CMMC for manufacturers

Protect your defense work.

SecureEnclave™ gives manufacturers a customer-controlled environment for selected Controlled Unclassified Information (CUI) workflows. It connects approved applications, safeguards, technical evidence, and recovery around the people, systems, and production steps that handle the work.

Explore enclave-fit planning or read the requirements context for contracts, safeguards, and assessment.

Illustration of an engineering workspace with a workstation, manufacturing machine, and local server inside a defined SecureEnclave™ boundary.
Conceptual manufacturing environment. The deployment design defines the approved physical, logical, identity, and administrative boundary.

From workflow to deployment

Bring the working environment together.

Once the CUI workflow is mapped, SecureEnclave™ turns the approved design into a maintained environment for the work.

The selected configuration connects applications and equipment with the identities, safeguards, and operating paths they need. These relationships remain part of the managed definition as the environment changes.

  • Applications and services

    Deploy the approved engineering, collaboration, storage, and supporting services required by the selected workflow.

  • Identity and safeguards

    Connect access controls, identity, and configured security services to the people and systems in the managed boundary.

  • Production dependencies

    Account for supported manufacturing systems, connected devices, inspection, and test equipment that the work depends on.

  • Operating paths

    Define permitted transfer, update, administration, and support paths, including who can authorize their use.

The design qualifies applications, equipment, interfaces, and operating constraints. Still defining the information path? Start with the manufacturing workflow.

Cutaway illustration of a customer facility with engineering, manufacturing, office, and server areas connected to a central NetThunder SecureEnclave™.
Conceptual site view. The approved design defines the workflow, equipment, dependencies, and data paths inside the physical and logical boundary.

Paths and authority

See the operating boundary.

See how approved connections reach managed systems, where technical evidence comes from, and which decisions remain with people.

Example operating modelBoundary, state, evidence, responsibility

Selected connections

Approved access and admin paths

SecureEnclave™ boundary

Selected CUI operating environment
Approved applications and joined systemsIdentity, certificates, and access servicesStorage and authorized data pathsBoundary firewalls and configured security servicesDesired and observed state for the managed scopeConfigured SIEM telemetry and technical evidenceSupported snapshots and known-state restorationStorm AI Factory™ when AI is in scope, or an approved integration path
Human review and assessmentAuthorization · risk · exceptions · assessment
Example architecture. The environment specification defines the final boundary, components, connections, managed scope, and operating responsibilities.
Read the SecureEnclave™ architecture
  1. Entry and administration: The environment specification defines ingress, transfer, updates, support, administration, and operating connectivity.
  2. Boundary: The environment specification defines which physical, logical, identity, and administrative boundaries apply.
  3. Included systems: The boundary can include approved applications, joined endpoints, identity and certificate services, storage, security services, monitoring, backup, and recovery.
  4. Managed state and evidence: SecureEnclave™ maintains desired and observed state for its managed scope. Configured security and operational telemetry flows to the SIEM for analysis and audit support.
  5. Recovery: Recovery scope is defined and tested for the deployment.
  6. AI: Storm AI Factory™ can run inside SecureEnclave™ when the AI workload belongs in assessment scope. Otherwise, SecureEnclave™ can connect to AI Factory on another NetThunder platform through an approved integration path.
  7. Operating modes: Operation can be connected, intermittently connected, or physically disconnected. Air-gap status depends on deployed physical and operating controls.
  8. Responsibility: People remain responsible for authorization, policy, risk, exceptions, incidents, and truthful affirmation. Assessors reach an independent conclusion.

Ongoing operations

Keep evidence current through change.

An application or configuration change also changes what the environment needs to demonstrate. SecureEnclave™ preserves change context and ties configured telemetry, technical checks, and artifacts to managed-system state.

Approved change

Carry the intended state forward.

  • Define the intended configuration through required state, rules, templates, and dependencies
  • Apply supported changes under the deployment's approval rules
  • Preserve requested and observed state and change history

Evidence in operation

Show what is running now.

  • Collect configured security and operational telemetry
  • Connect technical checks and artifacts to current managed state
  • Keep evidence sources, configuration context, and exceptions reviewable

Human authority

Accountability stays human.
People define scope, authorize access and change, approve policy, handle exceptions and incidents, accept risk, and make truthful affirmations. The applicable assessor determines the assessment result.
See the operating cycle
  1. Define

    Name the managed boundary, approved services, dependencies, paths, and responsibilities.

