CUI Data Flow in Defense Manufacturing: What Your CMMC Diagram Must Show

Explore the critical role of Data Flow Diagrams in CMMC compliance, including creation steps, challenges, best practices, and their significance in audits.

CUI Data Flow in Defense Manufacturing: What Your CMMC Diagram Must Show

In a defense manufacturing environment, controlled unclassified information does not move through your network the way a typical IT assessment assumes. CUI enters with the first drawing a customer sends, flows through business systems most manufacturers think of as operations, and ends up stored in machine controllers and quality equipment that have never appeared in a compliance conversation. A CMMC data flow diagram that stops at your firewall is incomplete. Here is what accurate data flows in a manufacturing environment actually look like.

Why Manufacturing CUI Data Flows Differently

Most DFD guidance written for CMMC is written for office environments — servers, workstations, email, cloud storage. That covers part of the picture for a defense subcontractor. The rest lives on the shop floor, in the quality room, and in systems that engineers and operations staff use every day without thinking of them as IT assets.

The data flow diagrams your CMMC assessors will review need to show where CUI enters, what systems it touches, where it is stored, and where it exits your environment. A data flow diagram is a visual representation of how data moves through your environment — showing external entities, processes, data stores, and the flows between them. In a manufacturing context, that map looks fundamentally different from what a corporate IT team would draw. Seven systems carry CUI from the moment a controlled drawing arrives to the moment a finished part ships.

Organizations handling only Federal Contract Information without CUI may qualify for CMMC Level 1 self-assessment. Most defense manufacturers receiving technical drawings handle FCI and CUI simultaneously, which means CMMC Level 2 certification and a full third-party assessment apply.

The Seven Steps Where CUI Lives in Your Manufacturing Environment

Step 1: Drawing Intake — Where CUI Enters

A customer sends a controlled engineering drawing. It arrives through a secure portal, by email, or on physical media. Someone downloads it and saves it to a file server before any engineering work begins.

That drawing is CUI from the moment it arrives — before anyone touches it, marks it, or assigns it a job number. What makes this the highest-risk step in the data flow is who handles the drawing first. It is rarely an engineer. Estimators reviewing drawings for quoting, operations managers triaging incoming work, and sales staff may all interact with a controlled drawing before it reaches an engineering workstation. These users typically work on general-purpose computers with no hardening, no data loss prevention controls, and sometimes on personal devices.

Email is one of the most common entry points for controlled drawings and is almost never treated as a controlled system in scope.

Step 2: ERP — Where CUI Becomes Business Data

Once a drawing is received, a job is created in the ERP system. The job ties the controlled drawing to a work order, a customer name, a part number, a bill of materials, a delivery schedule, and a production routing. All of these carry CUI exposure because they describe controlled work tied to a defense program. This information flows into ERP data storage and persists for the life of the job and often well beyond.

ERP systems are among the most consistently under-scoped assets in manufacturing CMMC assessments. Access is typically broad — accounting, purchasing, sales, and production scheduling staff all have accounts. If your ERP is a cloud-based platform that is not FedRAMP authorized, CUI stored there is a compliance exposure that most small manufacturers have never been told about. Platforms like NetSuite are widely used cloud ERPs that are not authorized to store controlled government information.

Step 3: CAD — Where Derivative CUI Is Created

An engineer works from the controlled drawing to build a 3D model. The CAD file is derivative CUI — it was created from the controlled drawing and contains the same sensitive technical data in a different format. That file needs to be protected and tracked the same way the original drawing does, and the workstation and shared drive where it lives are in scope for your CMMC Level 2 system boundary.

Step 4: CAM — Where the Model Becomes Machine Instructions

The CAD model is imported into CAM software to generate the toolpaths and G-code that will run on a CNC machine. CAM output files are derivative CUI. They contain the machining information needed to produce a controlled part, derived directly from the controlled drawing. The CAM workstation, the software license, and the output files it stores are all inside your authorization boundary.

Step 5: DNC / Program Management — Where Programs Are Stored and Distributed

DNC software — platforms like Predator DNC — serves as a centralized library for CNC machine programs. It stores, versions, and distributes G-code programs to machines across the shop floor. The DNC server is a CUI asset. The programs it stores are derivative CUI. The workstation running DNC software, the server it runs on, and the network connections that distribute programs to machines are all part of your data flow and must appear in your CMMC data flow diagram.

Step 6: Shop Floor — Where CUI Reaches Production

On the shop floor, CUI reaches the machine in one of two ways: through a CNC controller or through a PLC/HMI environment.

CNC machines store programs in their controllers. A controller may have a library of previously run programs sitting in its memory — derivative CUI at rest on shop floor equipment that almost never appears in compliance scoping. Network-connected machines are in scope and need to be on a controlled network segment. Older machines on RS-232 serial connections are not off the hook: the laptop used to transfer programs via USB-to-serial is handling derivative CUI every time it connects. USB drives used for transfer are removable media containing derivative CUI and need to be controlled.

