The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · aerospace sustainment and CMMC scope

CMMC for MRO and Aircraft Maintenance: 2026 Scope Map

Last updated:

Last verified: against 32 CFR Part 170, DFARS, the CUI Registry, DoD guidance, and related primary sources.

Current status — last verified August 17, 2026. The Department suspended the CMMC Phase II transition on July 13, 2026, including the originally scheduled November 10, 2026 start of Phase II. During the suspension, new procurement requirements may designate CMMC Level 1 (Self) or CMMC Level 2 (Self) only — not Level 2 (C3PAO) or Level 3 (DIBCAC). Phase I self-assessment requirements and DFARS 252.204-7012 remain in force. If an active solicitation, contract, or subcontract still names a third-party assessment, treat that written language as operative until it is formally amended or modified.

By The Defense Compliance Report Editorial Team · Last verified: August 17, 2026 · Editorial research — not formally reviewed by a CMMC Subject Matter Advisor.


The short answer

CMMC for MRO and aircraft maintenance is decided by the written procurement requirement and by each contractor information system that will process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) — not by the word “MRO.” It does not attach because you repair aircraft or hold an FAA repair-station certificate. If the procurement requires Level 2 for systems handling CUI, those systems enter the Level 2 path. If it requires Level 1 for FCI-only systems, those systems follow Level 1. A mixed maintenance business can have different boundaries across contracts and workflows, but “line of business” is not the legal unit the rule assesses.

Now the part that surprises people, and the reason this page exists: there is a second obligation that can land on a maintenance shop with no CUI at all. DFARS 252.204-7012 has a trigger most MROs have never read — one that expressly covers Government-designated logistical support essential to mobilization, deployment, or sustainment in a contingency operation. We'll get to it. First, four conditions decide your answer:

  • Which platform you're working on. A pure military platform and a commercial-derivative airframe are not the same data problem.
  • Where the task data came from. A government technical order and a commercial OEM manual are not the same document, legally.
  • Whether a government-furnished article, test set, or maintenance aid can store or transmit information. The FAR definition of government-furnished property expressly covers items furnished for repair, maintenance, and overhaul, but government ownership alone does not decide CMMC scope.
  • What your contract says about operationally critical support. This is the one nobody checks.

The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance. We work from primary sources, separate regulatory text from editorial analysis, and map a contractor's level, CUI scope, assessment type, and timeline to the provider category that fits before the contractor spends six figures.

One quick disambiguation, because the acronyms collide in this industry: CMMC is the Cybersecurity Maturity Model Certification, a Department of Defense cybersecurity program. It is not CMMS (maintenance management software) and not a CMM (Component Maintenance Manual). If you landed here looking for either of those, this isn't your page.


Who this is for — and who should stop reading

Question — Direct answer
QuestionDirect answer
Who this is forDefense-facing MROs, FAA Part 145 repair stations, component overhaul shops, depot and sustainment contractors, contractor logistics support providers, and lower-tier repair vendors trying to determine which maintenance workflows enter a CMMC boundary.
Who this is not forCivil-only maintenance organizations with no defense contract, no flow-down, and no FCI or CUI. Nothing on this page applies to you. Close the tab and go turn wrenches.
What actually decides the answerThe written procurement requirement, the real control status of the information, where that information physically and digitally travels, and what each system or device does. Not the letters “MRO.”
What changed in July 2026The Phase II transition and later milestones were suspended. Phase I self-assessment requirements and DFARS 252.204-7012 were not.
Your first moveAssemble the clause pack and walk one complete maintenance job end to end — before you price a platform, an enclave, or an assessment.

Jump to: Does it apply? · What the suspension changed · Which maintenance data is CUI · The zero-CUI clause · Is my shop floor in scope? · Why platform matters · Hangars, AOG, and vendors · Does AS9110 or Part 145 count? · Which level to plan for · Your first 30 days · Who to hire first · What goes wrong · FAQ


Who does CMMC for MRO and aircraft maintenance apply to?

CMMC applies to a maintenance organization when a DoD solicitation, contract, subcontract, or written flow-down requires a CMMC status for contractor information systems that will process, store, or transmit FCI or CUI in performance of that contract. 32 CFR § 170.3 reaches applicable DoD solicitations and contracts valued above the micro-purchase threshold, including commercial-item acquisitions, but excludes acquisitions solely for commercially available off-the-shelf (COTS) items. Holding an FAA repair-station certificate, an AS9110 certification, or an aerospace prime's approval does not by itself create a CMMC obligation.

We want to be blunt about this, because the sector gets sold on its own label. Vendor pages often argue that an MRO needs Level 2 because MROs handle sensitive technical data. That is a marketing syllogism, not the rule. The rule is contract-driven. Under § 170.3(d), the DoD program manager or requiring activity selects the CMMC status for a given procurement based on the type of information involved — FCI or CUI. It shows up in your solicitation. You don't infer it from your NAICS code.

The three questions that settle applicability

1. What does the written procurement document actually require?

Look for two things. DFARS 252.204-7025 is the solicitation provision that tells offerors which CMMC level applies; the contracting officer fills a blank with exactly one of four values — CMMC Level 1 (Self), CMMC Level 2 (Self), CMMC Level 2 (C3PAO), or CMMC Level 3 (DIBCAC). DFARS 252.204-7021 is the contract clause that makes maintaining that status a condition of eligibility for the duration of the contract, requires an annual affirmation, and requires flow-down of the substance of the clause. Record the exact level and assessment type. “CMMC required” is not a requirement you can act on.

One detail worth capturing while you're in there: 252.204-7025 requires the offeror to provide the CMMC unique identifier (UID) in the proposal for each system that will handle FCI or CUI. A CMMC UID is a 10-character alphanumeric identifier assigned to a CMMC assessment and reflected in SPRS — the Supplier Performance Risk System, the DoD database where assessment results and affirmations live. If you can't produce a UID and the solicitation asks for one, you have found your gap before it found you.

2. What information will your systems actually handle in performance?

Four honest answers: FCI only, verified CUI, both, or unresolved. “Unresolved” is a legitimate day-one answer. It is not a reason to guess high.

3. Which of your systems will touch it?

Not just the file server. The technical library, the maintenance management system, the engineering workstation, the hangar tablet, the printer, the field laptop, the backup, the security tooling, and every outside service in the path.

Quick applicability check

Your situation — Preliminary answer — Proof to obtain
Your situationPreliminary answerProof to obtain
Civil-only maintenance; no defense contract or flow-down; no FCI or CUICMMC is not triggered by being an MROConfirm the customer and data path; keep defense information out of the shop
Defense work, FCI only, written requirement states Level 1 (Self)Level 1 path with 15 basic safeguardsThe provision or clause, in-scope system list, annual self-assessment, current SPRS status, and affirmation
Defense work involving verified CUI, written requirement states Level 2 (Self)Level 2 self-assessment against all 110 NIST SP 800-171 Rev. 2 requirementsThe written requirement, CUI map, defined assessment scope, score, CMMC UID, and affirmation in SPRS
Active document still states Level 2 (C3PAO) after July 13, 2026Do not delete it yourselfA formal solicitation amendment, contract modification, or mutually executed subcontract change
Work occurs inside a Government system or service operated on the Government’s behalfThat federal system may fall outside Part 170Contract language, system ownership, authorization boundary, connection instructions, and control-responsibility documentation
You cannot determine whether records are controlledDo not declare all or declare noneMarkings, source, CUI authority, contract language, content review, and written guidance from the authorized customer authority
Procurement is solely for COTS items or valued at or below the micro-purchase thresholdPart 170 does not apply to that procurementThe solicitation, value, item classification, and a documented rationale

The carve-out almost nobody applies to sustainment work

Here is a provision we rarely see quoted on aerospace pages, and it matters more in maintenance than in manufacturing. 32 CFR § 170.3(b) says Part 170 does not apply to federal information systems operated by contractors or subcontractors on behalf of the Government. DFARS 252.204-7012 draws a parallel line at paragraph (b)(1): for covered contractor information systems that are part of an IT service or system operated on behalf of the Government, cloud services fall under DFARS 252.239-7010 and other services fall under requirements specified elsewhere in the contract.

Translate that into a hangar. A .mil login, a government laptop, or a GFE label does not prove the carve-out by itself. The question is whether the system is actually a federal information system operated by the contractor on behalf of the Government. If the contract and responsibility documentation establish that fact, that piece of the environment is governed differently from your corporate network. Contractor logistics support and depot-augmentation crews can encounter this split.

Two mistakes come out of it. The first is assuming that because the work happens in a .mil system, the company is out of CMMC entirely. It isn't — your own contractor information systems still enter scope when the written requirement applies and they process, store, or transmit FCI or CUI. The second is the reverse: dragging the whole corporate network into scope because technicians use a government portal. The correct move is to get the boundary in writing. Ask for the responsibility documentation, the connection instructions, and a plain statement of which side owns which controls.

Do not spend a dollar until this section is settled. Every cost decision downstream is built on it.


What the July 2026 CMMC Phase II suspension changed for maintenance contractors

On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II and the later implementation milestones, including the November 10, 2026 date on which Phase II was scheduled to begin. Phase I began November 10, 2025 and, under the original one-year schedule, was scheduled to run through November 9, 2026; the planned transition on November 10, 2026 is the milestone now suspended. The official CMMC status page says all Phase I self-assessment requirements remain in place. The implementing memorandum preserves Level 1 and Level 2 self-assessment designations, NIST SP 800-171 Revision 2 as the Level 2 baseline, SPRS posting, and annual affirmations where the applicable procurement or contract requires them. DFARS 252.204-7012 is untouched. A CMMC Reform Task Force was directed to report to the Department CIO within 60 days; that deadline falls on September 11, 2026.

We read the implementing memorandum ourselves rather than working from the press coverage, and three details in it change what you should do this month.

First, the designation limits are hard. During the suspension, program managers and requiring activities must only include CMMC Level 1 (Self) or CMMC Level 2 (Self), and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). The codified phase schedule still contains the original Phase I discretion language, but the later implementing memorandum controls Department designation practice during this suspension and says “may not.” Read the current memorandum, not the old rollout paragraph by itself.

Second, no waivers during the review. The memorandum states that no waivers shall be granted while the program is under review.

Third — and this is the one that costs money — existing requirements come out by paperwork, not by announcement. Active solicitations are to be amended. Requirements in awarded contracts are removed by modification prior to the exercise of the next option period or during the next scheduled administrative modification. Until your document is actually modified, the clause on your contract is still the clause on your contract. A news release is not a contract change. Ask your contracting officer in writing and keep the answer.

