
For defense manufacturers, an ERP belongs inside the CUI boundary only when it stores, processes, or transmits Controlled Unclassified Information. If controlled technical data, CUI-marked contract data, controlled attachments, exports, or mirrored integrations enter the ERP, the tenant, its users, connected services, endpoints, incident workflow, and subcontractor access all need a defensible scope under DFARS 252.204-7012 and the current CMMC regime.
Quick answer: your ERP is inside the CUI boundary if controlled drawings, specs, CUI-marked contract data, or derivative technical records live in transactions, attachments, reports, integrations, exports, or sandboxes. If that happens, standard commercial SaaS should not be assumed acceptable just because it is secure in general. For CMMC Level 2 environments, contractors typically need a government-suitable deployment with defensible FedRAMP Moderate equivalency evidence—or they must keep CUI out of the ERP entirely.
Start an ERP readiness assessment
The current operating distinction matters. After the February 2026 reset, assessment obligations moved through DFARS 252.204-7021 and the CMMC framework rather than the earlier clause path many contractors memorized. But DFARS 252.204-7012 did not go away. It still carries the safeguarding, external cloud, cyber-incident reporting, evidence-preservation, and flow-down duties that matter when CUI touches your systems.
That means an IT Director, compliance lead, or CISO at a Tier-2 or Tier-3 defense supplier should not read a changed assessment structure as permission to leave business systems unexamined. If your ERP handles CUI, 7012 still matters. CMMC Level 2 remains the assessment model tied to the 110 controls in NIST SP 800-171 Rev. 2, while DFARS 252.204-7012 remains the contract clause that drives adequate security, 72-hour reporting, and external cloud obligations.
The CUI boundary is the real set of systems, people, devices, services, logs, backups, and counterparties that store, process, transmit, or protect CUI. It is not automatically your whole network, and it is not automatically every ERP module. It is the actual path the data takes.
Take a precision-machining supplier receiving a controlled drawing from a prime. The drawing gets attached to a quote, referenced on a sales order, used to derive a bill of materials and routing, pushed to purchasing or planning through an integration, summarized in a quality packet, and then shared with a heat-treat or plating subcontractor. Once that happens, the likely boundary is no longer just “the ERP.” It may include the user laptop, identity provider, file storage, ERP tenant, integration middleware, reporting layer, exports, backups, shared mailboxes, and the downstream supplier environment.
An ERP used only for finance and ordinary purchasing can remain outside the CUI boundary—but only if CUI is truly prevented from entering fields, attachments, reports, integrations, exports, dashboards, analytics copies, and sandboxes. Calling a tenant “out of scope” while users still attach controlled technical data is the risky hybrid that fails under scrutiny.
For a broader manufacturing operating-model view, see ERP for Manufacturing. For the related aerospace quality transition, see AS9100 to IA9100 Changes: What’s Changing in 2026 and How Your ERP Must Adapt.
The wrong opening question is, “Is NetSuite CMMC compliant?” The right opening question is, “What exact data enters NetSuite?” A CUI-bearing ERP record may be a controlled drawing attachment, a controlled spec, a routing note, an inspection artifact, a CUI-marked line-item data set, an API payload, or a report that reproduces technical content. A transaction tied to a defense contract is not automatically CUI. Classification depends on the data itself, the markings, the contract, and the governing authority.
Review the whole application surface: item masters, BOMs, routings, work orders, purchase orders, project records, file storage, saved searches, generated PDFs, dashboards, emailed reports, APIs, EDI, backups, refresh copies, BI extracts, spreadsheets, and endpoint downloads. A tenant that looks controlled at the UI level can still pull CUI into lower-control places through exports and integrations.
When an external cloud service stores, processes, or transmits covered defense information, DFARS 7012 requires security equivalent to the FedRAMP Moderate baseline. It also requires support for cyber-incident reporting, malicious-software handling, evidence preservation, forensic support, and damage assessment. That is the cloud test that makes ERP deployment choice decisive.
Do not confuse broad vendor security messaging with service-specific evidence. SOC 2, ISO certifications, or a hyperscaler relationship do not by themselves prove that the exact SaaS service carrying your CUI meets the bar. Ask for evidence tied to the exact offering, the boundary description, hosting arrangement, shared-responsibility model, incident-support commitments, and whether the provider will support 7012 preservation and reporting duties. For the control baseline itself, use official references such as the FedRAMP Moderate overview and the current CMMC program page.
That is also why you should not position standard commercial NetSuite as CMMC Level 2-ready by default. General commercial NetSuite is not the same thing as a government-suitable environment for CUI. For L2 CUI storage, contractors usually need NetSuite Government or another government-suitable deployment with defensible evidence—or they need to keep CUI out of the ERP entirely and hold it in a separately controlled enclave.
