Current status — last verified August 17, 2026. The Department suspended the CMMC Phase II transition on July 13, 2026, including the originally scheduled November 10, 2026 start of Phase II. During the suspension, new procurement requirements may designate CMMC Level 1 (Self) or CMMC Level 2 (Self) only — not Level 2 (C3PAO) or Level 3 (DIBCAC). Phase I self-assessment requirements and DFARS 252.204-7012 remain in force. If an active solicitation, contract, or subcontract still names a third-party assessment, treat that written language as operative until it is formally amended or modified.
By The Defense Compliance Report Editorial Team · Last verified: August 17, 2026 · Editorial research — not formally reviewed by a CMMC Subject Matter Advisor.
The short answer
CMMC for MRO and aircraft maintenance is decided by the written procurement requirement and by each contractor information system that will process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) — not by the word “MRO.” It does not attach because you repair aircraft or hold an FAA repair-station certificate. If the procurement requires Level 2 for systems handling CUI, those systems enter the Level 2 path. If it requires Level 1 for FCI-only systems, those systems follow Level 1. A mixed maintenance business can have different boundaries across contracts and workflows, but “line of business” is not the legal unit the rule assesses.
Now the part that surprises people, and the reason this page exists: there is a second obligation that can land on a maintenance shop with no CUI at all. DFARS 252.204-7012 has a trigger most MROs have never read — one that expressly covers Government-designated logistical support essential to mobilization, deployment, or sustainment in a contingency operation. We'll get to it. First, four conditions decide your answer:
- Which platform you're working on. A pure military platform and a commercial-derivative airframe are not the same data problem.
- Where the task data came from. A government technical order and a commercial OEM manual are not the same document, legally.
- Whether a government-furnished article, test set, or maintenance aid can store or transmit information. The FAR definition of government-furnished property expressly covers items furnished for repair, maintenance, and overhaul, but government ownership alone does not decide CMMC scope.
- What your contract says about operationally critical support. This is the one nobody checks.
The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance. We work from primary sources, separate regulatory text from editorial analysis, and map a contractor's level, CUI scope, assessment type, and timeline to the provider category that fits before the contractor spends six figures.
One quick disambiguation, because the acronyms collide in this industry: CMMC is the Cybersecurity Maturity Model Certification, a Department of Defense cybersecurity program. It is not CMMS (maintenance management software) and not a CMM (Component Maintenance Manual). If you landed here looking for either of those, this isn't your page.
Who this is for — and who should stop reading
| Question | Direct answer |
|---|---|
| Who this is for | Defense-facing MROs, FAA Part 145 repair stations, component overhaul shops, depot and sustainment contractors, contractor logistics support providers, and lower-tier repair vendors trying to determine which maintenance workflows enter a CMMC boundary. |
| Who this is not for | Civil-only maintenance organizations with no defense contract, no flow-down, and no FCI or CUI. Nothing on this page applies to you. Close the tab and go turn wrenches. |
| What actually decides the answer | The written procurement requirement, the real control status of the information, where that information physically and digitally travels, and what each system or device does. Not the letters “MRO.” |
| What changed in July 2026 | The Phase II transition and later milestones were suspended. Phase I self-assessment requirements and DFARS 252.204-7012 were not. |
| Your first move | Assemble the clause pack and walk one complete maintenance job end to end — before you price a platform, an enclave, or an assessment. |
Jump to: Does it apply? · What the suspension changed · Which maintenance data is CUI · The zero-CUI clause · Is my shop floor in scope? · Why platform matters · Hangars, AOG, and vendors · Does AS9110 or Part 145 count? · Which level to plan for · Your first 30 days · Who to hire first · What goes wrong · FAQ
Who does CMMC for MRO and aircraft maintenance apply to?
CMMC applies to a maintenance organization when a DoD solicitation, contract, subcontract, or written flow-down requires a CMMC status for contractor information systems that will process, store, or transmit FCI or CUI in performance of that contract. 32 CFR § 170.3 reaches applicable DoD solicitations and contracts valued above the micro-purchase threshold, including commercial-item acquisitions, but excludes acquisitions solely for commercially available off-the-shelf (COTS) items. Holding an FAA repair-station certificate, an AS9110 certification, or an aerospace prime's approval does not by itself create a CMMC obligation.
We want to be blunt about this, because the sector gets sold on its own label. Vendor pages often argue that an MRO needs Level 2 because MROs handle sensitive technical data. That is a marketing syllogism, not the rule. The rule is contract-driven. Under § 170.3(d), the DoD program manager or requiring activity selects the CMMC status for a given procurement based on the type of information involved — FCI or CUI. It shows up in your solicitation. You don't infer it from your NAICS code.
The three questions that settle applicability
1. What does the written procurement document actually require?
Look for two things. DFARS 252.204-7025 is the solicitation provision that tells offerors which CMMC level applies; the contracting officer fills a blank with exactly one of four values — CMMC Level 1 (Self), CMMC Level 2 (Self), CMMC Level 2 (C3PAO), or CMMC Level 3 (DIBCAC). DFARS 252.204-7021 is the contract clause that makes maintaining that status a condition of eligibility for the duration of the contract, requires an annual affirmation, and requires flow-down of the substance of the clause. Record the exact level and assessment type. “CMMC required” is not a requirement you can act on.
One detail worth capturing while you're in there: 252.204-7025 requires the offeror to provide the CMMC unique identifier (UID) in the proposal for each system that will handle FCI or CUI. A CMMC UID is a 10-character alphanumeric identifier assigned to a CMMC assessment and reflected in SPRS — the Supplier Performance Risk System, the DoD database where assessment results and affirmations live. If you can't produce a UID and the solicitation asks for one, you have found your gap before it found you.
2. What information will your systems actually handle in performance?
Four honest answers: FCI only, verified CUI, both, or unresolved. “Unresolved” is a legitimate day-one answer. It is not a reason to guess high.
3. Which of your systems will touch it?
Not just the file server. The technical library, the maintenance management system, the engineering workstation, the hangar tablet, the printer, the field laptop, the backup, the security tooling, and every outside service in the path.
Quick applicability check
| Your situation | Preliminary answer | Proof to obtain |
|---|---|---|
| Civil-only maintenance; no defense contract or flow-down; no FCI or CUI | CMMC is not triggered by being an MRO | Confirm the customer and data path; keep defense information out of the shop |
| Defense work, FCI only, written requirement states Level 1 (Self) | Level 1 path with 15 basic safeguards | The provision or clause, in-scope system list, annual self-assessment, current SPRS status, and affirmation |
| Defense work involving verified CUI, written requirement states Level 2 (Self) | Level 2 self-assessment against all 110 NIST SP 800-171 Rev. 2 requirements | The written requirement, CUI map, defined assessment scope, score, CMMC UID, and affirmation in SPRS |
| Active document still states Level 2 (C3PAO) after July 13, 2026 | Do not delete it yourself | A formal solicitation amendment, contract modification, or mutually executed subcontract change |
| Work occurs inside a Government system or service operated on the Government’s behalf | That federal system may fall outside Part 170 | Contract language, system ownership, authorization boundary, connection instructions, and control-responsibility documentation |
| You cannot determine whether records are controlled | Do not declare all or declare none | Markings, source, CUI authority, contract language, content review, and written guidance from the authorized customer authority |
| Procurement is solely for COTS items or valued at or below the micro-purchase threshold | Part 170 does not apply to that procurement | The solicitation, value, item classification, and a documented rationale |
The carve-out almost nobody applies to sustainment work
Here is a provision we rarely see quoted on aerospace pages, and it matters more in maintenance than in manufacturing. 32 CFR § 170.3(b) says Part 170 does not apply to federal information systems operated by contractors or subcontractors on behalf of the Government. DFARS 252.204-7012 draws a parallel line at paragraph (b)(1): for covered contractor information systems that are part of an IT service or system operated on behalf of the Government, cloud services fall under DFARS 252.239-7010 and other services fall under requirements specified elsewhere in the contract.
Translate that into a hangar. A .mil login, a government laptop, or a GFE label does not prove the carve-out by itself. The question is whether the system is actually a federal information system operated by the contractor on behalf of the Government. If the contract and responsibility documentation establish that fact, that piece of the environment is governed differently from your corporate network. Contractor logistics support and depot-augmentation crews can encounter this split.
Two mistakes come out of it. The first is assuming that because the work happens in a .mil system, the company is out of CMMC entirely. It isn't — your own contractor information systems still enter scope when the written requirement applies and they process, store, or transmit FCI or CUI. The second is the reverse: dragging the whole corporate network into scope because technicians use a government portal. The correct move is to get the boundary in writing. Ask for the responsibility documentation, the connection instructions, and a plain statement of which side owns which controls.
Do not spend a dollar until this section is settled. Every cost decision downstream is built on it.
What the July 2026 CMMC Phase II suspension changed for maintenance contractors
On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II and the later implementation milestones, including the November 10, 2026 date on which Phase II was scheduled to begin. Phase I began November 10, 2025 and, under the original one-year schedule, was scheduled to run through November 9, 2026; the planned transition on November 10, 2026 is the milestone now suspended. The official CMMC status page says all Phase I self-assessment requirements remain in place. The implementing memorandum preserves Level 1 and Level 2 self-assessment designations, NIST SP 800-171 Revision 2 as the Level 2 baseline, SPRS posting, and annual affirmations where the applicable procurement or contract requires them. DFARS 252.204-7012 is untouched. A CMMC Reform Task Force was directed to report to the Department CIO within 60 days; that deadline falls on September 11, 2026.
We read the implementing memorandum ourselves rather than working from the press coverage, and three details in it change what you should do this month.
First, the designation limits are hard. During the suspension, program managers and requiring activities must only include CMMC Level 1 (Self) or CMMC Level 2 (Self), and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). The codified phase schedule still contains the original Phase I discretion language, but the later implementing memorandum controls Department designation practice during this suspension and says “may not.” Read the current memorandum, not the old rollout paragraph by itself.
Second, no waivers during the review. The memorandum states that no waivers shall be granted while the program is under review.
Third — and this is the one that costs money — existing requirements come out by paperwork, not by announcement. Active solicitations are to be amended. Requirements in awarded contracts are removed by modification prior to the exercise of the next option period or during the next scheduled administrative modification. Until your document is actually modified, the clause on your contract is still the clause on your contract. A news release is not a contract change. Ask your contracting officer in writing and keep the answer.