Planned rollout versus where things actually stand

Issue — Before July 13, 2026 — Verified status as of August 17, 2026
IssueBefore July 13, 2026Verified status as of August 17, 2026
Phase I windowBegan November 10, 2025; original one-year window was scheduled to end November 9, 2026Still in effect for applicable Level 1 (Self) and Level 2 (Self) requirements
November 10, 2026 Phase II transitionScheduledSuspended
New Level 1 (Self) designationsAvailableAllowed
New Level 2 (Self) designationsAvailable during Phase IAllowed
New Level 2 (C3PAO) designationsPermitted under the codified phase schedule and planned to expand in Phase IIProgram managers and requiring activities may not designate them during the suspension
New Level 3 (DIBCAC) designationsPlanned for a later phaseProgram managers and requiring activities may not designate them during the suspension
DFARS 252.204-7012 safeguarding and reportingIn forceStill in force
Voluntary Level 2 certification assessmentAvailableStill available; it is not a new Department designation
Level 2 (C3PAO) or Level 3 language already in a solicitation, contract, or subcontractControlled by the written documentTreat it as operative until formally amended, modified, or changed by the parties

While you were watching that, your clause numbers changed

This is separate from the suspension and it trips people up badly, because two subtractions landed within six months of each other and the combined effect reads like the whole program evaporated.

On February 1, 2026, a Department class deviation issued under the Revolutionary FAR Overhaul changed which cybersecurity clauses contracting officers are directed to use in covered actions. Under that deviation, DFARS 252.204-7019 is omitted, and DFARS 252.204-7020 is replaced by DFARS 252.240-7997 under Part 240. The deviation clause defines Medium and High assessments performed by the Government and removes the former Basic-assessment submission machinery. The FAR deviation model uses FAR 52.240-93 in place of FAR 52.204-21 with the same 15 basic safeguards. DFARS 252.204-7012, 252.204-7021, and 252.204-7025 are unchanged.

The governing instrument is Class Deviation 2026-O0025, now at Revision 2 dated July 16, 2026. Because this is deviation text ahead of formal rulemaking, the codified FAR and DFARS still display the legacy clause numbers, and older or unmodified instruments may still contain them. You may see either set. Read the clause actually incorporated into the document in front of you.

Codified or legacy citation — Treatment in covered deviation actions — What it means for a maintenance contractor
Codified or legacy citationTreatment in covered deviation actionsWhat it means for a maintenance contractor
DFARS 252.204-7019Omitted from the deviation’s covered solicitation and contract actionsThis is not a universal repeal of the codified provision. Older or unmodified documents may still contain it; read the provision actually incorporated.
DFARS 252.204-7020Replaced by DFARS 252.240-7997 in covered deviation actionsThe replacement defines Government-performed Medium and High assessments and does not carry forward the former Basic-assessment mechanism.
FAR 52.204-21FAR-deviation counterpart is FAR 52.240-93The same 15 basic safeguards are carried forward in the deviation model; 32 CFR Part 170 still cites the codified FAR 52.204-21 requirements.
DFARS 252.204-7012UnchangedNIST SP 800-171 safeguarding, 72-hour reporting, media preservation, malware handling, and flow-down remain.
DFARS 252.204-7021 and 252.204-7025UnchangedThe CMMC contract clause and solicitation provision still govern status, affirmation, UIDs, eligibility, and CMMC flow-down where included.

Two events in six months, both of them subtractions. Understandable that people concluded the program was dead. It isn't. The Phase II contract gate paused. Government assessment authority and the underlying security obligations did not.

Map your current requirement before you price anything

The fastest way to waste money right now is to buy against a milestone that no longer exists. Tell The Defense Compliance Report's Find My CMMC Path tool the level your document actually states, whether you handle FCI or CUI, your general environment, and your next contract or option date. It maps your situation to the provider category that fits the current requirement — no sales call, no obligation.

Map my current CMMC path →

Do not submit CUI, drawings, technical orders, aircraft or tail data, program names, or contract attachments. Category-level answers only.


Which aircraft maintenance data is actually CUI?

Maintenance information is not CUI because it is technical, nonpublic, tied to a military aircraft, or important to flight safety. For the most common category here — Controlled Technical Information — DFARS 252.204-7012 requires military or space application, dissemination controls, and information that would meet the criteria for Distribution Statements B through F under DoD Instruction 5230.24. To be covered defense information, it must also be controlled technical information or another CUI Registry category that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy and must fit one of the clause's two contract-performance prongs. The National Archives CUI Registry lists Controlled Technical Information as CUI Specified, banner marking CUI//SP-CTI, with 48 CFR 252.204-7012 as the authority. Verify each artifact against the full test before designing a boundary around it.

We spent real time in the clause text for this section, and three findings came out of it that change how a maintenance shop should think about its own paperwork.

Finding one: the clause names your document set out loud

The definition of "technical information" in DFARS 252.204-7012 comes with examples. Here they are, in the clause's own order: research and engineering data, engineering drawings and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses, and computer software executable and source code.

Process sheets. Manuals. Technical orders. That is not a manufacturing list. That is the contents of a technical library and a workbench. The CUI Registry's Controlled Technical Information entry repeats the same examples. And DoD Instruction 5230.24 — the instruction that supplies the distribution-statement criteria — states its own purpose as covering technical documents including research, development, engineering, test, sustainment, and logistics information. Sustainment is named in the source instruction. Maintenance was never an afterthought in this framework; the industry just read it that way.

Finding two: the marking is a signal, not the test

Read the definition again. Controlled Technical Information is information that would meet the criteria for Distribution Statements B through F. That is a characteristic of the information and its authorized dissemination controls, not merely a property of whether somebody remembered to stamp the cover page. A B-through-F statement is powerful evidence; it is not a substitute for checking the complete CUI authority, contract context, and content.

For quick orientation, the statements run: A — approved for public release, unlimited. B — U.S. Government agencies only. C — U.S. Government agencies and their contractors. D — DoD and U.S. DoD contractors only. E — DoD Components only. F — further dissemination only as directed by the controlling DoD office.

Practical consequence: an unmarked drawing can still be controlled when the contract or authorized Government source otherwise identifies it and the content meets the applicable category, and a marked document tells you a great deal. Neither fact licenses you to classify by vibe. When the status is unclear, the correct output is a written question to the customer's authorized data owner, program office, or contracting officer — not a homemade determination.

Finding three — the one that separates maintenance from manufacturing: you create it

Covered defense information under DFARS 252.204-7012 has two prongs. The first covers otherwise-qualifying controlled technical information or other CUI that is marked or otherwise identified in the contract and provided to you by or on behalf of DoD. Everybody knows that one. The second prong covers otherwise-qualifying information “collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.” The verb list expands how qualifying information can enter the clause; it does not turn every record created during performance into CUI.

Sit with that for a second, because it lands differently in an overhaul shop than in a machine shop.

A manufacturer receives a technical data package and makes a part. An overhaul shop receives a technical order — and then generates a body of technical information that did not previously exist. As-found condition reports. Teardown findings. Dimensional inspection results against military wear limits. Eddy current and ultrasonic results on a military component. Photographs of a crack in a specific structure. Repair dispositions and deviation requests routed to a government engineering authority.

Nobody handed you those. You made them. And under prong two they can be covered defense information when their content meets the Controlled Technical Information test or another applicable CUI category and they were developed in support of contract performance. This is, in our editorial judgment, one of the most consistently missed exposures in aviation sustainment. The data you're most careless with is often the data you produced yourself, because it doesn't arrive with a banner on it.

The five-part evidence test

Before you conclude anything about an artifact, capture five things. Every row in the table below assumes you've done this.

  1. Source. Government, prime, OEM, customer, your own derivative, or genuinely public and commercial.
  2. Authority or marking. CUI banner and category, distribution statement, export-control marking, contract instruction, or agency guidance.
  3. Purpose. Created, received, or used in performance of which contract or program.
  4. Content. Does it actually contain controlled technical detail — or only transactional, scheduling, and quality data?
  5. Written clarification. What did the customer or program office say when the answer wasn't obvious? Get it in writing and keep it with the record.

The MRO Data-Provenance Map

This is our editorial synthesis. No primary source supplies an artifact-by-artifact MRO map, so we applied the governing definitions to the records and devices that actually move through a repair station. Read the caveat that follows it before you use it.

Artifact or record — Evidence that could make it controlled — verify, do not assume — Where it travels — Scope treatment to test — Failure mode to test
Artifact or recordEvidence that could make it controlled — verify, do not assumeWhere it travelsScope treatment to testFailure mode to test
Military technical order or interactive electronic technical manualQualifying military or space technical content, a Distribution Statement B through F or other CUI authority, and one of the DFARS 252.204-7012 contract-performance prongsTechnical library, tablets, browser cache, printers, paper binders, backupsSystems handling verified CUI are CUI Asset candidates; paper needs a physical handling processLocal downloads, emailed copies, uncontrolled printing, or obsolete sections retained after supersession
Commercial OEM aircraft or component manual under a Type CertificateOrdinary commercial licensing or OEM proprietary status alone does not make it CUI; a controlled Government supplement, variant, or qualifying derivative can change the answerOEM portal, technical library, local PDF storeOut of scope only where the system cannot handle CUI; Contractor Risk Managed where capability exists but policy, procedures, and practice keep CUI outDeclaring every OEM manual controlled and pulling the civil business into scope
Technical data package or engineering drawing for a repairCUI marking or authority, restrictive distribution criteria, qualifying technical content, and contract contextCAD viewer, PLM, engineering workstation, email, display, printerCUI Asset candidates where verified CUI is presentUnsecured PDF export, local CAD cache, screen photo, uncontrolled redline
Process specification for plating, NDT, heat treat, bonding, or paintThe document name appears in the clause’s technical-information examples, but control still requires qualifying content, authority, and contract contextQuality system, binders, vendor packages, laminated station copiesCUI Asset candidates for systems with verified CUI; physical controls for paperSending a complete controlled specification to a special-process vendor that needed only a narrow requirement
Government-furnished aircraft, engine, component, test set, or maintenance aidGovernment-property status alone does not make information controlled; onboard memory or an embedded system may process, store, or transmit CUIDock, hangar, bench, field kitGFE Specialized Asset candidate only when it can handle CUI and cannot be fully secured; otherwise classify from actual functionTreating every Government-owned article as automatically in scope or automatically outside scope
As-found or teardown condition report created by the shopThe content independently meets a CUI category and the contractor-development prong of DFARS 252.204-7012 appliesMaintenance system, engineering, email, portal, attachmentsCUI Asset candidates where controlled technical detail is created or storedTreating self-generated findings as ordinary business records because nothing arrived stamped
NDT or NDI results, radiographs, eddy-current data, or ultrasonic dataQualifying military technical detail, controlled limits, platform condition, and applicable authority or contract contextInstrument memory, acquisition workstation, image server, USB, portalCUI Asset if normally securable; Specialized Asset candidate if it can handle CUI and cannot be fully securedInstrument retention, USB export, consumer file transfer, or vendor copies kept indefinitely
Repair disposition, engineering order, or deviation requestReproduction or derivation of qualifying controlled drawings, limits, platform condition, or other authorized CUIEngineering, email, maintenance system, printed packetCUI Asset candidates where verified CUI is presentA “summary” that copies controlled dimensions and defect detail into a broadly accessible system
Depot work requirement, statement of work, or contract attachmentNonpublic information provided by or generated for the Government may be FCI; CUI requires an authorized category and applicable control basisContract repository, proposal drive, email, e-signature serviceLevel 1 systems for FCI only; CUI Assets when controlled content is present and Level 2 is requiredMissing a cyber clause or data-handling instruction buried in an attachment
Configuration, modification, readiness, or tail-status dataAn identifier alone does not decide CUI; content, aggregation, authority, and contract context canConfiguration system, maintenance system, portal, analyticsCUI Asset candidates only where the dataset is verified CUITreating one tail number as automatically controlled or ignoring a controlled aggregated dataset
Work cards, travelers, route sheets, or job packetsControlled fields, copied limits, drawings, technical-order pages, photographs, or other attachmentsMaintenance system, kiosks, scanners, printers, packet racksAnywhere from CUI Asset to defensibly out of scope depending on what the workflow permitsPrinting a whole controlled technical package into the traveler or leaving packets unsecured
Illustrated parts breakdown with military part numbersThe document type can be technical information, but the source, authority, content, and distribution restrictions decide whether it is controlledTechnical library, planning, purchasing, printClassify from the source document and actual fields copied downstreamPasting controlled breakdowns into purchase orders and supplier emails
Photographs or video of damage, components, screens, or completed workThe image captures or creates qualifying controlled technical detail; not every aircraft image is CUICompany or personal phone, tablet, photo sync, chat, quality systemDevices used for verified controlled imagery are CUI Asset candidatesAutomatic consumer-cloud backup, text messaging, or uncontrolled metadata and retention
Calibration and metrology recordsCalibration status alone is ordinarily business or quality data; controlled procedures, program limits, or technical attachments can change itCalibration system, lab instruments, certificates, vendor portalUsually business or FCI systems; CUI path only where controlled content entersOverscoping every certificate or forwarding a controlled test procedure to a commercial lab
Shipping, receiving, traceability, and material-certification recordsUsually transactional or quality information; controlled fields or attachments can change the answerERP, scanners, supplier portal, labels, paper packetsLevel 1 or business systems unless verified CUI entersAttaching a full technical package to a purchase order for convenience
Avionics mission data, software load, or portable data-loader packageThe load’s content, platform, markings, dissemination authority, and contract decide; many are controlled, but not allData loader, diagnostic laptop, removable media, GFECUI Asset or Specialized Asset candidate depending on device function and securabilityTreating a loader as a hand tool while it retains a controlled software load

What this page will not do

We will not tell you that every military-aircraft maintenance record, tail number, part number, NDT image, technical manual, or work card is CUI. Nothing in the primary sources supports a blanket rule like that, and pages that assert one are selling you scope you may not owe. Where the status of a document is unresolved, the correct output is an evidence request — not a confident guess. Overscoping is not the safe choice. It is a different expensive mistake, and it is the one that makes technicians route around your controls.

Small next step, no email required: build your own version of the table above for one program. Source, marking, purpose, content, systems touched, unresolved question, owner, date. One page per program. That single artifact will do more for your budget conversation than any tool you buy this quarter.


The DFARS clause that can hit your shop with zero CUI

DFARS 252.204-7012 has a second trigger that has nothing to do with CUI. The clause defines “operationally critical support” as supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation services, or logistical support essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation. Where a contract designates and identifies performance as operationally critical support, the clause's cyber incident reporting duties attach to incidents that affect the contractor's ability to perform that work — whether or not covered defense information is involved.

Aircraft sustainment can fall squarely within that definition, but only when the Government makes the designation and the contract identifies the work. And this is where a maintenance organization can end up in a position no generic CMMC guide describes: carrying the incident-reporting machinery of DFARS 252.204-7012 while its CMMC path is only Level 1, or while Part 170 does not apply to the procurement at all.

Read paragraph (c)(1). The reporting duty attaches when the contractor discovers a cyber incident that affects a covered contractor information system, or the covered defense information in it, or that affects the contractor's ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract. Three separate triggers, joined by "or."

Then read paragraph (m)(1). The prime must include the clause in subcontracts "for operationally critical support, or for which subcontract performance will involve covered defense information." Operationally critical support is listed as its own category of subcontract, separate from covered defense information. A maintenance sub can receive this clause on logistics grounds alone.

The guardrail, stated plainly: it must be designated by the Government and identified in the contract. You cannot self-declare it. Neither can we, and neither can a vendor. It is a contract-reading question, which is exactly why the action item at the end of this section is a written question rather than a purchase order.

What attaches when it applies

If your contract designates operationally critical support — or if you hold covered defense information — DFARS 252.204-7012 paragraphs (c) through (g) put five operational duties on you. Not one of them is a control from the 110. All five are things you either set up in advance or fail in real time.

Duty — Clause paragraph — What it means on a Friday night
DutyClause paragraphWhat it means on a Friday night
Rapidly report(c)(1)(ii), with “rapidly report” defined in paragraph (a)Report through the DoD incident path within 72 hours of discovery. The clock runs on discovery, not final confirmation, and weekends do not stop it.
Review for compromise and operational impact(c)(1)(i)Identify affected computers, servers, data, and user accounts; examine other reachable systems; determine whether operationally critical support was affected.
Submit isolated malicious software(d)Follow DC3 instructions. Do not send malicious software to the contracting officer or by ordinary email.
Preserve media and monitoring data(e)Preserve and protect images of known affected systems plus relevant monitoring and packet-capture data for at least 90 days from report submission.
Support forensics and damage assessment(f) and (g)On request, provide access to additional information or equipment for forensic analysis and supply damage-assessment information.

The reporting-access problem you do not want to discover inside 72 hours

Paragraph (c)(3) of the clause states that in order to report cyber incidents, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate. The current DC3/DCISE reporting page says the certificate is required for the secure portal.

If the first time your team tests the reporting path is during an incident, the 72-hour clock is already running. Confirm the current portal path now, provision the required certificate for at least two named people, and write their names into your incident response plan. Then document the current emergency fallback: DC3 says a contractor that does not yet have the certificate and needs to report should email DC3.DCISE@us.af.mil or call 410-981-0104 for reporting assistance, and must not email malicious files. Provision normal access anyway. The fallback is not a substitute for readiness.

The scenario that makes this concrete

A component overhaul shop supports engine accessories under a sustainment contract. No engineering drawings on the network — the customer keeps those in a portal. The shop is confident it holds no CUI, and it may well be right.

On a Friday afternoon, a technician's workstation starts encrypting files. The maintenance management system goes down. Turnaround commitments on a fleet sustainment line slip. Nobody has exfiltrated a drawing, because there were no drawings to take.

Under the CUI analysis, this shop is at Level 1 or outside CMMC. Under paragraph (c)(1), if the contract designates and identifies its performance as operationally critical support, the incident affected its ability to perform that work — and the 72-hour clock started at discovery on Friday. Nobody is going to call and remind them.

That mismatch — safeguarding and reporting duties running ahead of the CMMC level — is the single most useful thing an MRO can learn from this page. It is also largely absent from generic MRO CMMC guidance.

Check your reporting readiness before you check anything else

The controls are what vendors sell; the incident duties are what can fail at 11:00 p.m. on a Friday. Our CMMC Readiness Checklist is a 32-point review mapped to the NIST SP 800-171 Revision 2 control families plus separate contract duties for reporting, evidence, malware handling, and media preservation. Those reporting duties are not part of the 110, which is exactly why they are easy to miss.

Download the CMMC Readiness Checklist →

Free, no obligation. Do not upload contracts, CUI, drawings, technical orders, incident details, or network diagrams through the form.


Is your shop floor in scope? The five asset categories in hangar language

At CMMC Level 2, an asset's treatment follows what it can and does process, store, transmit, or protect — not where it physically sits. 32 CFR § 170.19(c)(1) sorts assets into CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets, each carrying a different documentation and assessment burden. Specialized Assets can include six named types: Government Furnished Equipment, Internet of Things devices, Industrial Internet of Things devices, Operational Technology, Restricted Information Systems, and Test Equipment. At Level 2 they are in scope and must be documented, but they are not assessed against the other CMMC security requirements.

Here is the relief you came for, and then the catch.

The relief: if your engine test cell, avionics bench, eddy current set, or 1990s brick of a data loader actually meets the Specialized Asset definition, it is not assessed against the other 110 Level 2 requirements.

The catch: you do not get the label because a device is old, proprietary, inconvenient, or located on the floor. It must be able to process, store, or transmit CUI and be unable to be fully secured. At Level 2, a qualifying Specialized Asset is in scope for documentation, and the documentation is assessed. There is a real asymmetry in the rule that catches people who read about Level 1 and assumed it carried over. Under § 170.19(b)(2)(ii), Specialized Assets are outside the Level 1 self-assessment scope and are not assessed. Under § 170.19(c)(1), at Level 2 they are inside the assessment scope — documented in the asset inventory, addressed in the System Security Plan, shown on the network diagram, and managed under your risk-based security policy and procedures. Not assessed against the other requirements. Very much on the list.

The five categories

Category — What it means in a hangar — What the rule requires — MRO example to test — not a determination
CategoryWhat it means in a hangarWhat the rule requiresMRO example to test — not a determination
CUI AssetProcesses, stores, or transmits CUIAsset inventory, SSP treatment, network diagram, and assessment against Level 2 requirementsMaintenance system storing a verified controlled work package; tablet downloading a controlled technical order
Security Protection AssetProvides security functions or capabilities to the CMMC environment and may process Security Protection DataAsset inventory, SSP treatment, network diagram, and assessment against requirements relevant to the capability providedIdentity provider, firewall, endpoint detection, log platform, or MSP remote-management tooling
Contractor Risk Managed AssetCan handle CUI but is not intended to because documented policy, procedures, and practices keep it outInventory, SSP treatment, network diagram; no other requirement testing if documentation is sufficient, but a limited check is allowed when findings raise questionsShop-floor PC technically capable of receiving CUI but kept out of the approved path by controls that are actually enforced
Specialized AssetCan process, store, or transmit CUI, cannot be fully secured, and fits IoT, IIoT, OT, GFE, Restricted Information System, or Test EquipmentInventory, SSP treatment, network diagram, and risk-based management; reviewed in the SSP but not assessed against the other CMMC requirementsProprietary NDT appliance, unsupported data loader, or GFE test set when the facts meet the complete definition
Out-of-Scope AssetCannot process, store, or transmit CUI and provides no security protection for CUI Assets, or is physically or logically separated; the rule also includes a narrow KVM-only VDI exampleBe prepared to justify inability or separation; no Level 2 assessment requirementsCivil-only kiosk with enforced technical separation from every controlled path

Two disciplines matter more than the labels.

