BLOG

CMMC, NIST CSF, and Manufacturing Compliance: What US and Canadian Manufacturers Need to Know

CMMC compliance for manufacturers in the US and Canadian defence supply chain

By David Chernitzky, CEO, Armour Cybersecurity  ·  Serving Toronto and organizations across North America  ·  Last updated August 26, 2026

Key Takeaways

  • CMMC Level 1 requires 15 basic cybersecurity practices aligned to FAR 52.204-21 and applies to all DoD contractors handling Federal Contract Information.
  • CMMC Level 2 requires 110 practices aligned to NIST SP 800-171 and applies to contractors handling Controlled Unclassified Information. Third-party assessment is required for most Level 2 contractors.
  • Canadian manufacturers in the US defence supply chain receive CMMC requirements through contract flow-downs from prime contractors, making CMMC a practical requirement regardless of direct DoD relationship.
  • NIST CSF is the most widely adopted voluntary cybersecurity framework in North American manufacturing and is increasingly required by large automotive, aerospace, and industrial customers.
  • Building a CMMC-compliant programme also satisfies significant portions of NIST CSF, ISO 27001, and customer security questionnaire requirements, making compliance investment productive across multiple customer relationships.

What Is CMMC and Who Does It Apply To?

The Cybersecurity Maturity Model Certification programme was established by the US Department of Defense to ensure that contractors and subcontractors in the defence industrial base protect sensitive government information. CMMC replaced the previous self-attestation model under DFARS 252.204-7012 with a structured certification programme that requires third-party assessment for most contractors handling Controlled Unclassified Information.

CMMC applies to any entity in the DoD supply chain that handles Federal Contract Information or Controlled Unclassified Information. This includes prime contractors who hold DoD contracts directly, and subcontractors who receive CUI or FCI through flow-down from prime contracts. A manufacturer that produces components for a defence prime contractor, or that provides engineering services to a defence integrator, is likely in scope for CMMC requirements even without a direct DoD relationship.

The two levels relevant to most manufacturing contractors are Level 1 and Level 2. Level 1 covers 15 practices from FAR 52.204-21 and applies to contractors handling only Federal Contract Information. Level 2 covers 110 practices from NIST SP 800-171 and applies to contractors handling Controlled Unclassified Information. Level 2 requires annual self-assessment for some contractors and triennial third-party assessment by a C3PAO for those on prioritized programmes.

What Does CMMC Level 2 Actually Require?

CMMC Level 2 maps directly to NIST Special Publication 800-171, which organizes 110 security requirements across 14 domains: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

The practical implementation of these requirements covers the controls that constitute a mature cybersecurity programme: multi-factor authentication on all systems handling CUI, encryption of CUI in transit and at rest, audit logging with defined retention, documented incident response with reporting to the DoD within 72 hours of discovery, configuration management with defined baselines, and annual security assessments.

Manufacturers pursuing CMMC Level 2 must also maintain a System Security Plan that documents how each of the 110 practices is implemented, and a Plan of Action and Milestones for any practices that are not yet fully implemented. The SSP and POAM are living documents that must reflect the current state of the programme, not aspirational future controls. A C3PAO assessor reviewing a CMMC Level 2 programme will compare the SSP to the actual implementation in detail.

What Do Canadian Manufacturers Need to Know About CMMC?

Canadian manufacturers supplying into the US defence industrial base are subject to CMMC requirements through contract flow-down clauses in their agreements with prime contractors. When a US prime contractor includes DFARS and CMMC requirements in a subcontract, those requirements apply to the Canadian subcontractor regardless of the subcontractor’s location. Canadian manufacturers who have received CMMC flow-down requirements without fully understanding their implications are in a common and addressable situation.

Canada’s defence procurement environment has its own cybersecurity requirements under the Industrial and Technological Benefits policy and specific programme requirements such as those under the Canadian Surface Combatant and Joint Support Ship programmes. The Canadian Centre for Cyber Security has published guidance for defence industrial base participants in Canada that aligns with the NIST framework approach, and the Government of Canada is moving toward more explicit cybersecurity requirements in defence contracts.

For Canadian manufacturers who participate in both Canadian and US defence programmes, a cybersecurity programme built to CMMC Level 2 and NIST SP 800-171 requirements provides a foundation that satisfies the majority of both Canadian and US defence supply chain cybersecurity expectations. The investment in CMMC readiness creates dual-market value.

How Does NIST CSF Apply Beyond the Defence Supply Chain?

The NIST Cybersecurity Framework is a voluntary framework, but voluntary does not mean optional in practice for manufacturers in major supply chains. Automotive OEMs, aerospace prime contractors, and large industrial equipment manufacturers are increasingly requiring NIST CSF alignment from their suppliers as a condition of supply agreements. Customer security questionnaires that reference CSF functions and categories are becoming standard in procurement for major manufacturing programmes.

In its current version, CSF 2.0, the framework’s six functions, Govern, Identify, Protect, Detect, Respond, and Recover, provide a governance structure that applies across both IT and OT environments and can be demonstrated to customers without the detailed technical disclosure that specific standard compliance might require. Govern was added in 2024 to make governance and risk management explicit. A manufacturer that can map its controls to CSF categories and demonstrate maturity across all six functions has a credible, communicable security story for enterprise customers.

