Defense Machining Audit Prep Guide for NADCAP & AS9100

How to Prepare for a Defense Machining Audit in 48 Hours

Last updated: July 8, 2026

Key Takeaways

  • Traceability breaks, missing calibration records and incomplete special-process documentation trigger most audit findings in defense machining operations.
  • A structured 48-hour internal simulation that mirrors AS9100D, ITAR and CMMC Level 2 audit flows exposes gaps before an external audit.
  • Core preparation steps include certification baseline verification, material traceability mapping, calibration review, special-process validation and FAI/document-control audits.
  • Operator floor-walk preparation and a final 48-hour readiness checklist help teams demonstrate compliance and respond confidently to auditor questions.
  • Precision Advanced Manufacturing operates under AS9100D, ISO 9001:2015 and ITAR-registered quality systems, request a quote to discuss program requirements.

Why Defense Machining Audits Fail

Most defense machining audit failures trace back to three systemic gaps, not isolated mistakes.

The first gap is traceability failure. Traceability is the documented ability to track a component’s material origin, processing history and inspection results through every production step. When that chain breaks, auditors cannot confirm conformance.

The second gap is calibration control failure. Calibration control is the documented process that verifies measurement and production equipment performance stays within defined tolerances. Expired or unrecorded calibration events invalidate inspection data.

The third gap is special-process documentation failure. Special processes such as heat treating, plating and welding produce results that final inspection cannot fully verify. Missing process certifications or unapproved supplier records create immediate nonconformances.

Each of these three gaps becomes more severe when evaluated under multiple regulatory frameworks at the same time. A single documentation failure can trigger findings across AS9100D process control, ITAR record retention and CMMC access requirements.

AS9100D is the aerospace quality management standard that governs process control, product realization and continual improvement for aviation, space and defense suppliers. ITAR, the International Traffic in Arms Regulations, controls the export and handling of defense articles and technical data listed on the U.S. Munitions List (USML), requiring strict access controls and a minimum five-year record retention period after the final transaction. CMMC, the Cybersecurity Maturity Model Certification, governs protection of Controlled Unclassified Information (CUI) across the defense industrial base. The CMMC 2.0 final rule went into effect December 16, 2024, with Level 2 self-assessment requirements active as of November 10, 2025 and mandatory third-party C3PAO assessments beginning November 10, 2026.

Step 1: Confirm Certification Baseline and Scope

This step establishes the baseline that anchors every other audit preparation activity.

Actions: Pull current AS9100D, ISO 9001:2015 and ITAR registration certificates. Confirm expiration dates and scope statements match active contract requirements. This verification sets the reference point for the remaining steps.

Inputs: To complete this verification, gather certificate files, registration body contact records and current contract quality clauses.

Outputs: The result is a signed certification status log with expiration dates and responsible owners that serves as the reference document for the audit team.

Decision point: If any certificate is within 90 days of expiration or the scope excludes a required process, escalate to quality management before proceeding.

Cross-functional sign-off: Quality manager and contracts or compliance lead.

Step 2: Map the Material Traceability Chain

This step confirms that material history remains visible from mill certificate through shipment.

Actions: Select five active work orders. For each, trace material from the mill certificate through receiving inspection, in-process routing and final inspection records. Confirm heat or lot numbers appear on every document in the chain.

Inputs: Mill certifications, purchase orders, receiving inspection records, travelers and final inspection reports.

Outputs: A traceability map for each work order that shows every document link and any gaps.

Decision point: Any broken link, such as a missing heat number, an unsigned traveler step or an unmatched lot, requires a corrective action record before the audit.

Cross-functional sign-off: Quality engineer and production supervisor.

ITAR requires organizations to clearly label and track all controlled articles to prevent unauthorized access and support traceability. Confirm material records meet the ITAR retention requirement established earlier.

Step 3: Review Calibration and Equipment Control

This step protects the integrity of all measurement data presented during the audit.

Actions: Pull the calibration master list. Verify every measurement device used on active defense work orders carries a current calibration sticker and a corresponding calibration record. Check that out-of-tolerance events are documented with impact assessments on previously inspected parts.

Inputs: Calibration master list, individual calibration records, equipment ID tags and out-of-tolerance logs.

Outputs: A calibration status report that flags any overdue, missing or undocumented items.

Decision point: Any device used on defense work without a current calibration record requires immediate quarantine of affected parts and a documented impact assessment.

Cross-functional sign-off: Metrology or calibration technician and quality manager.

Step 4: Validate Special Processes and the Approved Supplier List

This step confirms that every special process and supplier meets contract and specification requirements.

Actions: Identify all special processes performed on active defense work orders. Confirm each process supplier appears on the Approved Supplier List (ASL) with a current approval status. Collect process certifications and verify they reference the correct specification revision.

Inputs: ASL, special-process purchase orders, process certifications and applicable specifications such as AMS or MIL-SPEC.

Outputs: A special-process compliance matrix that lists each process, supplier, approval status and certification currency.

Decision point: Any process performed by a supplier not on the ASL, or with an expired approval, constitutes a nonconformance that requires disposition before shipment.

Cross-functional sign-off: Supplier quality engineer and quality manager.

Vignette: A machining supplier preparing for a Tier 1 defense contractor audit discovered during a mock floor walk that a plating vendor had been removed from the ASL six months earlier after a process audit finding. Three active work orders had already been processed through that vendor. The supplier quality team initiated a material review board, obtained a customer deviation and re-sourced the plating to an approved vendor before the actual audit. The finding was documented as a corrective action rather than an open nonconformance, which preserved the supplier’s audit outcome. This scenario shows why pre-vetted special-process suppliers form a critical risk mitigation strategy that established ASL programs provide from program launch.