Contractor Risk Managed is not a synonym for out of scope. It is a documented, inventoried, diagrammed category for capable-but-controlled assets. Reaching for "out of scope" when you mean "we have a policy against it" is the fastest way to lose credibility in a scoping review. Out-of-scope requires inability or separation you can demonstrate — not intent.

The rule's narrow virtual-desktop example is narrow. § 170.19 contemplates an endpoint hosting a virtual desktop client, configured so that no CUI processing, storage, or transmission occurs beyond keyboard, video, and mouse, being treated as out of scope. That is a specific configuration, not a general permission slip for anything labeled "view only." Before you rely on it, test the actual behavior: cache, clipboard, local drives, downloads, print, screenshots, camera, and what survives a logout or a power cycle.

Two provisions written as though somebody had visited a hangar

An avionics test bench that must replicate a fielded configuration may fit the rule's own Enduring Exception example. 32 CFR § 170.4 defines an Enduring Exception as a special circumstance or system where remediation and full compliance are not feasible, and gives examples: systems required to replicate the configuration of “fielded” systems, medical devices, test equipment, operational technology, and IoT. It adds that no operational plan of action is required, but the circumstance must be documented within a System Security Plan, and that Specialized Assets and GFE may be Enduring Exceptions.

“A system required to replicate the configuration of a fielded system” can describe an avionics bench that genuinely has to match an aircraft baseline. It does not describe every test bench. If the facts fit, document why full remediation is infeasible, how the system is managed, and why the fielded configuration must be preserved. Do not use “Enduring Exception” as a label that ends the risk conversation.

Government-furnished property expressly covers overhaul work. Government Furnished Equipment takes its meaning from government-furnished property at FAR 45.101, which includes spares and property furnished for repair, maintenance, overhaul, or modification. The FAR definition names your business. But property status alone does not put an article into a CMMC asset category. If a government-furnished line replaceable unit, test set, or portable maintenance aid can process, store, or transmit CUI and cannot be fully secured, it is a GFE Specialized Asset candidate and belongs in the Level 2 inventory.

The Aircraft Maintenance Specialized-Asset Ledger

Shop-floor asset — Category to test first — Assessed against the 110? — Evidence to produce — MRO mistake
Shop-floor assetCategory to test firstAssessed against the 110?Evidence to produceMRO mistake
Avionics test bench or automated test equipmentTest Equipment candidate; Enduring Exception may apply when a fielded baseline must be preserved and full remediation is infeasibleNo if it satisfies the Specialized Asset definition; otherwise classify normallyFunction, data, storage, interfaces, supportability, fielded-configuration rationale, inventory, SSP, diagram, risk treatmentCalling every bench an Enduring Exception without proving the baseline or infeasibility
Engine test-cell instrumentationOperational Technology candidate only if it handles CUI and cannot be fully securedNo if Specialized; otherwise depends on actual functionData path, controller architecture, segmentation, supportability, inventory, SSP, diagramLeaving the cell off the diagram because “it is not IT”
Digital NDT equipmentTest Equipment candidate or CUI AssetDepends on whether it can be fully securedDevice dossier, storage, ports, network interfaces, export path, vendor supportLabeling it Specialized merely to avoid controls
Portable data loaderTest Equipment candidate or CUI AssetDependsLoads retained, duration, interfaces, custody, update and sanitization processTreating a loader that retains controlled data as a hand tool
CNC or repair-machining equipmentOperational Technology candidate only when it handles CUI and cannot be fully securedNo if Specialized; otherwise dependsProgram-transfer path, local storage, interfaces, segmentation, supportabilityProtecting the server but ignoring how the program reaches the machine
Calibration or metrology equipmentUsually out of CUI scope; Test Equipment or CUI Asset only when the data path supports itDepends on actual data and securabilityRecords location, procedures loaded, vendor transfer, storage behaviorSending a controlled procedure to a commercial calibration house
Portable maintenance aid or technical-order tabletGFE candidate if Government furnished; otherwise CUI Asset or Contractor Risk ManagedDependsCache, download, clipboard, print, camera, offline behavior, persistence after logoutTreating a shared tablet as a screen rather than a storage-capable endpoint
Government-furnished test setGFE Specialized Asset candidate only if it handles CUI and cannot be fully securedNo if SpecializedCustody, function, information handled, connection instructions, responsibility splitAssuming Government ownership alone proves it is outside scope or Specialized
Government-furnished article with onboard memoryGFE candidate; category follows actual information function and securabilityDependsMemory function, data retained, connection and download path, custodyInventorying the article as property but not as a possible information asset
Autoclave, paint-booth, or oven controllerOperational Technology candidate only if it handles CUI and cannot be fully securedNo if Specialized; otherwise generally outside CUI scope unless another role appliesData fields, network path, segmentation, supportabilityPutting controllers on a flat network next to CUI systems
Tool-crib RFID or shop sensorIoT or IIoT candidate only if it handles CUI and cannot be fully secured; otherwise often out of scopeDependsData fields, security function, network path, separationCalling every sensor a Specialized Asset because it is IoT
Printer, scanner, or multifunction deviceUsually a CUI Asset when it handles CUIYes when it processes, stores, or transmits CUIJob retention, scan destinations, admin access, disk handling, disposalStored print jobs, scan-to-personal-email, or drive replacement without sanitization
Shop-floor MES or ERP terminalCUI Asset or Contractor Risk ManagedDepends on what the workflow allowsField and attachment inventory; controls and evidence if risk-managedCalling it out of scope on the strength of a policy alone
Technician laptop opening a verified controlled technical orderCUI Asset unless a narrow out-of-scope architecture genuinely appliesYesStandard Level 2 evidence plus cache, browser, print, photo, and offline behaviorAssuming a browser session leaves nothing behind

If you take one operational habit from this section, take the device dossier. One page per specialized-device candidate: what it does, what data it handles, how it connects, what it stores, whether the vendor supports it, which interfaces it genuinely requires, who owns it, why it cannot be fully secured, and how you're managing the risk. It gives an assessor or readiness partner the facts the category requires instead of a label with nothing behind it. Building it is free.


Why the answer differs by platform — technical orders versus commercial derivative aircraft

The same repair station can end up with different CMMC boundaries across contracts and workflows because the provenance of the task data differs by platform. Work performed to government technical orders, technical data packages, and military process specifications often starts with DoD-origin technical information that may carry restrictive distribution controls. Work on military commercial derivative aircraft may instead rely on commercial OEM manuals and component maintenance manuals. Neither starting point decides CUI by itself. The correct scope-reduction strategy for a mixed MRO follows verified data provenance and the written requirement, not the organization chart.

This is editorial analysis built on the definitions above, and we want to be careful about how far it goes. The authorized Government data owner or agency determines whether Government information is CUI; the contract and contracting channels determine the requirement; federal-contracts counsel handles legal disputes; and an RP/RPO can help map the resulting technical scope. The logic is straightforward enough that you can use it to structure the question.

On a pure military platform, your task data may be a technical order or technical data package supplied through DoD channels with a restrictive distribution statement. That is a strong Controlled Technical Information indicator. It is still an artifact-level determination, not a platform-wide shortcut.

On a military commercial derivative airframe, the picture changes. Air Force Technical Order 00-5-3 provides one concrete service-specific example: commercial-derivative aircraft technical data may reference commercial manuals and component maintenance manuals, including vendor-hosted web manuals, subject to service review and acceptance. DoD Instruction 5030.61 separately permits an FAA certification to serve as a basis for DoD airworthiness when appropriate and when military-use gaps are addressed. Neither source is CUI authority. Together they prove the narrower point: commercial technical publications can sit inside a military maintenance program without becoming DoD-controlled technical information merely because of the platform.

A commercially issued manual licensed on ordinary OEM terms is not DoD-controlled technical information merely because a military customer uses the aircraft. It may be proprietary, export-controlled, supplemented by controlled Government data, or used to create a controlled derivative — and those facts change the answer. But proprietary is not the same legal animal as CUI.

Work performed — Typical task-data source — Control authority to verify — Likely consequence to test
Work performedTypical task-data sourceControl authority to verifyLikely consequence to test
Airframe or component work on a pure military platformGovernment technical orders, TDPs, or military process specificationsGovernment or prime markings, distribution authority, contract identification, and contentStrong Controlled Technical Information indicator; Level 2 follows only when CUI is verified and the written procurement requirement calls for Level 2
Work on a military commercial-derivative airframe using ordinary commercial manualsCommercial OEM manuals or component maintenance manualsOEM license and any Government supplements, markings, or contract instructionsProprietary commercial data may remain outside CUI; the workflow may be Level 1 or outside Part 170 if no CUI is present and no Level 2 status is required
Commercial-derivative work with a Government-controlled variant or supplementMixed commercial and Government sourcesEach document’s source, marking, authority, and derivative restrictionsKeep the verified controlled material in the Level 2 path without automatically treating the entire commercial library as CUI
Teardown, NDT, disposition, or configuration data generated during performanceContractor-created recordContent, CUI category, dissemination basis, and the contractor-development prongCUI is possible only when the generated content otherwise qualifies; contractor creation alone does not decide it

What this means for your architecture

Every generic CMMC guide tells a manufacturer to enclave "engineering." For a mixed MRO, that advice is close to useless — engineering isn't the variable. The variable is which platform's data set a workflow touches.

So the enclave question for a repair station is not "which department goes inside." It is "which data provenance goes inside, and where does work cross the line?" That reframing has real money attached. It is the difference between putting one hangar line's technical data path inside a controlled boundary and putting an entire multi-line business inside one.

Two guardrails on this. First, the moment your commercial-derivative line touches a government-supplied controlled variant, that document is controlled regardless of what the rest of the line looks like. Second, a Part 145 certificate is not a CMMC input. It governs what maintenance you are authorized to perform and return to service under 14 CFR Part 145 — nothing more. Worth knowing that FAA inspector guidance separately recognizes repair stations performing military-only maintenance, which is a useful reminder that FAA authority and military technical-data control are two different systems that happen to meet on your floor.