Planned rollout versus where things actually stand
| Issue | Before July 13, 2026 | Verified status as of August 17, 2026 |
|---|---|---|
| Phase I window | Began November 10, 2025; original one-year window was scheduled to end November 9, 2026 | Still in effect for applicable Level 1 (Self) and Level 2 (Self) requirements |
| November 10, 2026 Phase II transition | Scheduled | Suspended |
| New Level 1 (Self) designations | Available | Allowed |
| New Level 2 (Self) designations | Available during Phase I | Allowed |
| New Level 2 (C3PAO) designations | Permitted under the codified phase schedule and planned to expand in Phase II | Program managers and requiring activities may not designate them during the suspension |
| New Level 3 (DIBCAC) designations | Planned for a later phase | Program managers and requiring activities may not designate them during the suspension |
| DFARS 252.204-7012 safeguarding and reporting | In force | Still in force |
| Voluntary Level 2 certification assessment | Available | Still available; it is not a new Department designation |
| Level 2 (C3PAO) or Level 3 language already in a solicitation, contract, or subcontract | Controlled by the written document | Treat it as operative until formally amended, modified, or changed by the parties |
While you were watching that, your clause numbers changed
This is separate from the suspension and it trips people up badly, because two subtractions landed within six months of each other and the combined effect reads like the whole program evaporated.
On February 1, 2026, a Department class deviation issued under the Revolutionary FAR Overhaul changed which cybersecurity clauses contracting officers are directed to use in covered actions. Under that deviation, DFARS 252.204-7019 is omitted, and DFARS 252.204-7020 is replaced by DFARS 252.240-7997 under Part 240. The deviation clause defines Medium and High assessments performed by the Government and removes the former Basic-assessment submission machinery. The FAR deviation model uses FAR 52.240-93 in place of FAR 52.204-21 with the same 15 basic safeguards. DFARS 252.204-7012, 252.204-7021, and 252.204-7025 are unchanged.
The governing instrument is Class Deviation 2026-O0025, now at Revision 2 dated July 16, 2026. Because this is deviation text ahead of formal rulemaking, the codified FAR and DFARS still display the legacy clause numbers, and older or unmodified instruments may still contain them. You may see either set. Read the clause actually incorporated into the document in front of you.
| Codified or legacy citation | Treatment in covered deviation actions | What it means for a maintenance contractor |
|---|---|---|
| DFARS 252.204-7019 | Omitted from the deviation’s covered solicitation and contract actions | This is not a universal repeal of the codified provision. Older or unmodified documents may still contain it; read the provision actually incorporated. |
| DFARS 252.204-7020 | Replaced by DFARS 252.240-7997 in covered deviation actions | The replacement defines Government-performed Medium and High assessments and does not carry forward the former Basic-assessment mechanism. |
| FAR 52.204-21 | FAR-deviation counterpart is FAR 52.240-93 | The same 15 basic safeguards are carried forward in the deviation model; 32 CFR Part 170 still cites the codified FAR 52.204-21 requirements. |
| DFARS 252.204-7012 | Unchanged | NIST SP 800-171 safeguarding, 72-hour reporting, media preservation, malware handling, and flow-down remain. |
| DFARS 252.204-7021 and 252.204-7025 | Unchanged | The CMMC contract clause and solicitation provision still govern status, affirmation, UIDs, eligibility, and CMMC flow-down where included. |
Two events in six months, both of them subtractions. Understandable that people concluded the program was dead. It isn't. The Phase II contract gate paused. Government assessment authority and the underlying security obligations did not.
Map your current requirement before you price anything
The fastest way to waste money right now is to buy against a milestone that no longer exists. Tell The Defense Compliance Report's Find My CMMC Path tool the level your document actually states, whether you handle FCI or CUI, your general environment, and your next contract or option date. It maps your situation to the provider category that fits the current requirement — no sales call, no obligation.
Do not submit CUI, drawings, technical orders, aircraft or tail data, program names, or contract attachments. Category-level answers only.
Which aircraft maintenance data is actually CUI?
Maintenance information is not CUI because it is technical, nonpublic, tied to a military aircraft, or important to flight safety. For the most common category here — Controlled Technical Information — DFARS 252.204-7012 requires military or space application, dissemination controls, and information that would meet the criteria for Distribution Statements B through F under DoD Instruction 5230.24. To be covered defense information, it must also be controlled technical information or another CUI Registry category that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy and must fit one of the clause's two contract-performance prongs. The National Archives CUI Registry lists Controlled Technical Information as CUI Specified, banner marking CUI//SP-CTI, with 48 CFR 252.204-7012 as the authority. Verify each artifact against the full test before designing a boundary around it.
We spent real time in the clause text for this section, and three findings came out of it that change how a maintenance shop should think about its own paperwork.
Finding one: the clause names your document set out loud
The definition of "technical information" in DFARS 252.204-7012 comes with examples. Here they are, in the clause's own order: research and engineering data, engineering drawings and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses, and computer software executable and source code.
Process sheets. Manuals. Technical orders. That is not a manufacturing list. That is the contents of a technical library and a workbench. The CUI Registry's Controlled Technical Information entry repeats the same examples. And DoD Instruction 5230.24 — the instruction that supplies the distribution-statement criteria — states its own purpose as covering technical documents including research, development, engineering, test, sustainment, and logistics information. Sustainment is named in the source instruction. Maintenance was never an afterthought in this framework; the industry just read it that way.
Finding two: the marking is a signal, not the test
Read the definition again. Controlled Technical Information is information that would meet the criteria for Distribution Statements B through F. That is a characteristic of the information and its authorized dissemination controls, not merely a property of whether somebody remembered to stamp the cover page. A B-through-F statement is powerful evidence; it is not a substitute for checking the complete CUI authority, contract context, and content.
For quick orientation, the statements run: A — approved for public release, unlimited. B — U.S. Government agencies only. C — U.S. Government agencies and their contractors. D — DoD and U.S. DoD contractors only. E — DoD Components only. F — further dissemination only as directed by the controlling DoD office.
Practical consequence: an unmarked drawing can still be controlled when the contract or authorized Government source otherwise identifies it and the content meets the applicable category, and a marked document tells you a great deal. Neither fact licenses you to classify by vibe. When the status is unclear, the correct output is a written question to the customer's authorized data owner, program office, or contracting officer — not a homemade determination.
Finding three — the one that separates maintenance from manufacturing: you create it
Covered defense information under DFARS 252.204-7012 has two prongs. The first covers otherwise-qualifying controlled technical information or other CUI that is marked or otherwise identified in the contract and provided to you by or on behalf of DoD. Everybody knows that one. The second prong covers otherwise-qualifying information “collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.” The verb list expands how qualifying information can enter the clause; it does not turn every record created during performance into CUI.
Sit with that for a second, because it lands differently in an overhaul shop than in a machine shop.
A manufacturer receives a technical data package and makes a part. An overhaul shop receives a technical order — and then generates a body of technical information that did not previously exist. As-found condition reports. Teardown findings. Dimensional inspection results against military wear limits. Eddy current and ultrasonic results on a military component. Photographs of a crack in a specific structure. Repair dispositions and deviation requests routed to a government engineering authority.
Nobody handed you those. You made them. And under prong two they can be covered defense information when their content meets the Controlled Technical Information test or another applicable CUI category and they were developed in support of contract performance. This is, in our editorial judgment, one of the most consistently missed exposures in aviation sustainment. The data you're most careless with is often the data you produced yourself, because it doesn't arrive with a banner on it.
The five-part evidence test
Before you conclude anything about an artifact, capture five things. Every row in the table below assumes you've done this.
- Source. Government, prime, OEM, customer, your own derivative, or genuinely public and commercial.
- Authority or marking. CUI banner and category, distribution statement, export-control marking, contract instruction, or agency guidance.
- Purpose. Created, received, or used in performance of which contract or program.
- Content. Does it actually contain controlled technical detail — or only transactional, scheduling, and quality data?
- Written clarification. What did the customer or program office say when the answer wasn't obvious? Get it in writing and keep it with the record.
The MRO Data-Provenance Map
This is our editorial synthesis. No primary source supplies an artifact-by-artifact MRO map, so we applied the governing definitions to the records and devices that actually move through a repair station. Read the caveat that follows it before you use it.
