Key Takeaways
-
A structured seven-step vetting process covering ITAR, AS9100D, cybersecurity, capacity, traceability, audits and scorecard scoring creates a repeatable qualification framework.
-
Each step includes clear verification actions and red flag indicators that help procurement and quality teams screen out high-risk suppliers.
-
Context on ITAR obligations, ASL processes and CMMC levels clarifies regulatory expectations across the defense supply chain.
-
Defense programs move faster when suppliers maintain current certifications, complete traceability records and documented audit-ready systems.
-
Precision Advanced Manufacturing already satisfies every checkpoint in the vetting process, and the team can begin qualification with defense primes immediately.
Defense Machine Shop Certification Requirements Checklist
This checklist defines the baseline certifications and controls that every defense-approved machine shop must maintain before program award.
-
ITAR registration with the Directorate of Defense Trade Controls (DDTC)
-
AS9100D certification from an IAQG-accredited registrar (verifiable in OASIS)
-
ISO 9001:2015 registration as a quality management baseline
-
Active CAGE code registered in SAM.gov
-
CMMC Level 2 compliance or documented NIST SP 800-171 self-assessment for shops handling Controlled Unclassified Information (CUI)
-
Full material traceability documentation including mill certifications and certificates of conformance
-
Documented first article inspection (FAI) process aligned to AS9102
The checklist above establishes the baseline certifications that every defense-approved machine shop must hold. The following seven steps provide a structured process for verifying each requirement before program approval.
Step 1: Verify ITAR Registration to Eliminate Export-Control Program Delay Risk
-
Confirm active ITAR registration directly through the DDTC registrant database.
-
Request the ITAR registration number and cross-reference it against current program export-control requirements.
-
Confirm documented ITAR compliance procedures covering employee training, access controls and recordkeeping.
-
Verify that the ITAR scope covers the specific defense articles or technical data relevant to the program.
-
Confirm a designated Empowered Official holds responsibility for ITAR compliance decisions.
Red flag: A shop that cannot produce its ITAR registration number or lacks a documented compliance program presents immediate export-control risk and should be disqualified.
ITAR registration confirms export-control eligibility. AS9100D certification confirms the quality management system that governs every production step.
Step 2: Confirm AS9100D Certification to Prevent Traceability Failure
-
Verify the AS9100D certificate in the IAQG OASIS database to confirm current registration status and scope.
-
Review the certificate scope statement to confirm coverage of the processes and product categories required by the program.
-
Request the most recent surveillance or recertification audit report and review any open nonconformances.
-
Confirm the quality management system includes documented control of nonconforming product, corrective action and preventive action processes.
-
Verify that first article inspection records, in-process inspection checkpoints and final inspection documentation are maintained and retrievable.
Red flag: An expired certificate, a scope that excludes required processes or open major nonconformances from the most recent audit indicate systemic quality risk.
A current AS9100D certification establishes quality system confidence. The next step evaluates whether the cybersecurity posture protects the program data handled by the shop.
Step 3: Assess CMMC Compliance and Cybersecurity Controls
-
Determine whether the program involves CUI and identify the applicable CMMC level required by the prime flow-down requirements.
-
Request the most recent NIST SP 800-171 self-assessment score and associated System Security Plan.
-
Confirm a documented Plan of Action and Milestones exists for any unresolved security practices.
-
Verify that the IT environment segregates CUI from general business data and that access controls are documented.
-
Confirm awareness of the obligation to report cybersecurity incidents to the Department of Defense within the required timeframe.
Red flag: A shop with no documented NIST 800-171 assessment, no System Security Plan or no awareness of CMMC flow-down obligations represents a program security liability.
Cybersecurity controls protect program data. Production capacity and quality documentation determine whether the shop can execute the program at scale.
Step 4: Evaluate Scalable Production Capacity and Quality Documentation
-
Request a facility overview that documents available equipment, multi-axis CNC capabilities and production shift capacity. This baseline inventory shows whether the shop has the physical resources to support the program.
-
Confirm demonstrated experience transitioning programs from prototype to full-rate production without quality degradation. Past performance on similar transitions indicates whether quality holds as volume increases.
-
Review scheduling and capacity management processes to assess the ability to absorb production ramps without disrupting existing programs. Strong planning systems prevent bottlenecks when demand spikes.
-
Verify that quality documentation, including inspection reports, material certifications and certificates of conformance, is generated and retained for every production run. Consistent records support audits and field investigations.