NIST has also published a Manufacturing Profile of the CSF specifically for the sector, identifying the CSF subcategories most relevant to manufacturing operations and providing implementation guidance aligned to the production environment. The Manufacturing Profile connects CSF to IEC 62443 for OT-specific requirements, providing a unified framework that addresses both enterprise IT and production floor security.

How Does Compliance Investment Pay Off Beyond the Regulatory Requirement?

A CMMC Level 2 programme built properly produces documented controls, evidence, and a programme structure that transfers value well beyond the defence supply chain. The access control, audit logging, incident response, and risk assessment requirements of CMMC align closely with SOC 2, ISO 27001, and the customer security questionnaire requirements that large commercial customers impose. A manufacturer that builds for CMMC and maps the same controls to other frameworks avoids rebuilding its compliance evidence base for each customer or audit.

Cyber insurance premiums and coverage terms are also directly influenced by the maturity of a manufacturer’s cybersecurity programme. Insurers assess controls at renewal and price coverage based on the documented programme. A manufacturer with a CMMC-aligned programme, documented controls, and tested incident response demonstrates the risk profile that insurers price favourably. The premium savings over multiple years can be material relative to the compliance investment.

How Does Armour Cybersecurity Support CMMC Readiness?

Armour Cybersecurity’s compliance audit service covers CMMC Level 1 and Level 2 readiness. The programme begins with a gap assessment against the applicable NIST SP 800-171 practices, produces a prioritized remediation roadmap, supports control implementation, and builds the System Security Plan and evidence base required for assessment, delivered as part of the manufacturing cybersecurity services Armour provides to the sector.

The vCISO service provides the ongoing governance to maintain the programme between assessment cycles. For Canadian manufacturers navigating both CMMC flow-down requirements and Canadian defence programme obligations, Armour’s programme maps controls across both frameworks and produces evidence packages that satisfy both sets of requirements, so a firm does not maintain separate compliance programmes for separate customer relationships.

Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the manufacturers who treat CMMC as one build rather than a defence-only tax are the ones who get the most out of it. They map the same NIST SP 800-171 controls to their SOC 2, their ISO 27001, their customer questionnaires, and their insurance renewal, so a single System Security Plan and evidence base answers a defence prime, an automotive OEM, and a cyber insurer at once, and the certification that started as a contract requirement becomes the reason the business qualifies for work it could not have bid on before.

Frequently Asked Questions

What is a C3PAO and do we need one?

A C3PAO is a CMMC Third-Party Assessment Organization, an organization accredited by the Cyber AB to conduct official CMMC Level 2 assessments. Whether you need a C3PAO assessment depends on the specific contracts you hold and their prioritization by the DoD. Some Level 2 contractors may self-attest annually; others are required to have a triennial C3PAO assessment. Your prime contractor and the specific DFARS clauses in your contracts determine which applies. Armour prepares manufacturers for the C3PAO assessment without conducting the assessment itself.

How long does CMMC Level 2 readiness take?

A manufacturer starting from a basic IT security baseline typically requires twelve to eighteen months to achieve CMMC Level 2 readiness. The timeline depends on the number of gaps identified in the initial assessment, the manufacturer’s capacity to implement changes alongside production operations, and whether any significant infrastructure changes are required. Manufacturers that have already implemented NIST SP 800-171 controls as part of DFARS 252.204-7012 compliance may be closer to readiness and can move faster.

Does CMMC apply to our Canadian facility if the contract is with a US prime?

CMMC requirements flow through contract terms. If your contract with a US prime contractor includes DFARS 252.204-7021, the CMMC requirement applies to your facility regardless of location. The CMMC requirement follows the CUI, not the geography of the subcontractor. Canadian manufacturers who have received these flow-down requirements need to build a CMMC-compliant programme for the systems and facilities that handle the relevant CUI.

Is there a Canadian equivalent to CMMC?

Canada does not currently have a mandatory certification programme equivalent to CMMC, but the direction of Canadian defence procurement policy is toward more explicit cybersecurity requirements. The Canadian Centre for Cyber Security has published guidance aligned to the NIST framework, and specific programme requirements in major Canadian defence procurements include cybersecurity provisions. For Canadian manufacturers, building to CMMC Level 2 exceeds current Canadian programme requirements and positions the organization for both current and anticipated future obligations in both markets.

The Bottom Line

CMMC has turned defence-supply-chain cybersecurity from a self-attested checkbox into a gate on the work itself: Level 1 for Federal Contract Information, Level 2 and its 110 NIST SP 800-171 controls for Controlled Unclassified Information, with a C3PAO looking at whether the System Security Plan matches reality. For Canadian manufacturers the requirement arrives by flow-down, so location is no defence. The manufacturers who come out ahead treat the build as one investment rather than a defence-only cost, mapping the same controls to NIST CSF 2.0, ISO 27001, customer questionnaires, and their insurance renewal. Armour Cybersecurity helps manufacturers reach CMMC Level 1 and Level 2 readiness and build NIST CSF-aligned manufacturing cybersecurity services for US and Canadian supply chain requirements, so compliance stops being a cost centre and becomes the credential that opens markets.

Leave the first comment