How do you get programs to a Windows XP CNC control under CMMC?

Your controls run XP, Windows 7 or DOS, and programs still have to reach them. Pick one transfer method, keep the machines, time-box the builder's remote access, and write the controller up the way the rule allows.

Programs to old controls. One transfer path each. Keep the machines. Time-box the builder. Working guide.
In this guide

Updated September 30, 2026

"My Okumas are everything from Windows XP to Windows 10," one shop owner wrote on r/NISTControls, and every machine shop working through CMMC reaches that same wall. The programs are made in CAM from controlled drawings. The controls can't be patched, can't run antivirus, and some can't talk to anything newer than a 2001 file share. Meanwhile, USB sticks are "floating around," as another owner put it.

Keep the machines. Pick one transfer method per control, lock it down to a single path, and write each controller up as a Specialized Asset. The rule already expects old controls. What it won't tolerate is five informal ways for programs to reach them.

Some terms. CUI (controlled unclassified information) is the drawings and models the government marks as sensitive, and we treat a program made from a CUI model as CUI too (why). CMMC Level 2 checks 110 security requirements, and your SPRS score starts at 110 and loses points for each one you miss. The SSP (system security plan) is the document that says how you protect it all. The firewall rules that fence the cell off are in the segmentation field note; this post covers the transfer path, the builder's remote access and the spare images.

You don't need new machines

Somebody has probably told you a Windows XP control means a new machine. It doesn't. The CMMC rule sorts every asset into a category. Operational technology (programmable equipment that makes physical things happen, which covers a CNC control) and test equipment (your CMM, your vision system) are Specialized Assets. For those, the rule asks for four things: list the asset in your inventory, describe how you handle it in the SSP, show that it's managed under your own risk-based policies, and put it on the network diagram. The assessor's instruction for that row is plain: "Do not assess against other CMMC security requirements" (32 CFR 170.19, Table 3).

There's a second tool, the Enduring Exception. The rule defines it as a system "where remediation and full compliance with CMMC security requirements is not feasible," names OT and test equipment as examples, and requires no fix-it plan, only a write-up in the SSP (32 CFR 170.4). Scoring is explicit: an Enduring Exception described in the SSP with its mitigations "shall be assessed as MET" (32 CFR 170.24(b)). When it published the rule, the DoD even said a vendor's lack of FIPS-validated encryption "could be considered" an Enduring Exception (89 FR 83092).

Neither tool is a risk acceptance. You can't sign a memo that says "we accept the risk" on an office PC and have it scored MET. "You still cannot 'accept risk' or mark compensating controls," as one r/CMMC regular put it. A requirement is MET, NOT MET or not applicable. The exception covers equipment where fixing it isn't feasible. The programmer's Windows 10 desktop doesn't qualify, because an upgrade exists. Windows 10 support ended October 14, 2025 (Microsoft). That desktop is a CUI computer running an unsupported operating system, so it fails flaw remediation (3.14.1, 5 points) until you upgrade it. The control that Okuma shipped with Windows 10 on it is a different case, because the builder owns that operating system. That one is a Specialized Asset.

Pick one transfer method per control

Choose a row for each control and retire the others. Two methods on one machine means two paths to defend.

Method Use it when What it puts in scope The trap
DNC server on the controller segment You run 5+ networked controls, or you already own DNC software The DNC server is a full CUI computer: patched, managed, logged, backed up After lockdown, restarting DNC needs an admin password. Run it as a Windows service.
Transfer PC (one managed PC that pushes released programs) 2 to 10 controls, mixed ages, no DNC budget The transfer PC, as a CUI computer. Controls stay Specialized. People start using it for email and the internet. Give it one job only.
DMZ file server (office writes, floor reads) Programmers in the office, controls that can read a network share The file server, plus the permission split, which you have to prove XP controls only speak SMBv1. Turning SMBv1 on for a server the office also uses puts that risk on every connection.
Encrypted USB stick Controls with no network port, or a handful of machines The sticks, which count as removable media (3.8.7, 5 points) Loose, unnumbered sticks. Buy two to four hardware-encrypted sticks, number them, and keep them in the cell.
RS-232 serial from a transfer PC DOS-era and older controls The transfer PC. The cable runs inside your building. Serial isn't encrypted. Write down that the cable never leaves the controlled floor.

The default for most shops under 50 people is one transfer PC. Use USB only for the machines that have no network port at all. A DNC server earns its cost once you're past about ten machines, or if you already own the software.

What breaks after you lock down

The DNC server needs an admin to restart. This usually shows up the week after IT removes local admin rights from daily users (3.1.5, least privilege, which you should do). The program was started by hand from someone's desktop. Install it as a Windows service instead, so it starts at boot with nobody logged in. CIMCO, for one, documents running DNC-Max as a Windows service and warns that password or permission changes on the service account will stop it from starting (CIMCO). Give the service its own account, keep that account out of the admin group, and note its password owner in the SSP.

