TroutTrout
Back to Blog
CMMCAsset ManagementOT Security

CMMC Requirements for OT and IoT Specialized Assets

Trout Team5 min read

CMMC treats OT and IoT devices as specialized assets. They stay in scope. At Level 2, you list each one in your asset inventory, your System Security Plan (SSP) and your network diagram, and you show it is managed under your risk-based security policies. At Level 3 they are assessed, and an intermediary device can supply the controls the machine lacks.

That is the short answer. The rest of this page covers the five asset types, what each CMMC level asks of them, and how to document a machine that cannot meet a control.

What counts as a CMMC specialized asset?

32 CFR 170.4, the CMMC Program Rule, names five types:

TypeTypical examples on a defense shop floor
Operational technology (OT)PLCs, HMIs, SCADA and DCS, CNC controllers, welding robots
Internet of Things (IoT) or Industrial IoTNetworked sensors, cameras, embedded controllers
Test equipmentCalibrated instruments where a firmware change voids calibration
Government-furnished equipment (GFE)Customer hardware you are not allowed to reconfigure
Restricted information systemsSystems whose configuration is fixed by contract or export control

What they share: they can process, store or transmit CUI, but they cannot be fully secured. A PLC has no user accounts. A CNC controller receives G-code over plaintext protocols. Test rigs cannot take patches without losing calibration.

What does CMMC require for OT and IoT specialized assets?

The requirement depends on the level. 32 CFR 170.19 sets the scoping rules.

CMMC levelWhat you must doWhat the assessor does
Level 2Document the asset in the inventory, the SSP and the network diagram. Show it is managed under your risk-based security policies, procedures and practices.Reviews the SSP. Does not assess the asset against the other CMMC requirements.
Level 3Everything in Level 2, plus meet the Level 3 requirements. Intermediary devices may provide the capability the asset lacks.Limited check against Level 2, full assessment against Level 3.

"Not assessed" at Level 2 is not "exempt". The assessment scope rule does not change the DFARS 252.204-7012 obligation to protect CUI with NIST SP 800-171. The assessor will read your SSP, so "managed under risk-based policies" has to mean something you can show.

How do OT specialized assets differ from IT assets under CMMC?

NIST SP 800-171 assumes you can install agents, enforce passwords and push patches. Most OT cannot do any of that, and three things set it apart:

  • Availability comes first. A SCADA server cannot be rebooted mid-shift. Security work has to fit around production.
  • Legacy firmware. Controllers 10 to 20 years old often have no identity stack, no logging and no encryption.
  • Proprietary protocols. Modbus, EtherNet/IP and vendor protocols travel in plaintext and are invisible to standard IT tools.

For the full control-by-control comparison, see OT vs IT CMMC controls.

How do you document OT and IoT assets for CMMC?

Five steps cover what Level 2 asks of specialized assets.

  1. Build the inventory. List every OT and IoT device that touches CUI: type, firmware version, network address and owner. This is also the baseline inventory NIST SP 800-171 control 3.4.1 requires.
  2. Classify each asset. Mark it as specialized, CUI asset or security protection asset, and say why. Prioritize the machines that receive CUI, such as CNCs that load controlled drawings.
  3. Draw the boundary. Put each specialized asset on the network diagram of your assessment scope, with the paths that reach it.
  4. Control who reaches what. Limit access by role, require MFA for people reaching the segment, and log every session. When the machine cannot do this, a gateway in front of it can.
  5. Record what the machine cannot do. Where an asset cannot meet a specific control and cannot be fixed, write an Enduring Exception in the SSP and pair it with a compensating control.

Step 5 is where most of the documentation work sits. The guide to CMMC exceptions and compensating controls for OT lists the six things each exception entry must contain and the evidence an assessor asks for.

What changed with the Phase II suspension?

The Department of War suspended CMMC Phase II third-party assessments in July 2026 (what the suspension changes). The controls did not go away. NIST SP 800-171 still applies through DFARS 252.204-7012, and the score you post and affirm in SPRS under DFARS 252.204-7019 still covers your shop floor.

Start with the inventory.

If you cannot list every OT device that touches CUI, with its firmware version, network address and access rule, you are not ready to affirm. Map each device to the NIST 800-171 controls it can and cannot meet. The ones it can never meet become Enduring Exceptions. The ones you can fix become POA&M items.


Implementing CMMC on the shop floor? See CMMC compliance for defense manufacturers for the on-premise approach, or the Shared Responsibility Matrix for control-by-control coverage.

FAQ

Frequently Asked Questions

Are OT and IoT devices in scope for CMMC?
Yes. CMMC classes them as specialized assets. They stay in the assessment scope. At Level 2 you document them in the asset inventory, the SSP and the network diagram, and the assessor reviews the SSP rather than testing them against each requirement.
What are the five CMMC specialized asset types?
Government-furnished equipment, Internet of Things (IoT) or Industrial IoT, operational technology (OT), restricted information systems, and test equipment, as listed in 32 CFR 170.4.
Do specialized assets have to meet all 110 NIST 800-171 controls?
Not for the Level 2 assessment, which does not assess them against the other requirements. At Level 3 they get a limited check against Level 2 and are assessed against Level 3, and an intermediary device may supply a capability the asset lacks.
What if an OT machine cannot meet a control at all?
Record it as an Enduring Exception in the SSP and pair it with a compensating control that is running and produces evidence. The guide to CMMC exceptions and compensating controls for OT lists what each entry must contain.
Does the CMMC Phase II suspension change this?
It pauses third-party assessments, not the obligation. NIST SP 800-171 still applies through DFARS 252.204-7012, and the score you affirm in SPRS still covers the machines on your shop floor.