← Back to Blog

Manufacturing Trade Secrets and PQC

Manufacturing Trade Secrets and PQC - QNSQY post-quantum encryption guide

Manufacturing companies live and die by their trade secrets. The CAD models, process specifications, supplier relationships, tooling designs, and quality control data are often more valuable than the patents that surround them. When that company is part of the Defense Industrial Base (DIB), or supplies any controlled unclassified information to the federal government, the cryptographic protections become legally enforceable through NIST SP 800-171 and SP 800-172. The Department of Defense's Cybersecurity Maturity Model Certification (CMMC) program turned those publications into contractual requirements with audit consequences. Quantum computers will eventually break the RSA and ECDSA cryptography that those programs assumed when they were written. Manufacturing companies need to plan now.

This article walks through the controlled unclassified information (CUI) regime, the NIST SP 800-171 and 800-172 control families, the special handling required for CUI//SP-CUI categories, and how to build a post-quantum migration program that fits inside the DIB compliance reality.

Why Manufacturing IP Carries Long Cryptographic Sensitivity

Manufacturing trade secrets do not expire. Coca-Cola has protected its formula for over a century. Lockheed Martin's metallurgy for the SR-71 Blackbird remained classified for decades. The ceramic coating recipes used by jet engine manufacturers, the cell chemistry specifications for advanced batteries, the photolithography process windows for leading-edge semiconductor fabs, all of these are commercially decisive and commercially sensitive across the working life of the technology. That working life can be twenty, thirty, or fifty years.

The cryptographic problem is straightforward. If a CAD file is encrypted today with RSA-2048 protected key wrapping, and an adversary captures the encrypted bytes off the wire, that adversary can store them indefinitely. When a cryptographically relevant quantum computer (CRQC) eventually exists, the adversary decrypts the bytes. The CAD model from 2026 is still commercially valuable in 2046 if it describes a turbine blade, a semiconductor process, a material formulation, or a defense system. This is the harvest now, decrypt later threat as applied to the Defense Industrial Base, and it is exactly the threat NIST IR 8547 calls out.

For broader background see What Is Post-Quantum Cryptography and Harvest Now, Decrypt Later.

NIST SP 800-171 and the CUI Regime

NIST SP 800-171 specifies the security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems. The publication defines fourteen control families, including access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, physical protection, personnel security, risk assessment, security assessment, system and communications protection, and system and information integrity. Cryptographic controls live primarily in the system and communications protection family, with related controls in identification and authentication and media protection.

The cryptographic requirements call out FIPS-validated cryptography. Today that means FIPS 140-3 validated modules implementing AES, SHA-2, RSA, ECDSA, and the related primitives. NIST FIPS 203, 204, and 205 are now part of the FIPS-validated portfolio, and the Cryptographic Module Validation Program (CMVP) has been updating its testing and validation infrastructure to include the new algorithms. Manufacturers should be planning their cryptographic refresh around CMVP-validated modules that include ML-KEM and ML-DSA.

NIST SP 800-172 and Higher-Sensitivity CUI

SP 800-172 adds enhanced security requirements for CUI that supports a critical federal program or high-value asset. The control set in SP 800-172 includes more aggressive access control, dual authorization for sensitive operations, and stronger cryptographic protections. SP 800-172 explicitly calls for cryptographic agility and the ability to migrate algorithms in response to advances in cryptanalysis. Quantum is precisely the case the publication anticipates.

Manufacturers handling SP 800-172 data should already be planning hybrid post-quantum deployments. The risk profile of SP 800-172 data is high enough that the harvest-now-decrypt-later concern is not theoretical. Adversaries actively target high-value programs and they have the patience to wait for decryption capability to arrive. Hybrid encryption combining a classical algorithm with ML-KEM is the appropriate cryptographic posture today. See Hybrid Encryption for construction details.

CMMC and the Audit Reality

The Cybersecurity Maturity Model Certification program turned the NIST 800-171 controls into contractual requirements. CMMC Level 2 maps to the SP 800-171 control set and requires third-party assessment for many DIB contracts. CMMC Level 3 incorporates a subset of SP 800-172 controls and requires government assessment. The DoD has been clear that CMMC is the gating mechanism for new contracts.