The control can't talk once FIPS mode is on. "The CNC cannot talk across the network in FIPS mode," one shop reported on r/CMMC. That's expected. Microsoft's own documentation says a Windows computer with the FIPS setting on "cannot communicate by means of digitally encrypted or signed protocols with servers that do not support these algorithms" (Microsoft Learn). FIPS-validated encryption is required when encryption is what protects the CUI (3.13.11). But the requirement to encrypt CUI in transit (3.13.8) has an escape clause written into it: "unless otherwise protected by alternative physical safeguards" (NIST SP 800-171r2). Our position: turn FIPS mode on for the office machines, and leave it off on the link from the transfer PC to the control. That link runs on a walled-off segment inside a building you control, and the SSP says so in one sentence. Don't turn off FIPS mode for the whole company to make one lathe work.

The XP control needs SMBv1. Windows XP's file sharing only speaks SMB version 1. SMBv2 arrived with Vista. Microsoft calls SMBv1's vulnerabilities significant and doesn't install it by default on Windows 11 (Microsoft Learn). SMBv1 is switched on per computer, not per folder, so turn it on only on the transfer PC, which faces the controller segment and nothing else. Leave it off on the file server and everything the office uses. A small bridge box that speaks SMBv1 to the floor and something modern to the office also works; the box is then a CUI asset you manage.

The USB stick. Buy hardware-encrypted sticks with a keypad on the stick. Once unlocked, the control sees an ordinary USB drive. Apricorn's Aegis Secure Key 3.0 is FIPS 140-3 validated (certificate #5517) and starts at $169 for 16 GB (Apricorn). Buy 140-3 for new purchases. NIST moved every FIPS 140-2 certificate to its historical list on September 22, 2026 (NIST CMVP). Before you buy four, test one stick in your oldest control, because some older USB ports won't read large or USB 3 drives.

When the builder asks for your TeamViewer ID

The service tech asks for a TeamViewer ID and password. Or the salesman who sold you a vision system says its Windows 7 PC is "paired to the machine" and nobody may touch it. Neither is a reason to leave a tunnel open.

Two requirements apply. You must monitor and control remote access sessions (3.1.12). And a second login factor is required for remote maintenance, with the connection closed when the work is done (3.7.5). Each is worth 5 points (DoD Assessment Methodology). An always-on TeamViewer install with a password taped to the control fails both, so you're down 10 points on one machine.

Here's what we'd tell the builder:

  1. Remote sessions go through one maintenance PC or gateway on the controller segment, never software installed on the control itself.
  2. Your quality or maintenance lead opens a session for one ticket, one machine, and a window of four hours or less. Someone at the shop watches the screen.
  3. The session needs a second factor. TeamViewer's "two-factor authentication for connections" sends a push to your phone that you must approve before anyone connects (TeamViewer). Any remote tool that makes you approve each session works the same way.
  4. When the tech hangs up, close the session and shut the gateway off. Keep the ticket number, the approval, and the start and end times.

Leave the "paired" inspection PC alone. It's test equipment, so it's a Specialized Asset: unplug it from everything except the machine and the one folder its reports go to. The legacy lab field note has the full write-up for a Windows 7 CMM PC, and it fits a vision system word for word.

Image every control before it dies

An MSP on r/msp asked how to back up a new client's 37 unnetworked CNC machines. The answer that held up is the simplest: take a full disk image of each control PC as it runs today, with a free imaging tool like Clonezilla or whatever your MSP uses. Then write down everything the image can't carry. That means license dongles and what they're tied to (network card, CPU or drive), special interface boards and their drivers, install order, and the builder's phone number.

Two rules make the images count. First, the image holds whatever programs were on the control, so store it encrypted and treat it as CUI. A cloud backup of that image has to meet FedRAMP Moderate or equivalent (what that means). Second, re-image after every builder visit, because that's when the software changes. Label each image with the control, date and ticket number, and restore your most important machine's image to spare hardware once a year.

The SSP paragraph

This is the entry for one control. Write one per machine, and make every sentence something an assessor can walk over and check.

LATHE-03: Specialized Asset (operational technology). 2012 horizontal lathe; builder-supplied control on Windows 7 Embedded, not upgradable without replacing the control; no endpoint agent supported. Enduring Exception: patching and malware protection are not feasible on the builder's image. Connected only to the controller segment (VLAN 40); no internet route; no Wi-Fi. Programs arrive from TRANSFER-01 only, over SMB on a single read-only share; SMBv1 enabled on TRANSFER-01 only. FIPS mode not used on this link; CUI in transit is protected by the physically controlled shop floor (3.13.8). USB port used only with numbered encrypted sticks USB-01 and USB-02, kept in the cell cabinet. Builder remote support through MAINT-GW only, opened per ticket by the maintenance lead, second factor required, closed at end of session. Disk image taken 2026-08-14 after ticket 4471, stored encrypted; restore tested annually. Owner: maintenance lead.

Fill in your own asset names and dates, then walk the floor with the paragraph in hand. If the Wi-Fi card is still in the control, or a third USB stick lives in the setup drawer, fix the machine rather than the paragraph.

Mock assessment

Every control, one scope.

Garde1 records each machine as a Specialized Asset, draws it into the network topology and boundary diagram in your SSP, and scores the transfer PC and DNC server against all 110 requirements in a mock assessment.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE