The compliance guidance for programs like CPCSC quietly assumes an IT department. Somebody who knows what a VLAN is, a server room with a door, a patch cadence. The Canadian defence supply chain doesn’t look like that below tier 1. It looks like a 30-person machine shop where the CAD workstations, the CNC controllers, the front-office PCs, the shop-floor wifi, and the owner’s laptop all share one flat network behind the same class of router you’d buy for a house.
I’ve done security readiness work inside exactly these environments, small manufacturers preparing for ISO 27001 and NIST-based customer requirements, and the gap between the framework’s assumptions and the shop floor’s reality is where these projects live or die.
What “flat” actually costs you
On a flat network, the attestation questions collapse into each other. Asked where specified information lives, the true answer is everywhere: the drawing package sits on the CAD station, which shares a broadcast domain with a CNC controller running an embedded OS the vendor stopped patching years ago, which sits next to the wifi the shop floor uses for personal phones. Every control you’d attest to, access restriction, boundary protection, monitoring, has to be true for the whole network, because the whole network is one zone.
That’s what makes flat networks expensive for compliance. Not that they’re indefensible, but that the defensible boundary is enormous.
The move that changes everything
One intervention does most of the work: put the machines that touch sensitive data in their own segment. In practice, for a shop this size, that’s a small business-grade firewall and a managed switch, two or three VLANs, and a few deliberate rules. CAD and engineering in one zone. CNC and production equipment in another, because those controllers can’t be patched and shouldn’t see the internet at all. Everything else, office, wifi, the label printer, in a third.
Suddenly the attestation boundary shrinks from “the entire company” to “the engineering VLAN,” and every downstream question gets easier. Access control means the six people in that zone, not all 30. Monitoring means one firewall’s logs. The unpatched CNC controller stops being a compliance contradiction and becomes an isolated cell with a documented reason for existing.
The hardware for this lands in the low four figures. The design and the discipline are the actual product.
What I tell owners
Don’t start with a document set. A binder of policies describing a network that doesn’t exist is the most common readiness failure I’ve seen, and assessment regimes are getting better at catching it. Start with the segmentation, spend two or three focused days getting MFA onto the accounts that matter and the drawings out of personal email, and then write policies that describe what you actually built. The paperwork goes fast when it’s telling the truth.
A shop that does this is ready for more than a Level 1 attestation. The customer questionnaire, the insurance renewal, the bank’s security addendum, and the ISO conversation all get easier, because underneath the branding they’re all asking about the same flat network.
This is the readiness work I do with small manufacturers: segmentation design first, then paperwork that describes reality. If that’s the project on your desk, the CPCSC and CMMC readiness page is a reasonable place to start, and the segmentation guidance in the knowledge base covers the VLAN design in detail.