On November 10, 2026, the way a growing share of the defense industrial base proves it protects Controlled Unclassified Information starts changing from a signature to an audit. And for the manufacturers who actually cut metal, the hardest gap to close is the one sitting on the shop floor: the machines that touch CUI often cannot implement the controls a third-party assessor will now come to verify — and there is no version of "patch it" or "take the line down and rebuild it" that fits inside the runway that's left.
What Changes on November 10, 2026
CMMC's phased rollout has a hard inflection date. Under the DoD CIO's implementation schedule, Phase 2 begins November 10, 2026: from that date, DoD solicitations — "where applicable," in the Department's own phasing language — begin requiring CMMC Level 2 certification, an assessment performed by an authorized CMMC Third-Party Assessment Organization (C3PAO), instead of the self-assessment Phase 1 accepted. Kiteworks' analysis of the armament-manufacturing sector reads the same schedule as mandatory C3PAO assessment reaching most Level 2 CUI contracts over that phase. To be precise about the shape of it: this is a phased, contract-by-contract shift written into new solicitations as they issue — not a single switch flipped across every existing contract on one morning. But for a manufacturer bidding CUI work, the direction is one-way. Third-party validation is becoming a condition of award.
The contractual hook is already live. DFARS clause 252.204-7021 — the clause that writes CMMC level requirements into contracts — took effect on November 10, 2025. And the pressure is flowing downhill ahead of any solicitation date: Kiteworks reports that major defense primes including Lockheed Martin, Boeing, and Northrop Grumman have issued supplier directives demanding compliance documentation now. If you build parts, subassemblies, or test data for a prime, the requirement reaches you through the supply chain before it ever reaches you through a solicitation.
The OT Gap Nobody Can Close in Time
Here is the problem that makes November 10 different from a normal compliance deadline for manufacturers: the systems that handle CUI on a production line were never built to be governed the way the standard assumes.
The equipment on a defense factory floor has a service life measured in decades. Kiteworks' sector analysis describes the reality bluntly: CNC machines, coordinate measuring machines, and testing equipment often run Windows 7, Windows XP, or proprietary operating systems, and cannot easily implement the controls CMMC assesses. These aren't neglected assets — they're precision machines that do exactly the job they were bought for, and they will still be doing it in ten years. What they can't do is run a modern endpoint agent or accept the security patches the standard presumes.
The capability areas in question are specific: access enforcement, boundary protection, and software integrity. In NIST SP 800-53 terms those are AC-3, SC-7, and SI-7 — the control catalog from which NIST SP 800-171's CUI requirements are derived — and a Level 2 assessment walks the corresponding 800-171 requirement families: Access Control (3.1), System and Communications Protection (3.13), and System and Information Integrity (3.14). An assessor will look for those capabilities on the systems in scope, and a Windows 7 CNC controller structurally cannot provide them.
Two facts about a production line collide here. You cannot patch a proprietary OS into compliance before the deadline, and you cannot take a 24/7 line offline to rip-and-replace the controllers without stopping the deliveries the contract exists to produce. The gap is real, and the usual remediation playbook doesn't fit inside the runway.
The moment this becomes an AI-governance problem is concrete: an operator or manufacturing engineer, working from one of these boxes, pastes a CUI technical drawing or a fragment of a test report into ChatGPT or Claude to clean up the wording or interpret an error. Neither the legacy OT nor the consumer AI tool enforces the CUI boundary. The data crosses into a system that was never in the assessment scope, from an endpoint that can't enforce a thing.
The Control That's Left Lives at the Data-Crossing Point
If you can't put the control on the machine, the only place left to put it is between the machine and the destination the data is leaving for.
A browser/proxy data-boundary gateway sits at that crossing point. It doesn't require an agent on the CNC controller and it doesn't touch the legacy OS. It governs the data on its way out — at the browser surface or the network proxy where a paste into an AI tool actually happens — and makes the policy decision there: block this submission, redact that field, allow this one, and write a user-attributable line to the audit log either way.
That is the layer you actually control. When the endpoint itself can't enforce access, boundary, or integrity, the data-crossing point is where an equivalent boundary control can still live — the one place governance is possible without upgrading the un-upgradable. It maps to the intent of access enforcement and boundary protection — governing who can move what across a boundary — at the layer that's still under your control, and it produces the enforcement evidence an assessor's questions are ultimately about: not "is the CNC machine patched," but "can you show CUI doesn't leave this environment ungoverned, and prove it."
Why This Is the Edge and Air-Gapped Story Too
The same pattern holds where the cloud doesn't reach. Defense manufacturing runs plenty of environments that are disconnected, segmented, or fully air-gapped by design — classified cells, ITAR-controlled areas, isolated production networks. A governance model that depends on a round-trip to a cloud broker goes dark exactly there.
The architecture this calls for makes its decision locally, at the data boundary, without phoning home to enforce policy or write its audit record — the disconnected-then-reconcile pattern a governance layer built for denied, degraded, intermittent, and limited (DDIL) conditions relies on. To be direct about status, because our Trust page outranks our marketing: on-premises and air-gapped deployment of Containment.AI is a roadmap item, stated as such — the connected browser and proxy tiers are what operate today. That roadmap's design target is exactly this environment: a data-crossing point that stays enforceable whether or not there's a link to the outside, because that's the control that survives both the un-upgradable endpoint and the disconnected network.
Where This Leaves a Defense Manufacturer
November 10 opens the phase where, solicitation by solicitation, validation replaces attestation — it is not a grace period. Floor equipment that can't provide access enforcement, boundary protection, or integrity checking will surface as gaps in a Level 2 assessment, and honest scoping has to account for that. The practical move is to govern the boundary the data crosses — the point where CUI would otherwise leave through a browser tab or an AI tool on an endpoint you can't harden — and to generate the per-user enforcement evidence that shows it.
To be clear about what this is and isn't: CMMC, FedRAMP, and the NIST controls above are buyer context here, not certifications Containment.AI holds or confers. A gateway doesn't make a contractor CMMC-certified — certification is a program assessed by a C3PAO, not a product. What a data-boundary gateway addresses is the specific point-of-use gap the legacy floor can't close on its own, while producing the user-level enforcement record that gap otherwise leaves empty.
Containment.AI enforces AI-governance policy at the data boundary — at the browser/proxy crossing point where data leaves for an AI tool — with pre-submission blocking, per-user controls, and tamper-evident audit records, on endpoints you can't put an agent on. See how it works for aerospace & defense → or request a NatSec design-partner briefing.
Sources: Kiteworks, "CMMC Compliance for Armament Manufacturers" (updated February 5, 2026), Danielle Barbour; DoD CIO — About CMMC; NIST SP 800-171 Rev. 2.
This post was drafted with AI assistance and reviewed before publication.