Asset and boundary record
An inventory review and documented treatment of OT and other specialized assets, with information flows and access relationships for assessment planning.

03 / OT CYBERSECURITY
Connect shop-floor OT security with your contract and information-handling requirements. SSX360 scopes asset and access reviews and prepares evidence for CMMC and NIST SP 800-171 assessment work.
Review the agreed inventory of industrial controllers, CNC and test equipment, engineering workstations, and remote maintenance connections. Trace where controlled unclassified information (CUI) is handled and document the proposed assessment boundary.
Select the deliverables around your facility, review objective, and available records. Scope and acceptance criteria are agreed before work begins.
An inventory review and documented treatment of OT and other specialized assets, with information flows and access relationships for assessment planning.
An evidence index mapped to agreed NIST SP 800-171 review criteria, with supporting records, identified gaps, and remediation tracking for the responsible team.
Signed exports and offline verification for the agreed records. Hardware-assurance or SIGNET evaluation work is scoped separately against the actual configuration and evidence requirements.
ML-DSA-87 / MATRIX SCROLL / SCROLL CONSOLE
Matrix Scroll signs records with ML-DSA-87. Scroll Console organizes imported evidence, supports comparison with retained sources, and prepares controlled handoffs. These are private SSX360 tools used within an agreed engagement.
Explore the evidence workflowSOURCE REVIEW / OCT 09, 2026
The official CMMC program page reports that Phase II was suspended on July 13, 2026. The previously scheduled November 10, 2026 transition is not an active deadline. Phase I requirements remain in place. Confirm the assessment requirements in the applicable solicitation or contract.
Read the official sourceThe Level 2 scoping guide treats OT as a specialized-asset category with documentation requirements. Asset treatment belongs in the inventory, system security plan, and scope diagram. A shop-floor label alone does not settle the assessment boundary.
Read the official sourceThis is scoped assessment and evidence-preparation support. SSX360 does not issue CMMC certification through this service. The required assessment route follows the applicable contract and current program rules.
Hardware attestation and signed records address specific evidence questions. They do not replace the system security plan, required safeguards, or the applicable assessment. Any SIGNET work needs its own configuration and evaluation scope.
Share the facility type, general systems in scope, review objective, and target date. Keep network diagrams, credentials, CUI, and other sensitive records out of the first inquiry.