Shop-Floor and IT Processes to CMMC Level 2: NADCAP Aerospace Case Study

Last updated: 05/28/2026
Compliance

A tier-2 aerospace supplier had a mature AS9100D quality management system, NADCAP accreditation for chemical processing, and a longstanding IT environment that had never been built around protecting Controlled Unclassified Information. CMMC Level 2 demanded that two cultures - quality and cyber - start producing audit-ready evidence in lockstep.

Industry: Aerospace metal finishing, NADCAP-accredited Geography: Southern California CMMC scope: Level 2
68%

of DoD contractors report CMMC prep taking more than a yearRedspin 2025 (n=180)

31%

spending more than $250,000 on CMMC readinessRedspin 2025

~1,000

organizations CMMC Level 2 certified to dateThe Cyber AB

80,000

contractors in the Defense Industrial BaseDoD estimate

Industry context

An aerospace metal finishing supplier was running two parallel quality systems and a third one had just been added.

The organization at the center of this case study is a privately held, tier-2 aerospace metal finishing supplier in Southern California. It holds AS9100D certification across its quality management system and Performance Review Institute (PRI) NADCAP accreditations covering its chemical processing operations. Its customer base is the usual mix for a shop in that tier - primes and tier-1 suppliers on commercial and military aircraft programs, with a smaller volume of space and missile work flowing through. Its production floor handles parts that originate as controlled drawings from customers, and many of those drawings carry CUI markings or fall under International Traffic in Arms Regulations (ITAR) export controls.

Before the engagement began, the shop already operated under two disciplined quality regimes. AS9100D, the industry-standard quality management system for aviation, space, and defense, governs how the entire organization plans, produces, and inspects work. NADCAP, administered by PRI, accredits the specific special processes the shop performs - operations whose outputs cannot be fully verified through inspection alone, which is why the industry mandates a separate process-level audit. Both certifications are non-negotiable contractual requirements for the company's customer base.

What the shop did not have was a system designed to protect Controlled Unclassified Information at the same level of rigor. Its IT environment had grown organically over the years, sized for production traffic rather than for the kind of evidence trail CMMC Level 2 expects. CUI-marked drawings landed in customer-supplied PDFs, got printed for shop-floor use, traveled with parts on paper job travelers, and ended up in machinist toolboxes and inspector workstations. The information was being protected - but it was being protected by people, not by documented, repeatable, audit-ready controls.

The challenge

AS9100 is process-driven. CMMC is evidence-driven. They are not the same thing.

The most common mistake we see consultants make in environments like this one is treating CMMC as a cybersecurity project to be led out of IT. That framing fails for three reasons rooted in how manufacturing actually works.

First, manufacturing IT was never designed to be a compliance system. Coalfire Federal's own published analysis puts it directly: manufacturers have not culturally felt themselves to be targets of cyber attacks, and their IT operations are typically focused on enabling production connectivity rather than preventing unauthorized access. That is not negligence - it is a rational consequence of running a business where uptime and throughput pay the bills. The result, though, is that the existing IT documentation rarely meets the evidence standard NIST SP 800-171A applies during a C3PAO assessment.

Second, AS9100 and CMMC use different verbs. AS9100 is built around process control. The auditor asks: does the organization have a process? Is the process documented? Is it being followed? Is variation being tracked and addressed? CMMC, through the NIST SP 800-171A assessment methodology, is built around three verbs - Examine, Interview, and Test. Examine asks to see documentation. Interview asks whether the people responsible can explain the control in their own words. Test asks whether the control actually works the way the documentation claims. Documentation that satisfies an AS9100 auditor does not automatically satisfy a C3PAO assessor.

"Assessors will be looking for any disconnect between what the documentation says and the company's actual practice." - Greenberg Traurig LLP, October 2025

Third, the shop floor itself is in scope. Federal Contract Information and Controlled Unclassified Information do not stop at the office door. A paper traveler on a CNC operator's bench, a customer drawing printed and posted next to a heat-treat oven, a quality-inspection report sitting on a coordinate measuring machine workstation - all of these are CUI handling events. The Cyber AB and authoritative defense counsel have repeatedly confirmed that CMMC scope flows wherever CUI flows, and in a real manufacturer, CUI flows through quality, production, inspection, shipping, and receiving - not just through the email server.

Framework alignment

Where AS9100D and CMMC Level 2 share controls

Where AS9100D and CMMC Level 2 share controls AS9100D QUALITY MANAGEMENT SYSTEM CMMC Level 2 110 CONTROLS - 320 OBJECTIVES AS9100 ONLY Product realization Design control Risk-based thinking NADCAP special process accreditation Product traceability SHARED MANAGEMENT DISCIPLINES Document control Training and awareness Change control Internal audit Corrective action Supplier management Personnel security CMMC ONLY Access control Audit logging Cryptography (FIPS) Incident response Boundary protection Vulnerability management THE LEVERAGE A NADCAP-accredited shop already operates the disciplines in the center. CMMC Level 2 extends them - it does not replace them.

