Most defense contractors approach CMMC scoping by inventorying systems.
The organizations that succeed approach it differently: they follow Controlled Unclassified Information (CUI).
A single technical drawing can move from CAD to PLM, supplier portals, manufacturing systems, test environments, quality records, and subcontractor networks in hours. Every handoff can create another CUI repository, another in-scope user group, and another compliance obligation. That boundary can extend beyond the enterprise when suppliers and subcontractors receive, store, process, transmit, or share the same controlled information.
That is why many defense manufacturers discover their CMMC scope is far larger than originally expected. An unexpectedly large CMMC boundary can increase remediation costs, complicate assessment preparation, and expose previously overlooked risks across engineering and supplier environments. The later these connections are discovered, the more difficult they can be to address without disrupting established workflows.
Why defense contractors struggle with CMMC scope
For aerospace and defense manufacturers, CUI does not stay confined to one environment.
Engineering data moves continuously across:
- Design teams
- Manufacturing operations
- Suppliers and subcontractors
- Quality systems
- Program management
- Test and validation environments
As engineering and manufacturing become more digitally connected, CUI can move across systems, teams, and suppliers faster than organizations realize. The challenge is understanding where CUI exists, how it moves, and who can access it.
Organizations frequently underestimate:
- Which systems process CUI
- Which suppliers access CUI
- Which exports and replicas exist outside managed repositories
- How technical data moves between engineering and manufacturing
- How many users interact with controlled information
Those gaps may not surface until assessment preparation, when remediation is more expensive and disruptive.
New research: State of CMMC readiness across the defense industrial base
Explore ABI Research’s exclusive survey findings on CMMC readiness, engineering data security priorities, planned investments, and the biggest obstacles organizations face today.
Download the Report
Why the digital thread matters for CMMC
CMMC scoping should begin with one question: Where does CUI live?
Answering that question requires more than an application inventory. Organizations need to understand how controlled information is created, stored, processed, transmitted, and shared across the product lifecycle.
That means tracing the digital thread.
A technical drawing may originate in CAD, move into PLM, feed downstream manufacturing systems, appear in quality documentation, and later be shared with suppliers or sustainment partners. Every downstream connection can expand the compliance boundary.
Following the digital thread exposes:
- Hidden CUI repositories
- Unmanaged data duplication
- Supplier exposure
- Cross-domain integrations
- Inherited compliance risk
For defense contractors, this is especially important because engineering environments often sit at the center of the CUI ecosystem.
1. CAD systems
For many defense manufacturers, CUI first appears inside design engineering environments.
CAD systems often contain:
-
Technical drawings
- 3D models
- Engineering specifications
- Export-controlled technical data
- Program-specific design information
Questions to ask:
- Which CAD environments contain CUI?
- Who can access design data?
- Are files copied outside managed repositories?
Many organizations focus heavily on securing email and collaboration tools while overlooking engineering workstations and design repositories that contain highly sensitive technical data.
2. Product lifecycle management (PLM)
PLM systems can be central to a defense contractor's CMMC environment.
PLM platforms frequently contain:
- Released product definitions
- Bills of materials (BOMs)
- Engineering changes
- Configuration baselines
- Technical documentation
- Supplier-facing product data
Because PLM connects engineering, manufacturing, suppliers, and program execution, it can become a central hub for CUI across the enterprise.
Questions to ask:
- Does PLM contain controlled technical information?
- Which downstream systems consume PLM data?
- Which suppliers receive information originating from PLM?
Many organizations discover their PLM environment sits directly inside CMMC scope because it governs controlled product information across the digital thread.
3. Requirements and systems engineering platforms
Requirements management and systems engineering environments commonly contain:
- Government requirements
- Program specifications
- Verification criteria
- Technical constraints
- Mission and performance data
These systems inform downstream engineering decisions.
Questions to ask:
- Does the platform contain CUI or controlled program requirements?
- Are requirements shared across organizational boundaries?
- Are exports stored outside managed systems?
As defense systems become increasingly software-defined and model-based, requirements and systems engineering platforms warrant greater attention during CMMC scoping.
4. Test and validation systems
Validation environments generate highly sensitive technical data, including:
- Test procedures
- Qualification documentation
- Performance results
- Failure analysis
- Verification reports
Test data can be as sensitive as the original design itself.
Questions to ask:
- Where are test results stored?
- Who can access validation data?
- Are reports distributed outside managed environments?