CMMC assessments today do not specifically test for post-quantum cryptography, but the underlying control 3.13.11 (Cryptographic Protection) requires FIPS-validated cryptography, and the FIPS validation portfolio is expanding to include PQC. Forward-looking DIB contractors are getting in front of this curve. Cryptographic agility is one of the assessment criteria that distinguishes a mature security program from a checklist-compliant one.

For broader regulatory context see PQC for Government and Defense and the NIST FIPS Guide.

Where Cryptography Lives in Manufacturing

Manufacturing IT and OT environments are heterogeneous. Engineering workstations run CAD tools (Siemens NX, PTC Creo, Dassault CATIA, SolidWorks) that integrate with PLM systems (Teamcenter, Windchill, Enovia). Manufacturing execution systems (MES) like Rockwell FactoryTalk, Siemens Opcenter, and AVEVA System Platform connect to programmable logic controllers, distributed control systems, and SCADA. Quality systems (LIMS, SPC platforms) feed back into product development. ERP systems hold supplier and customer data.

Each of these layers has its own cryptographic footprint. PLM systems sign and encrypt CAD files at rest. MES systems use TLS to talk to industrial protocols. SCADA gateways increasingly use TLS for OPC UA and similar protocols. ERP systems encrypt customer and supplier records. Identity providers issue certificates that all of these systems trust.

A complete cryptographic inventory of a manufacturing enterprise will surface hundreds or thousands of cryptographic touchpoints, many of them embedded in third-party software where the enterprise has limited visibility. The inventory is the first phase of any PQC migration.

Defense Industrial Base Specific Concerns

DIB contractors face a specific concentration of risk. Adversary intelligence services have publicly attempted to exfiltrate IP from the DIB for at least two decades. The 2009 Lockheed Martin F-35 intrusion, the 2018 Navy contractor breach, and the 2023 Microsoft cloud intrusion that hit DoD email accounts all illustrate the pattern. Every successful exfiltration of encrypted data is a candidate for future quantum decryption.

DIB contractors should treat their cryptographic posture as a primary risk management concern, not a compliance afterthought. Cryptographic agility, hybrid post-quantum deployments at the perimeter and at high-value internal flows, and vendor coordination across the supply chain are the right practices. The DoD's Office of the Under Secretary for Acquisition and Sustainment has been increasingly vocal about supply chain cryptographic risk, and contract language is moving in that direction.

Supply Chain and the Cryptographic Inheritance Problem

A defense prime contracts with hundreds of subcontractors. Each subcontractor handles some portion of the CUI flow. If the prime is using PQC but a tier-three supplier is using TLS 1.2 with RSA-2048, the cryptographic posture of the entire supply chain is the weakest link. Adversaries know this. The 2020 SolarWinds compromise and the 2023 MOVEit Transfer compromise both targeted supply chain integration points.

The DIB ecosystem needs cryptographic alignment from prime through tier-three. The DoD's CMMC program is beginning to push this, but the alignment around PQC specifically is still in early stages. Primes should be including PQC migration commitments in subcontractor flowdowns now, and subcontractors should be providing CBOMs that document their cryptographic state.

Building the Migration Program

A practical migration program for a manufacturing enterprise has familiar phases. Phase one is inventory: a complete CBOM covering CAD systems, PLM, MES, ERP, identity, network perimeters, customer portals, vendor portals, and OT/SCADA. Phase two is risk classification: which CUI categories does each system handle, and what is the cryptographic sensitivity window? Phase three is pilot: typically a perimeter TLS upgrade combined with a high-value internal flow such as engineering data exchange with a key partner. Phase four is scale: enterprise-wide migration of TLS, signing keys, HSM platforms, and document encryption.

