The path to your machine is in scope.

If your shop handles Controlled Unclassified Information, how a program file gets from a programmer’s desk to a CNC control is part of your assessment — and for most shops it is the weakest part. Here is what our appliances do about it, and where their limits are.

Background

NIST SP 800-171 and CMMC, briefly

The two are related but not the same thing. One is the list of requirements; the other is how the Department of Defense checks that you have met them.

NIST SP 800-171

The standard set of security requirements for protecting Controlled Unclassified Information when it lives outside federal systems. That includes CNC programs and technical drawings sitting on your shop network. It runs to 110 requirements across 14 control families. Contractors handling CUI are obliged to implement them under DFARS 252.204-7012. Historically, companies self-assessed and asserted their own compliance.

CMMC

The Cybersecurity Maturity Model Certification Program exists because self-assessment alone did not produce results. CMMC 2.0 has three levels: Level 1 (foundational, self assessment permitted), Level 2 (advanced, aligned with the full NIST SP 800-171 set, with third-party assessment for prioritized contracts), and Level 3 (expert, built on NIST SP 800-172 and assessed by the government).

The practical difference is that CMMC generally requires third-party or government certification before you can bid, so the gaps that used to be quietly tolerated now have to be closed and evidenced.

The gap

Why the CNC file path is usually the hard part.

The machine can’t be secured directly

Controls run operating systems that stopped receiving patches years ago and cannot host a security agent. Nothing you install on your network reaches inside them.

The usual workarounds don’t hold up

A USB drive carried across the floor has no encryption, no access control, and no record of where it went. Putting the machine straight onto the office network solves the transfer problem and creates a bigger security one. Both are the kind of thing an assessor writes up.

There’s no evidence to hand over

Even where a shop’s practice is sound, sneakernet produces no logs. When an assessor asks who moved which file and when, there is nothing to show.

Control families

Where our appliances line up

Both products are built around the same security model. This is where that model touches the control families an assessor will walk through with you.

How Iron Glacier appliances relate to NIST SP 800-171 control families
Control family What it asks for What the appliance provides
Access Control (AC) Limit system access to authorized users, and limit what each can do Named accounts with per-user file isolation, a separate administrator role, and no anonymous access to the network side
Identification & Authentication (IA) Identify users uniquely and authenticate them before granting access Every transfer is tied to an individual account. No shared drop folder, no unauthenticated uploads
Media Protection (MP) Protect and control media containing CUI, including removable media Removes the uncontrolled USB drive from the routine entirely. Storage is encrypted and bound to its device, so it cannot be read elsewhere
System & Communications Protection (SC) Protect information in transit and control the boundary between systems Encrypted transport for every upload, a default-deny firewall, and a hard boundary that keeps the legacy control off your network
Audit & Accountability (AU) Create and retain records sufficient to trace individual actions File access and configuration changes logged with timestamps and user attribution, retained across reboots and preserved through a factory reset

What this does not mean

Installing a device does not make an organization compliant, and no product can. CMMC assesses your whole organization: policies, training, incident response, physical security, and much more besides. What CodePod and CodeNet do is close one specific, commonly-cited gap with something you can point at and produce evidence for.

We would rather be straight with you about that now than have it come up in an assessment. If a vendor tells you their box makes you CMMC compliant, be careful.

Security model

What is actually built in

Encrypted at rest

AES-256 full-disk encryption on every unit, with the key bound to that individual device. Removed storage cannot be read on other hardware.

Encrypted in transit

Uploads travel over SFTP or HTTPS. Certificates are generated per device, so no two units share an identity.

Default-deny boundary

The firewall drops anything not explicitly permitted, and traffic does not route between the machine side and your network. Only files cross.

Mandatory access control

Each service is confined to only the files and privileges it needs, so a fault in one cannot become access to everything.

No internet dependency

No cloud service, no telemetry, no outbound connections. Fully air-gapped operation is supported, including timekeeping without a network clock.

Hardened for production

Diagnostic tooling is stripped from shipping units, unused services are switched off rather than left listening, and remote root login is disabled.

Current status

Independent validation is still in progress

Both products are in beta. Independent penetration testing and third-party review are scheduled ahead of the full production release in September 2026, and we will share the outcome with customers.

If independent validation is a gate for your program, talk to us about timing before you order.


Long-term support

A device you can still defend in three years.

Security standards move. A device that was appropriate when it was installed and never updated afterwards becomes its own finding.

Iron Glacier commits to biannual releases aligned with standard release security cycles, keeping deployed units current as CMMC and NIST SP 800-171 evolve. Every two years we offer existing customers a discounted trade-in to the latest hardware, so the units on your floor stay supportable rather than quietly aging out.

The hardware is specified to match: industrial-grade components in a fully enclosed aluminum housing, built for a shop environment over a long service life.

Working through an assessment?

Tell us where you are in the process and what your assessor has flagged. We will tell you honestly whether we help with it.