The Ownership Problem

A prime contractor places controlled work with a manufacturer. The 110 requirements of CMMC Level 2, drawn from NIST SP 800-171 Revision 2, arrive as a single list. The list is handed to whoever runs the network, and the organization proceeds as though information technology owns the entire standard. That assumption is correct for roughly half of the control families and wrong for the other half.

Awareness training is delivered and tracked by the people who run onboarding. Personnel screening and the removal of access on termination belong to the same function. Physical protection of the production area belongs to whoever controls the building. The marking and disposal of removable media and printed drawings happen on the floor, in the hands of machinists and engineers who generate and consume technical data every day. When each of these requirements is assigned by default to information technology, it receives no function suited to perform it, and it is left without an effective owner. A control without an owner drifts, and the families most prone to drift are the ones whose work lives outside information technology.

CMMC Is a Company-Wide Project

Because the work distributes across the business, implementing CMMC is a company-wide project rather than a technical deployment. A program that touches access, training, screening, facilities, engineering data, the production floor, the quality system, and contract obligations has the structure of a cross-functional undertaking. It succeeds or fails on the same conditions that govern any such undertaking: a sponsor with authority, a named owner for each part of the work, a schedule that respects dependencies, and a regular accounting of progress. Run as a task list inside information technology, the effort stalls with the very families that live outside it.

The Responsibility Matrix

The paper maps the fourteen control families to the eight functions that actually perform the work inside an aerospace manufacturer: information technology and security, human resources, facilities, engineering, operations, quality, contracts, and executive leadership. Each family carries a primary owner, the supporting functions that contribute to it, and the narrow set of decisions reserved for leadership. The result is a single reference a manufacturer can bring into a readiness meeting and use to assign responsibility before any technical work begins.

Four codes carry the matrix. P marks the primary owner that performs the core work. S marks a supporting function that contributes execution, input, or data. O marks independent oversight. E marks an executive accountability that leadership cannot delegate.

The families sort into three bands. A handful are cleanly owned by information technology. A second group depends on a clean handoff between two or three functions, the place where access removal lags behind a departure. A third group distributes across four functions at once, and these are the families that stall when any contributing owner is unnamed.

Where the Standard Requires Two

Most families carry the risk of no owner. One small group carries the opposite risk, a single owner where the standard requires two. These are the requirements at the intersection of access and audit. Separation of duties at 3.1.4, the capture of privileged actions at 3.1.7, and the protection of audit information at 3.3.8 and 3.3.9 together establish a principle that a single owner cannot satisfy. The administrator who holds privileged access cannot also be the sole custodian of the logs that record how that access is used.

The audit trail needs an independent owner. An administrator who can act and then alter the record of the action defeats the purpose of the audit log. In a shop large enough to staff the roles separately, the system administrator is not the audit administrator. In a shop with a single administrator, that independent check becomes an oversight responsibility held by management.

It is the strongest argument for distributed ownership. Audit and accountability are among the families most often missed in Level 2 assessments, not because the logging is absent but because the separation that protects it was never established.

The Aerospace Advantage: Quality as an Existing System

An AS9100 manufacturer already operates document control, configuration control, and records retention as audited disciplines. Drawings carry revision levels and approval signatures, changes move through a controlled process with traceability, and records are produced on demand during quality audits. These are the same behaviors that configuration management and media protection require under CMMC, expressed in the language of aerospace quality rather than information security. For an AS9100 shop, much of the standard is an existing capability to extend rather than a new burden to build, which is why Quality earns a column of its own on the matrix.

From Matrix to Affirmation

A certification reflects the state of a program on the day it is assessed. The affirmation that follows, and the annual affirmation after it under 32 CFR 170.22, attest that the program has continued to operate. The distance between a point-in-time assessment and a continuing attestation is where drift occurs, and drift is almost always an ownership failure expressed over time. A matrix that names a primary owner for every family gives the program a structure that maintains itself, and the annual affirmation becomes a summary of functional owners confirming their portion rather than an act of faith by a single executive.

Download the Full White Paper

The full paper presents the complete responsibility matrix across all fourteen control families and eight functions, with a family by family analysis, the access and audit separation in detail, the reuse of the AS9100 quality system, and the scaling guidance for smaller shops and for managed and enclaved architectures. Every regulatory claim is supported by a pinpoint citation to NIST SP 800-171 Revision 2, 32 CFR part 170, and DFARS 252.204-7012.

Download PDF →
Related

The CMMC Decision, Second Edition

Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.

Read More →