Reading this diagram: the overlap zone in the center lists management disciplines a NADCAP-accredited shop already operates under AS9100. The CMMC-only region on the right is the genuine net-new cyber control surface. Sources: NIST SP 800-171 Rev 2, SAE AS9100D, PRI NADCAP.

How we approached this

Treat CMMC as an extension of the existing quality system - not as a separate IT project.

Most consultants approach CMMC as a cybersecurity initiative led out of IT. For a NADCAP shop with mature AS9100 muscle memory, that is the wrong organizing principle. Quality engineers, production supervisors, and shop-floor leads already know how to live inside a controlled, audited process. The work is to extend that discipline into the cyber controls - not to rebuild it from scratch.

Anchor CMMC scope inside the existing AS9100 management review cadence

The shop already conducted regular AS9100 management reviews with quality, production, and executive leadership in the same room. Rather than spinning up a separate CMMC steering committee, we extended the management-review agenda to include a CMMC control status section. Information security policies, incident response readiness, and evidence collection cadence became standing items, reviewed with the same discipline the team already applied to nonconformance reports and corrective actions.

Map every CMMC control to an existing AS9100 process where one existed

AS9100 already requires documented procedures for change control, configuration management, training, internal audits, supplier management, and corrective action. CMMC requires substantially overlapping controls. Where an AS9100 procedure already existed, we did not write a new CMMC procedure. We extended the existing procedure to cover the CMMC-specific elements - for example, adding cyber incident response notification to the existing nonconformance escalation workflow rather than creating a separate process disconnected from the rest of the business.

Classify shop-floor systems against the CMMC scope categories

Per The Cyber AB scoping guidance, every information system gets categorized as in-scope CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, or Out-of-Scope. Shop-floor systems - CNC controllers running older operating systems, machine-monitoring software, computer-aided inspection equipment - frequently belong in the Specialized Asset category, which acknowledges that legacy operational technology cannot always be patched or instrumented like modern IT.

Build a paper-aware document handling SOP

Paper does not go away in a real machine shop. Pretending it does is one of the fastest ways to author a System Security Plan that does not match reality, and SSP-to-practice disconnects are the single most common adverse finding in C3PAO assessments. We built a documented procedure covering how CUI-marked drawings get printed, how they are marked at the printer, who is authorized to handle them, how they travel on the shop floor, how they get destroyed at end of life, and how the destruction event gets recorded.

Connect the engineering data system, ERP, and quality records into one CUI inventory

Most aerospace shops have a quoting platform, an ERP or MRP for production, a quality management system for inspection records and certificates of conformance, and a file share or engineering data system holding customer drawings. CUI flows across all of these. We produced a documented CUI inventory mapping where each customer-supplied controlled drawing originates, where its derivative work products live, and what controls protect each location. That inventory directly feeds the System Security Plan.

Train the floor on what changed and what did not

Most CMMC-driven changes for a NADCAP shop happen at the policy and evidence layer. Operationally, the floor changes very little. We delivered targeted training - short, role-specific, in the language the operators already use - to confirm what had not changed and to highlight the specific new requirements that did affect daily work. The shop that cannot explain its own controls fails on Interview, regardless of how good the documentation looks on paper.

Outcomes

A production floor that runs the same way it always has - with a defensible audit trail behind it.

The end state is a single integrated quality and information security management system. AS9100 is not being run alongside CMMC. CMMC is being run as the cyber chapter of the quality system the shop already operated. Management reviews cover both. The same internal-audit team that reviews quality records can review information security evidence. The same corrective-action discipline that handles a NADCAP finding can handle a CMMC gap. The organizational cost of running CMMC after this engagement is materially lower than it would be if CMMC had been spun up as a parallel function with its own meetings, its own metrics, and its own reporting lines.

From the production floor's perspective, very little visibly changed. Paper still moves where it needs to move. Operators still run the parts that come down to them. What changed is that every CUI handling step now has a documented procedure behind it, and that procedure is followed because it is part of how the shop already works - not because someone in IT printed a new policy nobody reads.

From an assessor's perspective, what changed is much larger. The shop now produces evidence on a recurring cadence rather than producing it in a panic in the weeks before assessment. Documentation matches practice. Personnel can explain what they do. The Specialized Asset classifications are documented and defensible. The CUI inventory matches the boundary diagram in the SSP. The same shop that walked into this engagement with mature AS9100 discipline and minimal CMMC discipline now walks into C3PAO assessment with both - under one management system.

