CMMC treats OT and IoT devices as specialized assets. They stay in scope. At Level 2, you list each one in your asset inventory, your System Security Plan (SSP) and your network diagram, and you show it is managed under your risk-based security policies. At Level 3 they are assessed, and an intermediary device can supply the controls the machine lacks.
That is the short answer. The rest of this page covers the five asset types, what each CMMC level asks of them, and how to document a machine that cannot meet a control.
What counts as a CMMC specialized asset?
32 CFR 170.4, the CMMC Program Rule, names five types:
| Type | Typical examples on a defense shop floor |
|---|---|
| Operational technology (OT) | PLCs, HMIs, SCADA and DCS, CNC controllers, welding robots |
| Internet of Things (IoT) or Industrial IoT | Networked sensors, cameras, embedded controllers |
| Test equipment | Calibrated instruments where a firmware change voids calibration |
| Government-furnished equipment (GFE) | Customer hardware you are not allowed to reconfigure |
| Restricted information systems | Systems whose configuration is fixed by contract or export control |
What they share: they can process, store or transmit CUI, but they cannot be fully secured. A PLC has no user accounts. A CNC controller receives G-code over plaintext protocols. Test rigs cannot take patches without losing calibration.
What does CMMC require for OT and IoT specialized assets?
The requirement depends on the level. 32 CFR 170.19 sets the scoping rules.
| CMMC level | What you must do | What the assessor does |
|---|---|---|
| Level 2 | Document the asset in the inventory, the SSP and the network diagram. Show it is managed under your risk-based security policies, procedures and practices. | Reviews the SSP. Does not assess the asset against the other CMMC requirements. |
| Level 3 | Everything in Level 2, plus meet the Level 3 requirements. Intermediary devices may provide the capability the asset lacks. | Limited check against Level 2, full assessment against Level 3. |
"Not assessed" at Level 2 is not "exempt". The assessment scope rule does not change the DFARS 252.204-7012 obligation to protect CUI with NIST SP 800-171. The assessor will read your SSP, so "managed under risk-based policies" has to mean something you can show.
How do OT specialized assets differ from IT assets under CMMC?
NIST SP 800-171 assumes you can install agents, enforce passwords and push patches. Most OT cannot do any of that, and three things set it apart:
- Availability comes first. A SCADA server cannot be rebooted mid-shift. Security work has to fit around production.
- Legacy firmware. Controllers 10 to 20 years old often have no identity stack, no logging and no encryption.
- Proprietary protocols. Modbus, EtherNet/IP and vendor protocols travel in plaintext and are invisible to standard IT tools.
For the full control-by-control comparison, see OT vs IT CMMC controls.
How do you document OT and IoT assets for CMMC?
Five steps cover what Level 2 asks of specialized assets.
- Build the inventory. List every OT and IoT device that touches CUI: type, firmware version, network address and owner. This is also the baseline inventory NIST SP 800-171 control 3.4.1 requires.
- Classify each asset. Mark it as specialized, CUI asset or security protection asset, and say why. Prioritize the machines that receive CUI, such as CNCs that load controlled drawings.
- Draw the boundary. Put each specialized asset on the network diagram of your assessment scope, with the paths that reach it.
- Control who reaches what. Limit access by role, require MFA for people reaching the segment, and log every session. When the machine cannot do this, a gateway in front of it can.
- Record what the machine cannot do. Where an asset cannot meet a specific control and cannot be fixed, write an Enduring Exception in the SSP and pair it with a compensating control.
Step 5 is where most of the documentation work sits. The guide to CMMC exceptions and compensating controls for OT lists the six things each exception entry must contain and the evidence an assessor asks for.
What changed with the Phase II suspension?
The Department of War suspended CMMC Phase II third-party assessments in July 2026 (what the suspension changes). The controls did not go away. NIST SP 800-171 still applies through DFARS 252.204-7012, and the score you post and affirm in SPRS under DFARS 252.204-7019 still covers your shop floor.
Start with the inventory.
If you cannot list every OT device that touches CUI, with its firmware version, network address and access rule, you are not ready to affirm. Map each device to the NIST 800-171 controls it can and cannot meet. The ones it can never meet become Enduring Exceptions. The ones you can fix become POA&M items.
Implementing CMMC on the shop floor? See CMMC compliance for defense manufacturers for the on-premise approach, or the Shared Responsibility Matrix for control-by-control coverage.