| Artifact or record | Evidence that could make it controlled — verify, do not assume | Where it travels | Scope treatment to test | Failure mode to test |
|---|---|---|---|---|
| Military technical order or interactive electronic technical manual | Qualifying military or space technical content, a Distribution Statement B through F or other CUI authority, and one of the DFARS 252.204-7012 contract-performance prongs | Technical library, tablets, browser cache, printers, paper binders, backups | Systems handling verified CUI are CUI Asset candidates; paper needs a physical handling process | Local downloads, emailed copies, uncontrolled printing, or obsolete sections retained after supersession |
| Commercial OEM aircraft or component manual under a Type Certificate | Ordinary commercial licensing or OEM proprietary status alone does not make it CUI; a controlled Government supplement, variant, or qualifying derivative can change the answer | OEM portal, technical library, local PDF store | Out of scope only where the system cannot handle CUI; Contractor Risk Managed where capability exists but policy, procedures, and practice keep CUI out | Declaring every OEM manual controlled and pulling the civil business into scope |
| Technical data package or engineering drawing for a repair | CUI marking or authority, restrictive distribution criteria, qualifying technical content, and contract context | CAD viewer, PLM, engineering workstation, email, display, printer | CUI Asset candidates where verified CUI is present | Unsecured PDF export, local CAD cache, screen photo, uncontrolled redline |
| Process specification for plating, NDT, heat treat, bonding, or paint | The document name appears in the clause’s technical-information examples, but control still requires qualifying content, authority, and contract context | Quality system, binders, vendor packages, laminated station copies | CUI Asset candidates for systems with verified CUI; physical controls for paper | Sending a complete controlled specification to a special-process vendor that needed only a narrow requirement |
| Government-furnished aircraft, engine, component, test set, or maintenance aid | Government-property status alone does not make information controlled; onboard memory or an embedded system may process, store, or transmit CUI | Dock, hangar, bench, field kit | GFE Specialized Asset candidate only when it can handle CUI and cannot be fully secured; otherwise classify from actual function | Treating every Government-owned article as automatically in scope or automatically outside scope |
| As-found or teardown condition report created by the shop | The content independently meets a CUI category and the contractor-development prong of DFARS 252.204-7012 applies | Maintenance system, engineering, email, portal, attachments | CUI Asset candidates where controlled technical detail is created or stored | Treating self-generated findings as ordinary business records because nothing arrived stamped |
| NDT or NDI results, radiographs, eddy-current data, or ultrasonic data | Qualifying military technical detail, controlled limits, platform condition, and applicable authority or contract context | Instrument memory, acquisition workstation, image server, USB, portal | CUI Asset if normally securable; Specialized Asset candidate if it can handle CUI and cannot be fully secured | Instrument retention, USB export, consumer file transfer, or vendor copies kept indefinitely |
| Repair disposition, engineering order, or deviation request | Reproduction or derivation of qualifying controlled drawings, limits, platform condition, or other authorized CUI | Engineering, email, maintenance system, printed packet | CUI Asset candidates where verified CUI is present | A “summary” that copies controlled dimensions and defect detail into a broadly accessible system |
| Depot work requirement, statement of work, or contract attachment | Nonpublic information provided by or generated for the Government may be FCI; CUI requires an authorized category and applicable control basis | Contract repository, proposal drive, email, e-signature service | Level 1 systems for FCI only; CUI Assets when controlled content is present and Level 2 is required | Missing a cyber clause or data-handling instruction buried in an attachment |
| Configuration, modification, readiness, or tail-status data | An identifier alone does not decide CUI; content, aggregation, authority, and contract context can | Configuration system, maintenance system, portal, analytics | CUI Asset candidates only where the dataset is verified CUI | Treating one tail number as automatically controlled or ignoring a controlled aggregated dataset |
| Work cards, travelers, route sheets, or job packets | Controlled fields, copied limits, drawings, technical-order pages, photographs, or other attachments | Maintenance system, kiosks, scanners, printers, packet racks | Anywhere from CUI Asset to defensibly out of scope depending on what the workflow permits | Printing a whole controlled technical package into the traveler or leaving packets unsecured |
| Illustrated parts breakdown with military part numbers | The document type can be technical information, but the source, authority, content, and distribution restrictions decide whether it is controlled | Technical library, planning, purchasing, print | Classify from the source document and actual fields copied downstream | Pasting controlled breakdowns into purchase orders and supplier emails |
| Photographs or video of damage, components, screens, or completed work | The image captures or creates qualifying controlled technical detail; not every aircraft image is CUI | Company or personal phone, tablet, photo sync, chat, quality system | Devices used for verified controlled imagery are CUI Asset candidates | Automatic consumer-cloud backup, text messaging, or uncontrolled metadata and retention |
| Calibration and metrology records | Calibration status alone is ordinarily business or quality data; controlled procedures, program limits, or technical attachments can change it | Calibration system, lab instruments, certificates, vendor portal | Usually business or FCI systems; CUI path only where controlled content enters | Overscoping every certificate or forwarding a controlled test procedure to a commercial lab |
| Shipping, receiving, traceability, and material-certification records | Usually transactional or quality information; controlled fields or attachments can change the answer | ERP, scanners, supplier portal, labels, paper packets | Level 1 or business systems unless verified CUI enters | Attaching a full technical package to a purchase order for convenience |
| Avionics mission data, software load, or portable data-loader package | The load’s content, platform, markings, dissemination authority, and contract decide; many are controlled, but not all | Data loader, diagnostic laptop, removable media, GFE | CUI Asset or Specialized Asset candidate depending on device function and securability | Treating a loader as a hand tool while it retains a controlled software load |
What this page will not do
We will not tell you that every military-aircraft maintenance record, tail number, part number, NDT image, technical manual, or work card is CUI. Nothing in the primary sources supports a blanket rule like that, and pages that assert one are selling you scope you may not owe. Where the status of a document is unresolved, the correct output is an evidence request — not a confident guess. Overscoping is not the safe choice. It is a different expensive mistake, and it is the one that makes technicians route around your controls.
Small next step, no email required: build your own version of the table above for one program. Source, marking, purpose, content, systems touched, unresolved question, owner, date. One page per program. That single artifact will do more for your budget conversation than any tool you buy this quarter.
The DFARS clause that can hit your shop with zero CUI
DFARS 252.204-7012 has a second trigger that has nothing to do with CUI. The clause defines “operationally critical support” as supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation. Where a contract designates and identifies performance as operationally critical support, the clause's cyber incident reporting duties attach to incidents that affect the contractor's ability to perform that work — whether or not covered defense information is involved.
Aircraft sustainment can fall squarely within that definition, but only when the Government makes the designation and the contract identifies the work. And this is where a maintenance organization can end up in a position no generic CMMC guide describes: carrying the incident-reporting machinery of DFARS 252.204-7012 while its CMMC path is only Level 1, or while Part 170 does not apply to the procurement at all.
Read paragraph (c)(1). The reporting duty attaches when the contractor discovers a cyber incident that affects a covered contractor information system, or the covered defense information in it, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract. Three separate triggers, joined by "or."
Then read paragraph (m)(1). The prime must include the clause in subcontracts "for operationally critical support, or for which subcontract performance will involve covered defense information." Operationally critical support is listed as its own category of subcontract, separate from covered defense information. A maintenance sub can receive this clause on logistics grounds alone.
The guardrail, stated plainly: it must be designated by the Government and identified in the contract. You cannot self-declare it. Neither can we, and neither can a vendor. It is a contract-reading question, which is exactly why the action item at the end of this section is a written question rather than a purchase order.
What attaches when it applies
If your contract designates operationally critical support — or if you hold covered defense information — DFARS 252.204-7012 paragraphs (c) through (g) put five operational duties on you. Not one of them is a control from the 110. All five are things you either set up in advance or fail in real time.
| Duty | Clause paragraph | What it means on a Friday night |
|---|---|---|
| Rapidly report | (c)(1)(ii), with “rapidly report” defined in paragraph (a) | Report through the DoD incident path within 72 hours of discovery. The clock runs on discovery, not final confirmation, and weekends do not stop it. |
| Review for compromise and operational impact | (c)(1)(i) | Identify affected computers, servers, data, and user accounts; examine other reachable systems; determine whether operationally critical support was affected. |
| Submit isolated malicious software | (d) | Follow DC3 instructions. Do not send malicious software to the contracting officer or by ordinary email. |
| Preserve media and monitoring data | (e) | Preserve and protect images of known affected systems plus relevant monitoring and packet-capture data for at least 90 days from report submission. |
| Support forensics and damage assessment | (f) and (g) | On request, provide access to additional information or equipment for forensic analysis and supply damage-assessment information. |
The reporting-access problem you do not want to discover inside 72 hours
Paragraph (c)(3) of the clause states that in order to report cyber incidents, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate. The current DC3/DCISE reporting page says the certificate is required for the secure portal.
If the first time your team tests the reporting path is during an incident, the 72-hour clock is already running. Confirm the current portal path now, provision the required certificate for at least two named people, and write their names into your incident response plan. Then document the current emergency fallback: DC3 says a contractor that does not yet have the certificate and needs to report should email DC3.DCISE@us.af.mil or call 410-981-0104 for reporting assistance, and must not email malicious files. Provision normal access anyway. The fallback is not a substitute for readiness.
The scenario that makes this concrete
A component overhaul shop supports engine accessories under a sustainment contract. No engineering drawings on the network — the customer keeps those in a portal. The shop is confident it holds no CUI, and it may well be right.
On a Friday afternoon, a technician's workstation starts encrypting files. The maintenance management system goes down. Turnaround commitments on a fleet sustainment line slip. Nobody has exfiltrated a drawing, because there were no drawings to take.
Under the CUI analysis, this shop is at Level 1 or outside CMMC. Under paragraph (c)(1), if the contract designates and identifies its performance as operationally critical support, the incident affected its ability to perform that work — and the 72-hour clock started at discovery on Friday. Nobody is going to call and remind them.
That mismatch — safeguarding and reporting duties running ahead of the CMMC level — is the single most useful thing an MRO can learn from this page. It is also largely absent from generic MRO CMMC guidance.
Check your reporting readiness before you check anything else
The controls are what vendors sell; the incident duties are what can fail at 11:00 p.m. on a Friday. Our CMMC Readiness Checklist is a 32-point review mapped to the NIST SP 800-171 Revision 2 control families plus separate contract duties for reporting, evidence, malware handling, and media preservation. Those reporting duties are not part of the 110, which is exactly why they are easy to miss.
Download the CMMC Readiness Checklist →
Free, no obligation. Do not upload contracts, CUI, drawings, technical orders, incident details, or network diagrams through the form.
Is your shop floor in scope? The five asset categories in hangar language
At CMMC Level 2, an asset's treatment follows what it can and does process, store, transmit, or protect — not where it physically sits. 32 CFR § 170.19(c)(1) sorts assets into CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets, each carrying a different documentation and assessment burden. Specialized Assets can include six named types: Government Furnished Equipment, Internet of Things devices, Industrial Internet of Things devices, Operational Technology, Restricted Information Systems, and Test Equipment. At Level 2 they are in scope and must be documented, but they are not assessed against the other CMMC security requirements.
Here is the relief you came for, and then the catch.
The relief: if your engine test cell, avionics bench, eddy current set, or 1990s brick of a data loader actually meets the Specialized Asset definition, it is not assessed against the other 110 Level 2 requirements.
The catch: you do not get the label because a device is old, proprietary, inconvenient, or located on the floor. It must be able to process, store, or transmit CUI and be unable to be fully secured. At Level 2, a qualifying Specialized Asset is in scope for documentation, and the documentation is assessed. There is a real asymmetry in the rule that catches people who read about Level 1 and assumed it carried over. Under § 170.19(b)(2)(ii), Specialized Assets are outside the Level 1 self-assessment scope and are not assessed. Under § 170.19(c)(1), at Level 2 they are inside the assessment scope — documented in the asset inventory, addressed in the System Security Plan, shown on the network diagram, and managed under your risk-based security policy and procedures. Not assessed against the other requirements. Very much on the list.
The five categories
| Category | What it means in a hangar | What the rule requires | MRO example to test — not a determination |
|---|---|---|---|
| CUI Asset | Processes, stores, or transmits CUI | Asset inventory, SSP treatment, network diagram, and assessment against Level 2 requirements | Maintenance system storing a verified controlled work package; tablet downloading a controlled technical order |
| Security Protection Asset | Provides security functions or capabilities to the CMMC environment and may process Security Protection Data | Asset inventory, SSP treatment, network diagram, and assessment against requirements relevant to the capability provided | Identity provider, firewall, endpoint detection, log platform, or MSP remote-management tooling |
| Contractor Risk Managed Asset | Can handle CUI but is not intended to because documented policy, procedures, and practices keep it out | Inventory, SSP treatment, network diagram; no other requirement testing if documentation is sufficient, but a limited check is allowed when findings raise questions | Shop-floor PC technically capable of receiving CUI but kept out of the approved path by controls that are actually enforced |
| Specialized Asset | Can process, store, or transmit CUI, cannot be fully secured, and fits IoT, IIoT, OT, GFE, Restricted Information System, or Test Equipment | Inventory, SSP treatment, network diagram, and risk-based management; reviewed in the SSP but not assessed against the other CMMC requirements | Proprietary NDT appliance, unsupported data loader, or GFE test set when the facts meet the complete definition |
| Out-of-Scope Asset | Cannot process, store, or transmit CUI and provides no security protection for CUI Assets, or is physically or logically separated; the rule also includes a narrow KVM-only VDI example | Be prepared to justify inability or separation; no Level 2 assessment requirements | Civil-only kiosk with enforced technical separation from every controlled path |
Two disciplines matter more than the labels.
