ITAR vs CMMC vs NIST 800-171: Which One Applies to Your Manufacturing Business?
They aren't three options. NIST 800-171 is the control list, CMMC is the DoD's way of proving you follow it, and ITAR is a State Department export law about who can see defense technical data. Your contract and drawings decide.
Table of Contents
For a typical aerospace or defense job shop, all three land on the same manufacturing IT environment at once. The CMMC Phase 2 suspension in July 2026 paused third-party certification. It didn't pause NIST 800-171, your SPRS score, or ITAR, and the Justice Department is still settling cases over the first two.
A purchase order shows up from a prime. Page 14 lists DFARS 252.204-7012 and 252.204-7021. The drawing package has an export warning in the title block citing the Arms Export Control Act. Your quality manager wants to know if the shop is ITAR compliant. Your IT person asks whether that means CMMC. Nobody's sure who should answer.
Those are three different questions. Shops lose months treating them as one.
ITAR vs CMMC isn't a choice between two frameworks, and NIST 800-171 isn't a third option sitting next to them. They stack. For a machine shop, a PCB house, or a metal finisher on an aerospace program, each one asks something different of your network, each one has a different agency behind it, and each one can cost you a contract on its own. What follows is how to read your own paperwork, figure out which of the three you actually owe, and build one environment that answers all of them.

What's the Actual Difference Between ITAR, CMMC, and NIST 800-171?
NIST 800-171 is a list of 110 requirements for protecting Controlled Unclassified Information (CUI). CMMC is the Department of War program that checks whether you meet them. ITAR is an export-control law that decides who may access defense technical data.
Department of War? It's been the DoD's secondary name since September 2025. Your contract clauses still say DFARS. CUI is government information that isn't classified but still comes with handling rules. On a shop floor that usually means drawings, specs, tolerances, inspection data, and anything else a DoD customer hands you to build a part, including the copy on the CAM workstation and the one printed out and taped up next to the machine. NIST SP 800-171 Rev 2 sorts its 110 requirements into 14 families, from access control to incident response.
Different questions entirely. ITAR asks who's allowed to see the data. NIST 800-171 asks how the systems holding it are protected. CMMC asks whether you can prove the second one to an assessor. A shop can pass one and fail the other two on the same afternoon, which is roughly what happens when the person handling export compliance and the person running IT never end up in the same meeting.
There's no such thing as an ITAR certification. The State Department registers manufacturers and issues licenses. It doesn't certify anybody's IT, so an MSP or software vendor advertising itself as "ITAR certified" is describing something the regulation doesn't offer. Ask what they mean. Press them and it usually turns out their support staff are U.S. persons. Useful. Still not a certificate.

Which Paperwork Tells You What Applies?
You don't need a consultant to answer this one. You need the PO terms, the drawing package, and your DDTC registration status, and two of those three are probably in a filing cabinet already. The paperwork answered the question when the contract was signed. Read it before a software vendor answers it for you.
The clauses in your contract
Pull up the PO terms and Ctrl+F for these numbers.
- FAR 52.204-21 is about Federal Contract Information (FCI), the non-public details of the contract itself, like your delivery schedule and unit pricing. It sets 15 basic safeguards and maps to CMMC Level 1.
- DFARS 252.204-7012 is the big one. If it's there and you hold CUI, you owe all 110 NIST 800-171 requirements, a 72-hour cyber incident report to the DoD, and cloud services equivalent to the FedRAMP Moderate baseline.
- DFARS 7019 and 7020? Those require a current self-assessment score in the Supplier Performance Risk System (SPRS), the DoD database primes and contracting officers check. Scores run from -203 to 110.
- DFARS 7021 and 7025 name the CMMC level you need to win the award.
Flowdowns count. If your prime's contract has 7012 and they send you CUI, the clause rides along to you whether or not anyone mentioned it on the phone.
The markings on your drawings
Check the banner first. Then the title block. A banner reading CUI//SP-EXPT or CUI//EXPT means export-controlled CUI under the National Archives CUI Registry, and that single marking puts you under both an export regime and NIST 800-171. An export warning that cites the Arms Export Control Act points at ITAR specifically.
Watch for the other export regime, too. If the drawing references an ECCN or the EAR, that's the Commerce Department's Export Administration Regulations, not ITAR. Different agency, different rules, similar foreign-person problem.
And unmarked drawings? Ask the prime in writing what the data is. A two-line email answer is worth more than a week of guessing.
Your DDTC registration
Build-to-print shops miss this one. Under 22 CFR 122.1, anyone who manufactures a defense article has to register with DDTC, even if they never export anything. A shop that machines one USML-listed bracket for a domestic prime, one time, is in. DDTC doesn't ask how big the order was.
If you're making those parts unregistered, fix that before you spend a dollar on IT.
Which of the Six Manufacturer Profiles Are You?
Find your row and read across.

Row 5 is where a typical aerospace manufacturing job shop sits, usually with one person wearing the export compliance hat and an outside IT provider wearing the other. Leadership sees the DDTC registration and figures security is covered. Or it sees a respectable SPRS score and figures ITAR is. Somebody signs off on a risk nobody measured. Neither covers the other. A CMMC assessor doesn't check the citizenship of the people who can open your file server. DDTC doesn't care about your SPRS score.
Row 4 gets missed because nobody ever sends those shops a DFARS clause, so nobody asks about 800-171. ITAR applies anyway, every word of it. And since ITAR never says how to secure anything, those shops tend to borrow 800-171 as the recipe.
Row 1 shops can honestly stop reading here. With no defense data, none of the three apply, and a NIST Cybersecurity Framework program is a better place to put the money.
Where Does ITAR Ask for More Than NIST 800-171?
ITAR restricts who can see the data based on nationality. NIST 800-171 controls how systems are secured. It never asks anyone's citizenship. That gap catches shops with foreign-national engineers, offshore IT support, or files sitting in a commercial cloud tenant.
Under ITAR, showing technical data to a foreign person counts as an export, even when that person sits at a desk in your building. Geography doesn't save you. A U.S. person, for ITAR purposes, means a citizen, a lawful permanent resident, or a protected individual like an asylee. A design engineer on an H-1B visa isn't one, and neither is a help desk technician in another country who can remote into the CAD workstation at 2 a.m. to fix a license server.
That last part trips up more shops than the engineering floor does. Your IT provider sits inside the boundary. If their after-hours team includes foreign persons with admin rights to the server that holds your drawings, you've got an access problem that 800-171 alone won't flag. The IT side of ITAR compliance starts with knowing who on your provider's side can reach that data.
Cloud is the other fork. You've got two legitimate paths.
- A government cloud. Microsoft makes contractual ITAR commitments on data location and U.S.-person access for its government clouds, including GCC High, and not for commercial Microsoft 365.
- The encryption carve-out in 22 CFR 120.54(a)(5), which says end-to-end encrypted technical data isn't an export if the encryption uses FIPS 140 validated modules, the cloud provider never holds the keys, and the data isn't deliberately stored in or routed through a country listed in ITAR §126.1.
Commercial Microsoft 365 with default settings is neither. It's also where a lot of ITAR drawings live right now, attached to an email from 2023 that went to purchasing, got forwarded to an outside processor for a quote, and has sat in three mailboxes nobody's thought about since. For a deeper look at the technical controls, the ITAR cybersecurity guide for electronics manufacturers walks through them family by family.
Did the CMMC Phase 2 Suspension Change What You Owe?
It changed when third-party certification starts. It didn't change NIST 800-171, DFARS 7012, Level 1 and Level 2 self-assessments, or the SPRS score you've already posted. Those obligations, and the legal exposure attached to them, are still live.
Start with November 10, 2025. That's when the DFARS CMMC rule took effect, which started Phase 1 and put self-assessment requirements into new contracts. Phase 2, which would have made a C3PAO certification a condition of award for most Level 2 contracts, was set for November 10, 2026. On July 13, 2026, the Department of War suspended Phase 2 and opened a 60-day review, and a September 3 class deviation made that binding on contracting officers. The reform task force's report went to the DoD CIO on September 11 and, as of late September, hadn't been made public.
The certificate is on hold. The 110 controls never were.
On September 1, 2026, Honeywell Aerospace agreed to pay $2,042,518 to resolve False Claims Act allegations that one of its networks didn't meet NIST 800-171 from April 2020 through December 2023. Nearly four years. No breach. No leaked drawings. The allegation was simply that the controls the contract required weren't in place while the company was being paid. Three months earlier, a smaller Alabama defense contractor settled for $507,144 over the same kind of gap.
So the risk didn't go away when Phase 2 did. It moved. A self-assessed SPRS score is a statement to the government, and an inflated one is now the thing that gets companies sued. If your score was posted in 2023 by an IT manager who's since left, and nobody has re-checked it against the network you actually run today, it's worth an hour this month to find out whether it's still true. The DFARS 7012 vs CMMC breakdown lays out how that score ties 7012 to CMMC.
What Does Each One Cost, and What Does Getting It Wrong Cost?

The DoD published both CMMC figures itself, in the cost analysis attached to the CMMC program rule. They cover the assessment and the yearly sign-off, nothing else. Remediation isn't in there, and for a shop starting from a flat network and shared logins, remediation is the bill.
$1,271,078 is the ceiling in 22 CFR 127.10, and there was no inflation bump for 2026 because OMB skipped the annual adjustment this year. The words per violation do the damage. Ten drawings emailed to the wrong person can be ten violations, which on paper is more than $12M.
How Do You Build One Environment That Meets All Three?
Draw a boundary around the people and systems that touch CUI and ITAR data, apply NIST 800-171 inside it, and restrict every account and admin inside it to U.S. persons. One enclave, built once, answers all three.

The costly mistake is scoping the whole company. Consilien worked with a 70-person aerospace supplier that was being pushed toward moving everyone into GCC High. When we mapped where the controlled data actually went, about 10 people touched it, mostly engineers, program management, and quality inspectors. A full GCC High migration was estimated at 6-12 months. The enclave they chose instead was running in weeks, and the other 60 people kept working in the Microsoft 365 tenant they already had.
That won't fit every shop. If CUI touches the ERP, every CNC programmer, the receiving dock, and the outside processor who anodizes your parts, an enclave gets awkward fast and a wider migration starts to make sense. The point is to find out before someone quotes you the big version. Map it first.
Roughly in order, the work looks like this:
- Trace where drawings actually go. The ERP (Epicor, JobBOSS, whatever you run), the CAM workstations, the shared drive, email, and the CMM software in quality all count.
- Draw the boundary around those systems and the people who need them.
- Inside it, apply the 110 NIST 800-171 requirements and a U.S.-persons-only rule for user accounts, admins, and your IT provider's staff.
- Write the system security plan (SSP), the document an assessor reads first, and a plan of action and milestones (POA&M) for anything still open. The NIST 800-171 to CMMC crosswalk shows how each requirement maps.
- Post an SPRS score you'd be comfortable defending to a Justice Department lawyer.
Consilien is a security-first IT and cybersecurity provider that works with businesses nationwide, with a deep bench in manufacturing. Compliance work, including NIST 800-171 readiness and CMMC compliance services, is its own engagement, separate from managed IT. We scope the boundary, close the gaps, and build the evidence. The certificate itself comes from a C3PAO, not from us. If you're sorting out where CMMC fits alongside your other obligations, the broader manufacturing IT compliance picture and the compliance services overview are good next reads.