CMMC applies the same NIST 800-171 controls to IT and OT. What changes is where you enforce them: on the endpoint for IT, on the network around the machine for OT.
Why do IT and OT implement CMMC controls differently?
CMMC was written with IT systems in mind. The 110 controls in NIST 800-171 assume you can install endpoint agents, enforce password policies, and push patches on a schedule. In OT environments, where a PLC has no user accounts and a SCADA server cannot be rebooted mid-shift, applying those same controls requires adaptation. This guide explains where IT and OT implementations of CMMC controls diverge and provides specific strategies for each.
How do IT and OT systems differ?
IT systems manage data.
IT systems are primarily concerned with the management, storage, and processing of data. They support business operations by ensuring data integrity, confidentiality, and availability. Common IT components include servers, databases, and network devices, which are governed by protocols and standards such as NIST 800-171 and the broader CMMC framework.
OT systems run physical processes.
In contrast, OT systems manage and control physical processes and machinery. These systems are prevalent in industries like manufacturing, energy, and defense. OT environments include SCADA systems, PLCs, and DCS, which often utilize proprietary protocols and legacy systems that were not originally designed with cybersecurity in mind.
Which CMMC controls work the same in IT and OT?
The shared goals.
Both IT and OT environments are subject to CMMC controls, which aim to protect Controlled Unclassified Information (CUI). At their core, these controls focus on:
- Access Control: Ensuring only authorized personnel access sensitive information.
- Incident Response: Establishing procedures to detect, report, and respond to security incidents.
- Risk Management: Identifying and mitigating risks to information systems.
Where OT breaks the IT assumptions.
OT environments face unique challenges when implementing CMMC controls due to:
- Legacy Systems: Many OT components lack modern security features, making them susceptible to attacks.
- Availability Requirements: OT systems often require continuous uptime, complicating the application of traditional IT security measures.
- Proprietary Protocols: The use of custom and proprietary communication protocols can hinder standard security practices.
Many of these machines are what CMMC calls specialized assets, which changes how they are scoped and assessed. That question has its own page: CMMC requirements for OT and IoT specialized assets.
How do you implement IT-style controls in OT?
| Control area | Typical IT implementation | Typical OT implementation |
|---|---|---|
| Access control (AC 3.1.1, 3.1.2) | User accounts and roles on the system | Role-based rules at a gateway in front of the machine |
| MFA (IA 3.5.3) | MFA prompt at login | MFA at the gateway before any session reaches the machine |
| Audit logging (AU 3.3.1) | Agent or syslog on the host | Session logging at the network layer |
| Patching (SI 3.14.1) | Scheduled patch cycles | Planned maintenance windows, isolation when a patch is impossible |
| Encryption in transit (SC 3.13.8) | TLS on the application | Encrypted path up to an isolated segment, since most industrial protocols are plaintext |
Adapting IT practices for OT.
- Network Segmentation: Implement network segmentation to isolate OT systems from IT networks, reducing the risk of lateral movement by attackers.
- Protocol Whitelisting: Use protocol whitelisting to restrict communication to only necessary and approved protocols, minimizing the potential attack surface.
- Patch Management: Develop a structured patch management strategy that accounts for OT systems' operational constraints, ensuring security updates do not disrupt critical processes.
OT-specific tools.
- Industrial Firewalls: Deploy industrial-grade firewalls that understand OT protocols and can enforce security policies without impeding system performance.
- Anomaly Detection Systems: Implement OT-specific intrusion detection systems that can identify deviations from normal operational patterns, signaling potential security threats.
How do you keep IT and OT controls compliant over time?
Monitor and review.
Compliance with CMMC is not a one-time event but a continuous process. To maintain compliance:
- Regular Audits: Conduct regular audits to evaluate the effectiveness of implemented controls and identify areas for improvement.
- Training and Awareness: Provide ongoing cybersecurity training to all personnel involved in OT operations, emphasizing the importance of maintaining security vigilance.
Apply zero trust to both.
Adopting a Zero Trust approach can further enhance security in OT environments by:
- Minimizing Trust Assumptions: Enforcing the principle of "never trust, always verify" to all network transactions and user access requests.
- Enhancing Visibility: Improving network and device visibility to detect and respond to threats in real-time.
Run two implementation plans.
CMMC compliance in mixed IT/OT environments requires two parallel implementation plans: one for IT systems using standard controls, and one for OT systems using compensating controls where direct implementation is not feasible. Document every deviation and its compensating measure in your SSP. Assessors expect this for OT; what they will not accept is silence about how OT systems are covered.
Many OT machines also qualify as CMMC specialized assets, with their own scoping rules. See CMMC requirements for OT and IoT specialized assets for what that category requires, and CMMC exceptions and compensating controls for OT for machines that cannot meet a control. The Shared Responsibility Matrix shows control-by-control coverage, and the CMMC Compliance for On-Premise hub collects the broader resources.