Test artifacts may be distributed across engineering and supplier teams, creating additional locations where CUI must be identified and protected.
5. Manufacturing systems
CUI frequently spreads from engineering into manufacturing operations.
Manufacturing systems may contain:
- Work instructions
- Production specifications
- Manufacturing process documentation
- Technical data packages
- Configuration information
Once engineering data reaches production, CUI may become accessible to a broader group of manufacturing users.
Questions to ask:
- Which manufacturing systems consume engineering data?
- Is CUI replicated from upstream systems?
- Who can access controlled technical data on the shop floor?
Manufacturing environments can significantly expand the CMMC boundary as controlled engineering data moves into production systems and workflows.
6. Quality management systems
Quality systems often contain:
- Inspection criteria
- Nonconformance records
- Corrective actions
- Audit documentation
- Product traceability information
Quality records frequently inherit CUI from engineering and manufacturing systems.
Questions to ask:
- Does quality data reference controlled technical information?
- Are records shared externally?
- Which suppliers participate in corrective action workflows?
7. Supplier collaboration environments
Supplier collaboration can extend CUI beyond internally managed systems and into the broader defense supply chain.
Defense contractors routinely share controlled technical information with suppliers, subcontractors, manufacturing partners, joint development teams, and sustainment providers. These organizations may work directly within engineering, manufacturing, quality, and supplier collaboration environments.
As a result, supplier exposure is not limited to file transfers. Organizations also need to understand which subcontractors can access systems containing CUI, what information they can access, and how that access is governed.
Questions to ask:
- Which suppliers and subcontractors access CUI?
- Which systems do they access?
- Do they download CUI or work directly within controlled environments?
- How is supplier access granted and revoked?
- Can controlled information be downloaded or redistributed?
Not every supplier creates the same CUI exposure. For CMMC scoping, supplier size, spend, or position in the supply chain is less important than whether the supplier receives, stores, processes, or shares CUI. A small engineering subcontractor with access to controlled technical drawings may have a greater impact on the CMMC boundary than a much larger supplier that never handles CUI.
From system inventory to data mapping
A practical way to uncover hidden CMMC scope is to trace a single piece of CUI across its lifecycle.
For example, follow a technical drawing as it is created in CAD, managed in PLM, shared with a manufacturing subcontractor, referenced during inspection, and stored in supplier documentation systems. Each step may introduce another system, user group, or external organization that needs to be considered during scoping.
Start with:
- A technical drawing
- A requirement
- A test report
- A manufacturing specification
Ask:
- Where is it created?
- Where is it stored?
- Where is it shared?
- Who accesses it?
- Which systems consume it?
- Which suppliers receive it?
This exercise can reveal systems, users, integrations, copies, and supplier connections that a traditional application inventory may miss. Those connections help organizations build a more complete picture of their CMMC boundary before gaps surface during assessment preparation.
Bring greater control to CUI across the digital thread
Mapping CUI becomes more difficult when engineering and product data are fragmented across disconnected systems, uncontrolled copies, and supplier environments.
PTC solutions help defense contractors govern product data, engineering collaboration, configuration management, and supplier access across the digital thread.
This can help organizations:
- Identify systems that may fall within CMMC scope
- Understand how CUI moves across the product lifecycle
- Govern access to controlled technical information
- Reduce uncontrolled data duplication
- Strengthen supplier collaboration
- Identify potential scoping gaps earlier
For many defense contractors, PLM sits at the center of this environment because it governs technical drawings, product definitions, configuration baselines, engineering changes, and supplier-facing product information.
For organizations managing CUI in the cloud, PTC's FedRAMP Certified Windchill+ offering provides a secure environment for engineering and product data. Its FedRAMP Certification provides an independently assessed security foundation that can support an organization's broader CMMC compliance strategy.
Before you can protect CUI, you have to know where it lives
The organizations that navigate CMMC most effectively do not start with a checklist. They start by mapping their data across systems, users, and organizational boundaries. That includes understanding not only where CUI exists internally, but where it travels when suppliers and subcontractors become part of the digital thread.
Start by tracing one technical drawing, requirement, or test record across your digital thread. The systems, users, copies, and supplier connections you uncover can provide a clearer picture of your true CMMC scope and where additional controls may be needed.
Topics
Digital Thread
Regulatory Compliance
Up Next
CMMC readiness starts with protecting engineering data
Learn how to secure engineering and product data while maintaining collaboration across the digital thread.
Discover Why PTC Is Different