Hangars, AOG teams, and lower-tier vendors: scoping without breaking maintenance

The defensible boundary in a maintenance operation is the one that matches what technicians actually do. Start with the work sequence rather than the network diagram: follow one representative defense job from contract receipt through planning, engineering, shop execution, test, outside processing, quality release, customer delivery, archive, and field support. Controls that survive contact with a hangar are the ones that give people an approved path faster than the workaround you are trying to prohibit.

Walk one job, all the way

Pick one representative defense job and physically follow it. Not a diagram — the actual job.

Contract and technical package arrive. Somebody puts them somewhere. Planning builds the work cards. The packet gets printed, or doesn't. Access is granted on the floor. A technician photographs a crack. Measurements go somewhere. Engineering writes a disposition. A part ships to an outside plating house. NDT runs and stores images. Quality reviews and releases. Records go to a customer portal. Everything gets archived, backed up, retained, and eventually destroyed. Eighteen months later, an AOG call reopens the whole file in a hangar three states away.

Every arrow in that sequence is a scope decision. When that map does not exist, the quotes that follow are guesses dressed up as scopes.

Controls that fit humans

Good programs fail on the floor for entirely predictable reasons. If a control adds friction to a task performed all shift, it will be defeated by lunch — and the workaround will be worse than the risk you were managing.

Design for the reality: individual identity without punishing delays. An approved offline procedure for when the network drops mid-job. Controlled printing with a real staging and pickup process. A sanctioned way to take a photograph, because technicians are going to take photographs. Shared-device logout behavior you have actually tested. Glove-compatible authentication where your platform supports it. Shift turnover, temporary labor, visitors, vendors, and after-hours physical custody all thought through in advance.

None of that is in the rule. All of it determines whether your controls exist in practice or only in your System Security Plan.

AOG and field maintenance

Field work is a common scope gap because the boundary was drawn around a building.

If a field device accesses or stores controlled data, the data followed the work. A temporary location does not suspend anything. Build a standard field kit and a written field-data sequence covering approved remote access, offline cache behavior and what gets purged on return, mobile connectivity, portable printing and media, physical custody in a vehicle or hotel room, photo capture, the incident reporting route, and sanitization when the kit comes home.

Test the offline behavior before you deploy it, not after. "What is on this laptop right now" is a question you want answered on your terms.

Lower-tier repair and special-process vendors

A defense-facing MRO is often a contractor and a customer at the same time. Parts go out for plating, NDT, heat treat, machining, calibration, and component repair, and each of those handoffs is a data decision.

Work through it in this order: what does the vendor genuinely need — not what is easiest to forward? Is that information FCI or CUI? What does the subcontract require, and what should flow down under DFARS 252.204-7021 and 32 CFR § 170.23? How does it transfer securely? What happens to it afterward — return, retention, destruction? Is the vendor's portal, or your transfer service, an external service provider in your scope?

Two failure modes, opposite directions. Sending the whole technical package because it takes less time than trimming it. And imposing a blanket Level 2 demand on every supplier who touches a part, which is expensive, slow, and often wrong. Minimize the package first. The cheapest scope reduction available to a repair station is not sending data you didn't need to send.

The honest problem with MRO scoping

A CUI enclave — the product most often quoted to a maintenance shop — cannot solve the parts of a maintenance operation that actually leak. It does not solve a paper job packet left on a cart. It does not solve a photograph on a technician's personal phone that syncs to a consumer cloud before anyone thinks about it. It does not solve an NDT instrument whose only export path is a USB stick. It does not solve an AOG laptop caching a work package in a hotel room in Alaska.

We route readers to readiness and enclave provider categories. Saying that the flagship product in that market does not fully solve the maintenance problem is against our commercial interest. It is also true, and you would have discovered it three months into an implementation.

Here is why that is good news. It means the expensive part of your program is not the license count — it is the workflow map, and the workflow map is the part you can start this week, for free, with a clipboard. An enclave used after the map is a precise instrument: it shrinks a digital boundary around a genuinely bounded set of workflows and it can take real cost out of an assessment. An enclave bought before the map is a very expensive way to discover that CUI was never confined to the systems it covers.

Buy the map first. Then buy the architecture that fits it.

Compare provider categories against your actual scope

Once you know which contracts and workflows hold controlled data and which assets sit in which category, the vendor conversation changes completely — you stop receiving license quotes and start receiving scoped proposals. Our provider-category breakdown lays out what each category does, what it cannot do, and what to verify before you sign.

Compare provider categories → · Already know what you need? Request scoped quotes →

Do not submit CUI, drawings, technical orders, aircraft data, network diagrams, or contract attachments.


Does FAA Part 145, AS9110, ITAR, or an OEM approval satisfy CMMC?

No. None of them establishes a CMMC level or status. 14 CFR Part 145 governs repair-station certification and the maintenance functions a station is authorized to perform and return to service. AS9110 is an aerospace quality-management standard for maintenance organizations. ITAR and the EAR control the export and transfer of covered articles, services, technical data, and technology. CMMC assesses specified safeguarding requirements for contractor information systems under 32 CFR Part 170. Existing aviation and export-control programs can supply reusable evidence, but none of them substitutes for the required CMMC status.

If you're irritated by this section, we understand. A defense-facing repair station may hold an FAA certificate, an AS9110 certification, ITAR registration, a Joint Certification Program certification, multiple OEM approvals, and half a dozen customer quality approvals — and still be told it has to start something new. That's a fair grievance. It's also the situation.

Regime or approval — Authority — What it governs — Evidence you may reuse — What it does not establish
Regime or approvalAuthorityWhat it governsEvidence you may reuseWhat it does not establish
FAA Part 145 repair stationFAA, 14 CFR Part 145Certification, ratings, authorized maintenance functions, inspection, alteration, and return to serviceTraining, manuals, facilities, calibration, contract-maintenance procedures, recordsA CMMC level or status; implementation of NIST SP 800-171 Rev. 2
AS9110 certificationSAE and IAQG aerospace quality ecosystemQuality management for maintenance organizationsDocument control, revision management, traceability, corrective action, supplier control, competence, internal auditCMMC status, security-control effectiveness, or a CUI boundary
ITARDepartment of State, 22 CFR Parts 120–130Export and transfer of defense articles, services, and technical data, including data used for operation, repair, testing, maintenance, and modificationForeign-person controls, data identification, transfer approvals, access restrictionsThat all ITAR technical data is CUI, that CMMC is met, or that a particular cloud is sufficient
EARDepartment of Commerce, 15 CFRExport, reexport, and transfer controls for covered items, software, and technologyClassification and technology-control processesA CMMC status or an automatic Level 2 requirement
Joint Certification Program and DD Form 2345U.S.–Canada JCP under DoDD 5230.25 and DLA proceduresEligibility to request access to unclassified militarily critical technical data, subject to repository and business-need controlsData-custodian roles, access discipline, training, approved purposeGuaranteed release of a data package, a security assessment, or a CMMC status
OEM or customer quality approvalOEM or customerAuthorization and quality capability for specified workCustomer procedures, access lists, technical-data control, supplier monitoringA Government CUI determination or a CMMC status
CMMC and DFARS32 CFR Part 170 plus the applicable acquisition clausesRequired cybersecurity status, assessment scope, safeguarding, affirmation, reporting, and flow-down for covered systems and contractsFAA airworthiness authority, a quality certification, or an export authorization

The two gates MRO shops most often confuse

This one is worth its own paragraph, because it produces a specific and expensive misunderstanding.

DD Form 2345, the Militarily Critical Technical Data Agreement, is an access authorization. It is not a security assessment. Processed through the Joint Certification Program administered by the Defense Logistics Agency, it certifies your organization to receive unclassified militarily critical technical data. Notice how directly the underlying definition speaks to maintenance: militarily critical technical data under DoDD 5230.25 covers technical information usable to design, engineer, produce, manufacture, operate, repair, overhaul, or reproduce military or space equipment. Repair and overhaul, named in the definition.

So the Joint Certification Program is one gate that can make you eligible to request or receive unclassified militarily critical technical data. It does not guarantee access: DLA's current process also requires an approved DIBBS/cFolders account and a demonstrated business need for DLA export-controlled data. DFARS 252.204-7012 and CMMC govern what you must do once qualifying data reaches your systems. Two gates, different authorities, neither substituting for the other. A current JCP certification is not evidence of a CMMC posture, and a prime's supplier questionnaire will find that out quickly.

One practical note: we did not verify a universal official JCP processing time. The current DLA access path layers JCP approval, account approval, enhanced validation, and business-need review, and corrections or missing evidence can add delay. If your ability to bid depends on receiving a technical data package, treat the access path as long-lead — because it has multiple gates.

Reusing evidence without claiming equivalency

The good news buried in this section: a well-run AS9110 shop is further along than it thinks — just not where it thinks.

You likely already maintain documented roles and training, controlled procedures under revision management, supplier approval and surveillance, calibration and equipment control, a corrective-action process, internal audits, record retention schedules, and physical access control to controlled work areas. All of that is reusable material.

What it is not is an evidence statement. "We passed our AS9110 audit" does not answer a CMMC assessment objective. "Here is our access-control procedure, here is the training record for the technicians it applies to, here is the audit that tested it, and here is the requirement it maps to" does. The work is the mapping, not the creation. That is genuinely less expensive than starting from nothing — which is the honest, encouraging version of this section.


Which CMMC level should an MRO plan for right now?

Plan from the written requirement, not from an industry average. During the current suspension, new procurement designations are limited to Level 1 (Self) for FCI and Level 2 (Self) for CUI. 32 CFR § 170.14 defines Level 1 as the 15 basic safeguarding requirements from FAR 52.204-21(b)(1), Level 2 as all 110 NIST SP 800-171 Revision 2 requirements across 14 families, and Level 3 as 24 selected requirements from the February 2021 version of NIST SP 800-172, with a Final Level 2 (C3PAO) status required first. Level 2 (C3PAO) and Level 3 remain defined in Part 170, but new designations for those paths are paused. See the CMMC Levels guide for the rule-by-rule level comparison.