-
Confirm engineering support capabilities, including in-house CNC programming and design for manufacturability review. These capabilities help stabilize launches and reduce change cycles.
Red flag: A shop that cannot demonstrate a documented prototype-to-production transition process or that relies on external subcontractors for core machining operations introduces supply chain fragmentation risk.
Capacity and documentation confirm execution capability. Material and process traceability systems confirm that every component produced can be traced back to its source.
Step 5: Review Material and Process Traceability Systems
-
Confirm a documented material control procedure links each production lot to its mill certification and certificate of conformance.
-
Verify that traveler documents or equivalent records capture every process step, inspection result and operator identification for each part.
-
Confirm that the traceability system supports full forward and backward traceability from raw material receipt through final shipment.
-
Review how the shop manages and documents approved special processes such as heat treatment, anodizing, passivation or plating performed by external processors.
-
Confirm that traceability records are retained for the period required by the applicable contract or regulatory requirement.
Red flag: A shop that cannot demonstrate lot-level material traceability or that lacks documented control of special processes performed off-site creates compliance gaps that can invalidate program deliverables.
Traceability systems confirm documentation integrity. An on-site or virtual audit confirms that documented procedures reflect actual shop-floor practice.
Step 6: Conduct On-Site or Virtual Audit Readiness Assessment
-
Schedule a facility audit, on-site or virtual, and use the certification requirements checklist as the audit agenda.
-
Observe the shop floor for evidence of 5S or equivalent workplace organization, which reflects process discipline and reduces contamination risk for precision components.
-
Interview the quality manager and production supervisor to assess familiarity with AS9100D requirements, ITAR obligations and customer flow-down clauses.
-
Request a live demonstration of the nonconforming material control process, including how suspect parts are identified, segregated and dispositioned.
-
Review a sample of completed traveler packages to verify that documentation matches the stated procedures.
Red flag: A shop that resists an audit, cannot produce documentation on request or shows significant gaps between documented procedures and observed shop-floor practice should not advance in the qualification process.
The audit assessment generates the evidence needed to complete the final step, which scores the supplier against a standardized qualification scorecard.
Step 7: Score the Supplier Using the Qualification Scorecard
The qualification scorecard converts the evidence from the first six steps into a clear sourcing recommendation. Each criterion below aligns with a specific checkpoint in the vetting process.
Apply the following criteria to generate a qualification score. Rate each as Meets Requirement, Conditional or Does Not Meet Requirement before a sourcing decision.
-
ITAR registration: active, verified and scoped to program requirements
-
AS9100D certification: current, OASIS-verified and scoped to applicable processes
-
CMMC or NIST 800-171 compliance: documented assessment, System Security Plan and Plan of Action and Milestones in place
-
CAGE code: active and registered in SAM.gov
-
Material traceability: full lot-level traceability from raw material to shipment
-
Production capacity: demonstrated ability to scale from prototype to full-rate production
-
Quality documentation: complete inspection records, first article inspection capability and certificate of conformance process
-
Audit readiness: no major open nonconformances and procedures that match observed practice
-
Special process control: documented approved processor list and traceability for off-site processes
-
Engineering support: in-house programming, design for manufacturability capability and technical responsiveness
A supplier that scores Meets Requirement across all ten criteria satisfies the compliance baseline for defense prime approval and is ready for contract flow-down review.
Definition of an ITAR Machine Shop
An ITAR machine shop is a manufacturing facility registered with the U.S. State Department Directorate of Defense Trade Controls under the International Traffic in Arms Regulations. Registration authorizes the shop to manufacture, handle or process defense articles and technical data controlled under the U.S. Munitions List. ITAR registration is a legal prerequisite, not a voluntary credential, for any shop that machines components for defense programs involving U.S. Munitions List controlled hardware or data.
Clear assignment of ITAR registration obligations clarifies which organizations in the supply chain must maintain active registration.
ITAR Registration Responsibilities in the Defense Supply Chain
Any U.S. person or company that manufactures, exports, temporarily imports, brokers or furnishes defense services related to U.S. Munitions List controlled articles must register with the Directorate of Defense Trade Controls. In the defense supply chain, this group includes prime contractors, subcontractors and machine shops that fabricate controlled components, even when those shops never export hardware directly. Registration requirements apply at the entity level, and each facility handling controlled articles or technical data must maintain its own active registration.