Contractor Risk Managed is not a synonym for out of scope. It is a documented, inventoried, diagrammed category for capable-but-controlled assets. Reaching for "out of scope" when you mean "we have a policy against it" is the fastest way to lose credibility in a scoping review. Out-of-scope requires inability or separation you can demonstrate — not intent.
The rule's narrow virtual-desktop example is narrow. § 170.19 contemplates an endpoint hosting a virtual desktop client, configured so that no CUI processing, storage, or transmission occurs beyond keyboard, video, and mouse, being treated as out of scope. That is a specific configuration, not a general permission slip for anything labeled "view only." Before you rely on it, test the actual behavior: cache, clipboard, local drives, downloads, print, screenshots, camera, and what survives a logout or a power cycle.
Two provisions written as though somebody had visited a hangar
An avionics test bench that must replicate a fielded configuration may fit the rule's own Enduring Exception example. 32 CFR § 170.4 defines an Enduring Exception as a special circumstance or system where remediation and full compliance are not feasible, and gives examples: systems required to replicate the configuration of “fielded” systems, medical devices, test equipment, operational technology, and IoT. It adds that no operational plan of action is required, but the circumstance must be documented within a System Security Plan, and that Specialized Assets and GFE may be Enduring Exceptions.
“A system required to replicate the configuration of a fielded system” can describe an avionics bench that genuinely has to match an aircraft baseline. It does not describe every test bench. If the facts fit, document why full remediation is infeasible, how the system is managed, and why the fielded configuration must be preserved. Do not use “Enduring Exception” as a label that ends the risk conversation.
Government-furnished property expressly covers overhaul work. Government Furnished Equipment takes its meaning from government-furnished property at FAR 45.101, which includes spares and property furnished for repair, maintenance, overhaul, or modification. The FAR definition names your business. But property status alone does not put an article into a CMMC asset category. If a government-furnished line replaceable unit, test set, or portable maintenance aid can process, store, or transmit CUI and cannot be fully secured, it is a GFE Specialized Asset candidate and belongs in the Level 2 inventory.
The Aircraft Maintenance Specialized-Asset Ledger
| Shop-floor asset | Category to test first | Assessed against the 110? | Evidence to produce | MRO mistake |
|---|---|---|---|---|
| Avionics test bench or automated test equipment | Test Equipment candidate; Enduring Exception may apply when a fielded baseline must be preserved and full remediation is infeasible | No if it satisfies the Specialized Asset definition; otherwise classify normally | Function, data, storage, interfaces, supportability, fielded-configuration rationale, inventory, SSP, diagram, risk treatment | Calling every bench an Enduring Exception without proving the baseline or infeasibility |
| Engine test-cell instrumentation | Operational Technology candidate only if it handles CUI and cannot be fully secured | No if Specialized; otherwise depends on actual function | Data path, controller architecture, segmentation, supportability, inventory, SSP, diagram | Leaving the cell off the diagram because “it is not IT” |
| Digital NDT equipment | Test Equipment candidate or CUI Asset | Depends on whether it can be fully secured | Device dossier, storage, ports, network interfaces, export path, vendor support | Labeling it Specialized merely to avoid controls |
| Portable data loader | Test Equipment candidate or CUI Asset | Depends | Loads retained, duration, interfaces, custody, update and sanitization process | Treating a loader that retains controlled data as a hand tool |
| CNC or repair-machining equipment | Operational Technology candidate only when it handles CUI and cannot be fully secured | No if Specialized; otherwise depends | Program-transfer path, local storage, interfaces, segmentation, supportability | Protecting the server but ignoring how the program reaches the machine |
| Calibration or metrology equipment | Usually out of CUI scope; Test Equipment or CUI Asset only when the data path supports it | Depends on actual data and securability | Records location, procedures loaded, vendor transfer, storage behavior | Sending a controlled procedure to a commercial calibration house |
| Portable maintenance aid or technical-order tablet | GFE candidate if Government furnished; otherwise CUI Asset or Contractor Risk Managed | Depends | Cache, download, clipboard, print, camera, offline behavior, persistence after logout | Treating a shared tablet as a screen rather than a storage-capable endpoint |
| Government-furnished test set | GFE Specialized Asset candidate only if it handles CUI and cannot be fully secured | No if Specialized | Custody, function, information handled, connection instructions, responsibility split | Assuming Government ownership alone proves it is outside scope or Specialized |
| Government-furnished article with onboard memory | GFE candidate; category follows actual information function and securability | Depends | Memory function, data retained, connection and download path, custody | Inventorying the article as property but not as a possible information asset |
| Autoclave, paint-booth, or oven controller | Operational Technology candidate only if it handles CUI and cannot be fully secured | No if Specialized; otherwise generally outside CUI scope unless another role applies | Data fields, network path, segmentation, supportability | Putting controllers on a flat network next to CUI systems |
| Tool-crib RFID or shop sensor | IoT or IIoT candidate only if it handles CUI and cannot be fully secured; otherwise often out of scope | Depends | Data fields, security function, network path, separation | Calling every sensor a Specialized Asset because it is IoT |
| Printer, scanner, or multifunction device | Usually a CUI Asset when it handles CUI | Yes when it processes, stores, or transmits CUI | Job retention, scan destinations, admin access, disk handling, disposal | Stored print jobs, scan-to-personal-email, or drive replacement without sanitization |
| Shop-floor MES or ERP terminal | CUI Asset or Contractor Risk Managed | Depends on what the workflow allows | Field and attachment inventory; controls and evidence if risk-managed | Calling it out of scope on the strength of a policy alone |
| Technician laptop opening a verified controlled technical order | CUI Asset unless a narrow out-of-scope architecture genuinely applies | Yes | Standard Level 2 evidence plus cache, browser, print, photo, and offline behavior | Assuming a browser session leaves nothing behind |
If you take one operational habit from this section, take the device dossier. One page per specialized-device candidate: what it does, what data it handles, how it connects, what it stores, whether the vendor supports it, which interfaces it genuinely requires, who owns it, why it cannot be fully secured, and how you're managing the risk. It gives an assessor or readiness partner the facts the category requires instead of a label with nothing behind it. Building it is free.
Why the answer differs by platform — technical orders versus commercial derivative aircraft
The same repair station can end up with different CMMC boundaries across contracts and workflows because the provenance of the task data differs by platform. Work performed to government technical orders, technical data packages, and military process specifications often starts with DoD-origin technical information that may carry restrictive distribution controls. Work on military commercial derivative aircraft may instead rely on commercial OEM manuals and component maintenance manuals. Neither starting point decides CUI by itself. The correct scope-reduction strategy for a mixed MRO follows verified data provenance and the written requirement, not the organization chart.
This is editorial analysis built on the definitions above, and we want to be careful about how far it goes. The authorized Government data owner or agency determines whether Government information is CUI; the contract and contracting channels determine the requirement; federal-contracts counsel handles legal disputes; and an RP/RPO can help map the resulting technical scope. The logic is straightforward enough that you can use it to structure the question.
On a pure military platform, your task data may be a technical order or technical data package supplied through DoD channels with a restrictive distribution statement. That is a strong Controlled Technical Information indicator. It is still an artifact-level determination, not a platform-wide shortcut.
On a military commercial derivative airframe, the picture changes. Air Force Technical Order 00-5-3 provides one concrete service-specific example: commercial-derivative aircraft technical data may reference commercial manuals and component maintenance manuals, including vendor-hosted web manuals, subject to service review and acceptance. DoD Instruction 5030.61 separately permits an FAA certification to serve as a basis for DoD airworthiness when appropriate and when military-use gaps are addressed. Neither source is CUI authority. Together they prove the narrower point: commercial technical publications can sit inside a military maintenance program without becoming DoD-controlled technical information merely because of the platform.
A commercially issued manual licensed on ordinary OEM terms is not DoD-controlled technical information merely because a military customer uses the aircraft. It may be proprietary, export-controlled, supplemented by controlled Government data, or used to create a controlled derivative — and those facts change the answer. But proprietary is not the same legal animal as CUI.
| Work performed | Typical task-data source | Control authority to verify | Likely consequence to test |
|---|---|---|---|
| Airframe or component work on a pure military platform | Government technical orders, TDPs, or military process specifications | Government or prime markings, distribution authority, contract identification, and content | Strong Controlled Technical Information indicator; Level 2 follows only when CUI is verified and the written procurement requirement calls for Level 2 |
| Work on a military commercial-derivative airframe using ordinary commercial manuals | Commercial OEM manuals or component maintenance manuals | OEM license and any Government supplements, markings, or contract instructions | Proprietary commercial data may remain outside CUI; the workflow may be Level 1 or outside Part 170 if no CUI is present and no Level 2 status is required |
| Commercial-derivative work with a Government-controlled variant or supplement | Mixed commercial and Government sources | Each document’s source, marking, authority, and derivative restrictions | Keep the verified controlled material in the Level 2 path without automatically treating the entire commercial library as CUI |
| Teardown, NDT, disposition, or configuration data generated during performance | Contractor-created record | Content, CUI category, dissemination basis, and the contractor-development prong | CUI is possible only when the generated content otherwise qualifies; contractor creation alone does not decide it |
What this means for your architecture
Every generic CMMC guide tells a manufacturer to enclave "engineering." For a mixed MRO, that advice is close to useless — engineering isn't the variable. The variable is which platform's data set a workflow touches.
So the enclave question for a repair station is not "which department goes inside." It is "which data provenance goes inside, and where does work cross the line?" That reframing has real money attached. It is the difference between putting one hangar line's technical data path inside a controlled boundary and putting an entire multi-line business inside one.
Two guardrails on this. First, the moment your commercial-derivative line touches a government-supplied controlled variant, that document is controlled regardless of what the rest of the line looks like. Second, a Part 145 certificate is not a CMMC input. It governs what maintenance you are authorized to perform and return to service under 14 CFR Part 145 — nothing more. Worth knowing that FAA inspector guidance separately recognizes repair stations performing military-only maintenance, which is a useful reminder that FAA authority and military technical-data control are two different systems that happen to meet on your floor.
Hangars, AOG teams, and lower-tier vendors: scoping without breaking maintenance
The defensible boundary in a maintenance operation is the one that matches what technicians actually do. Start with the work sequence rather than the network diagram: follow one representative defense job from contract receipt through planning, engineering, shop execution, test, outside processing, quality release, customer delivery, archive, and field support. Controls that survive contact with a hangar are the ones that give people an approved path faster than the workaround you are trying to prohibit.
Walk one job, all the way
Pick one representative defense job and physically follow it. Not a diagram — the actual job.
