CMMC Ready Now
Compliance Guide

Specialized Assets Under CMMC: Why Your CNC Machine Is Not an Exemption

Under CMMC Level 2 scoping, a CNC machine can be categorized as a Specialized Asset, which means it is not assessed against the full set of security requirements. That is not the same thing as being out of scope, and treating it as an exemption is one of the fastest ways to turn a clean assessment into a finding. The machine gets relief from specific controls. You do not get relief from the work.

The distinction matters because Specialized Assets carry their own affirmative obligations: inventory, documentation, network diagram representation, and risk-based management that you have to be able to describe and defend. Below is what the scoping guidance requires, where the assessment is really won or lost, and how to categorize a CNC machine without handing an assessor a finding.

Asset requirements comparison across CUI Assets, Specialized Assets, and Out-of-Scope Assets, showing which require inventory, SSP entry, network diagram representation, and full control assessment.
CUI Assets and Specialized Assets both require inventory, SSP entry, and a network diagram. Only CUI Assets get the full control assessment.

What Actually Counts as a Specialized Asset?

The CMMC Program rule at 32 CFR Part 170, and DoD CIO CMMC Assessment Scope guidance, define Specialized Assets as assets that can process, store, or transmit CUI but cannot be fully secured. The category is broken into subcategories:

  • Government Furnished Equipment (GFE).
  • IoT and IIoT, meaning sensors, gateways, connected metrology, environmental monitors, and badge readers.
  • Operational Technology, meaning CNC controllers, PLCs, robotic cells, SCADA and HMI, and additive manufacturing.
  • Restricted Information Systems.
  • Test Equipment, meaning CMMs, oscilloscopes, and embedded-OS instrumentation.

The category exists because the asset touches CUI. A CNC controller holding G-code derived from a controlled technical data package is handling CUI. That is what puts it in scope in the first place.

One qualifier is easy to abuse. Cannot be fully secured is a technical determination, not a business preference. A Windows 10 CAM workstation is not a Specialized Asset just because patching is inconvenient. It is a normal endpoint, and it is assessed like one.

If Specialized Assets Are Not Assessed, Why Is My CNC Still a Problem?

Because the scoping guidance attaches requirements to the category itself: inventory, SSP documentation of how the asset is managed, network diagram representation, and risk-based management. The SSP is a requirement in its own right under CA.L2-3.12.4.

Here is how that bites. If the SSP says the CNC cell is isolated on a segmented VLAN with no outbound internet, and the assessor finds an always-on vendor support tunnel, the finding is against your SSP, your boundary protection under SC.L2-3.13.1, and your remote access controls under AC.L2-3.1.12 and AC.L2-3.1.14. It is not against the CNC itself. The category shifts the burden from the machine to the documentation and to the assets around it.

What Is Actually in Scope Around the Machine?

Walk a routine job flow. An engineer opens a controlled drawing on a CAM workstation, generates toolpath, writes it to a USB stick, and loads it at the controller. A technician dials in through a vendor portal to troubleshoot. Every asset in that sentence except the controller is fully in scope.

  • The CAM workstation is a CUI Asset, fully in scope, assessed against AC.L2-3.1.1, AC.L2-3.1.2, IA.L2-3.5.1, IA.L2-3.5.2, CM.L2-3.4.1, CM.L2-3.4.6, SI.L2-3.14.1, and AU.L2-3.3.1.
  • The USB stick is removable media. MP.L2-3.8.7 controls its use, and MP.L2-3.8.8 prohibits ownerless portable storage.
  • The vendor remote session is nonlocal maintenance. MA.L2-3.7.5 requires MFA and session termination, and MA.L2-3.7.6 requires supervision of unauthorized personnel.
  • A jump host or file transfer server is a Security Protection Asset.
  • Physical access falls under PE.L2-3.10.1.

None of this goes away because the controller itself is a Specialized Asset. The workstation, the USB drive, the technician laptop, and the firewall rule are where assessments are won or lost.

Does Any of This Apply at CMMC Level 1?

The Specialized Asset category is a Level 2 construct. Level 1 scoping under 32 CFR §170.19 provides no such carve-out. If a machine processes, stores, or transmits FCI, the fifteen Level 1 requirements apply, including:

  • AC.L1-3.1.1 and AC.L1-3.1.2, limit access to authorized users and to authorized transactions.
  • IA.L1-3.5.1 and IA.L1-3.5.2, identification and authentication, which is a real problem where an entire shift shares one login taped to the enclosure.
  • AC.L1-3.1.20, external system connections, where vendor telemetry lives.
  • SC.L1-3.13.1, boundary protection.