Path — Information and written-requirement trigger — Requirement set — Current designation posture — Status mechanics
PathInformation and written-requirement triggerRequirement setCurrent designation postureStatus mechanics
Level 1 (Self)Written requirement for contractor systems that process, store, or transmit FCI15 basic safeguarding requirements from FAR 52.204-21; covered deviation actions may use FAR 52.240-93 with the same safeguardsAllowed during the suspensionAnnual self-assessment and current affirmation in SPRS; no POA&M
Level 2 (Self)Written Level 2 (Self) requirement for systems handling CUIAll 110 NIST SP 800-171 Rev. 2 requirements across 14 familiesAllowed during the suspensionAssessment generally current for three years; annual affirmation; Conditional status and a 180-day POA&M only within the rule’s limits
Level 2 (C3PAO)Written Level 2 (C3PAO) requirement or a voluntary certification decisionThe same 110 Rev. 2 requirementsNew Department designations paused; existing written requirements remain until changed; voluntary assessments remain availableIndependent C3PAO assessment, CMMC UID and status in SPRS, annual affirmation, three-year status window subject to rule conditions
Level 3 (DIBCAC)DoD-selected requirement for CUI needing enhanced protectionFinal Level 2 (C3PAO) plus 24 selected requirements from the February 2021 NIST SP 800-172New Department designations pausedFinal Level 2 (C3PAO) prerequisite; DCMA DIBCAC assessment; annual affirmation and three-year status window subject to rule conditions

Three mechanics that decide eligibility more often than control implementation does:

“Current” has a definition. Under DFARS 252.204-7021, a Final Level 1 (Self) status must be not older than one year with a current affirmation; Final Level 2 (Self), Final Level 2 (C3PAO), and Final Level 3 statuses must be not older than three years with an affirmation not older than one year. Conditional statuses carry their own 180-day window. A solid control set with a lapsed affirmation is not a current status.

The POA&M math is unforgiving. Under 32 CFR § 170.21, a Conditional Level 2 requires a score of at least 88 of 110; only 1-point requirements are eligible for a Plan of Action and Milestones; six specific requirements are excluded by name, including your System Security Plan; there is one narrow exception for CUI encryption where encryption is in place but not FIPS-validated; and everything on the POA&M closes within 180 days or the Conditional status expires. Practical effect for a maintenance shop: a single unmet 5-point requirement removes the Conditional path at any score. You can meet 109 of 110 and have no conditional route if the gap is a heavy one.

Revision 2 is still the target. CMMC Level 2 is tied to NIST SP 800-171 Revision 2 under 32 CFR § 170.14(c)(3), and DoD Class Deviation 2024-O0013 pins Revision 2 in the DFARS 252.204-7012 context. NIST has published Revision 3, and NIST's catalog now marks Revision 2 as withdrawn and superseded. That is a NIST publication-status question, not a CMMC baseline change. The same distinction now matters at Level 3: NIST published SP 800-172 Revision 3 in May 2026 and withdrew the original publication, but Part 170 still incorporates the February 2021 SP 800-172 and its selected 24 requirements. If a vendor offers to “future-proof” you onto a newer NIST revision as though it were the current CMMC-controlling version, that is a sales position, not a compliance one. Build the evidence set the rule currently requires, plan for future migration separately, and keep an explicit Revision 2 map. Our Rev. 2 versus Rev. 3 comparison tracks every instrument that could change that.

What does this actually cost a maintenance shop?

We are going to be straight with you: there is no credible MRO-specific cost dataset, and we are not going to invent one. What exists is the Government's own published estimates, and they are worth knowing because they set the frame for every quote you'll receive.

Around the July 13, 2026 suspension, the Small Business Administration published two figures for a small firm's total compliance cost: approximately $593,800 for a firm requiring third-party assessment and approximately $388,600 for a firm eligible for self-assessment. Treat both as SBA scenario estimates, not as a settled MRO price. The arithmetic difference is $205,200. SBA did not publish a line-item allocation that lets us call that difference “the audit fee” or assign the remaining amount to implementation. The defensible conclusion is narrower: the self-assessment scenario is still expensive, because the security implementation and evidence work did not disappear with Phase II.

For a maintenance shop specifically, the biggest lever on that number is not vendor selection. It is whether you scoped by platform and data provenance before you bought anything. Getting that wrong is what turns a narrow Level 2 boundary into a company-wide invoice — or treats an FCI-only workflow as though every system held CUI. For dollar-level detail by level and company size, see our CMMC Level 2 cost guide.


Your first 30 days after a CMMC flow-down lands

Do not begin with a software purchase or a company-wide control rollout. In the first 30 days, preserve the written requirement, identify the information, walk one maintenance workflow end to end, categorize your assets and external providers, verify your current status in SPRS, and assemble a decision packet. That sequence exposes the real boundary before cost and architecture harden around a guess.

1. Build the clause pack. Save the solicitation, the contract or subcontract, the purchase order, security exhibits, data markings and handling instructions, every modification, and the prime correspondence. Write down the exact CMMC status requested and the next award, option, or extension date. That is the procurement deadline that controls this plan — not a generic milestone you read in a headline.

2. Create the information register. Categories only. Do not centralize actual controlled data to do this exercise. For each artifact family record source, marking or authority, program, owner, systems touched, physical form, and unresolved questions.

3. Walk one real job. Receipt to archive, including paper, photographs, removable media, field work, customer portals, outside processing, backups, and security tooling. Take notes on what people actually do, not what the procedure says.

4. Build the first-pass asset map. Hypotheses, not final labels: CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, Out-of-Scope, external service provider, physical handling process. Next to each one, write the evidence you'd need to prove it.

5. Map external responsibilities. For every cloud service, MSP or MSSP, technical-library host, maintenance software vendor, backup service, security operations provider, file-transfer tool, and lower-tier repair vendor: what data it handles, what security function it performs, what authorization evidence exists, what the responsibility matrix says, and what the contract requires.

6. Verify your current status. Check the relevant SPRS record, assessment date, affirmation, and system or UID against the written requirement. Confirm who at your company can access dibnet.dod.mil, and fix it now if the answer is nobody.

7. Choose the provider category, not the provider. Questions about what the Government designated as CUI go to the authorized customer or agency data owner. Clause ambiguity and legal disputes go through the contracting channel and, where needed, to qualified federal-contracts counsel. Technical scoping, readiness, SSP, and POA&M work goes to an RP/RPO or readiness provider. Ongoing security operations go to an MSSP. Boundary architecture goes to an enclave provider. Evidence workflow goes to a GRC platform. Formal assessment goes to a CMMC Third-Party Assessment Organization when a valid current requirement calls for it — and only after the Cyber AB conflict rules have been checked against every organization and person that performed preparation work.

The letter to send this week

Reciprocity with no strings: copy this, adapt it, send it. It costs nothing and it resolves more than any tool will.

Subject: Clarification request — cybersecurity and CMMC requirements, [contract/solicitation number]

We are confirming our obligations under [contract/solicitation number] and request written clarification on the following:

  1. Which CMMC level and assessment type apply, under which clause or provision, and at what point — bid, award, option exercise, or subcontract flow-down?
  2. Which CUI categories and distribution statements apply to the technical data we will receive or generate in performance? Please identify the controlling markings and any handling instructions.
  3. Is any portion of our performance designated as operationally critical support and identified in the contract for purposes of DFARS 252.204-7012?
  4. Does any government-furnished property under this contract include an item capable of storing or transmitting controlled information?
  5. If this contract or solicitation currently references a CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, please advise on the status of the amendment or modification following the July 13, 2026 Phase II suspension.

We are not requesting any controlled technical data in response — only the applicable requirements and markings.

Send it to your contracting officer for a direct contract, or to your prime's supplier quality or contracts contact for a flow-down. Keep the answer with your clause pack. It is evidence, and evidence dated before you spent money is the best kind.

What you should be holding at day 30

A clause and status summary. An information register. One workflow diagram. An asset-category hypothesis list. An external-provider map. A written list of unresolved customer questions. Your current SPRS status record. A provider-category brief. And a budget request built on scope rather than headcount.

Turn that into a first-pass scope map

If you'd rather not build the packet from scratch, our Find My CMMC Path tool takes category-level answers — the level your document states, which maintenance workflows you run, your general environment, whether you have field or AOG work, whether outside vendors receive data, and your next contract date — and returns the provider category that fits the unresolved work.

Build my first-pass scope map →

Category answers only. No file uploads. Do not enter CUI, drawings, technical orders, tail numbers, program names, or credentials.


Which CMMC provider category should an MRO hire first?

Hire for the unresolved problem, not for the most impressive credential. An RPO or Registered Practitioner helps map technical scope and prepares you; an MSSP operates security day to day; a CUI enclave provider designs a smaller controlled environment; a GRC platform organizes evidence; a CMMC Third-Party Assessment Organization performs the independent formal assessment when that path is actually required. Under 32 CFR § 170.9 and the Cyber AB Code of Professional Conduct v2.0, a C3PAO and every assessment-team member are prohibited from participating in a Level 2 certification assessment when they served as a consultant to prepare that organization for any CMMC assessment within the prior three years. The same code prohibits guarantees of assessment or certification results.

We do not publish named provider rankings on this page, and that is deliberate. This is a scope-determination page. Dropping vendor names into the moment you're deciding what you owe would undercut the only thing that makes this page worth reading. When you know your category, our Who to Hire First guide, provider category guide, and directory go deeper — with role, status, and last-verified date documented.

Provider category — Use it when — Do not treat it as — What an MRO should verify first
Provider categoryUse it whenDo not treat it asWhat an MRO should verify first
RPO or RPTechnical scoping, readiness, gap analysis, SSP and POA&M development, and implementation roadmapThe authorized Government source for a CUI determination, federal-contracts counsel, or the independent assessor when the three-year conflict rule appliesCurrent Cyber AB status where relevant, named practitioners, MRO and shop-floor experience, exact deliverables you own
MSP or MSSPIdentity, endpoint, network, logging, incident response, backup, vulnerability, and administration operationsProof that CMMC is metRequirements owned by each party, Security Protection Data handling, service description, customer-responsibility matrix, evidence export
CUI enclave providerA genuinely bounded group of users and workflows can be isolated without constant leakageA cure for paper, photographs, test equipment, AOG work, or supplier handoffsSupported maintenance workflows, offline behavior, printing, photographs, field use, data transfer, exit plan
GRC platformEvidence management, requirement mapping, policy workflow, SSP and POA&M trackingA control implementation or certificationCorrect Rev. 2 mapping, evidence ownership and export, assessor access, version control
CMMC Third-Party Assessment OrganizationYou are assessment-ready and a valid written or voluntary decision calls for Level 2 certificationA readiness consultant and assessor for the same organization within the prohibited three-year window; a source of guaranteed outcomesCurrent authorized Marketplace status, scope assumptions, written conflict analysis for the C3PAO and every proposed assessment-team member, no guarantees
Federal-contracts counselClause conflict, amendment, suspension, flow-down dispute, allocation of contractual risk, or contested CUI authorityA technical implementation teamRelevant acquisition and CUI experience, written scope, coordination with the contracting officer, customer authority, and readiness team

Ten questions that separate a scoped proposal from a license quote

Ask these before you sign anything. A provider who has actually scoped hangar work should be able to answer them without retreating into a generic license count.

