Aligning Shop-Floor and IT Processes to CMMC Level 2: NADCAP Aerospace Case Study
A tier-2 aerospace supplier had a mature AS9100D quality management system, NADCAP accreditation for chemical processing, and a longstanding IT environment that had never been built around protecting Controlled Unclassified Information. CMMC Level 2 demanded that two cultures - quality and cyber - start producing audit-ready evidence in lockstep.
of DoD contractors report CMMC prep taking more than a yearRedspin 2025 (n=180)
spending more than $250,000 on CMMC readinessRedspin 2025
organizations CMMC Level 2 certified to dateThe Cyber AB
contractors in the Defense Industrial BaseDoD estimate
An aerospace metal finishing supplier was running two parallel quality systems and a third one had just been added.
The organization at the center of this case study is a privately held, tier-2 aerospace metal finishing supplier in Southern California. It holds AS9100D certification across its quality management system and Performance Review Institute (PRI) NADCAP accreditations covering its chemical processing operations. Its customer base is the usual mix for a shop in that tier - primes and tier-1 suppliers on commercial and military aircraft programs, with a smaller volume of space and missile work flowing through. Its production floor handles parts that originate as controlled drawings from customers, and many of those drawings carry CUI markings or fall under International Traffic in Arms Regulations (ITAR) export controls.
Before the engagement began, the shop already operated under two disciplined quality regimes. AS9100D, the industry-standard quality management system for aviation, space, and defense, governs how the entire organization plans, produces, and inspects work. NADCAP, administered by PRI, accredits the specific special processes the shop performs - operations whose outputs cannot be fully verified through inspection alone, which is why the industry mandates a separate process-level audit. Both certifications are non-negotiable contractual requirements for the company's customer base.
What the shop did not have was a system designed to protect Controlled Unclassified Information at the same level of rigor. Its IT environment had grown organically over the years, sized for production traffic rather than for the kind of evidence trail CMMC Level 2 expects. CUI-marked drawings landed in customer-supplied PDFs, got printed for shop-floor use, traveled with parts on paper job travelers, and ended up in machinist toolboxes and inspector workstations. The information was being protected - but it was being protected by people, not by documented, repeatable, audit-ready controls.
AS9100 is process-driven. CMMC is evidence-driven. They are not the same thing.
The most common mistake we see consultants make in environments like this one is treating CMMC as a cybersecurity project to be led out of IT. That framing fails for three reasons rooted in how manufacturing actually works.
First, manufacturing IT was never designed to be a compliance system. Coalfire Federal's own published analysis puts it directly: manufacturers have not culturally felt themselves to be targets of cyber attacks, and their IT operations are typically focused on enabling production connectivity rather than preventing unauthorized access. That is not negligence - it is a rational consequence of running a business where uptime and throughput pay the bills. The result, though, is that the existing IT documentation rarely meets the evidence standard NIST SP 800-171A applies during a C3PAO assessment.
Second, AS9100 and CMMC use different verbs. AS9100 is built around process control. The auditor asks: does the organization have a process? Is the process documented? Is it being followed? Is variation being tracked and addressed? CMMC, through the NIST SP 800-171A assessment methodology, is built around three verbs - Examine, Interview, and Test. Examine asks to see documentation. Interview asks whether the people responsible can explain the control in their own words. Test asks whether the control actually works the way the documentation claims. Documentation that satisfies an AS9100 auditor does not automatically satisfy a C3PAO assessor.
"Assessors will be looking for any disconnect between what the documentation says and the company's actual practice." - Greenberg Traurig LLP, October 2025
Third, the shop floor itself is in scope. Federal Contract Information and Controlled Unclassified Information do not stop at the office door. A paper traveler on a CNC operator's bench, a customer drawing printed and posted next to a heat-treat oven, a quality-inspection report sitting on a coordinate measuring machine workstation - all of these are CUI handling events. The Cyber AB and authoritative defense counsel have repeatedly confirmed that CMMC scope flows wherever CUI flows, and in a real manufacturer, CUI flows through quality, production, inspection, shipping, and receiving - not just through the email server.
Where AS9100D and CMMC Level 2 share controls
Reading this diagram: the overlap zone in the center lists management disciplines a NADCAP-accredited shop already operates under AS9100. The CMMC-only region on the right is the genuine net-new cyber control surface. Sources: NIST SP 800-171 Rev 2, SAE AS9100D, PRI NADCAP.
Treat CMMC as an extension of the existing quality system - not as a separate IT project.
Most consultants approach CMMC as a cybersecurity initiative led out of IT. For a NADCAP shop with mature AS9100 muscle memory, that is the wrong organizing principle. Quality engineers, production supervisors, and shop-floor leads already know how to live inside a controlled, audited process. The work is to extend that discipline into the cyber controls - not to rebuild it from scratch.
Anchor CMMC scope inside the existing AS9100 management review cadence
The shop already conducted regular AS9100 management reviews with quality, production, and executive leadership in the same room. Rather than spinning up a separate CMMC steering committee, we extended the management-review agenda to include a CMMC control status section. Information security policies, incident response readiness, and evidence collection cadence became standing items, reviewed with the same discipline the team already applied to nonconformance reports and corrective actions.