PLC environments in automated production lines add another dimension. If the PLC logic was written using specifications derived from a controlled drawing — controlled dimensions, feed rates, tolerances, process parameters — that logic is derivative CUI. Recipe files containing controlled specifications are derivative CUI. FactoryTalk Historian may be logging process parameters tied to controlled part numbers, making an operational data system a CUI exposure point that sits entirely outside the corporate network.

Step 7: CMM / Quality — The Most Overlooked Step

A CMM is a coordinate measuring machine — the final step in production before a part ships. The CMM program is written directly from the controlled customer drawing. The inspection report it produces contains actual measured dimensions of a controlled part.

CMM workstations are the most consistently overlooked asset in manufacturing CMMC assessments. They sit in the quality room, are operated by quality staff rather than IT staff, and almost never appear in scoping conversations. The workstation running CMM software, the programs stored on it, and the inspection reports it produces are all inside the CUI data flow.

What Your CMMC Data Flow Diagram Must Show

A data flow diagram for CMMC compliance needs to capture where CUI enters and leaves your environment, all data storage locations, and every system that processes or transmits it. For a manufacturing organization that means the DFD extends well beyond the corporate network and includes:

  • Entry points: email, customer portals, physical media — and the workstations that receive them
  • Business systems: ERP, including cloud-based platforms
  • Engineering systems: CAD, CAM
  • Program management: DNC server and workstations
  • Shop floor equipment: CNC controllers, PLC environments, HMI systems
  • Quality systems: CMM software, inspection report storage
  • Exit points: how finished part documentation, inspection reports, and program files leave your environment

Your network diagram shows the physical and logical infrastructure. Your data flow diagram shows what CUI actually does within that infrastructure. CMMC assessors expect both documents. They also expect them to be consistent with each other and with your System Security Plan.

Creating data flow diagrams at this level of manufacturing detail requires input from more than just your IT staff. When you create a data flow diagram for CMMC, involve your operations manager and quality lead — they know how programs reach machines and how CMM reports are stored. Tools like Visio or Lucidchart are commonly used to build DFDs that meet CMMC documentation standards, but the diagram is only as accurate as the environment knowledge behind it.

Keeping Your Data Flow Diagram Current

A DFD that accurately reflected your environment at certification can drift from reality quickly. A new machine on the floor, a new ERP module, a move to cloud storage, a new vendor connection — any of these can change the CUI boundary. Review and update your data flow diagram whenever significant system changes occur, not just at the next assessment cycle.

CMMC requirements include annual affirmations by senior leadership confirming that controls remain in place and your security posture has not degraded. Under CMMC 2.0, Level 2 organizations must affirm compliance annually. A stale data flow map that no longer reflects how your environment actually handles CUI undermines your ability to protect CUI and affirm compliance with confidence.

Right Hand Technology Group works with defense subcontractors to scope their CUI environments and build data flow maps that accurately reflect how manufacturing environments actually operate — shop floor systems included. Review our CMMC compliance services to understand how we approach manufacturing environments, or schedule a free assessment to map your CUI boundary before your next customer questionnaire or assessment.

 

Frequently Asked Questions

How do I know if data in my manufacturing systems qualifies as CUI?

Check your contracts for DFARS 252.204-7012 language or references to covered defense information. If that clause appears — directly or through flow-down from a prime contractor — CUI protection requirements apply. For manufacturing-specific systems, the key question is whether the data was derived from a controlled customer drawing. CAD files, CAM programs, CNC controller programs, and CMM inspection reports created from controlled drawings carry CUI designation even if they are not explicitly marked. When in doubt, scope the system in and confirm with a compliance review.

Does my CNC machine need to be in my CMMC system boundary?

Yes, if it stores programs derived from controlled customer drawings. A CNC controller that retains G-code programs tied to defense work is storing derivative CUI at rest. The same logic applies to the DNC server that distributes those programs, the laptop used to transfer programs to older machines via serial connection, and the USB drives used in that transfer. In most manufacturing CMMC assessments, the largest compliance gaps are not in the office IT environment — they are in shop floor equipment that was never considered part of the system boundary.

What is the difference between a network diagram and a data flow diagram for CMMC?

A network diagram shows your physical and logical infrastructure — servers, workstations, switches, firewalls, and how they connect. A data flow diagram shows what CUI actually does within that infrastructure — where it enters, what systems process or store it, and where it exits the environment. CMMC assessors review both documents, and they expect them to be consistent with each other and with your System Security Plan. The network diagram confirms your infrastructure meets technical control requirements. The DFD confirms you have accurately identified your authorization boundaries and the CUI data flows within them.

Our Blog

Why Every Business Needs an IT Risk Assessment?

Why Every Business Needs an IT Risk Assessment?

An IT risk assessment identifies where client data actually lives, who can reach it, and…

Why Your Small Business Network Setup Matters More Than You Think?

Why Your Small Business Network Setup Matters More Than You Think?

A small business network setup includes more than a router and a Wi-Fi password.…

Windows 10 ESU Cost: What Delaying Your Upgrade Will Really Cost

Windows 10 ESU Cost: What Delaying Your Upgrade Will Really Cost

Windows 10 Extended Security Updates cost $61 per device for Year One, and the…