  1. Which maintenance workflows did you include, and which did you exclude?
  2. How did you determine which artifacts are actually controlled, rather than assuming by document name?
  3. How will you handle technical publications, paper packets, shared devices, photographs, test equipment, and AOG work?
  4. Which of our assets are you proposing as Contractor Risk Managed or Specialized, and what evidence supports that classification?
  5. Which external providers enter our scope, and which responsibility matrices exist for them?
  6. What does your quote assume about the July 2026 suspension and about the exact status our contract states?
  7. Which deliverables do we own at the end — asset inventory, network diagram, SSP, POA&M, procedures, evidence index, responsibility matrix?
  8. What is expressly excluded from this quote?
  9. Have your organization or any proposed assessment-team members performed CMMC preparation work for us within the prior three years, and will you put the conflict analysis in writing?
  10. What happens to this engagement if the Department changes the program after the current review?

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial and Advertising Policy.


What goes wrong in MRO CMMC programs

The expensive failures in maintenance CMMC programs usually happen before a single control is implemented. The shop declares everything controlled, or nothing controlled, or trusts a written policy the floor does not follow, or buys a boundary architecture without mapping the paths that cross it. The remedy is not weaker security — it is a boundary matched to the contract, the information, the real workflow, and the evidence you can actually produce.

Failure mode — Why it costs you — Better move — Evidence that closes it
Failure modeWhy it costs youBetter moveEvidence that closes it
Treating every defense-related record as controlledOverscopes systems, users, vendors, and cost; technicians route around the burdenRun the five-part evidence test and obtain written clarification where unresolvedArtifact register with source, authority, content, purpose, owner, and dated customer response
Treating unmarked or commercial-looking data as automatically safeMisses qualifying contract-derived or contractor-created CUICheck authority, content, contract prong, distribution criteria, and customer guidanceMarking review, CUI-category basis, contract excerpt, and written data-owner guidance
Assuming the suspension erased DFARS 252.204-7012 or existing C3PAO languageLeaves real contractual and incident exposurePreserve required protections and obtain the formal amendment or modificationExecuted solicitation amendment, contract modification, or subcontract change
Buying an enclave, Government cloud, or GRC platform before scopingArchitecture hardens around a guessMap data and workflows firstApproved workflow map, asset hypothesis list, and responsibility matrix before procurement
Calling every legacy or test device SpecializedMisuses a narrow category and damages credibilityProve CUI capability, inability to fully secure, named asset type, and risk treatmentDevice dossier, SSP entry, diagram, supportability evidence, and risk decision
Calling policy-only endpoints Out of ScopeOut-of-scope requires inability or separation, not intentUse Contractor Risk Managed where the facts fitTechnical test of data paths plus policy, procedure, enforcement evidence, and SSP treatment
Ignoring printers, photographs, paper, and removable mediaThe workflow escapes the digital boundaryDesign approved physical and digital bridgesPrint, scan, photo, media, custody, retention, and destruction procedures tested on one job
Ignoring AOG and field workField devices become undocumented data pathsStandardize a managed field kit and return processField-kit inventory, offline test, custody log, incident route, sanitization record
Sending full technical packages to lower tiersExpands exposure and drives unnecessary flow-downMinimize the package before deciding the requirementData-minimization record, subcontract clause analysis, transfer and destruction evidence
Letting MSP tickets, logs, and remote tools escape analysisSecurity Protection Data and privileged access can pull services into scopeMap data, tenancy, access, and responsibilitiesService description, customer-responsibility matrix, access roster, evidence-export test
Shared shop-floor accountsDestroys attribution and clean terminationBuild usable individual identity around real shift patternsNamed-account roster, authentication test, termination test, exception log
Using a readiness provider as the C3PAO without applying the three-year ruleCan disqualify the C3PAO or assessment-team member from that certification assessmentSeparate roles and obtain written conflict analysis before signingPrior-services disclosure for the organization and every proposed team member
Treating AS9110 or FAA audit evidence as CMMC equivalencyLeaves the cybersecurity requirements unprovedReuse artifacts but map them to specific CMMC objectivesEvidence crosswalk showing policy, implementation, test, owner, and date for each objective
Building to NIST SP 800-171 Revision 3 and claiming current Level 2 complianceMisstates the controlling CMMC baselineMaintain an explicit Rev. 2 evidence map until the governing instrument changesVersion-controlled Rev. 2 matrix and a separate future-migration plan
Never provisioning or testing DIBNet accessCreates delay and forces the emergency assistance path while the 72-hour clock runsProvision at least two people, test normal access, and record DC3’s fallbackCertificate and account owner list, test record, expiry tracking, incident-plan contact block

What one MRO publicly claimed — and what the public record does not prove

In July 2026, Duncan Aviation announced that it had achieved what the company described as formal compliance with the CMMC Level 2 framework, and described establishing a controlled area for its manufacturing division with restricted physical access and entry records. We report this as one company's public account of its own approach — not as independent verification of any claim in it, not as a typical result, and not as evidence that the same architecture fits another repair station. DFARS 252.204-7021 defines seven CMMC statuses, and “CMMC compliant” is not one of them.

We include this because it is the most instructive public artifact in the sector right now, and because it demonstrates exactly the vocabulary problem this page exists to solve.

What the company said, in its own words. The announcement, dated July 29, 2026, states that Duncan Aviation "achieved formal compliance with the DoD (Department of Defense/War) CMMC ... Level 2 framework," notes that it did so "bypassing a third-party audit," and states that achieving Level 2 means the company "is now listed in the federal SAM.gov (System for Award Management) database" and is qualified to continue bidding on defense work in depot-level maintenance, aircraft modifications, and parts manufacturing and repair. Later in the same release it refers to "the CMMC certification." It also emphasizes that the company established its manufacturing division as a controlled space, limiting physical access to authorized personnel and maintaining records of who enters those shop areas.

Two corrections, offered neutrally. CMMC assessment results and affirmations are posted in SPRS, not SAM.gov — SAM.gov registration is a separate federal system with a different purpose. And “compliance,” “alignment,” and “certification” are not interchangeable under the rule; the seven statuses in DFARS 252.204-7021 are specific. The phrase “bypassing a third-party audit” suggests a self-assessment path, but a press release does not verify whether an official Final Level 2 (Self) status exists, what system it covers, or whether its affirmation is current.

And a point in the company's favor that most commentary would miss. During the suspension, Level 2 (Self) is the only Level 2 path the Department may newly designate in a procurement requirement. Voluntary C3PAO assessments remain available, and existing contract language remains until formally changed. So a Level 2 self-assessment is not inherently a shortcut — for a new Department designation right now, it is the permitted path. The underlying work described in that announcement, particularly the physical control of a work area with access records, is substantive and directly relevant to a control family most shops underestimate.

Which brings us to the point that is actually useful to you. CMMC is often reduced to an IT problem. In maintenance, a large share of the controlled information can live on a workbench: a printed work card, a marked-up process sheet, a tablet clipped to a stand, a binder in the tool crib, a photograph on a phone. Physical protection is not a footnote to your program. Our CMMC Level 2 checklist covers the full evidence set, including Physical Protection.

Five questions to ask any maintenance partner who claims CMMC

  1. Which of the seven CMMC statuses do you hold, exactly as it appears in SPRS?
  2. What was the assessment date, and is your annual affirmation current?
  3. What scope does the status cover — which systems, which CAGE codes?
  4. Was it a self-assessment or an assessment by a CMMC Third-Party Assessment Organization?
  5. What contract, proposal, CMMC UID, or authorized verification path substantiates the claimed status and scope beyond the press release?

A partner with a real posture will answer all five in one email. That is the test.


What we actually verified for this guide

We do not ask you to take our word for any of it. Here is what we read, and what each source supports.

Source read — What it supports
Source readWhat it supports
DFARS 252.204-7012Controlled Technical Information and covered defense information definitions; operationally critical support; 72-hour reporting; medium-assurance certificate; malware submission; 90-day preservation; forensic support; subcontract flow-down
DFARS 252.204-7021 and 252.204-7025Seven CMMC statuses; current-status mechanics; affirmations; CMMC UID; SPRS posting; eligibility; solicitation designation; CMMC flow-down
32 CFR § 170.3Applicability; federal-system carve-out; commercial-item, COTS, and micro-purchase treatment; status selection; original phase schedule
32 CFR § 170.19 and § 170.4Level 1 and Level 2 scoping; five Level 2 asset categories; six Specialized Asset types; VDI example; external-service-provider treatment; Enduring Exceptions
32 CFR § 170.14 and § 170.21The 15, 110, and 24 requirement sets; Rev. 2 and February 2021 SP 800-172 incorporation; score and POA&M rules; 88-point threshold; 180-day closeout
NIST SP 800-171 Rev. 2 and NIST SP 800-171 Rev. 3NIST publication history and the distinction between NIST’s current catalog and the version incorporated into CMMC
NIST SP 800-172 and SP 800-172 Rev. 3Original and current NIST publication status; Part 170 still controls which Level 3 requirements apply
FAR 45.101Government-furnished property includes spares and property furnished for repair, maintenance, overhaul, or modification
National Archives CUI Registry: Controlled Technical Information and Export ControlledCUI//SP-CTI and CUI//SP-EXPT categories, authorities, markings, and handling context
DoD Instruction 5230.24Distribution Statements A through F and the instruction’s coverage of sustainment and logistics technical documents
July 13, 2026 suspension release and implementing memorandumPhase II suspension; self-assessment designation limits; no waivers during review; amendment and modification path; continuing DFARS 252.204-7012 obligations
Class Deviation 2026-O0025, Revision 2Covered-action treatment of DFARS 252.204-7019 and 252.204-7020, the Part 240 replacement, and the FAR-overhaul cybersecurity clause structure
Cyber AB Code of Professional Conduct v2.0Three-year C3PAO and assessment-team consulting prohibition; conflict disclosure and mitigation; prohibition on guaranteed outcomes
DC3 and DCISE incident-reporting pageNormal medium-assurance-certificate requirement; emergency email and hotline assistance; incident fields; malware-upload instructions
DoDD 5230.25, DD Form 2345, and DLA JCP materialsMilitarily critical technical data used to operate, repair, or overhaul military equipment; JCP as access eligibility rather than a security assessment or guaranteed release
14 CFR Part 145 and IAQG 9110 materialsRepair-station authority and the maintenance quality-management role of AS9110
22 CFR § 120.33 and 15 CFR export-control rulesITAR technical-data scope and the separate role of EAR export controls; neither substitutes for CMMC status
Air Force Technical Order 00-5-3 and DoD Instruction 5030.61Use of commercial technical publications and FAA certification in military commercial-derivative aircraft programs; neither source makes a CUI determination
SBA release, July 13, 2026SBA’s $593,800 and $388,600 small-firm scenario estimates and the exact limits of what those figures establish
Duncan Aviation newsroom, July 29, 2026The company’s own claims, treated as company-stated and not as independent verification of an SPRS status

What we could not establish

We think this list matters as much as the one above.