Contract and technical package arrive. Somebody puts them somewhere. Planning builds the work cards. The packet gets printed, or doesn't. Access is granted on the floor. A technician photographs a crack. Measurements go somewhere. Engineering writes a disposition. A part ships to an outside plating house. NDT runs and stores images. Quality reviews and releases. Records go to a customer portal. Everything gets archived, backed up, retained, and eventually destroyed. Eighteen months later, an AOG call reopens the whole file in a hangar three states away.
Every arrow in that sequence is a scope decision. When that map does not exist, the quotes that follow are guesses dressed up as scopes.
Controls that fit humans
Good programs fail on the floor for entirely predictable reasons. If a control adds friction to a task performed all shift, it will be defeated by lunch — and the workaround will be worse than the risk you were managing.
Design for the reality: individual identity without punishing delays. An approved offline procedure for when the network drops mid-job. Controlled printing with a real staging and pickup process. A sanctioned way to take a photograph, because technicians are going to take photographs. Shared-device logout behavior you have actually tested. Glove-compatible authentication where your platform supports it. Shift turnover, temporary labor, visitors, vendors, and after-hours physical custody all thought through in advance.
None of that is in the rule. All of it determines whether your controls exist in practice or only in your System Security Plan.
AOG and field maintenance
Field work is a common scope gap because the boundary was drawn around a building.
If a field device accesses or stores controlled data, the data followed the work. A temporary location does not suspend anything. Build a standard field kit and a written field-data sequence covering approved remote access, offline cache behavior and what gets purged on return, mobile connectivity, portable printing and media, physical custody in a vehicle or hotel room, photo capture, the incident reporting route, and sanitization when the kit comes home.
Test the offline behavior before you deploy it, not after. "What is on this laptop right now" is a question you want answered on your terms.
Lower-tier repair and special-process vendors
A defense-facing MRO is often a contractor and a customer at the same time. Parts go out for plating, NDT, heat treat, machining, calibration, and component repair, and each of those handoffs is a data decision.
Work through it in this order: what does the vendor genuinely need — not what is easiest to forward? Is that information FCI or CUI? What does the subcontract require, and what should flow down under DFARS 252.204-7021 and 32 CFR § 170.23? How does it transfer securely? What happens to it afterward — return, retention, destruction? Is the vendor's portal, or your transfer service, an external service provider in your scope?
Two failure modes, opposite directions. Sending the whole technical package because it takes less time than trimming it. And imposing a blanket Level 2 demand on every supplier who touches a part, which is expensive, slow, and often wrong. Minimize the package first. The cheapest scope reduction available to a repair station is not sending data you didn't need to send.
The honest problem with MRO scoping
A CUI enclave — the product most often quoted to a maintenance shop — cannot solve the parts of a maintenance operation that actually leak. It does not solve a paper job packet left on a cart. It does not solve a photograph on a technician's personal phone that syncs to a consumer cloud before anyone thinks about it. It does not solve an NDT instrument whose only export path is a USB stick. It does not solve an AOG laptop caching a work package in a hotel room in Alaska.
We route readers to readiness and enclave provider categories. Saying that the flagship product in that market does not fully solve the maintenance problem is against our commercial interest. It is also true, and you would have discovered it three months into an implementation.
Here is why that is good news. It means the expensive part of your program is not the license count — it is the workflow map, and the workflow map is the part you can start this week, for free, with a clipboard. An enclave used after the map is a precise instrument: it shrinks a digital boundary around a genuinely bounded set of workflows and it can take real cost out of an assessment. An enclave bought before the map is a very expensive way to discover that CUI was never confined to the systems it covers.
Buy the map first. Then buy the architecture that fits it.
Compare provider categories against your actual scope
Once you know which contracts and workflows hold controlled data and which assets sit in which category, the vendor conversation changes completely — you stop receiving license quotes and start receiving scoped proposals. Our provider-category breakdown lays out what each category does, what it cannot do, and what to verify before you sign.
Compare provider categories → · Already know what you need? Request scoped quotes →
Do not submit CUI, drawings, technical orders, aircraft data, network diagrams, or contract attachments.
Does FAA Part 145, AS9110, ITAR, or an OEM approval satisfy CMMC?
No. None of them establishes a CMMC level or status. 14 CFR Part 145 governs repair-station certification and the maintenance functions a station is authorized to perform and return to service. AS9110 is an aerospace quality-management standard for maintenance organizations. ITAR and the EAR control the export and transfer of covered articles, services, technical data, and technology. CMMC assesses specified safeguarding requirements for contractor information systems under 32 CFR Part 170. Existing aviation and export-control programs can supply reusable evidence, but none of them substitutes for the required CMMC status.
If you're irritated by this section, we understand. A defense-facing repair station may hold an FAA certificate, an AS9110 certification, ITAR registration, a Joint Certification Program certification, multiple OEM approvals, and half a dozen customer quality approvals — and still be told it has to start something new. That's a fair grievance. It's also the situation.
| Regime or approval | Authority | What it governs | Evidence you may reuse | What it does not establish |
|---|---|---|---|---|
| FAA Part 145 repair station | FAA, 14 CFR Part 145 | Certification, ratings, authorized maintenance functions, inspection, alteration, and return to service | Training, manuals, facilities, calibration, contract-maintenance procedures, records | A CMMC level or status; implementation of NIST SP 800-171 Rev. 2 |
| AS9110 certification | SAE and IAQG aerospace quality ecosystem | Quality management for maintenance organizations | Document control, revision management, traceability, corrective action, supplier control, competence, internal audit | CMMC status, security-control effectiveness, or a CUI boundary |
| ITAR | Department of State, 22 CFR Parts 120–130 | Export and transfer of defense articles, services, and technical data, including data used for operation, repair, testing, maintenance, and modification | Foreign-person controls, data identification, transfer approvals, access restrictions | That all ITAR technical data is CUI, that CMMC is met, or that a particular cloud is sufficient |
| EAR | Department of Commerce, 15 CFR | Export, reexport, and transfer controls for covered items, software, and technology | Classification and technology-control processes | A CMMC status or an automatic Level 2 requirement |
| Joint Certification Program and DD Form 2345 | U.S.–Canada JCP under DoDD 5230.25 and DLA procedures | Eligibility to request access to unclassified militarily critical technical data, subject to repository and business-need controls | Data-custodian roles, access discipline, training, approved purpose | Guaranteed release of a data package, a security assessment, or a CMMC status |
| OEM or customer quality approval | OEM or customer | Authorization and quality capability for specified work | Customer procedures, access lists, technical-data control, supplier monitoring | A Government CUI determination or a CMMC status |
| CMMC and DFARS | 32 CFR Part 170 plus the applicable acquisition clauses | Required cybersecurity status, assessment scope, safeguarding, affirmation, reporting, and flow-down for covered systems and contracts | — | FAA airworthiness authority, a quality certification, or an export authorization |
The two gates MRO shops most often confuse
This one is worth its own paragraph, because it produces a specific and expensive misunderstanding.
DD Form 2345, the Militarily Critical Technical Data Agreement, is an access authorization. It is not a security assessment. Processed through the Joint Certification Program administered by the Defense Logistics Agency, it certifies your organization to receive unclassified militarily critical technical data. Notice how directly the underlying definition speaks to maintenance: militarily critical technical data under DoDD 5230.25 covers technical information usable to design, engineer, produce, manufacture, operate, repair, overhaul, or reproduce military or space equipment. Repair and overhaul, named in the definition.
So the Joint Certification Program is one gate that can make you eligible to request or receive unclassified militarily critical technical data. It does not guarantee access: DLA's current process also requires an approved DIBBS/cFolders account and a demonstrated business need for DLA export-controlled data. DFARS 252.204-7012 and CMMC govern what you must do once qualifying data reaches your systems. Two gates, different authorities, neither substituting for the other. A current JCP certification is not evidence of a CMMC posture, and a prime's supplier questionnaire will find that out quickly.
One practical note: we did not verify a universal official JCP processing time. The current DLA access path layers JCP approval, account approval, enhanced validation, and business-need review, and corrections or missing evidence can add delay. If your ability to bid depends on receiving a technical data package, treat the access path as long-lead — because it has multiple gates.
Reusing evidence without claiming equivalency
The good news buried in this section: a well-run AS9110 shop is further along than it thinks — just not where it thinks.
You likely already maintain documented roles and training, controlled procedures under revision management, supplier approval and surveillance, calibration and equipment control, a corrective-action process, internal audits, record retention schedules, and physical access control to controlled work areas. All of that is reusable material.
What it is not is an evidence statement. "We passed our AS9110 audit" does not answer a CMMC assessment objective. "Here is our access-control procedure, here is the training record for the technicians it applies to, here is the audit that tested it, and here is the requirement it maps to" does. The work is the mapping, not the creation. That is genuinely less expensive than starting from nothing — which is the honest, encouraging version of this section.
Which CMMC level should an MRO plan for right now?
Plan from the written requirement, not from an industry average. During the current suspension, new procurement designations are limited to Level 1 (Self) for FCI and Level 2 (Self) for CUI. 32 CFR § 170.14 defines Level 1 as the 15 basic safeguarding requirements from FAR 52.204-21(b)(1), Level 2 as all 110 NIST SP 800-171 Revision 2 requirements across 14 families, and Level 3 as 24 selected requirements from the February 2021 version of NIST SP 800-172, with a Final Level 2 (C3PAO) status required first. Level 2 (C3PAO) and Level 3 remain defined in Part 170, but new designations for those paths are paused. See the CMMC Levels guide for the rule-by-rule level comparison.
| Path | Information and written-requirement trigger | Requirement set | Current designation posture | Status mechanics |
|---|---|---|---|---|
| Level 1 (Self) | Written requirement for contractor systems that process, store, or transmit FCI | 15 basic safeguarding requirements from FAR 52.204-21; covered deviation actions may use FAR 52.240-93 with the same safeguards | Allowed during the suspension | Annual self-assessment and current affirmation in SPRS; no POA&M |
| Level 2 (Self) | Written Level 2 (Self) requirement for systems handling CUI | All 110 NIST SP 800-171 Rev. 2 requirements across 14 families | Allowed during the suspension | Assessment generally current for three years; annual affirmation; Conditional status and a 180-day POA&M only within the rule’s limits |
| Level 2 (C3PAO) | Written Level 2 (C3PAO) requirement or a voluntary certification decision | The same 110 Rev. 2 requirements | New Department designations paused; existing written requirements remain until changed; voluntary assessments remain available | Independent C3PAO assessment, CMMC UID and status in SPRS, annual affirmation, three-year status window subject to rule conditions |
| Level 3 (DIBCAC) | DoD-selected requirement for CUI needing enhanced protection | Final Level 2 (C3PAO) plus 24 selected requirements from the February 2021 NIST SP 800-172 | New Department designations paused | Final Level 2 (C3PAO) prerequisite; DCMA DIBCAC assessment; annual affirmation and three-year status window subject to rule conditions |
Three mechanics that decide eligibility more often than control implementation does:
“Current” has a definition. Under DFARS 252.204-7021, a Final Level 1 (Self) status must be not older than one year with a current affirmation; Final Level 2 (Self), Final Level 2 (C3PAO), and Final Level 3 statuses must be not older than three years with an affirmation not older than one year. Conditional statuses carry their own 180-day window. A solid control set with a lapsed affirmation is not a current status.
