The Question Everyone Argues, Stated Correctly
A prime contractor sends a machine shop a set of drawings and models marked as Controlled Unclassified Information. The shop opens the files, programs the work, runs the machines, inspects the parts, and records the results. Then the question surfaces that no one in the shop answers the same way twice. Is the posted G-code itself CUI? What about the toolpath file, the inspection program, the scan data, or the traveler that follows the job across the floor?
Two positions tend to harden, and each is stated with confidence. One holds that every file touched during a controlled job is automatically CUI because it came from a controlled source. The other holds that G-code is only a stream of coordinates and feed rates and therefore can never be controlled. The correct answer comes from two questions asked together. What information does the specific file actually contain, and does an applicable authority require that information to be controlled? CUI is determined by the content of a given artifact in a given scenario, not by a blanket rule applied to a file type.
What Makes a File CUI
Under the National Archives definition and Department of Defense Instruction 5200.48, CUI is information that a law, regulation, or Government-wide policy requires to be safeguarded. Status attaches to the information, so a file extension, a software product, a storage medium, a network location, or the absence of a visible marking does not by itself decide the question. A new file built from a controlled drawing falls within the re-use concept when it carries the controlled content forward, and the same authorities read the word document broadly enough to include electronic files, data, images, and metadata.
In aerospace and space work the category most often implicated is Controlled Technical Information, which expressly covers drawings, instructions, computer software, and documentation usable to manufacture military or space items, along with process sheets and detailed manufacturing data. The data-rights definitions in the regulation help establish whether an artifact is technical data or software, but they do not by themselves make an artifact CUI. Over-designation cuts the other way, since marking information as controlled when no authority requires it is itself a misuse of the program.
The G-Code Answer, Directly
A posted numerical control program is not CUI because it carries an NC, TAP, or TXT extension, and not because a particular toolpath system produced it. By the same logic, it is not exempt because a controller reads it as motion commands. The defensible basis is the controlled content carried into the output and the use of that output in performing the contract. A program should be treated as CUI when it encodes controlled geometry, coordinates, toolpaths, drilling patterns, machining sequences, or special operations that can be used to manufacture the controlled part. A generic post-processor, machine definition, tool library, or blank template is not controlled merely because the same system also processes controlled work.
This resolves the dispute by rejecting both slogans. The claim that all G-code is controlled ignores the many programs and components that carry no controlled content. The claim that G-code is never controlled ignores the encoded geometry and manufacturing instructions that often qualify as Controlled Technical Information. The file type does not answer the question. The content does.
Content and authority decide it. Not the extension, not the software that produced the file, not where it is stored, and not the lineage alone. A derivative file is CUI when it incorporates, restates, encodes, reveals, or operationalizes controlled technical information.
Both overbroad positions fail. Everything is CUI ignores the generic files that carry no controlled content. Nothing the shop makes is CUI ignores the encoded geometry and manufacturing instructions that qualify as Controlled Technical Information.
Generic is not controlled by proximity. A post-processor, a tool library, a blank template, or a public training example does not become CUI because it sits near a controlled job.
Through the Shop, Artifact by Artifact
The same test applies at every station. Native project and toolpath files usually carry controlled geometry and operations. Machine transfer does not change status, whether the program moves by direct numerical control server, network share, removable media, or manual entry, and an air-gapped machine that actually processes controlled information is not outside the assessment scope. Additive build files preserve geometry and part-specific build strategy. Inspection programs, ballooned drawings, first article reports, point clouds, and nondestructive testing data are controlled when they reproduce or reveal controlled geometry, tolerances, materials, or acceptance criteria. Detailed travelers are controlled when they restate controlled sequences, dimensions, special processes, or inspection characteristics, while a status-only routing record may not be.
One scenario from recent scoping work shows how a minor instrument can place controlled information in motion. A shop measured a part at the CNC using a wireless caliper paired by Bluetooth to a laptop, and the measurement application displayed a picture of the part with the inspection points mapped onto it. A single caliper reading is one value. The display on the laptop reproduces the controlled geometry and the inspection characteristic layout, which makes the laptop a CUI Asset, and the wireless link is a transmission pathway that belongs in the data-flow review.
From CUI Determination to CMMC Scope
Two distinct questions are often run together. The first is the determination question: what information is CUI? The second is the scoping question: which assets process, store, transmit, or protect it? Determination comes first. Once the content is known, the assets that handle it map to the CMMC Level 2 categories under 32 CFR 170.19. A CUI Asset is assessed against all applicable requirements. A Specialized Asset, which includes operational technology and test equipment, can carry CUI but cannot be fully secured, and it remains inside the Level 2 scope under risk-based policies. Many machine tools, additive systems, measuring machines, and testing systems may qualify there. The assessment organization evaluates compliance with the certification requirements. It does not designate CUI, and it does not resolve the underlying status of a given file.
Specialized Assets are inside the scope, not outside it. A CNC controller, an additive system, a coordinate measuring machine, or a testing instrument that handles controlled information is in scope at Level 2, with system security plan documentation and risk-based policies rather than assessment against every other requirement.
Escalation belongs in the contract. Unresolved questions go to the prime, the information originator, or the Government contracting activity, in writing. The flowdown clause requires the prime or higher-tier contractor to determine whether subcontract information remains covered defense information and, as needed, to consult the Contracting Officer.
Download the Full White Paper
The full paper sets out the content and authority test, answers the G-code question directly, and carries the method through CAD/CAM, CNC and machine transfer, additive manufacturing, inspection and metrology, nondestructive testing, and travelers, with treatment and asset-categorization matrices. It separates the data-rights definitions from the CUI determination, distinguishes CUI-revealing aggregation from compilation that raises the classification level, and supports every legal proposition with a pinpoint citation to NARA, DoD Instruction 5200.48, DFARS, and 32 CFR part 170.
The CMMC Decision, Second Edition
Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.
Read More →