  • Which distribution statement is on any specific document you hold. You have to read your own cover page. No page on the internet can do that for you.
  • The specific CMMC status Duncan Aviation holds. A press release is not the verification route, and we did not verify it.
  • Whether your organization’s normal DIBNet access is active, tested, and assigned to current personnel. The clause and DC3 both state the medium-assurance-certificate requirement, and DC3 publishes an emergency assistance path. We cannot verify your certificate, account, or internal readiness from this page.
  • Any MRO-specific cost or timeline dataset. None exists that we would publish. The figures in this article are attributed government estimates, not maintenance-sector benchmarks.
  • The CUI status of any artifact in the Data-Provenance Map for your shop. That table is an editorial framework and an evidence checklist. It is not a determination.

How this page was produced, and why

Who: The Defense Compliance Report Editorial Team. This is editorial research and was not formally reviewed by a CMMC Subject Matter Advisor.

How: We read the governing rule sections and clause text at their sources — eCFR, acquisition.gov, NIST CSRC, the National Archives CUI Registry, the Cyber AB, DC3, FAA, DLA, and the July 2026 suspension materials — and then applied those definitions to the artifacts and equipment that actually move through a repair station. Where a conclusion is ours rather than the rule's, we say so in the sentence. See our Methodology, Editorial Standards, Editorial Review Process, and Corrections Policy.

Why: Because maintenance organizations have been reading manufacturing guidance and paying for manufacturing scope. Those are different data problems, and the difference is worth real money.

This article is educational research, not legal, contractual, export-control, aviation, or compliance advice. Confirm contract interpretation and disputes with your contracting officer and, where needed, qualified federal-contracts counsel. Obtain CUI markings or determinations from the authorized Government data owner, program office, or other responsible customer authority. Use an RP/RPO or other qualified readiness professional to map the resulting technical scope and evidence requirements. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense or Department of War, DCMA DIBCAC, NIST, the FAA, SAE International, or any U.S. government agency.

A note on names: official 2026 release and CIO pages use “Department of War,” while 32 CFR Part 170 and the DFARS text still use “Department of Defense” and “DoD.” This article uses the name that matches the cited source and uses DoD when referring to the governing rule or clause.


Frequently asked questions

Do all aircraft MROs need CMMC?

No. Being an MRO or an FAA repair station is not the trigger. A CMMC status applies when a solicitation, contract, subcontract, or written flow-down requires one for systems that process, store, or transmit FCI or CUI in performance of that contract, under 32 CFR § 170.3. Read the document first; then map your data.

Does an FAA Part 145 certificate trigger CMMC?

No. 14 CFR Part 145 governs repair-station certification, ratings, and the maintenance you are authorized to perform and return to service. It can generate reusable process evidence — training, calibration, manuals, recordkeeping — but it does not assign a CMMC level or status.

Does AS9110 satisfy CMMC?

No. AS9110 is an aerospace quality-management standard for maintenance organizations. Document control, traceability, corrective action, supplier control, and audit discipline from an AS9110 program are genuinely reusable, but they must be mapped to specific CMMC requirements and assessment objectives. "We passed our AS9110 audit" is not an evidence statement.

Are aircraft maintenance manuals and technical orders CUI?

Some are, and some are not. Under DFARS 252.204-7012, controlled technical information is technical information with military or space application that would meet the criteria for Distribution Statement B through F under DoD Instruction 5230.24. Technical orders and manuals are named in the clause's own examples of technical information, so they frequently qualify — but a commercially available civil OEM manual is a different document with a different provenance. Check the source, the markings, the contract, and the content.

Are work cards, travelers, tail numbers, or part numbers automatically CUI?

No blanket rule supports that. A record may contain or derive from controlled information, but the artifact's name or an identifier on it does not settle the question. Look at what fields and attachments the record actually carries, where it came from, and what the contract and customer instructions say.

Is my teardown report or NDT finding CUI even though nobody gave it to me?

Possibly, and this is one of the most-missed exposures in maintenance. Covered defense information under DFARS 252.204-7012 includes otherwise-qualifying controlled technical information or other CUI “collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.” Data you generate — as-found condition, dimensional results against military limits, NDT findings, repair dispositions — can fall under that prong when the content meets an applicable CUI category. Verify the content and the contract; do not assume that self-generated means uncontrolled, and do not assume that contract-generated automatically means CUI.

Are paper maintenance records part of CMMC scope?

Paper containing controlled information still requires protection, and the systems that print, scan, store, or capture it are categorized separately under 32 CFR § 170.19. Paper is not forced into an electronic asset category, but a digital enclave does not make a printed work card disappear. Map issuance through destruction.

Is diagnostic or NDT test equipment automatically a Specialized Asset?

No. Test Equipment is one of the six named Specialized Asset types listed in 32 CFR § 170.19, but the category applies when the asset can handle CUI and cannot be fully secured. If the device can be secured like a normal endpoint, it may simply be a CUI Asset. Build a device dossier — function, storage, ports, network interfaces, vendor supportability, feasible controls — and classify from the facts.

Is my engine test cell or avionics bench going to be audited against 110 controls?

Not if it is properly classified as a Specialized Asset. At Level 2, Specialized Assets are part of the assessment scope and must be documented in the asset inventory, addressed in the System Security Plan, shown on the network diagram, and managed under your risk-based security policy — but they are not assessed against the other CMMC security requirements. Note the asymmetry: at Level 1 they are outside the scope entirely.

Can a hangar tablet or shared kiosk be out of scope?

Possibly, but "view only" is not sufficient. 32 CFR § 170.19 contemplates a narrow configuration — an endpoint hosting a virtual desktop client where no CUI processing, storage, or transmission occurs beyond keyboard, video, and mouse. Test the actual device behavior: cache, clipboard, downloads, print, screenshots, camera, and what survives logout. If the capability exists but policy keeps controlled data out, Contractor Risk Managed is usually the honest category.

Do AOG and field maintenance teams expand our boundary?

They can. If a field device accesses or stores controlled information, that device and the supporting processes follow the data outside your facility. Temporary location does not suspend anything. Standardize a managed field kit with documented offline behavior, remote access, physical custody, photo capture, an incident reporting route, and sanitization on return.

Do our outside NDT, plating, calibration, or component-repair vendors need CMMC?

It depends on what you send them and what the subcontract requires. Determine what information the vendor genuinely needs, whether it is FCI or CUI, and what should flow down under DFARS 252.204-7021 and 32 CFR § 170.23. Do not send the full technical package for convenience, and do not impose a blanket Level 2 demand on every supplier who touches a part.

Does ITAR-controlled technical data automatically mean CMMC Level 2?

Not mechanically. ITAR (22 CFR Parts 120–130) controls export and transfer; CMMC assesses safeguarding of contractor systems. The two frequently overlap on the same document, and export-controlled information has its own CUI Registry category (CUI//SP-EXPT), but one label does not establish the other. Check the CUI authority and contract for the CUI question, and the required CMMC status separately.

Does our DD Form 2345 cover CMMC?

No. DD Form 2345, processed through the Joint Certification Program, is an access-eligibility credential for unclassified militarily critical technical data, not a security assessment and not a guarantee that a particular repository will release data. DLA also requires account approval and a business need for its export-controlled data. What you must do once qualifying data reaches your systems is governed by the applicable contract clauses, including DFARS 252.204-7012 and CMMC where required.

Do we still need to do self-assessment work during the Phase II suspension?

Yes, where your contract requires it. Phase I self-assessment requirements remain in force, the implementation memorandum preserves Level 1 (Self) and Level 2 (Self) designations, and DFARS 252.204-7012 is unchanged. The exact action depends on your solicitation, contract, and the applicable clauses.

Can we still get a third-party certification voluntarily?

Yes. The Cyber AB confirmed in July 2026 that CMMC Level 2 certification assessments, training, examinations, and Registered Practitioner services remain operational. But the Department may not newly designate Level 2 (C3PAO) or Level 3 during the suspension. An existing solicitation, contract, or subcontract can still contain that language until it is formally amended or modified, and a contractor may also pursue a C3PAO assessment voluntarily. Read the document you actually have before deciding why you are doing it.

Our prime is demanding Level 2. What do we ask?

Ask four things in writing: which CMMC level and assessment type, tied to which clause; whether the requirement is at bid, award, option exercise, or subcontract flow-down; what FCI or CUI will actually reach our systems; and what the prime's post-July-13 flow-down position is. Relief given to the Government's contracting officers does not automatically rewrite a subcontract — under DFARS 252.204-7021 the prime flows down the substance of the clause, and that agreement stands until the parties change it.

What if we hold no CUI at all — are we finished?

Not necessarily, and this is the finding most maintenance shops have never seen. DFARS 252.204-7012's reporting duties can attach where a contract designates and identifies performance as operationally critical support — defined in the clause as supplies or services designated by the Government as critical for airlift, sealift, intermodal transportation, or logistical support essential to the mobilization, deployment, or sustainment of the Armed Forces in a contingency operation. Aircraft sustainment can fit that description, but neither you nor a vendor can make the designation. Ask your contracting officer whether any part of your performance carries it.

Should an MRO buy a CUI enclave?

Only after mapping the workflows. An enclave can meaningfully shrink a digital boundary when controlled data can genuinely stay inside it, and for a mixed MRO the boundary should follow data provenance rather than the organization chart. It will not, by itself, resolve paper packets, phone photographs, USB-only test equipment, field work, or uncontrolled vendor transfers.

Is CMMC the same as CMMS?

No. CMMC is the Cybersecurity Maturity Model Certification, a Department of Defense cybersecurity program established at 32 CFR Part 170. CMMS is computerized maintenance management software. A CMM in aviation is a Component Maintenance Manual. Three unrelated things that share an unfortunate number of letters.


The bottom line

You do not need to memorize 110 controls this week. You need four answers, in this order.

One: what your contract actually requires — the level, the assessment type, the clause, and the date. Two: which contracts and maintenance workflows use verified Government-controlled task data and which do not. Three: which contractor information systems and shop-floor devices land in which asset category, and what evidence supports each call. Four: whether any part of your performance is designated as operationally critical support, because that duty runs on its own clock and does not wait for a CMMC level.

Get those four, and every quote you receive afterward becomes legible. Skip them, and you will buy scope you don't owe while missing a reporting obligation you do.

Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Find My CMMC Path → · Download the CMMC Readiness Checklist →

Already know what you need? Request scoped quotes from matched provider categories →

Do not submit CUI, drawings, technical orders, work cards, aircraft or tail data, photographs, program names, network diagrams, credentials, or sensitive contract details. This intake is for provider-category routing only.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial and Advertising Policy.


Related reading