The POA&M math is unforgiving. Under 32 CFR § 170.21, a Conditional Level 2 requires a score of at least 88 of 110; only 1-point requirements are eligible for a Plan of Action and Milestones; six specific requirements are excluded by name, including your System Security Plan; there is one narrow exception for CUI encryption where encryption is in place but not FIPS-validated; and everything on the POA&M closes within 180 days or the Conditional status expires. Practical effect for a maintenance shop: a single unmet 5-point requirement removes the Conditional path at any score. You can meet 109 of 110 and have no conditional route if the gap is a heavy one.
Revision 2 is still the target. CMMC Level 2 is tied to NIST SP 800-171 Revision 2 under 32 CFR § 170.14(c)(3), and DoD Class Deviation 2024-O0013 pins Revision 2 in the DFARS 252.204-7012 context. NIST has published Revision 3, and NIST's catalog now marks Revision 2 as withdrawn and superseded. That is a NIST publication-status question, not a CMMC baseline change. The same distinction now matters at Level 3: NIST published SP 800-172 Revision 3 in May 2026 and withdrew the original publication, but Part 170 still incorporates the February 2021 SP 800-172 and its selected 24 requirements. If a vendor offers to “future-proof” you onto a newer NIST revision as though it were the current CMMC-controlling version, that is a sales position, not a compliance one. Build the evidence set the rule currently requires, plan for future migration separately, and keep an explicit Revision 2 map. Our Rev. 2 versus Rev. 3 comparison tracks every instrument that could change that.
What does this actually cost a maintenance shop?
We are going to be straight with you: there is no credible MRO-specific cost dataset, and we are not going to invent one. What exists is the Government's own published estimates, and they are worth knowing because they set the frame for every quote you'll receive.
Around the July 13, 2026 suspension, the Small Business Administration published two figures for a small firm's total compliance cost: approximately $593,800 for a firm requiring third-party assessment and approximately $388,600 for a firm eligible for self-assessment. Treat both as SBA scenario estimates, not as a settled MRO price. The arithmetic difference is $205,200. SBA did not publish a line-item allocation that lets us call that difference “the audit fee” or assign the remaining amount to implementation. The defensible conclusion is narrower: the self-assessment scenario is still expensive, because the security implementation and evidence work did not disappear with Phase II.
For a maintenance shop specifically, the biggest lever on that number is not vendor selection. It is whether you scoped by platform and data provenance before you bought anything. Getting that wrong is what turns a narrow Level 2 boundary into a company-wide invoice — or treats an FCI-only workflow as though every system held CUI. For dollar-level detail by level and company size, see our CMMC Level 2 cost guide.
Your first 30 days after a CMMC flow-down lands
Do not begin with a software purchase or a company-wide control rollout. In the first 30 days, preserve the written requirement, identify the information, walk one maintenance workflow end to end, categorize your assets and external providers, verify your current status in SPRS, and assemble a decision packet. That sequence exposes the real boundary before cost and architecture harden around a guess.
1. Build the clause pack. Save the solicitation, the contract or subcontract, the purchase order, security exhibits, data markings and handling instructions, every modification, and the prime correspondence. Write down the exact CMMC status requested and the next award, option, or extension date. That is the procurement deadline that controls this plan — not a generic milestone you read in a headline.
2. Create the information register. Categories only. Do not centralize actual controlled data to do this exercise. For each artifact family record source, marking or authority, program, owner, systems touched, physical form, and unresolved questions.
3. Walk one real job. Receipt to archive, including paper, photographs, removable media, field work, customer portals, outside processing, backups, and security tooling. Take notes on what people actually do, not what the procedure says.
4. Build the first-pass asset map. Hypotheses, not final labels: CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, Out-of-Scope, external service provider, physical handling process. Next to each one, write the evidence you'd need to prove it.
5. Map external responsibilities. For every cloud service, MSP or MSSP, technical-library host, maintenance software vendor, backup service, security operations provider, file-transfer tool, and lower-tier repair vendor: what data it handles, what security function it performs, what authorization evidence exists, what the responsibility matrix says, and what the contract requires.
6. Verify your current status. Check the relevant SPRS record, assessment date, affirmation, and system or UID against the written requirement. Confirm who at your company can access dibnet.dod.mil, and fix it now if the answer is nobody.
7. Choose the provider category, not the provider. Questions about what the Government designated as CUI go to the authorized customer or agency data owner. Clause ambiguity and legal disputes go through the contracting channel and, where needed, to qualified federal-contracts counsel. Technical scoping, readiness, SSP, and POA&M work goes to an RP/RPO or readiness provider. Ongoing security operations go to an MSSP. Boundary architecture goes to an enclave provider. Evidence workflow goes to a GRC platform. Formal assessment goes to a CMMC Third-Party Assessment Organization when a valid current requirement calls for it — and only after the Cyber AB conflict rules have been checked against every organization and person that performed preparation work.
The letter to send this week
Reciprocity with no strings: copy this, adapt it, send it. It costs nothing and it resolves more than any tool will.
Subject: Clarification request — cybersecurity and CMMC requirements, [contract/solicitation number]
We are confirming our obligations under [contract/solicitation number] and request written clarification on the following:
- Which CMMC level and assessment type apply, under which clause or provision, and at what point — bid, award, option exercise, or subcontract flow-down?
- Which CUI categories and distribution statements apply to the technical data we will receive or generate in performance? Please identify the controlling markings and any handling instructions.
- Is any portion of our performance designated as operationally critical support and identified in the contract for purposes of DFARS 252.204-7012?
- Does any government-furnished property under this contract include an item capable of storing or transmitting controlled information?
- If this contract or solicitation currently references a CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, please advise on the status of the amendment or modification following the July 13, 2026 Phase II suspension.
We are not requesting any controlled technical data in response — only the applicable requirements and markings.
Send it to your contracting officer for a direct contract, or to your prime's supplier quality or contracts contact for a flow-down. Keep the answer with your clause pack. It is evidence, and evidence dated before you spent money is the best kind.
What you should be holding at day 30
A clause and status summary. An information register. One workflow diagram. An asset-category hypothesis list. An external-provider map. A written list of unresolved customer questions. Your current SPRS status record. A provider-category brief. And a budget request built on scope rather than headcount.
Turn that into a first-pass scope map
If you'd rather not build the packet from scratch, our Find My CMMC Path tool takes category-level answers — the level your document states, which maintenance workflows you run, your general environment, whether you have field or AOG work, whether outside vendors receive data, and your next contract date — and returns the provider category that fits the unresolved work.
Build my first-pass scope map →
Category answers only. No file uploads. Do not enter CUI, drawings, technical orders, tail numbers, program names, or credentials.
Which CMMC provider category should an MRO hire first?
Hire for the unresolved problem, not for the most impressive credential. An RPO or Registered Practitioner helps map technical scope and prepares you; an MSSP operates security day to day; a CUI enclave provider designs a smaller controlled environment; a GRC platform organizes evidence; a CMMC Third-Party Assessment Organization performs the independent formal assessment when that path is actually required. Under 32 CFR § 170.9 and the Cyber AB Code of Professional Conduct v2.0, a C3PAO and every assessment-team member are prohibited from participating in a Level 2 certification assessment when they served as a consultant to prepare that organization for any CMMC assessment within the prior three years. The same code prohibits guarantees of assessment or certification results.
We do not publish named provider rankings on this page, and that is deliberate. This is a scope-determination page. Dropping vendor names into the moment you're deciding what you owe would undercut the only thing that makes this page worth reading. When you know your category, our Who to Hire First guide, provider category guide, and directory go deeper — with role, status, and last-verified date documented.
| Provider category | Use it when | Do not treat it as | What an MRO should verify first |
|---|---|---|---|
| RPO or RP | Technical scoping, readiness, gap analysis, SSP and POA&M development, and implementation roadmap | The authorized Government source for a CUI determination, federal-contracts counsel, or the independent assessor when the three-year conflict rule applies | Current Cyber AB status where relevant, named practitioners, MRO and shop-floor experience, exact deliverables you own |
| MSP or MSSP | Identity, endpoint, network, logging, incident response, backup, vulnerability, and administration operations | Proof that CMMC is met | Requirements owned by each party, Security Protection Data handling, service description, customer-responsibility matrix, evidence export |
| CUI enclave provider | A genuinely bounded group of users and workflows can be isolated without constant leakage | A cure for paper, photographs, test equipment, AOG work, or supplier handoffs | Supported maintenance workflows, offline behavior, printing, photographs, field use, data transfer, exit plan |
| GRC platform | Evidence management, requirement mapping, policy workflow, SSP and POA&M tracking | A control implementation or certification | Correct Rev. 2 mapping, evidence ownership and export, assessor access, version control |
| CMMC Third-Party Assessment Organization | You are assessment-ready and a valid written or voluntary decision calls for Level 2 certification | A readiness consultant and assessor for the same organization within the prohibited three-year window; a source of guaranteed outcomes | Current authorized Marketplace status, scope assumptions, written conflict analysis for the C3PAO and every proposed assessment-team member, no guarantees |
| Federal-contracts counsel | Clause conflict, amendment, suspension, flow-down dispute, allocation of contractual risk, or contested CUI authority | A technical implementation team | Relevant acquisition and CUI experience, written scope, coordination with the contracting officer, customer authority, and readiness team |
Ten questions that separate a scoped proposal from a license quote
Ask these before you sign anything. A provider who has actually scoped hangar work should be able to answer them without retreating into a generic license count.
- Which maintenance workflows did you include, and which did you exclude?
- How did you determine which artifacts are actually controlled, rather than assuming by document name?
- How will you handle technical publications, paper packets, shared devices, photographs, test equipment, and AOG work?
- Which of our assets are you proposing as Contractor Risk Managed or Specialized, and what evidence supports that classification?
- Which external providers enter our scope, and which responsibility matrices exist for them?
- What does your quote assume about the July 2026 suspension and about the exact status our contract states?
- Which deliverables do we own at the end — asset inventory, network diagram, SSP, POA&M, procedures, evidence index, responsibility matrix?
- What is expressly excluded from this quote?
- Have your organization or any proposed assessment-team members performed CMMC preparation work for us within the prior three years, and will you put the conflict analysis in writing?
- What happens to this engagement if the Department changes the program after the current review?
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial and Advertising Policy.
