The technical work of defense manufacturing is often the familiar part. Machining is machining. Controls are controls. What disqualifies more commercially excellent suppliers than any technical gap is everything that has to be true about the building, the network, and the people before the first controlled drawing arrives.
This is a plain-language explainer of what a secure integration floor actually means for a manufacturer, written from the perspective of a company that is building one and documenting the journey publicly. SMT Automation is building this floor now, so this is not theory. It is access rosters, network diagrams, and training records. This article describes both the general requirements and, honestly, exactly where SMT stands on each one, including what we have not yet earned.
Start with the data, not the parts
The first conceptual shift for a commercial shop is that defense security obligations attach primarily to information, not hardware. The governing concept is Controlled Unclassified Information (CUI): information that is not classified, but that law, regulation, or government-wide policy requires be safeguarded. For a manufacturer, CUI usually shows up as controlled technical information: drawings, models, specifications, process documents, test data.
The practical consequences are immediate and physical. If a drawing is controlled, then the workstation that opens it, the server that stores it, and the programming laptop that imports the model are all systems that handle controlled data. The supplier question is never "do we have a firewall." It is: where does controlled data flow in our shop, and can we draw that boundary on a diagram? Everything else follows from that boundary.
The cybersecurity spine: NIST 800-171, stated precisely
The contractual hook arrives through the DFARS safeguarding clause, which requires contractors handling covered defense information to implement NIST Special Publication 800-171, maintain a System Security Plan, and report cyber incidents within 72 hours. It flows down to subcontractors whose work involves that information. Sub-tier suppliers are not exempt; the requirement follows the data down the chain.
Translated out of policy language, 800-171 groups into questions any plant manager already understands. Who can touch what? Do you know what happened, and can the logs reconstruct it? Are the machines kept in a known state? Are the network walls real, with the controlled enclave segmented from the office and guest networks? Are the people trained before they encounter controlled data? What happens when something goes wrong, and can you hit a 72-hour reporting clock?
Here is where SMT stands, stated exactly, because in this domain precision is the difference between credibility and a compliance problem:
- Our NIST 800-171 self-assessment is complete, our score is posted in SPRS, and we maintain a System Security Plan with plans of action and milestones for the gaps. We are actively closing POA&M items.
- Our CMMC readiness work is underway. We are not CMMC certified, we do not claim to be, and anyone who hears otherwise from a supplier should ask to see the certificate. CMMC does not add a new security model; it adds verification. A supplier who builds the 800-171 environment honestly is building toward the assessment. A supplier who paper-complies is building toward a failed one.
- Controlled data moves through Kiteworks, a FedRAMP Authorized private data network, with least-privilege access limited to trained personnel. Email attachments and consumer file-sharing links are not a controlled-data architecture.
Two pieces of practical guidance for peers walking this path. First, scope ruthlessly: the cost of 800-171 is proportional to the size of the boundary, so a small, segmented enclave is achievable for a mid-size shop where "bring the whole plant into scope" is not. Second, the SSP is the deliverable: an honest System Security Plan with a real plan of action is the artifact primes and program offices actually evaluate.
A supplier who builds the environment honestly is building toward the assessment. A supplier who paper-complies is building toward a failed one.
The people layer: U.S. Persons, screened
Export control is the second pillar, and it is widely misunderstood in one specific way. Under ITAR, releasing controlled technical data to a foreign person inside the United States, on the shop floor, in a design review, over a shared server, is treated as an export to that person's country. That is why ITAR-scoped programs impose U.S.-persons requirements on everyone with access to controlled data.
For a manufacturer this is an HR fact and an access-architecture fact at the same time: you must know which employees are U.S. persons, and you must architect data and floor access so controlled programs touch only that population. At SMT, all personnel assigned to government-related work are U.S. Persons and background screened, and access to controlled information runs on a least-privilege roster, not an open file share. SMT is ITAR Registered, which is the registration obligation that attaches to manufacturing defense articles, not just exporting them. Registration is not a certification and we do not present it as one; it is a legal obligation met and a signal that we take the regime seriously.
The physical layer
Now translate the above into a building. A credible secure-integration posture for unclassified defense manufacturing looks like this, and none of it requires a classified facility:
- A bounded, access-controlled work area for controlled programs, with access limited to assigned, screened U.S.-persons staff rather than general shop traffic.
- Controlled work in process: drawings and travelers locked when unattended, camera and phone discipline, marking per the CUI conventions.
- Visitor control as a process, not a clipboard: identity verification, escorts, and a pre-visit screening habit, because a walk-through of a controlled work area is a release of technical data if the wrong things are visible.
- Layered security systems. At SMT this means firewall-segmented networks, electronic access control, 24/7 monitored intrusion alarms, cameras, and sensors, layered so no single failure opens the floor.
- Disciplined machine connectivity: controllers and metrology equipment inventoried and patched like IT assets, with vendor remote access disabled or brokered through a controlled gateway.
The pleasant surprise for operations people: the security architecture and the quality architecture reinforce each other. The same habits that make traceability work, controlled documents, named accountability, disciplined change, are the habits that make an information boundary hold.
The honest sequence
For a supplier starting from commercial excellence, the readiness sequence that holds up is: map the data flow first and define the smallest defensible enclave; write the SSP honestly, gaps and all; put an export-control screening step and a U.S.-persons access roster in place; build the physical boundary once and reuse it across programs; then pursue verification when the pipeline justifies it.
None of this is exotic, and none of it is fast. It is quarters of unglamorous work, done before the purchase order, with the same process discipline you would apply to a product launch. That is exactly why we publish where we are on each step: the suppliers who will populate the defense supply chain in three years are the ones doing this work now, and saying honestly what they have and have not yet earned.
- 32 CFR Part 2002 (Controlled Unclassified Information); National Archives CUI Registry. https://www.archives.gov/cui
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting
- NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. https://csrc.nist.gov/pubs/sp/800/171/r3/final
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program. https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
- 22 CFR Parts 120 and 122 (ITAR definitions; registration of manufacturers). https://www.ecfr.gov/current/title-22/chapter-I/subchapter-M
Talk to the SMT team.
Program offices, Tier 1 procurement and small-business liaisons: 20 minutes with our team, or walk the floor in Bruce Township.

