A machine shop in Harrison, Ohio running Epicor or SYSPRO on the same flat network as its CNC controllers is a common setup — and a growing liability. If that shop holds a DoD subcontract, even a small one flowing through a Tier 1 or Tier 2 prime, CMMC 2.0 now requires documented network segmentation, access controls, and continuous monitoring around any system that touches Controlled Unclassified Information (CUI). Most shops built their network for uptime and convenience, not for an assessor's checklist, and that gap is what's failing them.
The Cybersecurity Maturity Model Certification program has moved past the discussion phase. CMMC 2.0 Level 2 requirements are showing up in DFARS clauses on new contracts and modifications, and primes are increasingly pushing self-assessment attestations down the supply chain before they'll place another purchase order. A Harrison manufacturer that assumed CMMC was someone else's problem is now getting a questionnaire from a customer's procurement office asking for a System Security Plan and a Plan of Action and Milestones. Neither document writes itself, and neither one survives scrutiny if the underlying network doesn't match what's on paper.
Where the Shop Floor Breaks the Model
The core CMMC Level 2 control set — 110 practices drawn from NIST SP 800-171 — assumes CUI lives in a definable boundary. In practice, a lot of Harrison manufacturers have ERP terminals, quality management software, CAD workstations, and shop-floor HMI panels all sitting on one VLAN, sometimes one that also carries guest Wi-Fi for the front office. Epicor and SYSPRO installations frequently predate any segmentation project, and nobody wants to touch production systems that are running fine — until an assessor asks to see the network diagram and there isn't a real boundary to point to.
That flat topology is also the reason ransomware incidents at manufacturers tend to be catastrophic rather than contained. When a phishing email compromises an office workstation, lateral movement to the ERP server and the machine controllers is trivial on an unsegmented network. Production stops, and if backups are reachable from the same segment, recovery stretches from hours to weeks. Veeam-based backup and disaster recovery with immutable, offsite copies is the baseline CMMC practices assume — and the baseline most shops don't actually have tested.
The Controls That Actually Matter First
Not every one of the 110 NIST 800-171 practices carries equal weight for a first assessment pass. The practical starting point for a Harrison manufacturer is access control and network segmentation: isolating the CUI-relevant systems — ERP modules handling contract data, engineering drawings, quality records — from general office and shop-floor operational networks. That's a wireless networking and VLAN project, not a rip-and-replace, and it's usually the single change that most improves an assessment outcome.
Multifactor authentication is next, and it's non-negotiable under Level 2. Every account with access to CUI-adjacent systems needs MFA, including the ERP admin accounts that often get exempted "because it's inconvenient." Microsoft 365 tenants running without Conditional Access policies are a frequent finding — legacy authentication left enabled, no device compliance checks, no location-based risk scoring. Titan Tech's Microsoft 365 management covers this configuration work directly.
Audit logging and continuous monitoring round out the practical priority list. CMMC assessors want evidence of who accessed what and when, not just a policy stating that logging happens. A SIEM platform paired with managed detection and response — Titan Tech runs SentinelOne EDR with Huntress MDR behind it — gives a shop the log retention and 24/7 human review that satisfies both the compliance requirement and the actual security need. Automated alerts without a person reviewing them don't hold up under DIBCAC scrutiny.
Physical Security Isn't Separate From the CMMC Story
Manufacturers sometimes treat physical security as a facilities issue disconnected from cybersecurity compliance, but NIST 800-171 explicitly covers physical protection of CUI. A machine shop with drawings and specs printed at a shared plotter, in a building with unmonitored after-hours access, has a documentation gap regardless of how good its firewall rules are. Access control systems that log entry by credential, paired with IP video surveillance covering engineering areas and server rooms, give a shop the physical control evidence an assessor will ask for — and they close a real theft and tampering risk in the process.
Building the Actual Program, Not Just the Paperwork
A defensible CMMC posture for a shop this size doesn't require an internal security team. It requires a managed IT partner who understands both the shop-floor operational constraints and the specific 800-171 control language, and who can produce a System Security Plan that reflects what's actually deployed — not an aspirational document that falls apart the first time someone asks to see the segmentation in action. Managed IT services built around this framework — network segmentation, MFA, SIEM/MDR, tested backup, access control — get a Harrison manufacturer to an honest assessment position instead of a fragile one.
If your shop has a DoD subcontract, or a prime is starting to ask for CMMC documentation, the time to find the gaps is before the assessment request lands, not after. Contact Titan Tech to schedule a network and compliance review — we work with manufacturers across Harrison and the greater Cincinnati region on exactly this kind of readiness.