  2. Deploy

    Realize the selected infrastructure, applications, identity, and safeguards.

  3. Enforce

    Maintain intended state across the managed scope.

  4. Observe

    Collect configured security and operational telemetry.

  5. Test

    Run configured technical checks against the environment in operation.

  6. Evidence

    Generate technical artifacts tied to current system state.

  7. Recover

    Return supported components to a selected known state.

Technical detail

Review controls and recovery.

Inspect the configured safeguards and evidence sources. Coordinated snapshots and known-state restoration cover supported components; recovery planning defines what can be restored, in what order, and how to validate the result against the workflow.

State, telemetry, and technical evidence

SecureEnclave™ maintains desired and observed state for managed infrastructure, identities, certificates, applications, and configurations. Configured security and operational telemetry flows to its SIEM for analysis and audit support.

  • Identify the approved state and the state being observed
  • Connect technical checks and artifacts to the environment being reviewed
  • Use the same operational telemetry for security operations and audit support
  • Keep evidence source, time, configuration context, and exceptions reviewable
Boundary, identity, and approved paths

The approved design identifies the workloads and management, transfer, update, support, and external paths included in the managed scope; which operating authority and responsibility applies; and when each path may be enabled, restricted, monitored, or physically disconnected.

  • Define physical, logical, identity, and administrative boundaries
  • Record authorization and change rules for permitted paths
  • Validate what continues to operate in connected, intermittent, and physically disconnected modes
  • Control reconnection, transfer, update, and support procedures
Safeguards and validated cryptography

A selected configuration can include boundary firewalls, MFA, SIEM, centralized logging, identity, certificate and trust services, monitoring, backup, recovery, and mapped operating procedures.

Supported configurations can incorporate specific FIPS 140-2 or FIPS 140-3 validated cryptographic modules in their approved modes and operational environments. FIPS validation applies to the named module, approved mode, and operational environment. SecureEnclave™-wide validation requires separate evidence.

Recovery and operational validation

SecureEnclave™ can capture coordinated snapshots and restore supported components to a selected known state. The deployment defines what is captured, how consistency is handled, how keys and credentials are protected, what restores first, and how recovery is tested.

  • Validate restoration against selected data and business-service requirements
  • Test identity, networking, security services, applications, storage relationships, and workflow dependencies
  • Document recovery assumptions, failure cases, approvals, and operator responsibilities
  • Set, measure, and validate recovery objectives for the deployed workflow
Policies, procedures, and assessment responsibility

A SecureEnclave™ engagement can include mapped operational and managerial policies and procedures intended to support applicable CMMC Level 2 and NIST SP 800-171 Revision 2 implementation requirements.

Technical evidence supports examination and testing. Interviews, organizational behavior, policy approval, personnel practices, physical security, risk acceptance, and assessment conclusions remain human responsibilities. When a certification assessment applies, the C3PAO reaches the independent conclusion.

Deployment context

Place private AI deliberately.

Storm AI Factory™ can run inside the managed boundary when an AI workload belongs in CMMC assessment scope. Otherwise, SecureEnclave™ can connect to AI Factory on another NetThunder platform through an explicitly approved integration path.

Define the AI boundary

The selected configuration qualifies models, capacity, data paths, connectivity, tools, permissions, and operating responsibilities.

  • Is the AI workload inside the CMMC assessment scope, outside it, or connected through an approved integration?
  • Which models, data, tools, identities, logs, update paths, and administrative paths belong in scope?
  • Which agent actions require approval, and which outputs remain advisory?
  • How are model provenance, evaluation, changes, and rollback governed?
Compare AI Factory deployment contexts
Manufacturing project context

MxD project 23-11-03

Cybersecure Enclave Infrastructure as Code

MxD named NetThunder as the project team for work focused on simplifying secure-environment provisioning, deployment, and maintenance for small and midsized manufacturers supporting DoD production.

Project team
NetThunder
Manufacturing focus
Small and midsized manufacturers supporting DoD production
Project objective
Simplify secure-environment provisioning, deployment, and maintenance

Architecture review

Discuss your operating needs.

Bring one representative CUI workflow and the operating questions it raises. The first conversation focuses on SecureEnclave™ fit, open questions, and the next design decisions. The planning wizard can help organize your brief.

Email NetThunder +1 847.477.7676