Map every CMMC control to an existing AS9100 process where one existed
AS9100 already requires documented procedures for change control, configuration management, training, internal audits, supplier management, and corrective action. CMMC requires substantially overlapping controls. Where an AS9100 procedure already existed, we did not write a new CMMC procedure. We extended the existing procedure to cover the CMMC-specific elements - for example, adding cyber incident response notification to the existing nonconformance escalation workflow rather than creating a separate process disconnected from the rest of the business.
Classify shop-floor systems against the CMMC scope categories
Per The Cyber AB scoping guidance, every information system gets categorized as in-scope CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, or Out-of-Scope. Shop-floor systems - CNC controllers running older operating systems, machine-monitoring software, computer-aided inspection equipment - frequently belong in the Specialized Asset category, which acknowledges that legacy operational technology cannot always be patched or instrumented like modern IT.
Build a paper-aware document handling SOP
Paper does not go away in a real machine shop. Pretending it does is one of the fastest ways to author a System Security Plan that does not match reality, and SSP-to-practice disconnects are the single most common adverse finding in C3PAO assessments. We built a documented procedure covering how CUI-marked drawings get printed, how they are marked at the printer, who is authorized to handle them, how they travel on the shop floor, how they get destroyed at end of life, and how the destruction event gets recorded.
Connect the engineering data system, ERP, and quality records into one CUI inventory
Most aerospace shops have a quoting platform, an ERP or MRP for production, a quality management system for inspection records and certificates of conformance, and a file share or engineering data system holding customer drawings. CUI flows across all of these. We produced a documented CUI inventory mapping where each customer-supplied controlled drawing originates, where its derivative work products live, and what controls protect each location. That inventory directly feeds the System Security Plan.
Train the floor on what changed and what did not
Most CMMC-driven changes for a NADCAP shop happen at the policy and evidence layer. Operationally, the floor changes very little. We delivered targeted training - short, role-specific, in the language the operators already use - to confirm what had not changed and to highlight the specific new requirements that did affect daily work. The shop that cannot explain its own controls fails on Interview, regardless of how good the documentation looks on paper.
A production floor that runs the same way it always has - with a defensible audit trail behind it.
The end state is a single integrated quality and information security management system. AS9100 is not being run alongside CMMC. CMMC is being run as the cyber chapter of the quality system the shop already operated. Management reviews cover both. The same internal-audit team that reviews quality records can review information security evidence. The same corrective-action discipline that handles a NADCAP finding can handle a CMMC gap. The organizational cost of running CMMC after this engagement is materially lower than it would be if CMMC had been spun up as a parallel function with its own meetings, its own metrics, and its own reporting lines.
From the production floor's perspective, very little visibly changed. Paper still moves where it needs to move. Operators still run the parts that come down to them. What changed is that every CUI handling step now has a documented procedure behind it, and that procedure is followed because it is part of how the shop already works - not because someone in IT printed a new policy nobody reads.
From an assessor's perspective, what changed is much larger. The shop now produces evidence on a recurring cadence rather than producing it in a panic in the weeks before assessment. Documentation matches practice. Personnel can explain what they do. The Specialized Asset classifications are documented and defensible. The CUI inventory matches the boundary diagram in the SSP. The same shop that walked into this engagement with mature AS9100 discipline and minimal CMMC discipline now walks into C3PAO assessment with both - under one management system.
The published controls and authorities behind this work.
Every Consilien engagement maps to specific, citeable controls and publications. This is the regulatory and standards footprint of the work described above.
CA.L2-3.12.4CM.L2-3.4.1 / 3.4.2AT.L2-3.2.1 / 3.2.2AU.L2-3.3.1 - 3.3.9PE.L2-3.10.1 - 3.10.6AS9100DNADCAP (PRI)If you are a NADCAP-accredited shop, AS9100 is the asset most consultants miss.
If you are running a NADCAP-accredited aerospace shop in Southern California or anywhere else, you already have a competitive advantage most CMMC content does not recognize. AS9100D and your NADCAP scope require process discipline, documented procedures, internal audit cadence, corrective-action workflow, training records, and change control - every one of which has a direct counterpart in CMMC Level 2 controls. The cost and time of CMMC preparation drops materially when the program is run as an extension of the compliance system you already have, rather than as a separate IT project.
The mistake to avoid is letting your IT vendor lead CMMC as a technology refresh. Technology is downstream of scope, and scope is set by where CUI actually flows in your business. In a real metal finishing shop, that includes the shop floor, the QA lab, the customer-supplied drawing repository, the heat-treat oven control software, and the inspection plan database - none of which are the email server.
The Cyber AB reports that approximately 1,000 organizations have achieved CMMC Level 2 certification across a Defense Industrial Base estimated at 80,000 contractors. The bottleneck is not C3PAO capacity. The bottleneck is contractor readiness. For NADCAP shops, the fastest path to readiness runs through the AS9100 system you already trust.
The published controls and authorities behind this work.
Is your shop floor in scope for CMMC?
If your AS9100 system is mature but your IT environment was not designed for CUI, Consilien can scope your engagement against your real production processes. Gap assessment, remediation, documentation, and C3PAO preparation delivered as a structured program with predictable timelines.