Review the NIST SP 800-171 Rev. 2 reference here.
Environment or use case | Practical CUI position |
|---|---|
Standard commercial NetSuite with no CUI | Can stay outside the CUI boundary only if CUI is actively blocked from records, attachments, integrations, exports, reports, analytics copies, and backups. |
Standard commercial NetSuite containing CUI | Do not treat as CMMC Level 2-ready by default. Generic SaaS security claims are not proof of DFARS 7012 Moderate-equivalent treatment for the exact service. |
NetSuite Government or other government-suitable deployment | Potentially defensible only after validating the exact service scope, current evidence, contractual incident support, shared responsibilities, and whether the service is approved for the intended CUI use case. |
Commercial NetSuite plus separate controlled enclave | Often the cleaner pattern when finance and standard operations stay in ERP while drawings, controlled specs, and technical packages remain in a separate controlled environment. |
Authorized infrastructure under a custom workload | Infrastructure status alone does not automatically extend to the ERP application, integrations, endpoints, support access, or connected services. |
The question is never just “NetSuite or not NetSuite.” It is the specific service offering, hosting model, evidence package, configuration, integrations, user roles, and operating discipline.
Look for controlled drawings, technical data packages, specs, work instructions, deliverables, attachments, and exports. ITAR-controlled data deserves special care, but ITAR is not a shortcut that makes every defense record CUI. Verify the actual basis.
Review the ERP, file storage, integration platform, reporting tool, backup service, support tooling, and sandboxes. If any store, process, or transmit CUI, they belong in scope.
Role-based access has to cover records, files, searches, reports, export rights, API identities, admins, consultants, and support users. A buyer may need a part number without seeing the full controlled drawing package.
Check browser traffic, attachments, backups, APIs, file transfer, middleware, BI extracts, endpoint downloads, and mobile access. Encryption is necessary, but weak permissions and unmanaged endpoints can still break the model.
DFARS 7012 defines rapid reporting as within 72 hours of discovery. Your process has to identify who triages, who contacts the provider, how logs are gathered, how the DoD report is submitted, and how relevant evidence is preserved for at least 90 days after reporting.
If a subcontractor, MSP, implementation partner, supplier portal user, or external lab can access ERP-hosted CUI, the contractual duties and technical review both have to follow that access path. Flow-down is not just a paper clause exercise.
No one should describe standard commercial NetSuite as CMMC Level 2-ready by default. CMMC applies to a contractor’s scoped environment, and DFARS 7012 requires Moderate-equivalent protection for covered defense information in external cloud services.
It is the requirement that an external cloud service handling covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline. The evidence has to be specific to the service handling the data.
Not always. If CUI is operationally essential and the service, integrations, endpoints, and evidence package are defensible, the ERP can be inside the boundary. If they are not, CUI should stay out.
DFARS 7012 addresses safeguarding, cloud obligations, 72-hour reporting, evidence preservation, and flow-down. DFARS 7021 is the current CMMC clause that carries the assessment mechanism and required level.
For a qualifying cyber incident, DFARS 7012 requires rapid reporting within 72 hours of discovery. The organization also has to preserve required evidence for at least 90 days after submission.
Flow-down applies as specified in the clause to lower-tier contractual relationships, and a cloud ERP provider handling covered defense information also has distinct obligations under 7012. Review both separately.
AS9100 and IA9100 address aerospace quality-system expectations, while DFARS 7012 addresses safeguarding and cyber-incident duties. They overlap operationally in records control, traceability, supplier discipline, and evidence integrity, but they are not substitutes for one another.
The real question is not whether an ERP logo is “CMMC-ready.” It is whether your organization can show where CUI goes, who can access it, which services support it, how it is protected, how an incident is reported, and how duties follow it to lower tiers.
If the answer is incomplete, choose deliberately: keep CUI outside the ERP through enforceable separation, or design an ERP environment that sits inside the CUI boundary with the necessary cloud evidence and operating controls. The accidental hybrid—commercial ERP declared out of scope but routinely used for CUI—is the model to eliminate.
Softype can help turn that boundary decision into implementation-ready scoping: role models, attachment rules, workflow approvals, reporting controls, integration review, sandbox governance, and documented data-flow decisions. Book a 30-min DFARS 7012 + CMMC ERP scoping call.
This article is general information, not legal, export-control, cybersecurity-certification, or compliance advice. Confirm the clauses, deviations, data markings, cloud-service evidence, and solicitation-specific requirements with qualified counsel and security professionals.