PGH Networks

CMMC Compliance for Manufacturers: A Pittsburgh Case Study

July 10, 2026· PGH Networks Team· 5 min readCompliance
CMMC Compliance for Manufacturers: A Pittsburgh Case Study

A 60-person precision machining shop in the Mon Valley makes parts for two Tier 1 defense primes. In late Q3, both primes sent the same message: flow-down clauses now require CMMC Level 2 certification before the next contract renewal. The shop's owner had heard "NIST 800-171" for years, treated it as a checkbox, and now had roughly nine months to reach a score of 110 across 110 controls — with a C3PAO assessment at the end of it. This is the reality driving demand for CMMC compliance for manufacturers across Western Pennsylvania right now, and it is the scenario we want to walk through in detail.

The shop had a typical small-manufacturer IT footprint: a mix of Windows 10 and Windows 11 workstations, a domain controller older than some of the apprentices, a Fortinet firewall no one had audited in three years, CAD/CAM files sitting on a flat file share, and email running in Microsoft 365 Business Standard — which is not an accredited enclave for Controlled Unclassified Information (CUI).

The challenge

The prime's flow-down was unambiguous: any system that stores, processes, or transmits CUI had to meet all 110 NIST SP 800-171 Rev. 2 controls, produce a System Security Plan (SSP) and Plan of Action & Milestones (POA&M), and survive an assessment by an authorized C3PAO. The shop's internal "IT guy" was a shared resource with the maintenance department. There was no SIEM, no documented incident response plan, no FIPS-validated encryption on laptops, and no MFA on the VPN. A self-attested SPRS score, run honestly, would have landed somewhere near negative 90.

Three constraints made this harder than a generic compliance project. First, the production floor could not tolerate downtime — machine controllers on the shop LAN talk to the file share constantly. Second, the budget could not absorb a full GCC High migration for every user; only the eight engineers who actually touch CUI drawings needed that level. Third, the C3PAO assessment window was fixed by the prime's contract calendar.

A CMMC project fails the moment you try to lift every user, every laptop, and every file share into the CUI boundary instead of drawing that boundary as tightly as the business allows.

Linkedin data privacy settings on a smartphone screen

How it was solved

We ran the engagement in four phases over eight months.

Phase 1 — Scoping and gap assessment (weeks 1–4). We mapped every asset that touched CUI and drew an enclave boundary around the eight-person engineering team. Everything outside that boundary — accounting, HR, shop-floor MES, the front-office receptionist — was documented as out-of-scope Contractor Risk Managed Assets or Specialized Assets, which is legitimate under the CMMC scoping guide and dramatically reduces cost. We produced a control-by-control gap analysis against all 110 practices and a preliminary SPRS score.

Phase 2 — Enclave build (weeks 5–14). The eight engineers were migrated to Microsoft 365 GCC High with Azure Government identity, Intune-managed FIPS-encrypted laptops, and Defender for Endpoint. CUI drawings moved from the flat share into a SharePoint site inside the GCC High tenant with sensitivity labels enforcing "CUI//SP-CTI" handling. Everyone else stayed on commercial M365 — cheaper, and out of scope.

Phase 3 — Controls, documentation, and monitoring (weeks 15–28). We deployed a SIEM with 90-day hot log retention and one-year cold retention, wrote the SSP and 14 required policies against the client's actual environment (not a generic template), stood up MFA everywhere including the firewall admin plane, and ran two tabletop incident response exercises. Vulnerability scanning and monthly patch reporting became a standing deliverable.

Phase 4 — Pre-assessment and C3PAO support (weeks 29–34). We conducted a mock assessment, closed the remaining POA&M items, and sat in the room during the C3PAO's on-site evidence review.

TL;DR: Scope the CUI enclave tightly, migrate only the users who need GCC High, and document the environment you actually run — not a template.

Outcomes

The shop passed its CMMC Level 2 assessment on the first attempt. Roughly 52 of 60 employees stayed on commercial Microsoft 365, which kept licensing costs proportional to the actual CUI footprint. The SPRS score submitted to DoD moved from a deeply negative number to 110. Contract renewal with both primes proceeded on schedule, and the shop has since been added to a third prime's approved supplier list — CMMC certification is now a business-development asset, not just a cost center.

Equally important: the security controls put in place for CMMC — MFA, endpoint detection, log retention, documented IR — are the same controls that defend against the ransomware campaigns hitting Pittsburgh-area manufacturers in Cranberry, Monroeville, Washington, and the Mon Valley on a monthly basis.

Wooden letter blocks spelling 'CYBER SECURITY' on a wooden grid background for data protection themes.

Why PGH Networks

We are a Pittsburgh-based MSP inside the 75-mile radius of 15220, which means our engineers can be on your floor in Aliquippa, Latrobe, or New Kensington the same day. We work in the regulatory frameworks Western PA actually deals with — CMMC and NIST 800-171 for defense manufacturing, HIPAA for the region's healthcare networks, and PCI for retail — and we have opinions about how to implement them without breaking production.

Two things we do differently on CMMC compliance for manufacturers. First, we scope aggressively: your CUI enclave should be as small as your contracts allow, because every user you drop into GCC High is a recurring cost. Second, our AI-workflows practice means we can help your engineers use Copilot and other LLM tooling safely inside a compliant boundary — a question every manufacturing client is now asking, and one most compliance-only shops are not equipped to answer.

Takeaway and next step

If your shop just received a flow-down clause, or if a prime has asked for your current SPRS score and you are not sure what to say, the nine-month clock is already running. The scenario above is repeatable, but only if scoping is done correctly at the start — mistakes made in week one are expensive to undo in week thirty.

Schedule a 30-minute CMMC scoping call with our team. We will review your contract's flow-down language, sketch a realistic enclave boundary, and give you a defensible SPRS score estimate before you commit a dollar to remediation. Call PGH Networks at 724.888.7007 or request a consultation through our contact form.

Share

Related reading

CMMC Compliance Consultant in Pennsylvania

Pittsburgh-based CMMC compliance consultant for Pennsylvania defense contractors: step-by-step path to Level 2 readiness, SPRS scores, and DoD contract eligibility.

HIPAA Compliant MSP in Pittsburgh

A Pittsburgh case study in how a HIPAA compliant MSP hardened a 60-person specialty practice ahead of an OCR-triggered risk review. See the playbook.