Securing the OT/IT Boundary for Mid-Market Manufacturers
ICS/SCADA monitoring, NIST 800-171 and CMMC-aligned CUI protection, and production-floor physical security for manufacturers and their defense and industrial supply chains — delivered across Armorstack’s four portfolios: VERITY, CORE, SENTRY, and CITADEL.
Discrete & Process Manufacturing
Automotive & Aerospace Supply Chain
Industrial Controls & SCADA
Multi-Plant Operations
A Ransomware Event on the Shop Floor Isn’t an IT Ticket — It’s a Stopped Line
Manufacturers run two networks that were never designed to be one: a corporate IT environment built for confidentiality, and an operational technology environment — PLCs, HMIs, SCADA historians — built decades ago for uptime, with security bolted on if at all. Many mid-market manufacturers are also defense or aerospace subcontractors, which means a network segmentation failure isn’t just downtime, it’s a Controlled Unclassified Information exposure with federal contract consequences. Armorstack treats the OT/IT boundary as the primary threat surface, not an afterthought.
Five Frameworks Every Manufacturer Should Know
Whether or not you touch defense contracts, these are the real, named standards governing OT security and export-controlled data in manufacturing.
CMMC 2.0
Any manufacturer receiving Federal Contract Information or Controlled Unclassified Information as a defense prime or subcontractor needs Level 1 (FCI, self-attestation) or Level 2 (CUI, 110 NIST 800-171 controls, C3PAO-assessed) certification. DFARS 252.204-7021 became a contract gate effective November 10, 2025; the requirement to include Level 2 C3PAO assessments in solicitations begins phasing in November 10, 2026. There is no small-business exemption — the requirement flows down through the supply chain.
Source: Acquisition.gov, DFARS 252.204-7021/-7025 (acquisition.gov)NIST SP 800-171
The 110 security controls across 14 families that CMMC Level 2 is built on, governing how CUI must be protected on non-federal systems. This is the control baseline your System Security Plan and Plan of Action & Milestones get scored against for SPRS.
Source: National Institute of Standards and Technology, NIST SP 800-171 Rev. 2 (csrc.nist.gov)NIST SP 800-82 Rev. 3
Published September 2023 and retitled “Guide to Operational Technology (OT) Security,” this is the reference guidance for protecting SCADA, distributed control systems, and PLCs on the shop floor, organized around 19 control families mapped to the NIST Cybersecurity Framework.
Source: National Institute of Standards and Technology, NIST SP 800-82r3 (csrc.nist.gov)IEC 62443
The international standards series for industrial automation and control system security, defining a zones-and-conduits architecture, four Security Levels, and requirements spanning asset owners, integrators, and equipment suppliers — the common language OT vendors and manufacturers use to talk about control-system security.
Source: International Electrotechnical Commission / ISA Global Cybersecurity Alliance (isagca.org)ITAR & EAR Export Controls
Manufacturers producing parts or technical data for defense or dual-use applications — sometimes as narrow as machined fasteners for military aircraft — can fall under ITAR (State Department, defense articles) or EAR (Commerce Department, dual-use and commercial items). Giving a foreign-national employee access to controlled technical data counts as an export and can require a license.
Source: U.S. Department of State, ITAR (pmddtc.state.gov); U.S. Department of Commerce, EAR (bis.gov)How Armorstack Secures Manufacturers
One converged model, four coordinated portfolios — each mapped directly to the standards above.
OT/ICS Network Monitoring
Protocol-aware passive monitoring purpose-built for SCADA, DCS, and PLC environments — visibility across the IT/OT boundary without disrupting production uptime, aligned to NIST SP 800-82r3 and IEC 62443’s zones-and-conduits model.
Production-Floor Physical Security
Access control and surveillance for production floors, tool cribs, and CUI-scoped work areas — supporting CMMC physical safeguard requirements and export-control access restrictions for ITAR-controlled technical data.
CMMC & SSP/POA&M Governance
vCISO-led System Security Plan and Plan of Action & Milestones maintenance, SPRS score management, and C3PAO assessment preparation — keeping your CUI boundary and control evidence audit-ready between assessment cycles.
Segmented IT Backbone
Hardened, redundant network infrastructure for the corporate-IT side of the house, segmented cleanly from OT per IEC 62443’s zones model, so a phishing incident on the office network never reaches the control-system network.
Manufacturing Security & Compliance Questions
Do we need CMMC if we’re only a small subcontractor, not a prime?
Yes, in most cases. DFARS 252.204-7021 flows down through the supply chain, and there is no small-business exemption. If you receive FCI or CUI from a prime or another sub upstream of you, the same CMMC level applies to your environment, and the prime is contractually obligated to verify your certification.
Is OT security the same discipline as our IT cybersecurity program?
No. OT environments prioritize availability and safety over confidentiality, often run on legacy protocols with no native authentication, and can’t tolerate the same patching cadence or active scanning IT networks use. NIST SP 800-82r3 and IEC 62443 exist because IT security controls, applied directly to OT, can cause outages rather than prevent them.
Could a small machine shop really be subject to ITAR?
Yes. ITAR covers any technical data required for the design, production, or maintenance of a defense article — that can include a shop producing custom fasteners or brackets for a military aircraft program, not just large defense primes. Registration and controlled-data-handling obligations apply regardless of company size.
How does CMMC 2.0 relate to NIST 800-171?
CMMC Level 2 is essentially a third-party assessment of your implementation of the 110 NIST SP 800-171 Rev. 2 controls. Organizations that have already built a NIST 800-171-aligned program have done most of the work required for CMMC Level 2; the certification adds a formal C3PAO assessment on top of self-attestation.
What does an Armorstack Manufacturing Security Assessment look at?
A structured review of your OT/IT network segmentation, CMMC/NIST 800-171 control implementation and SSP documentation, physical security in CUI-scoped and export-controlled work areas, and detection coverage across the IT-OT boundary — benchmarked against the frameworks that actually apply to your contracts.
Ready to Close the Gap at the OT/IT Boundary?
Talk to Armorstack about a Manufacturing Security Assessment — scoped to your production floor, your CUI boundary, and your actual contracts.
Schedule a Consultation