The machine can’t be secured directly
Controls run operating systems that stopped receiving patches years ago and cannot host a security agent. Nothing you install on your network reaches inside them.
When your shop handles Controlled Unclassified Information, how a program file gets from a programmer’s desk to a CNC control is part of your assessment, and for most shops it is the weakest part. The upgrade closes that gap on a CodePod or CodeNet. Order it with your unit, or add it the day a contract requires it.
CUI is a burden by design. When a contract puts it on your floor, that burden is the requirement, and the path a file takes to your machine has to carry the same authority as everything else in scope.
Authority means you can name every person who touched a file and prove they were who they said they were, then produce that record months later when somebody asks for it. That is a higher bar than keeping a machine safe, and it is meant to be. The upgrade is what raises a CodePod or CodeNet to it: certificates issued to your users, certificate-based sign-in, enforced password rotation, and an audit log built to be handed over.
The upgrade also brings real administration with it, and you should hear that here rather than after the order. Certificates get issued and replaced. Passwords rotate whether or not it is convenient. The log earns its keep only if somebody reads it. Under a contract the upgrade pays that work back the first time somebody asks for the record.
Without a contract, it is friction. The device already solves the file problem on its own: the machine stays off your network, files are encrypted at rest, every user signs in, and only the file types you allow get through. Since the upgrade is a signed software update on hardware you already own, it is there the day a contract puts you in scope.
NIST SP 800-171 is the list of requirements, 110 of them, covering Controlled Unclassified Information held outside government systems. That includes the CNC programs on your shop network. CMMC is how the Department of Defense checks you have met it, in most cases through third-party assessment before you can bid.
Controls run operating systems that stopped receiving patches years ago and cannot host a security agent. Nothing you install on your network reaches inside them.
A USB drive carried across the floor has no encryption, no access control, and no record of where it went. Putting the machine straight onto the office network solves the transfer problem and creates a bigger security one. Both are the kind of thing an assessor writes up.
Even where a shop’s practice is sound, sneakernet produces no logs. When an assessor asks who moved which file and when, there is nothing to show.
The upgrade adds the identity and evidence machinery an assessment asks for. Everything that keeps your machine off the network and your files encrypted is already in the box.
Available on CodePod and CodeNet. Nothing under “On every unit” changes when you add it.
Both products are built around the same security model. This is where that model touches the control families an assessor will walk through with you. Everything below describes a unit with the Compliance Upgrade installed, and nothing on this page should be read as a claim about a unit without it.
| Control family | What it asks for | What the appliance provides |
|---|---|---|
| Access Control (AC) | Limit system access to authorized users, and limit what each can do | Named accounts with per-user file isolation, a separate administrator role, and no anonymous access to the network side |
| Identification & Authentication (IA) | Identify users uniquely and authenticate them before granting access | Every transfer is tied to an individual account, with certificates issued to your users. No shared drop folder, no unauthenticated uploads |
| Media Protection (MP) | Protect and control media containing CUI, including removable media | Removes the uncontrolled USB drive from the routine entirely. Storage is encrypted and bound to its device, so it cannot be read elsewhere |
| System & Communications Protection (SC) | Protect information in transit and control the boundary between systems | Encrypted transport for every upload, a default-deny firewall, and a hard boundary that keeps the control off your network |
| Audit & Accountability (AU) | Create and retain records sufficient to trace individual actions | File access and configuration changes logged with timestamps and user attribution, retained across reboots and preserved through a factory reset |
Installing a device does not make an organization compliant, and no product can. CMMC assesses your whole organization, from policy and training through to physical security. The upgrade closes one specific, commonly-cited gap and gives you something you can point at and produce evidence for.
Better you hear that here than in an assessment. If a vendor tells you their box makes you CMMC compliant, be careful.
Independent penetration testing and third-party review are scheduled, and we will share the outcome with customers.
If independent validation is a gate for your program, talk to us about timing before you order.
We come at this from inside manufacturing, and we bring in outside expertise where the work calls for it. Where that background comes from →
A device that was appropriate when it was installed and never updated afterwards becomes its own finding. This applies to every unit we ship, with the upgrade or without it.
Units under support receive security updates as issues come to light, on no fixed schedule and independent of the release calendar. How long a unit stays under support is set in your agreement, so the term is known before you order.
Separately, a new release lands in September of every even year, aligned with standard release security cycles, so deployed units keep pace as CMMC and NIST SP 800-171 change. The next three are September 2026, 2028, and 2030.
At the end of a unit’s support term you can exchange it at a reduced price against the unit you send back, buy current hardware outright, or arrange extended support and keep running what you have. If your own policy will not let a unit that has held CUI leave the building, raise it early. The terms of all of this belong in your agreement.
The upgrade is a signed software update, and every CodePod and CodeNet already carries the hardware for it. Order it with your unit and it arrives configured. Order it three years later and it unlocks on the unit you already have, with no swap and no return.
Pricing, and the support terms that come with running a unit under assessment, belong in your quote. Tell us where you are in the process and we will tell you whether the upgrade is what you need, or whether it is not.
Tell us what your assessor has flagged and we will tell you whether we help with it.