PGH Networks

AI Readiness Assessment for Manufacturers

July 22, 2026· PGH Networks Team· 5 min readAI & Automation
AI Readiness Assessment for Manufacturers

A 180-person contract manufacturer near Canonsburg makes precision machined parts for two defense primes and a handful of commercial aerospace customers. The CEO came back from a trade show convinced the shop needed to "do something with AI" before the next fiscal year. The plant manager wanted a chatbot that could answer questions about work instructions. The controller wanted to stop paying two people to key in supplier invoices. And the primes had just sent a fresh reminder that CUI handling under DFARS 7012 was going to be audited, hard.

That's the point where most manufacturers call us. They don't need a keynote about generative AI. They need a grown-up AI readiness assessment for manufacturers that tells them, in plain English, what to fix first, what's safe to turn on, and what will get them in trouble with a prime contractor or an auditor.

The challenge

The shop floor ran on a mix of an older ERP, a homegrown MES built in Access years ago, PDF travelers, and tribal knowledge. Engineering drawings and CUI lived in a shared drive with permissions no one had touched since 2019. Microsoft 365 was deployed, but sensitivity labels were not. Two engineers had already been pasting drawing revisions into public ChatGPT to "save time" writing customer emails.

The fastest way to fail a CMMC Level 2 assessment is to roll out Copilot on top of a file share you haven't cleaned up.

So the real problem wasn't "should we use AI." It was: the same data hygiene, identity, and labeling work required for CMMC Level 2 is the exact prerequisite for turning on Microsoft 365 Copilot safely. Doing them as one project is cheaper than doing them twice.

an abstract image of a sphere with dots and lines

How it was solved: the AI readiness assessment for manufacturers

We ran a six-week engagement combining our AI advisory practice with the vCIO team. Week one was discovery: interviews with the CEO, plant manager, quality lead, controller, and two floor supervisors. We mapped every system that held CUI, every place data crossed a trust boundary, and every "AI-ish" tool people were already using without IT's knowledge (there were nine).

Weeks two and three focused on data and identity. We inventoried the file shares, tagged CUI candidates, and modeled what Microsoft 365 Copilot would surface if enabled today. The answer was: too much. Salary data, an acquisition NDA, and unredacted drawings all would have been reachable by any licensed user. We built a remediation backlog against NIST SP 800-171 controls, because that work double-counts for compliance and for a defensible Copilot rollout.

Weeks four and five scored use cases. Every idea the leadership team had floated got rated on business value, data sensitivity, and build complexity. The supplier-invoice pain point became a scoped document automation project using Azure OpenAI inside the tenant, not a public model. The "work instructions chatbot" was deferred until the underlying documents were cleaned and versioned, because a chatbot that confidently cites a superseded revision is worse than no chatbot at all.

Week six was the readout: a prioritized 12-month roadmap, a written acceptable-use policy, a Copilot pilot plan for a 15-person cohort in engineering and finance, and a fixed-fee proposal for the invoice AI workflow automation build.

What's included in the assessment

TL;DR: You leave the engagement with a scored use-case backlog, a data and identity remediation plan mapped to NIST 800-171, a Copilot readiness verdict, and a written AI acceptable-use policy, not a slide deck full of possibilities.

Every AI readiness assessment for manufacturers we deliver includes: a systems and data-flow map, a CUI and sensitive-data inventory, a Microsoft 365 and Entra ID configuration review, a Copilot readiness verdict (green/yellow/red by workload), a scored use-case backlog with rough-order build estimates, an acceptable-use policy draft, and a 12-month roadmap tied to your fiscal calendar.

Outcomes

Within the first quarter after the readout, the Canonsburg shop closed 22 of 34 NIST 800-171 gaps, retired the shadow-AI tools, launched the Copilot pilot to 15 users with sensitivity labels enforced, and moved the supplier-invoice process to an internal AI tool that routes exceptions to the controller instead of consuming her afternoons. The primes got a straight answer about CUI handling. The CEO got a roadmap he could defend to the board.

Who this is for

This engagement fits Pittsburgh-region manufacturers between roughly 50 and 500 employees, especially job shops and contract manufacturers in the defense, aerospace, medical device, and energy supply chains. If you're in Washington, Butler, Westmoreland, Beaver, or Allegheny County and you're feeling pressure from a prime, an insurer, or a curious CEO, this is built for you. It's also a fit if you already have decent managed IT but no one internally who owns AI strategy.

a computer chip with the letter a on top of it

Why PGH Networks

We're local: our team is within 75 miles of 15220 and on-site is a drive, not a flight. We run cybersecurity, CMMC Level 2 prep, and the AI advisory practice under one roof, so the Copilot rollout and the DFARS work don't get handed between two vendors who blame each other. And we build the custom pieces when off-the-shelf isn't enough, from a custom chatbot grounded in your work instructions to invoice and quoting automations.

Takeaway and next step

Manufacturers who treat AI as a separate project from compliance pay for the same cleanup twice. Manufacturers who sequence them correctly get a defensible CMMC posture and a working Copilot pilot for roughly the cost of the compliance work alone.

If that's the conversation you want to have, call 724.888.7007 or reach us through the contact form and ask for an AI readiness assessment for manufacturers. We'll tell you within a 30-minute call whether it's the right next step.

Share

Related reading

AI Automation for Law Firms in Pittsburgh

AI automation for law firms in Pittsburgh: intake, drafting, and document review workflows built with privilege, confidentiality, and PA Bar ethics in mind.