A Level 1 shop reading Level 2 guidance and concluding that machines are exempt is reading the wrong document.

Where Does This Fit Against What Is Circulating About CMMC Right Now?

General CMMC explainers covering level structure, self-assessment versus C3PAO, SPRS scoring, and SSP and POA&M are accurate at the overview level, but they share a common gap. They skip the scoping decision that determines what the assessment covers. Scope is settled before an assessor arrives, and wrong asset categorization means everything downstream is wrong, including your SPRS score.

Be careful of confident certification-start-date claims. The phase-in schedule is not settled. Plan on the technical work, which is stable, rather than a date, which is not.

And not every requirement is POA&M eligible. Eligibility rules are in the program rule, not in the assessor discretion, so check before assuming you can defer a shop floor control.

How Do You Scope a CNC Machine Correctly?

Work the problem in order. Each step produces an artifact an assessor can read.

  1. Inventory the equipment honestly. Every controller, embedded OS, and network interface. CM.L2-3.4.1 requires baseline configurations and inventories.
  2. Determine what data actually lands on it. Toolpath from a controlled technical data package is generally CUI, and export-controlled technical data is CUI. Write down the reasoning per asset.
  3. Categorize each asset against the definitions. Specialized Asset, CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, or out of scope. Categorize by function, not by department or building.
  4. Document Specialized Assets in the SSP with actual mitigations. Segmentation, data flow restrictions, physical controls, monitored egress, and media handling. NIST SP 800-82 is a reasonable reference for risk-based OT mitigations.
  5. Draw the network diagram to match reality. If the diagram and the firewall disagree, fix the firewall first.
  6. Harden the surrounding assets to full requirements. The CUI assets and Security Protection Assets around the machine are where the assessment actually happens.

If you have not settled the base categories yet, start with our guide to scoping CUI assets versus Security Protection Assets, then come back to the shop floor.

Not Sure Your Shop Floor Equipment Is Scoped Correctly?

Book a free 30-minute call with Rick and walk your asset inventory against the Level 2 scoping definitions before you commit to an assessment date, with no sales pitch. We never touch your CUI.

Book a Free Call with Rick

Frequently Asked Questions

Is a CNC machine in scope for CMMC?

Yes, if it processes, stores, or transmits CUI or FCI. At Level 2 it is typically categorized as a Specialized Asset in the Operational Technology subcategory, which means it must appear in your asset inventory, in your System Security Plan, and on your network diagram. Specialized Assets are not assessed against the full set of CMMC security requirements, but the documentation and risk-based management obligations are real and are reviewed.

What is the difference between a Specialized Asset and an out of scope asset?

An out of scope asset does not process, store, or transmit CUI or FCI and is not a security protection asset. A Specialized Asset can handle CUI but is unable to be fully secured, which is why it receives different treatment rather than exclusion. Out of scope assets require no documentation in the assessment scope, while Specialized Assets must be inventoried, documented in the SSP, and shown on the network diagram.

Does the Specialized Asset category exist at CMMC Level 1?

No. The Specialized Asset category is defined for Level 2 scoping. At Level 1, any asset that processes, stores, or transmits Federal Contract Information is in scope for the Level 1 requirements, including AC.L1-3.1.1, AC.L1-3.1.2, IA.L1-3.5.1, IA.L1-3.5.2, and SC.L1-3.13.1.

Do vendor remote support connections to shop floor equipment need to be controlled?

Yes. Remote vendor sessions into equipment inside your assessment scope are nonlocal maintenance. MA.L2-3.7.5 requires multifactor authentication to establish those sessions and termination of the connection when the work is finished, and MA.L2-3.7.6 requires supervision of maintenance personnel who lack required access authorization. An always-on vendor tunnel is one of the more common findings in manufacturing environments.

Can I put shop floor gaps on a POA&M and deal with them later?

Sometimes, but not automatically. POA&M eligibility is defined in the CMMC Program rule rather than negotiated with an assessor, and not every requirement can be deferred. Check the eligibility of the specific requirement before you build a remediation plan that assumes it.

Sources

  • CMMC Program final rule, 32 CFR Part 170, including the Level 2 scoping provisions and the Specialized Asset definitions (ecfr.gov)
  • DoD CIO CMMC documentation library, including CMMC Assessment Scope guidance for Level 1 and Level 2 (dodcio.defense.gov)
  • NIST SP 800-171 Revision 2, the security requirement set CMMC Level 2 is built on (csrc.nist.gov)
  • NIST SP 800-82 Revision 3, Guide to Operational Technology Security, for risk-based OT mitigations (csrc.nist.gov)