Standards and controls touched

The published controls and authorities behind this work.

Every Consilien engagement maps to specific, citeable controls and publications. This is the regulatory and standards footprint of the work described above.

Standard / Control
Why it applies here
CA.L2-3.12.4
System Security Plan - must accurately reflect the assessment scope, including the CUI footprint across IT and operational technology.
CM.L2-3.4.1 / 3.4.2
Baseline configuration and change control - extended to cover shop-floor specialized assets, with documented risk acceptance for legacy systems.
AT.L2-3.2.1 / 3.2.2
Security awareness training and role-based training - aligned with existing AS9100 training records to avoid duplicate systems.
AU.L2-3.3.1 - 3.3.9
Audit logging and review - integrated into the existing AS9100 internal audit discipline.
PE.L2-3.10.1 - 3.10.6
Physical protection of CUI - the shop-floor controls family, including escort, area access, and device protection.
AS9100D
Quality Management System standard - the existing operating system the CMMC controls were aligned to.
NADCAP (PRI)
Special process accreditation - defines the chemical processing operations subject to industry-managed audit.
Why this matters for similar manufacturers

If you are a NADCAP-accredited shop, AS9100 is the asset most consultants miss.

If you are running a NADCAP-accredited aerospace shop in Southern California or anywhere else, you already have a competitive advantage most CMMC content does not recognize. AS9100D and your NADCAP scope require process discipline, documented procedures, internal audit cadence, corrective-action workflow, training records, and change control - every one of which has a direct counterpart in CMMC Level 2 controls. The cost and time of CMMC preparation drops materially when the program is run as an extension of the compliance system you already have, rather than as a separate IT project.

The mistake to avoid is letting your IT vendor lead CMMC as a technology refresh. Technology is downstream of scope, and scope is set by where CUI actually flows in your business. In a real metal finishing shop, that includes the shop floor, the QA lab, the customer-supplied drawing repository, the heat-treat oven control software, and the inspection plan database - none of which are the email server.

The Cyber AB reports that approximately 1,000 organizations have achieved CMMC Level 2 certification across a Defense Industrial Base estimated at 80,000 contractors. The bottleneck is not C3PAO capacity. The bottleneck is contractor readiness. For NADCAP shops, the fastest path to readiness runs through the AS9100 system you already trust.

Sources and references

The published controls and authorities behind this work.

Is your shop floor in scope for CMMC?

If your AS9100 system is mature but your IT environment was not designed for CUI, Consilien can scope your engagement against your real production processes. Gap assessment, remediation, documentation, and C3PAO preparation delivered as a structured program with predictable timelines.

Common Questions About CMMC for NADCAP Shops

Does AS9100 certification satisfy CMMC Level 2?
No. AS9100 is process-driven and CMMC is evidence-driven. They use different assessment verbs - AS9100 auditors check that a documented process exists and is followed; NIST SP 800-171A assessors run Examine, Interview, and Test. AS9100 discipline is the strongest possible foundation for CMMC readiness, but it does not replace any CMMC control. The smart move is to extend AS9100 procedures to cover CMMC-specific elements rather than build a parallel program.
Is the shop floor in scope for CMMC?
Yes, wherever CUI flows. A paper traveler on a CNC operator's bench, a customer drawing printed and posted next to a heat-treat oven, a quality-inspection report sitting on a coordinate measuring machine workstation - all are CUI handling events. The Cyber AB scoping guidance is explicit that scope follows the data, not the department. Production floors, QA labs, and inspection workstations are routinely in scope for tier-2 aerospace suppliers.
How long does CMMC Level 2 take for a NADCAP shop?
The 2025 Redspin study of 180 DoD contractors found 68 percent reported CMMC preparation taking more than a year, with 31 percent spending over $250,000. For NADCAP shops that anchor the work inside their existing AS9100 management review cadence, timelines and costs drop materially because the underlying process discipline is already in place. The bottleneck is usually evidence collection, not technology.
What is a Specialized Asset classification and why does it matter?
Under CMMC scoping guidance, every information system is classified as CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, or Out-of-Scope. Shop-floor systems like CNC controllers on older operating systems frequently belong in Specialized Asset, which acknowledges that legacy operational technology cannot always be patched or instrumented like modern IT. Properly classifying these systems removes false-positive findings from scope.
What is the most common reason shops fail a C3PAO assessment?
A disconnect between what the System Security Plan claims and what the floor actually does. Greenberg Traurig's October 2025 analysis put it directly: assessors look for any gap between documentation and practice. The fix is not better documentation - it is making the documented procedure the same procedure people actually follow. That is where AS9100 muscle memory pays off for NADCAP shops.