What goes wrong in MRO CMMC programs
The expensive failures in maintenance CMMC programs usually happen before a single control is implemented. The shop declares everything controlled, or nothing controlled, or trusts a written policy the floor does not follow, or buys a boundary architecture without mapping the paths that cross it. The remedy is not weaker security — it is a boundary matched to the contract, the information, the real workflow, and the evidence you can actually produce.
| Failure mode | Why it costs you | Better move | Evidence that closes it |
|---|---|---|---|
| Treating every defense-related record as controlled | Overscopes systems, users, vendors, and cost; technicians route around the burden | Run the five-part evidence test and obtain written clarification where unresolved | Artifact register with source, authority, content, purpose, owner, and dated customer response |
| Treating unmarked or commercial-looking data as automatically safe | Misses qualifying contract-derived or contractor-created CUI | Check authority, content, contract prong, distribution criteria, and customer guidance | Marking review, CUI-category basis, contract excerpt, and written data-owner guidance |
| Assuming the suspension erased DFARS 252.204-7012 or existing C3PAO language | Leaves real contractual and incident exposure | Preserve required protections and obtain the formal amendment or modification | Executed solicitation amendment, contract modification, or subcontract change |
| Buying an enclave, Government cloud, or GRC platform before scoping | Architecture hardens around a guess | Map data and workflows first | Approved workflow map, asset hypothesis list, and responsibility matrix before procurement |
| Calling every legacy or test device Specialized | Misuses a narrow category and damages credibility | Prove CUI capability, inability to fully secure, named asset type, and risk treatment | Device dossier, SSP entry, diagram, supportability evidence, and risk decision |
| Calling policy-only endpoints Out of Scope | Out-of-scope requires inability or separation, not intent | Use Contractor Risk Managed where the facts fit | Technical test of data paths plus policy, procedure, enforcement evidence, and SSP treatment |
| Ignoring printers, photographs, paper, and removable media | The workflow escapes the digital boundary | Design approved physical and digital bridges | Print, scan, photo, media, custody, retention, and destruction procedures tested on one job |
| Ignoring AOG and field work | Field devices become undocumented data paths | Standardize a managed field kit and return process | Field-kit inventory, offline test, custody log, incident route, sanitization record |
| Sending full technical packages to lower tiers | Expands exposure and drives unnecessary flow-down | Minimize the package before deciding the requirement | Data-minimization record, subcontract clause analysis, transfer and destruction evidence |
| Letting MSP tickets, logs, and remote tools escape analysis | Security Protection Data and privileged access can pull services into scope | Map data, tenancy, access, and responsibilities | Service description, customer-responsibility matrix, access roster, evidence-export test |
| Shared shop-floor accounts | Destroys attribution and clean termination | Build usable individual identity around real shift patterns | Named-account roster, authentication test, termination test, exception log |
| Using a readiness provider as the C3PAO without applying the three-year rule | Can disqualify the C3PAO or assessment-team member from that certification assessment | Separate roles and obtain written conflict analysis before signing | Prior-services disclosure for the organization and every proposed team member |
| Treating AS9110 or FAA audit evidence as CMMC equivalency | Leaves the cybersecurity requirements unproved | Reuse artifacts but map them to specific CMMC objectives | Evidence crosswalk showing policy, implementation, test, owner, and date for each objective |
| Building to NIST SP 800-171 Revision 3 and claiming current Level 2 compliance | Misstates the controlling CMMC baseline | Maintain an explicit Rev. 2 evidence map until the governing instrument changes | Version-controlled Rev. 2 matrix and a separate future-migration plan |
| Never provisioning or testing DIBNet access | Creates delay and forces the emergency assistance path while the 72-hour clock runs | Provision at least two people, test normal access, and record DC3’s fallback | Certificate and account owner list, test record, expiry tracking, incident-plan contact block |
What one MRO publicly claimed — and what the public record does not prove
In July 2026, Duncan Aviation announced that it had achieved what the company described as formal compliance with the CMMC Level 2 framework, and described establishing a controlled area for its manufacturing division with restricted physical access and entry records. We report this as one company's public account of its own approach — not as independent verification of any claim in it, not as a typical result, and not as evidence that the same architecture fits another repair station. DFARS 252.204-7021 defines seven CMMC statuses, and “CMMC compliant” is not one of them.
We include this because it is the most instructive public artifact in the sector right now, and because it demonstrates exactly the vocabulary problem this page exists to solve.
What the company said, in its own words. The announcement, dated July 29, 2026, states that Duncan Aviation "achieved formal compliance with the DoD (Department of Defense/War) CMMC ... Level 2 framework," notes that it did so "bypassing a third-party audit," and states that achieving Level 2 means the company "is now listed in the federal SAM.gov (System for Award Management) database" and is qualified to continue bidding on defense work in depot-level maintenance, aircraft modifications, and parts manufacturing and repair. Later in the same release it refers to "the CMMC certification." It also emphasizes that the company established its manufacturing division as a controlled space, limiting physical access to authorized personnel and maintaining records of who enters those shop areas.
Two corrections, offered neutrally. CMMC assessment results and affirmations are posted in SPRS, not SAM.gov — SAM.gov registration is a separate federal system with a different purpose. And “compliance,” “alignment,” and “certification” are not interchangeable under the rule; the seven statuses in DFARS 252.204-7021 are specific. The phrase “bypassing a third-party audit” suggests a self-assessment path, but a press release does not verify whether an official Final Level 2 (Self) status exists, what system it covers, or whether its affirmation is current.
And a point in the company's favor that most commentary would miss. During the suspension, Level 2 (Self) is the only Level 2 path the Department may newly designate in a procurement requirement. Voluntary C3PAO assessments remain available, and existing contract language remains until formally changed. So a Level 2 self-assessment is not inherently a shortcut — for a new Department designation right now, it is the permitted path. The underlying work described in that announcement, particularly the physical control of a work area with access records, is substantive and directly relevant to a control family most shops underestimate.
Which brings us to the point that is actually useful to you. CMMC is often reduced to an IT problem. In maintenance, a large share of the controlled information can live on a workbench: a printed work card, a marked-up process sheet, a tablet clipped to a stand, a binder in the tool crib, a photograph on a phone. Physical protection is not a footnote to your program. Our CMMC Level 2 checklist covers the full evidence set, including Physical Protection.
Five questions to ask any maintenance partner who claims CMMC
- Which of the seven CMMC statuses do you hold, exactly as it appears in SPRS?
- What was the assessment date, and is your annual affirmation current?
- What scope does the status cover — which systems, which CAGE codes?
- Was it a self-assessment or an assessment by a CMMC Third-Party Assessment Organization?
- What contract, proposal, CMMC UID, or authorized verification path substantiates the claimed status and scope beyond the press release?
A partner with a real posture will answer all five in one email. That is the test.
What we actually verified for this guide
We do not ask you to take our word for any of it. Here is what we read, and what each source supports.
| Source read | What it supports |
|---|---|
| DFARS 252.204-7012 | Controlled Technical Information and covered defense information definitions; operationally critical support; 72-hour reporting; medium-assurance certificate; malware submission; 90-day preservation; forensic support; subcontract flow-down |
| DFARS 252.204-7021 and 252.204-7025 | Seven CMMC statuses; current-status mechanics; affirmations; CMMC UID; SPRS posting; eligibility; solicitation designation; CMMC flow-down |
| 32 CFR § 170.3 | Applicability; federal-system carve-out; commercial-item, COTS, and micro-purchase treatment; status selection; original phase schedule |
| 32 CFR § 170.19 and § 170.4 | Level 1 and Level 2 scoping; five Level 2 asset categories; six Specialized Asset types; VDI example; external-service-provider treatment; Enduring Exceptions |
| 32 CFR § 170.14 and § 170.21 | The 15, 110, and 24 requirement sets; Rev. 2 and February 2021 SP 800-172 incorporation; score and POA&M rules; 88-point threshold; 180-day closeout |
| NIST SP 800-171 Rev. 2 and NIST SP 800-171 Rev. 3 | NIST publication history and the distinction between NIST’s current catalog and the version incorporated into CMMC |
| NIST SP 800-172 and SP 800-172 Rev. 3 | Original and current NIST publication status; Part 170 still controls which Level 3 requirements apply |
| FAR 45.101 | Government-furnished property includes spares and property furnished for repair, maintenance, overhaul, or modification |
| National Archives CUI Registry: Controlled Technical Information and Export Controlled | CUI//SP-CTI and CUI//SP-EXPT categories, authorities, markings, and handling context |
| DoD Instruction 5230.24 | Distribution Statements A through F and the instruction’s coverage of sustainment and logistics technical documents |
| July 13, 2026 suspension release and implementing memorandum | Phase II suspension; self-assessment designation limits; no waivers during review; amendment and modification path; continuing DFARS 252.204-7012 obligations |
| Class Deviation 2026-O0025, Revision 2 | Covered-action treatment of DFARS 252.204-7019 and 252.204-7020, the Part 240 replacement, and the FAR-overhaul cybersecurity clause structure |
| Cyber AB Code of Professional Conduct v2.0 | Three-year C3PAO and assessment-team consulting prohibition; conflict disclosure and mitigation; prohibition on guaranteed outcomes |
| DC3 and DCISE incident-reporting page | Normal medium-assurance-certificate requirement; emergency email and hotline assistance; incident fields; malware-upload instructions |
| DoDD 5230.25, DD Form 2345, and DLA JCP materials | Militarily critical technical data used to operate, repair, or overhaul military equipment; JCP as access eligibility rather than a security assessment or guaranteed release |
| 14 CFR Part 145 and IAQG 9110 materials | Repair-station authority and the maintenance quality-management role of AS9110 |
| 22 CFR § 120.33 and 15 CFR export-control rules | ITAR technical-data scope and the separate role of EAR export controls; neither substitutes for CMMC status |
| Air Force Technical Order 00-5-3 and DoD Instruction 5030.61 | Use of commercial technical publications and FAA certification in military commercial-derivative aircraft programs; neither source makes a CUI determination |
| SBA release, July 13, 2026 | SBA’s $593,800 and $388,600 small-firm scenario estimates and the exact limits of what those figures establish |
| Duncan Aviation newsroom, July 29, 2026 | The company’s own claims, treated as company-stated and not as independent verification of an SPRS status |
What we could not establish
We think this list matters as much as the one above.
- Which distribution statement is on any specific document you hold. You have to read your own cover page. No page on the internet can do that for you.
- The specific CMMC status Duncan Aviation holds. A press release is not the verification route, and we did not verify it.
- Whether your organization’s normal DIBNet access is active, tested, and assigned to current personnel. The clause and DC3 both state the medium-assurance-certificate requirement, and DC3 publishes an emergency assistance path. We cannot verify your certificate, account, or internal readiness from this page.
