← Custodia
CMMC Level 1 · Industrial equipment

CMMC Level 1 for industrial machinery & equipment suppliers

Manufacturers and overhaul shops supplying machinery, generators, material handling equipment, and ground support equipment to the military sit at CMMC Level 1 for build to print and repair work. POs, drawings, manuals, and delivery records are Federal Contract Information (FCI). Marked technical data under a DFARS 252.204-7012 flow-down moves specific programs to Level 2.

Overview

If you build, supply, or overhaul industrial machinery, generators, pumps, material handling equipment, or ground support equipment for the military, your purchase orders, drawings, technical manuals, and delivery records are Federal Contract Information. That triggers FAR 52.204-21 and a CMMC Level 1 self-assessment with an annual SPRS affirmation.

Equipment supply and overhaul is usually Level 1 because the work is build to print or repair from unmarked packages. A specific program reaches Level 2 only when a prime flows down DFARS 252.204-7012 and sends marked technical data.

These shops run on an ERP or MRP system, engineering and service stations, and an email tenant. Level 1 covers the systems that hold program FCI, which means named accounts, MFA, controlled access to drawings and manuals, and a clean boundary.

Typical contracts you'll see

  • Subcontracts and direct buys for machinery, generators, and pumps
  • Material handling and ground support equipment contracts
  • Equipment overhaul, rebuild, and repair contracts
  • DLA buys for machinery parts and assemblies
  • GSA and SEWP supply of industrial equipment

What FCI actually looks like for you

Anything below is Federal Contract Information and triggers FAR 52.204-21. None of it is CUI on its own.

Purchase orders and statements of work from an agency or prime
Assembly and service drawings that are not marked CUI
Technical and maintenance manuals produced under the contract
Delivery schedules, packing slips, and DD-250 acceptance documents
Warranty, repair, and corrective action records

Common pitfalls in this industry

  • Storing drawings and manuals on an open share readable by everyone, which fails FAR 52.204-21 (b)(1)(iii).
  • Running the ERP or service system on a shared login, which fails (b)(1)(i) and (ii).
  • Emailing POs and drawings from personal accounts, which fails (b)(1)(iii).
  • Assuming heavy equipment work is out of scope. The FCI in the paperwork is what triggers CMMC.
  • Missing a real -7012 flow-down on a specific program.
  • Letting the annual SPRS affirmation lapse.

Your Level 1 action plan

  1. 01Confirm with each prime or agency whether any -7012 flow-down applies and whether marked technical data is in play.
  2. 02Inventory the systems that hold program FCI: ERP or MRP, engineering and service stations, the file share, email, and backups.
  3. 03Move PO and drawing exchange onto a paid Microsoft 365 or Google Workspace tenant with MFA enforced.
  4. 04Give every engineer and service tech a named account and set drawing and manual access to least privilege.
  5. 05Separate program systems from public web browsing and the company website.
  6. 06Write a short boundary description naming the systems that hold program FCI and who can access them.
  7. 07Run the 15 practice self-assessment, capture evidence, then have a senior official affirm the score in SPRS and set the annual reminder.

Most common NAICS codes

Use these when searching SAM.gov, filing for set-asides, or checking size standards.

  • 333120Construction Machinery Manufacturing
  • 333611Turbine & Turbine Generator Set Units Manufacturing
  • 333924Industrial Truck, Tractor, Trailer & Stacker Machinery Manufacturing
  • 333998All Other Miscellaneous General Purpose Machinery Manufacturing
  • 811310Commercial & Industrial Machinery & Equipment Repair & Maintenance

Frequently asked questions

Q.We just supply generators to a base. Do we need CMMC?

Yes, once you hold a federal contract or subcontract. The purchase orders, drawings, manuals, and delivery records are Federal Contract Information, and FAR 52.204-21 applies to the systems that hold them. The 15 practices are basic protections on your ERP and email, not on the equipment.

Q.When would equipment work be Level 2?

When a prime flows down DFARS 252.204-7012 and sends technical data explicitly marked as CUI or Controlled Technical Information for a specific program. General machinery supply and overhaul from unmarked packages stays at Level 1.

Q.Are our technical manuals FCI or CUI?

Manuals you produce or receive under the contract are FCI unless they are explicitly marked as CUI. Look for a CUI banner and category. If something should be marked but is not, ask the contracting officer rather than assuming.

Q.Do I need an SSP at Level 1?

No. Level 1 does not require a System Security Plan under 32 CFR Part 170. You need evidence the 15 practices are met for the systems that handle FCI, plus a short boundary description and a current list of authorized users.

Related clauses

Related terms

Read more in the Library

Other Level 1 industries
Machine shops & precision manufacturers
Read the machine shops guide →
SBIR Phase I awardees
Read the sbir phase i winners guide →
Construction, facilities & base-services subcontractors
Read the construction & facilities guide →
IT services & managed service providers (MSPs)
Read the it services & msps guide →
Software & application development firms
Read the software development guide →
Aerospace & aircraft parts manufacturers
Read the aerospace parts guide →
Metal fabrication & welding shops
Read the metal fabrication guide →
Base operations & facilities O&M contractors
Read the facilities & base ops guide →
Logistics, warehousing & distribution contractors
Read the logistics & warehousing guide →
Electronics & circuit card manufacturers
Read the electronics manufacturing guide →
Management & professional services consultants
Read the professional consulting guide →
Staffing & workforce services firms
Read the staffing services guide →
Janitorial & custodial services contractors
Read the janitorial & custodial guide →
Engineering services firms
Read the engineering services guide →
Medical & pharmaceutical supply distributors
Read the medical supply distribution guide →
Defense electronics & instrument makers
Read the defense electronics guide →
Shipbuilding & marine repair contractors
Read the shipbuilding & marine guide →
Plastics & rubber products manufacturers
Read the plastics & rubber guide →
Textiles, apparel & uniform manufacturers
Read the textiles & apparel guide →
PPE & safety equipment suppliers
Read the ppe & safety equipment guide →
Medical device & instrument manufacturers
Read the medical devices guide →
Specialty trade subcontractors (electrical, plumbing)
Read the specialty trades guide →
HVAC & mechanical contractors
Read the hvac & mechanical guide →
Landscaping & grounds maintenance contractors
Read the landscaping & grounds guide →
Environmental & remediation services contractors
Read the environmental services guide →
Telecommunications & networking contractors
Read the telecommunications guide →
Cybersecurity & IT security services firms
Read the cybersecurity services guide →
Architecture & design firms
Read the architecture & design guide →
Security & guard services contractors
Read the security & guard services guide →
Training & education services providers
Read the training & education guide →
Marketing, media & creative services firms
Read the marketing & media guide →
Trucking & transportation contractors
Read the trucking & transportation guide →
Wholesale & product distribution contractors
Read the wholesale distribution guide →
Food services & catering contractors
Read the food services & catering guide →
Vehicle & equipment maintenance contractors
Read the vehicle maintenance guide →
Printing & reprographics contractors
Read the printing & reprographics guide →
Research, development & testing labs
Read the research & development guide →
Office & operating supplies distributors
Read the office & operating supplies guide →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)