The Compliance Upgrade makes your file path CMMC-ready.

When your shop handles Controlled Unclassified Information, how a program file gets from a programmer’s desk to a CNC control is part of your assessment, and for most shops it is the weakest part. The upgrade closes that gap on a CodePod or CodeNet. Order it with your unit, or add it the day a contract requires it.

When you need it

CUI is what decides it.

CUI is a burden by design. When a contract puts it on your floor, that burden is the requirement, and the path a file takes to your machine has to carry the same authority as everything else in scope.

Authority means you can name every person who touched a file and prove they were who they said they were, then produce that record months later when somebody asks for it. That is a higher bar than keeping a machine safe, and it is meant to be. The upgrade is what raises a CodePod or CodeNet to it: certificates issued to your users, certificate-based sign-in, enforced password rotation, and an audit log built to be handed over.

The upgrade also brings real administration with it, and you should hear that here rather than after the order. Certificates get issued and replaced. Passwords rotate whether or not it is convenient. The log earns its keep only if somebody reads it. Under a contract the upgrade pays that work back the first time somebody asks for the record.

Without a contract, it is friction. The device already solves the file problem on its own: the machine stays off your network, files are encrypted at rest, every user signs in, and only the file types you allow get through. Since the upgrade is a signed software update on hardware you already own, it is there the day a contract puts you in scope.

Background

NIST SP 800-171 and CMMC, briefly

NIST SP 800-171 is the list of requirements, 110 of them, covering Controlled Unclassified Information held outside government systems. That includes the CNC programs on your shop network. CMMC is how the Department of Defense checks you have met it, in most cases through third-party assessment before you can bid.

The gap

Why the CNC file path is usually the hard part.

The machine can’t be secured directly

Controls run operating systems that stopped receiving patches years ago and cannot host a security agent. Nothing you install on your network reaches inside them.

The usual workarounds don’t hold up

A USB drive carried across the floor has no encryption, no access control, and no record of where it went. Putting the machine straight onto the office network solves the transfer problem and creates a bigger security one. Both are the kind of thing an assessor writes up.

There’s no evidence to hand over

Even where a shop’s practice is sound, sneakernet produces no logs. When an assessor asks who moved which file and when, there is nothing to show.

Where the line sits

What you get either way

The upgrade adds the identity and evidence machinery an assessment asks for. Everything that keeps your machine off the network and your files encrypted is already in the box.

On every unit

  • The machine never touches your network, and no traffic routes across
  • Files encrypted at rest: full disk on CodePod, nothing readable on CodeNet
  • Uploads over SFTP or HTTPS, authenticated every time
  • Named accounts with per-user file isolation, and no anonymous access
  • Default-deny firewall, with each service confined to what it needs
  • Only the file types you allow reach the control, with the rest refused at the upload
  • No cloud service, no telemetry, and no outbound connections of any kind

With the Compliance Upgrade

  • Audit logging with user attribution, retained and ready to hand over
  • Certificates issued to your users
  • Certificate-based authentication
  • Enforced password rotation
  • Sign-in restricted to HTTPS, with no fallback
  • Support geared to an assessment rather than to a shop floor

Available on CodePod and CodeNet. Nothing under “On every unit” changes when you add it.

Control families

Where an upgraded unit lines up

Both products are built around the same security model. This is where that model touches the control families an assessor will walk through with you. Everything below describes a unit with the Compliance Upgrade installed, and nothing on this page should be read as a claim about a unit without it.

How an upgraded Iron Glacier appliance relates to NIST SP 800-171 control families
Control family What it asks for What the appliance provides
Access Control (AC) Limit system access to authorized users, and limit what each can do Named accounts with per-user file isolation, a separate administrator role, and no anonymous access to the network side
Identification & Authentication (IA) Identify users uniquely and authenticate them before granting access Every transfer is tied to an individual account, with certificates issued to your users. No shared drop folder, no unauthenticated uploads
Media Protection (MP) Protect and control media containing CUI, including removable media Removes the uncontrolled USB drive from the routine entirely. Storage is encrypted and bound to its device, so it cannot be read elsewhere
System & Communications Protection (SC) Protect information in transit and control the boundary between systems Encrypted transport for every upload, a default-deny firewall, and a hard boundary that keeps the control off your network
Audit & Accountability (AU) Create and retain records sufficient to trace individual actions File access and configuration changes logged with timestamps and user attribution, retained across reboots and preserved through a factory reset

What this does not mean

Installing a device does not make an organization compliant, and no product can. CMMC assesses your whole organization, from policy and training through to physical security. The upgrade closes one specific, commonly-cited gap and gives you something you can point at and produce evidence for.

Better you hear that here than in an assessment. If a vendor tells you their box makes you CMMC compliant, be careful.

Current status

Independent validation is still in progress

Independent penetration testing and third-party review are scheduled, and we will share the outcome with customers.

If independent validation is a gate for your program, talk to us about timing before you order.

We come at this from inside manufacturing, and we bring in outside expertise where the work calls for it. Where that background comes from →


Long-term support

A device you can still defend in three years.

A device that was appropriate when it was installed and never updated afterwards becomes its own finding. This applies to every unit we ship, with the upgrade or without it.

Units under support receive security updates as issues come to light, on no fixed schedule and independent of the release calendar. How long a unit stays under support is set in your agreement, so the term is known before you order.

Separately, a new release lands in September of every even year, aligned with standard release security cycles, so deployed units keep pace as CMMC and NIST SP 800-171 change. The next three are September 2026, 2028, and 2030.

At the end of a unit’s support term you can exchange it at a reduced price against the unit you send back, buy current hardware outright, or arrange extended support and keep running what you have. If your own policy will not let a unit that has held CUI leave the building, raise it early. The terms of all of this belong in your agreement.

Ordering

Nothing ships back to us.

The upgrade is a signed software update, and every CodePod and CodeNet already carries the hardware for it. Order it with your unit and it arrives configured. Order it three years later and it unlocks on the unit you already have, with no swap and no return.

Pricing, and the support terms that come with running a unit under assessment, belong in your quote. Tell us where you are in the process and we will tell you whether the upgrade is what you need, or whether it is not.

Working through an assessment?

Tell us what your assessor has flagged and we will tell you whether we help with it.