03 / OT CYBERSECURITY

Make the shop-floor boundary reviewable.

Connect shop-floor OT security with your contract and information-handling requirements. SSX360 scopes asset and access reviews and prepares evidence for CMMC and NIST SP 800-171 assessment work.

What your team receives
ENGAGEMENT TYPE
Scoped service
PLANNING CONTEXT
CMMC / NIST SP 800-171
REVIEW OUTPUT
Assessment + signed evidence

What we review

Review the agreed inventory of industrial controllers, CNC and test equipment, engineering workstations, and remote maintenance connections. Trace where controlled unclassified information (CUI) is handled and document the proposed assessment boundary.

What your team receives

Select the deliverables around your facility, review objective, and available records. Scope and acceptance criteria are agreed before work begins.

Asset and boundary record

An inventory review and documented treatment of OT and other specialized assets, with information flows and access relationships for assessment planning.

CMMC evidence preparation pack

An evidence index mapped to agreed NIST SP 800-171 review criteria, with supporting records, identified gaps, and remediation tracking for the responsible team.

Signed review and hardware-assurance scope

Signed exports and offline verification for the agreed records. Hardware-assurance or SIGNET evaluation work is scoped separately against the actual configuration and evidence requirements.

ML-DSA-87 / MATRIX SCROLL / SCROLL CONSOLE

Evidence your reviewers can inspect

Matrix Scroll signs records with ML-DSA-87. Scroll Console organizes imported evidence, supports comparison with retained sources, and prepares controlled handoffs. These are private SSX360 tools used within an agreed engagement.

Explore the evidence workflow

Regulatory context

SOURCE REVIEW / OCT 09, 2026

CMMC / Current implementation status

The official CMMC program page reports that Phase II was suspended on July 13, 2026. The previously scheduled November 10, 2026 transition is not an active deadline. Phase I requirements remain in place. Confirm the assessment requirements in the applicable solicitation or contract.

Read the official source

Level 2 / Specialized assets

The Level 2 scoping guide treats OT as a specialized-asset category with documentation requirements. Asset treatment belongs in the inventory, system security plan, and scope diagram. A shop-floor label alone does not settle the assessment boundary.

Read the official source

Questions before you scope the work

Is this a CMMC certification service?

This is scoped assessment and evidence-preparation support. SSX360 does not issue CMMC certification through this service. The required assessment route follows the applicable contract and current program rules.

Does a SIGNET attestor replace CMMC evidence?

Hardware attestation and signed records address specific evidence questions. They do not replace the system security plan, required safeguards, or the applicable assessment. Any SIGNET work needs its own configuration and evaluation scope.

Start with the facility and the decision.

Share the facility type, general systems in scope, review objective, and target date. Keep network diagrams, credentials, CUI, and other sensitive records out of the first inquiry.

Request a briefing.

Prepare a message for mission@ssx360.com, then send it from your email app.

Share your area of interest, general requirements, and the decision your team needs to make.

Keep this first message to general requirements. Arrange confidentiality terms before sharing nonpublic information.

Read our Privacy notice and legal contact information.