Defense primes use a structured supplier approval process to confirm that every tier of the supply chain meets these and other program requirements.
How Defense Primes Approve Machine Shop Suppliers
Defense primes typically approve suppliers through a formal Approved Supplier List process that combines documentation review, quality system verification and on-site or remote audit. The process evaluates ITAR registration, AS9100D or equivalent quality certification, CAGE code status, financial stability, production capacity and traceability systems. Program-specific approvals may add flow-down requirements covering special processes, first article inspection, statistical process control or cybersecurity controls. Suppliers that satisfy all flow-down requirements are added to the Approved Supplier List and remain subject to periodic surveillance audits to maintain approved status. The following profile shows how one supplier meets every requirement in this approval process.
Precision Advanced Manufacturing maintains the documentation and certifications required for this approval process.
Precision Advanced Manufacturing: A Supplier Aligned With Defense Prime Requirements
Precision Advanced Manufacturing is a U.S.-based ITAR-registered machine shop operating under AS9100D and ISO 9001:2015 certified quality management systems. Facilities in California and Texas support multi-axis CNC machining, precision sheet metal fabrication, specialty welding, integrated finishing and kitting under a single quality system.
The scalable production platform supports programs from initial prototype through sustained multi-shift full-rate production. Complete material traceability, documented inspection processes and full certificate of conformance packages are standard on every production order. Engineering support, including in-house CNC programming and design for manufacturability review, is available from the first quote through production completion.
Procurement teams, program managers and supplier quality engineers working through the seven-step qualification process will find that Precision Advanced Manufacturing satisfies every scorecard criterion before the first audit is scheduled.
Frequently Asked Questions
How long does the defense supplier qualification process typically take?
Qualification timelines vary by prime contractor and program complexity. A straightforward documentation review and remote audit can be completed in a matter of weeks. Programs requiring on-site audits, special process approvals or program-specific flow-down verification may take longer. Suppliers that maintain current AS9100D certification, active ITAR registration and complete quality documentation shorten qualification time because the core evidence package is already assembled.
What documentation should a machine shop provide during supplier qualification?
A qualified machine shop should provide ITAR registration confirmation, an AS9100D certificate with current OASIS verification, CAGE code, quality manual or quality management system overview, sample inspection records and certificates of conformance, material traceability examples, most recent external audit results and any CMMC or NIST 800-171 assessment documentation required by the program flow-down clauses.
Can a machine shop be qualified mid-program if the original supplier fails to meet requirements?
Mid-program supplier transitions are manageable when the replacement shop provides complete documentation, material traceability and engineering support to ensure continuity. A structured onboarding approach, beginning with pilot builds or validation runs, reduces transition risk. The replacement shop must demonstrate that its quality system and traceability records satisfy the prime Approved Supplier List requirements without disrupting program schedules.
What is the difference between CMMC Level 1 and Level 2 for machine shops?
CMMC Level 1 covers basic cyber hygiene practices and applies to suppliers that handle Federal Contract Information but not Controlled Unclassified Information. CMMC Level 2 requires implementation of all 110 security practices from NIST SP 800-171 and applies to suppliers that handle Controlled Unclassified Information. Most machine shops supporting defense programs with technical drawings, specifications or program data classified as Controlled Unclassified Information are subject to Level 2 requirements and must maintain a documented System Security Plan and assessment score.
Does AS9100D certification automatically satisfy defense prime quality requirements?
AS9100D certification establishes a recognized quality management system baseline that most defense primes require, but it does not automatically satisfy every program-specific flow-down requirement. Primes may impose additional requirements covering first article inspection procedures, statistical process control, approved special processor lists or customer-specific quality clauses. The AS9100D certification scope must also cover the processes and product categories relevant to the program to be considered applicable.
Conclusion: Use a Structured Process to Reduce Program Risk
The seven-step vetting process verifies ITAR registration, confirms AS9100D certification, assesses CMMC compliance, evaluates production capacity, reviews traceability systems, conducts an audit readiness assessment and scores against the qualification scorecard. This process gives procurement, program and supplier quality teams a repeatable framework for approving defense machine shop suppliers.
The seven-step process also highlights the value of suppliers that maintain current certifications, documented traceability systems and scalable capacity. These shops reduce qualification time, support smoother launches and lower program risk across the defense supply chain.
Start the qualification conversation with a supplier that already meets every defense prime checkpoint.