The machine can’t be secured directly
Controls run operating systems that stopped receiving patches years ago and cannot host a security agent. Nothing you install on your network reaches inside them.
If your shop handles Controlled Unclassified Information, how a program file gets from a programmer’s desk to a CNC control is part of your assessment — and for most shops it is the weakest part. Here is what our appliances do about it, and where their limits are.
The two are related but not the same thing. One is the list of requirements; the other is how the Department of Defense checks that you have met them.
The standard set of security requirements for protecting Controlled Unclassified Information when it lives outside federal systems. That includes CNC programs and technical drawings sitting on your shop network. It runs to 110 requirements across 14 control families. Contractors handling CUI are obliged to implement them under DFARS 252.204-7012. Historically, companies self-assessed and asserted their own compliance.
The Cybersecurity Maturity Model Certification Program exists because self-assessment alone did not produce results. CMMC 2.0 has three levels: Level 1 (foundational, self assessment permitted), Level 2 (advanced, aligned with the full NIST SP 800-171 set, with third-party assessment for prioritized contracts), and Level 3 (expert, built on NIST SP 800-172 and assessed by the government).
The practical difference is that CMMC generally requires third-party or government certification before you can bid, so the gaps that used to be quietly tolerated now have to be closed and evidenced.
Controls run operating systems that stopped receiving patches years ago and cannot host a security agent. Nothing you install on your network reaches inside them.
A USB drive carried across the floor has no encryption, no access control, and no record of where it went. Putting the machine straight onto the office network solves the transfer problem and creates a bigger security one. Both are the kind of thing an assessor writes up.
Even where a shop’s practice is sound, sneakernet produces no logs. When an assessor asks who moved which file and when, there is nothing to show.
Both products are built around the same security model. This is where that model touches the control families an assessor will walk through with you.
| Control family | What it asks for | What the appliance provides |
|---|---|---|
| Access Control (AC) | Limit system access to authorized users, and limit what each can do | Named accounts with per-user file isolation, a separate administrator role, and no anonymous access to the network side |
| Identification & Authentication (IA) | Identify users uniquely and authenticate them before granting access | Every transfer is tied to an individual account. No shared drop folder, no unauthenticated uploads |
| Media Protection (MP) | Protect and control media containing CUI, including removable media | Removes the uncontrolled USB drive from the routine entirely. Storage is encrypted and bound to its device, so it cannot be read elsewhere |
| System & Communications Protection (SC) | Protect information in transit and control the boundary between systems | Encrypted transport for every upload, a default-deny firewall, and a hard boundary that keeps the legacy control off your network |
| Audit & Accountability (AU) | Create and retain records sufficient to trace individual actions | File access and configuration changes logged with timestamps and user attribution, retained across reboots and preserved through a factory reset |
Installing a device does not make an organization compliant, and no product can. CMMC assesses your whole organization: policies, training, incident response, physical security, and much more besides. What CodePod and CodeNet do is close one specific, commonly-cited gap with something you can point at and produce evidence for.
We would rather be straight with you about that now than have it come up in an assessment. If a vendor tells you their box makes you CMMC compliant, be careful.
AES-256 full-disk encryption on every unit, with the key bound to that individual device. Removed storage cannot be read on other hardware.
Uploads travel over SFTP or HTTPS. Certificates are generated per device, so no two units share an identity.
The firewall drops anything not explicitly permitted, and traffic does not route between the machine side and your network. Only files cross.
Each service is confined to only the files and privileges it needs, so a fault in one cannot become access to everything.
No cloud service, no telemetry, no outbound connections. Fully air-gapped operation is supported, including timekeeping without a network clock.
Diagnostic tooling is stripped from shipping units, unused services are switched off rather than left listening, and remote root login is disabled.
Both products are in beta. Independent penetration testing and third-party review are scheduled ahead of the full production release in September 2026, and we will share the outcome with customers.
If independent validation is a gate for your program, talk to us about timing before you order.
Security standards move. A device that was appropriate when it was installed and never updated afterwards becomes its own finding.
Iron Glacier commits to biannual releases aligned with standard release security cycles, keeping deployed units current as CMMC and NIST SP 800-171 evolve. Every two years we offer existing customers a discounted trade-in to the latest hardware, so the units on your floor stay supportable rather than quietly aging out.
The hardware is specified to match: industrial-grade components in a fully enclosed aluminum housing, built for a shop environment over a long service life.
Tell us where you are in the process and what your assessor has flagged. We will tell you honestly whether we help with it.