- Any MRO-specific cost or timeline dataset. None exists that we would publish. The figures in this article are attributed government estimates, not maintenance-sector benchmarks.
- The CUI status of any artifact in the Data-Provenance Map for your shop. That table is an editorial framework and an evidence checklist. It is not a determination.
How this page was produced, and why
Who: The Defense Compliance Report Editorial Team. This is editorial research and was not formally reviewed by a CMMC Subject Matter Advisor.
How: We read the governing rule sections and clause text at their sources — eCFR, acquisition.gov, NIST CSRC, the National Archives CUI Registry, the Cyber AB, DC3, FAA, DLA, and the July 2026 suspension materials — and then applied those definitions to the artifacts and equipment that actually move through a repair station. Where a conclusion is ours rather than the rule's, we say so in the sentence. See our Methodology, Editorial Standards, Editorial Review Process, and Corrections Policy.
Why: Because maintenance organizations have been reading manufacturing guidance and paying for manufacturing scope. Those are different data problems, and the difference is worth real money.
This article is educational research, not legal, contractual, export-control, aviation, or compliance advice. Confirm contract interpretation and disputes with your contracting officer and, where needed, qualified federal-contracts counsel. Obtain CUI markings or determinations from the authorized Government data owner, program office, or other responsible customer authority. Use an RP/RPO or other qualified readiness professional to map the resulting technical scope and evidence requirements. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense or Department of War, DCMA DIBCAC, NIST, the FAA, SAE International, or any U.S. government agency.
A note on names: official 2026 release and CIO pages use “Department of War,” while 32 CFR Part 170 and the DFARS text still use “Department of Defense” and “DoD.” This article uses the name that matches the cited source and uses DoD when referring to the governing rule or clause.
Frequently asked questions
Do all aircraft MROs need CMMC?
No. Being an MRO or an FAA repair station is not the trigger. A CMMC status applies when a solicitation, contract, subcontract, or written flow-down requires one for systems that process, store, or transmit FCI or CUI in performance of that contract, under 32 CFR § 170.3. Read the document first; then map your data.
Does an FAA Part 145 certificate trigger CMMC?
No. 14 CFR Part 145 governs repair-station certification, ratings, and the maintenance you are authorized to perform and return to service. It can generate reusable process evidence — training, calibration, manuals, recordkeeping — but it does not assign a CMMC level or status.
Does AS9110 satisfy CMMC?
No. AS9110 is an aerospace quality-management standard for maintenance organizations. Document control, traceability, corrective action, supplier control, and audit discipline from an AS9110 program are genuinely reusable, but they must be mapped to specific CMMC requirements and assessment objectives. "We passed our AS9110 audit" is not an evidence statement.
Are aircraft maintenance manuals and technical orders CUI?
Some are, and some are not. Under DFARS 252.204-7012, controlled technical information is technical information with military or space application that would meet the criteria for Distribution Statement B through F under DoD Instruction 5230.24. Technical orders and manuals are named in the clause's own examples of technical information, so they frequently qualify — but a commercially available civil OEM manual is a different document with a different provenance. Check the source, the markings, the contract, and the content.
Are work cards, travelers, tail numbers, or part numbers automatically CUI?
No blanket rule supports that. A record may contain or derive from controlled information, but the artifact's name or an identifier on it does not settle the question. Look at what fields and attachments the record actually carries, where it came from, and what the contract and customer instructions say.
Is my teardown report or NDT finding CUI even though nobody gave it to me?
Possibly, and this is one of the most-missed exposures in maintenance. Covered defense information under DFARS 252.204-7012 includes otherwise-qualifying controlled technical information or other CUI “collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.” Data you generate — as-found condition, dimensional results against military limits, NDT findings, repair dispositions — can fall under that prong when the content meets an applicable CUI category. Verify the content and the contract; do not assume that self-generated means uncontrolled, and do not assume that contract-generated automatically means CUI.
Are paper maintenance records part of CMMC scope?
Paper containing controlled information still requires protection, and the systems that print, scan, store, or capture it are categorized separately under 32 CFR § 170.19. Paper is not forced into an electronic asset category, but a digital enclave does not make a printed work card disappear. Map issuance through destruction.
Is diagnostic or NDT test equipment automatically a Specialized Asset?
No. Test Equipment is one of the six named Specialized Asset types listed in 32 CFR § 170.19, but the category applies when the asset can handle CUI and cannot be fully secured. If the device can be secured like a normal endpoint, it may simply be a CUI Asset. Build a device dossier — function, storage, ports, network interfaces, vendor supportability, feasible controls — and classify from the facts.
Is my engine test cell or avionics bench going to be audited against 110 controls?
Not if it is properly classified as a Specialized Asset. At Level 2, Specialized Assets are part of the assessment scope and must be documented in the asset inventory, addressed in the System Security Plan, shown on the network diagram, and managed under your risk-based security policy — but they are not assessed against the other CMMC security requirements. Note the asymmetry: at Level 1 they are outside the scope entirely.
Can a hangar tablet or shared kiosk be out of scope?
Possibly, but "view only" is not sufficient. 32 CFR § 170.19 contemplates a narrow configuration — an endpoint hosting a virtual desktop client where no CUI processing, storage, or transmission occurs beyond keyboard, video, and mouse. Test the actual device behavior: cache, clipboard, downloads, print, screenshots, camera, and what survives logout. If the capability exists but policy keeps controlled data out, Contractor Risk Managed is usually the honest category.
Do AOG and field maintenance teams expand our boundary?
They can. If a field device accesses or stores controlled information, that device and the supporting processes follow the data outside your facility. Temporary location does not suspend anything. Standardize a managed field kit with documented offline behavior, remote access, physical custody, photo capture, an incident reporting route, and sanitization on return.
Do our outside NDT, plating, calibration, or component-repair vendors need CMMC?
It depends on what you send them and what the subcontract requires. Determine what information the vendor genuinely needs, whether it is FCI or CUI, and what should flow down under DFARS 252.204-7021 and 32 CFR § 170.23. Do not send the full technical package for convenience, and do not impose a blanket Level 2 demand on every supplier who touches a part.
Does ITAR-controlled technical data automatically mean CMMC Level 2?
Not mechanically. ITAR (22 CFR Parts 120–130) controls export and transfer; CMMC assesses safeguarding of contractor systems. The two frequently overlap on the same document, and export-controlled information has its own CUI Registry category (CUI//SP-EXPT), but one label does not establish the other. Check the CUI authority and contract for the CUI question, and the required CMMC status separately.
Does our DD Form 2345 cover CMMC?
No. DD Form 2345, processed through the Joint Certification Program, is an access-eligibility credential for unclassified militarily critical technical data, not a security assessment and not a guarantee that a particular repository will release data. DLA also requires account approval and a business need for its export-controlled data. What you must do once qualifying data reaches your systems is governed by the applicable contract clauses, including DFARS 252.204-7012 and CMMC where required.
Do we still need to do self-assessment work during the Phase II suspension?
Yes, where your contract requires it. Phase I self-assessment requirements remain in force, the implementation memorandum preserves Level 1 (Self) and Level 2 (Self) designations, and DFARS 252.204-7012 is unchanged. The exact action depends on your solicitation, contract, and the applicable clauses.
Can we still get a third-party certification voluntarily?
Yes. The Cyber AB confirmed in July 2026 that CMMC Level 2 certification assessments, training, examinations, and Registered Practitioner services remain operational. But the Department may not newly designate Level 2 (C3PAO) or Level 3 during the suspension. An existing solicitation, contract, or subcontract can still contain that language until it is formally amended or modified, and a contractor may also pursue a C3PAO assessment voluntarily. Read the document you actually have before deciding why you are doing it.
Our prime is demanding Level 2. What do we ask?
Ask four things in writing: which CMMC level and assessment type, tied to which clause; whether the requirement is at bid, award, option exercise, or subcontract flow-down; what FCI or CUI will actually reach our systems; and what the prime's post-July-13 flow-down position is. Relief given to the Government's contracting officers does not automatically rewrite a subcontract — under DFARS 252.204-7021 the prime flows down the substance of the clause, and that agreement stands until the parties change it.
What if we hold no CUI at all — are we finished?
Not necessarily, and this is the finding most maintenance shops have never seen. DFARS 252.204-7012's reporting duties can attach where a contract designates and identifies performance as operationally critical support — defined in the clause as supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation, or logistical support essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation. Aircraft sustainment can fit that description, but neither you nor a vendor can make the designation. Ask your contracting officer whether any part of your performance carries it.
Should an MRO buy a CUI enclave?
Only after mapping the workflows. An enclave can meaningfully shrink a digital boundary when controlled data can genuinely stay inside it, and for a mixed MRO the boundary should follow data provenance rather than the organization chart. It will not, by itself, resolve paper packets, phone photographs, USB-only test equipment, field work, or uncontrolled vendor transfers.
Is CMMC the same as CMMS?
No. CMMC is the Cybersecurity Maturity Model Certification, a Department of Defense cybersecurity program established at 32 CFR Part 170. CMMS is computerized maintenance management software. A CMM in aviation is a Component Maintenance Manual. Three unrelated things that share an unfortunate number of letters.
The bottom line
You do not need to memorize 110 controls this week. You need four answers, in this order.
One: what your contract actually requires — the level, the assessment type, the clause, and the date. Two: which contracts and maintenance workflows use verified Government-controlled task data and which do not. Three: which contractor information systems and shop-floor devices land in which asset category, and what evidence supports each call. Four: whether any part of your performance is designated as operationally critical support, because that duty runs on its own clock and does not wait for a CMMC level.
Get those four, and every quote you receive afterward becomes legible. Skip them, and you will buy scope you don't owe while missing a reporting obligation you do.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
Find My CMMC Path → · Download the CMMC Readiness Checklist →
Already know what you need? Request scoped quotes from matched provider categories →
Do not submit CUI, drawings, technical orders, work cards, aircraft or tail data, photographs, program names, network diagrams, credentials, or sensitive contract details. This intake is for provider-category routing only.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial and Advertising Policy.
Related reading
- 32 CFR Part 170: What the CMMC Final Rule Requires
- What the July 2026 Phase II Suspension Changed
- CMMC Scoping Guide: Level 2 Asset Categories
- CMMC for Aerospace Suppliers — the broader industry guide, for new-part production rather than sustainment
- CMMC for Machine Shops
- CMMC for Subcontractors: Flow-Down Explained
- NIST SP 800-171 Rev. 2 vs Rev. 3
- CMMC Level 2 Checklist: Evidence Across All 110 Requirements
- CMMC Managed Enclaves: Scope Reduction
- SPRS Scores and CMMC Status Records
- CMMC Level 2 Cost Guide
- CMMC Levels · Who to Hire First · Provider Categories
- Our Methodology · Editorial Standards · Corrections Policy