The OT/SCADA layer deserves special attention. Industrial control systems have long lifecycles, often twenty years or more, and many cannot be retrofitted with new cryptography. The migration plan needs to account for systems that will need replacement or air-gap-style isolation rather than algorithmic upgrade. NIST SP 800-82 (Guide to Industrial Control Systems Security) provides the relevant guidance.

The intersection between IT and OT cryptography is where many real-world manufacturing breaches happen. The 2017 NotPetya outbreak that hit Maersk, Merck, and FedEx propagated through Windows authentication and lateral movement, then encrypted both IT systems and the industrial systems that depended on Windows endpoints for operator interfaces. PQC migration programs that address only the IT side miss the OT exposure that ultimately matters for production continuity. A complete migration plan tracks every cryptographic dependency that crosses the IT-OT boundary, including Active Directory domain controllers that authenticate engineering workstations into MES systems, file shares that hold CAD models referenced by manufacturing equipment, and the firewall and DMZ infrastructure that enforces network segmentation.

Export Control and ITAR Considerations

Manufacturers in the defense industrial base also have to manage export controls. The International Traffic in Arms Regulations (ITAR) under the U.S. Department of State and the Export Administration Regulations (EAR) under the Department of Commerce restrict the export of certain technologies and technical data. Cryptographic protection of ITAR-controlled or EAR-controlled data is a compliance requirement, and the cryptography itself must be NIST-validated and used in a manner consistent with the relevant export licenses.

For PQC, the export control question is whether post-quantum algorithms are themselves export-controlled and whether they meet the cryptographic protection requirements for controlled technical data. NIST FIPS-validated PQC modules will satisfy the cryptographic requirements. Manufacturers exporting cryptographic technology need to track Export Control Classification Number (ECCN) updates as PQC products move through the export licensing review.

For sector context across critical infrastructure see PQC for Critical Infrastructure Grid.

Frequently Asked Questions

Does CMMC require post-quantum cryptography?

Not specifically as of 2026. CMMC Level 2 requires FIPS-validated cryptography per NIST SP 800-171 control 3.13.11. As FIPS-validated PQC modules become more common, the assessment expectations will likely follow. Forward-looking DIB contractors are not waiting.

What is the cryptographic sensitivity window for manufacturing IP?

For trade secrets the window is effectively indefinite. For patented technologies it runs at least the patent life of twenty years. For DIB programs it can extend the operational life of the system, which for major weapons platforms is decades.

How do I handle CUI in CAD files specifically?

PLM systems should be configured to encrypt CAD files at rest with FIPS-validated cryptography and to enforce access controls based on CUI marking. The PLM vendor's PQC roadmap should be part of the procurement discussion. CAD file exchange with partners should be over TLS 1.3 with hybrid post-quantum where supported.

What about industrial control systems that cannot be upgraded?

SP 800-82 recommends defense in depth, network segmentation, and compensating controls when cryptographic upgrades are not feasible. Long-lived ICS may need to be isolated behind PQC-capable gateways rather than upgraded directly.

Is there a federal mandate for PQC migration in the DIB?

Not yet a single comprehensive mandate, but the threads are pulling together. NIST IR 8547 sets the deprecation timeline for classical algorithms. CISA's quantum readiness guidance applies across critical infrastructure including the DIB. The DoD CIO has signaled that PQC migration will become a formal requirement for federal systems and the contractors that support them.

Sources

  • NIST. "SP 800-171 Rev 3: Protecting Controlled Unclassified Information in Nonfederal Systems." nist.gov.
  • NIST. "SP 800-172: Enhanced Security Requirements for Protecting Controlled Unclassified Information." nist.gov.
  • NIST. "FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism." nist.gov.
  • NIST. "NIST IR 8547: Transition to Post-Quantum Cryptography Standards." nist.gov.
  • DoD. "Cybersecurity Maturity Model Certification (CMMC) Program." defense.gov.
  • NIST. "SP 800-82 Rev 3: Guide to Operational Technology (OT) Security." nist.gov.
  • CISA, NIST, NSA. "Quantum-Readiness: Migration to Post-Quantum Cryptography." cisa.gov.

Related Articles

Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

Try QNSQY