TroutTrout
CMMC compliance for defense manufacturers

Protect CUI on every machine in your plant.

Trout Access Gate protects the OT on your shop floor for CMMC Level 2: CNCs, PLCs, CMMs and the legacy machines CMMC calls specialized assets. It connects to your existing network, with nothing to install on machines. It enforces 87 of the 110 NIST 800-171 controls. Installed in a day.

Last updated:

CUI FLOW MAP · ON-PREMISELIVECUI ENCLAVEFILE SERVERCUI REPOSITORYCUI DBENGINEERINGWSWSWSWSENGINEERING WORKSTATIONSPRINT SRVTAGGENERAL IT / OTEMAILERPCNCPLCHMIPRODUCTION FLOORCONTRACTORNIST 800-171 CONTROLSAC 3.1.1AC 3.1.2SC 3.13.1SC 3.13.8AU 3.3.1MP 3.8.1CUI flows controlled through Access Gate proxy: identity-verified, encrypted, logged

Trusted by defense manufacturers and partners

ThalesDefense prime
Elna MagneticsDefense manufacturing
Millbrook MachineManufacturing
NATO Navy LabDefense
Naval GroupDefense prime
The problem: CUI needs to reach machines on your floor

Drawings go to printers. Toolpaths go to CNCs. Results come back from CMMs. Many are legacy OT machines, too old to patch. Your IT team or MSP cannot install anything on them.

Update: July 2026

CMMC Phase II third-party assessments are suspended. The NIST 800-171 obligation stands: the self-assessment and the SPRS affirmation still apply.

How Access Gate protects CUI on the floor

One appliance does four jobs.

Access Gate connects to your existing network, beside your machines. Nothing is installed on the machines themselves.

01

See every machine.

List every machine that handles CUI in the asset inventory, as NIST 800-171 3.4.1 asks, and see who reached it and when.

02

Control who reaches what.

MFA and per-machine rules, even on machines too old to support them.

03

Reach any machine, securely.

Vendors get scoped, time-limited sessions with MFA. Every session is recorded.

04

Prove every audit.

Evidence for 87 of the 110 NIST 800-171 controls, ready for your assessor.

What it covers for CMMC

What Access Gate covers for CMMC Level 2.

What Access Gate takes off your plate for a CMMC Level 2 assessment, on the machines your IT team cannot touch.

Access control (AC)
Named people only, per machine
Authentication (IA)
MFA, even on old machines
Audit (AU)
Every session logged
Network protection (SC)
CUI machines kept apart
Assessment scope
Only the enclave is in scope
Trout Access Gate Essential, a compact 1/2U appliance with four network ports

Access Gate Essential

1/2U appliance · Up to 200 assets

CUI Vault

Trout + CUI Vault

One CMMC solution from cloud to machine.

  1. CUI Vault enclave
  2. FIPS 140-3 tunnel
  3. Access Gate
  4. Authorized machines

CUI Vault by NtelSec keeps your CUI in a managed Microsoft GCC High enclave. Access Gate carries it to the machines on your floor. Each part has a fixed price, decided up front. The full setup, from cloud enclave to machine, is up in a week.

Customer proof: Elna Magnetics

Elna Magnetics secured 100% of its CUI flows.

Elna Magnetics
100%

of on-site CUI flows secured and documented for CMMC Level 2. Deployed without downtime.

Read the case study
87

of the 110 NIST 800-171 controls enforced at the network layer. The remaining 23 are customer-owned process controls, listed in the Shared Responsibility Matrix.

See the coverage matrix
“CUI was flowing everywhere (engineering, shop floor, file servers) with no access control and no audit trail. The Access Gate gave us enclave isolation and full logging.”

IT Director

Defense Manufacturer · Elna Magnetics

FAQ

Common questions about CMMC compliance.

1 day

to be up and running on your shop floor. The full CUI enclave is complete in a week.

It works either way. For CUI that stays on site, Access Gate covers the controls on premises, and whether you also need GCC High depends on your contract. If you run GCC High or CUI Vault, the two are complementary. The enclave holds CUI in the cloud. Access Gate protects it where it reaches your plant and its machines, which is where the enclave's boundary ends.

CMMC Level 2 requires all 110 controls of NIST SP 800-171 for contractors that handle CUI. Third-party C3PAO assessments have been suspended since 13 July 2026. The controls, the self-assessment and the SPRS affirmation still apply. Access Gate covers the technical network controls on site: access, audit, identification and encryption.

A CMMC Level 2 checklist maps to the 110 NIST 800-171 controls across 14 families. They include access control, audit, identification and authentication, configuration management and communications protection. Access Gate enforces 87 of the 110 at the network layer and produces the evidence for each. The remaining 23 are customer-owned process controls, tracked in a Shared Responsibility Matrix.

Access Gate is installed in a day. It connects to your existing network, with no re-cabling and no IP changes. A single-plant CUI enclave is complete in a week, including scope, policies and evidence. With CUI Vault, the full setup from cloud enclave to machine is up in a week.

Access Gate provides enforcement evidence for 87 of the 110 NIST 800-171 controls. Coverage is strongest in access control, audit, configuration management, identification and authentication, and communications protection. The other 23, such as physical security and personnel screening, are customer-owned. The Shared Responsibility Matrix shows which controls Access Gate enforces, which it supports and which stay with you. Assessors can review access logs, policies and session recordings on demand.

Yes. Vendors log in with MFA and reach only the machines you allow, for a limited time. Every session is recorded. The link runs over the VPN built into Access Gate CMMC Edition, which uses a FIPS 140-3 validated cryptographic module.

A CUI enclave is an isolated part of your network that holds every system touching CUI: file servers, engineering workstations, printers and the shop-floor machines that receive drawings and toolpaths. Only the enclave is in scope for a CMMC Level 2 assessment. It can run on premise or extend a GCC High enclave such as CUI Vault down to your plant. See the CUI enclave architecture.

The gate is the first service you run, not the last.

Protect CUI from cloud to machine.

Tell us about your plant. We show you the path from your enclave to your machines, with a fixed price up front.