Request a quote from Precision Advanced Manufacturing to discuss special-process supplier qualification for defense programs.

Step 5: Audit FAI Packages and Document Control

This step verifies that first article and drawing controls match current engineering and contract requirements.

A First Article Inspection (FAI) is a formal, documented verification that a production process produces a part that conforms to all engineering and drawing requirements. FAI records rank among the first documents auditors request for defense programs.

Actions: Confirm a complete AS9102 FAI package exists for every active part number. Verify the FAI references the current drawing revision. Check that design changes since the original FAI triggered a partial or full re-FAI per contract requirements.

Inputs: FAI packages, drawing revision logs, engineering change orders and contract quality requirements.

Outputs: An FAI status register that shows part number, drawing revision, FAI date and re-FAI trigger status.

Decision point: Any part number in active production without a complete, revision-current FAI package requires immediate escalation to the program manager and customer notification.

Cross-functional sign-off: Quality engineer, engineering and program manager.

Step 6: Prepare Operators for Floor Walks

This step builds operator confidence and consistency during direct auditor interactions.

Actions: Brief all operators on active defense work orders. Review likely auditor questions and confirm operators can locate travelers, inspection records and calibration tags for their equipment without assistance.

Inputs: Active travelers, inspection records, calibration tags and operator training records.

Outputs: A floor-walk readiness sign-off sheet that confirms each operator’s awareness of documentation responsibilities.

Decision point: If an operator cannot locate a required document or explain a process step, assign a quality escort for that workstation during the actual audit.

Cross-functional sign-off: Production supervisor and quality engineer.

Sample operator Q&A for floor-walk preparation:

  • Q: Where is the traveler for the part currently in the machine? A: The operator retrieves the traveler immediately and points to the current operation step.
  • Q: How is calibration status confirmed for inspection equipment? A: The operator points to the calibration sticker and confirms the expiration date has not passed.
  • Q: What happens when a nonconforming part is produced? A: The operator describes the nonconforming material process, tags the part, segregates it and notifies the quality team.
  • Q: Where is the material certification for the stock in use? A: The operator directs the auditor to the traveler packet or the designated material storage location where certifications are filed.
  • Q: Who can access CUI drawings for this program? A: The operator identifies the access control process and confirms that only authorized personnel handle controlled technical data.

CMMC Level 2 requires physical visitor logs and badges to prevent unauthorized access to CUI drawings on shop floors. Operators must understand and demonstrate these controls during a floor walk.

Step 7: Run the Final 48-Hour Readiness Checklist

This step consolidates all preparation work into a single, time-bound review.

Complete each item in sequence and assign an owner and completion timestamp for every line.

  1. Certification baseline verified and status log signed off.
  2. Material traceability maps completed for all active defense work orders.
  3. Calibration master list reviewed, all overdue items resolved or quarantined.
  4. Special-process compliance matrix completed, all ASL approvals current.
  5. FAI status register complete, all part numbers revision-current.
  6. Operator floor-walk briefings completed, readiness sign-off sheets filed.
  7. System Security Plan (SSP) reviewed and current, CUI access controls confirmed active.
  8. ITAR-controlled documents labeled and access logs current, records retained per the five-year minimum requirement.
  9. Open corrective actions reviewed, status documented and communicated to auditors proactively.
  10. Audit readiness briefing held with quality, production and program management leads.

Precision Advanced Manufacturing’s AS9100D and ITAR-compliant production systems support this level of audit readiness, request a quote to discuss program requirements.

CMMC-to-AS9100D Mapping for Audit Planning

This section links key CMMC Level 2 domains to related AS9100D clauses so audit teams can plan integrated evidence sets.

  • Access Control (AC): CMMC AC.L2-3.1.1 through AC.L2-3.1.22 map to AS9100D Clause 7.5.3 on control of documented information and Clause 7.1.4 on environment for operation of processes. Evidence includes controlled drawing access, visitor logs and workstation access rules.
  • Configuration Management (CM): CMMC CM.L2-3.4.1 through CM.L2-3.4.9 map to AS9100D Clause 8.5.6 on control of changes and Clause 7.5.3.2 on documented information control. Evidence includes engineering change orders, CNC program revision logs and FAI impact assessments.
  • System and Information Integrity (SI): CMMC SI.L2-3.14.1 through SI.L2-3.14.7 map to AS9100D Clause 8.5.1 on control of production and service provision. Evidence includes antivirus status on programming terminals, patch logs and monitoring of systems that handle CUI.

Troubleshooting: Five Common Audit Findings in Precision Machining Shops

  1. Broken material traceability chain. Root cause: heat or lot numbers not transcribed onto travelers at receiving. Mitigation: implement a receiving inspection hold step that requires traceability data entry before material release to the floor.
  2. Expired calibration records. Root cause: calibration due dates not linked to production scheduling. Mitigation: integrate calibration expiration alerts into the production planning process so equipment is pulled for calibration before assignment to a defense work order.
  3. Unapproved special-process suppliers. Root cause: ASL not reviewed when new subcontractors are added. Mitigation: require purchasing to verify ASL status before issuing any special-process purchase order.
  4. Incomplete or revision-mismatched FAI packages. Root cause: engineering changes processed without a re-FAI review. Mitigation: add an FAI impact assessment to the engineering change order workflow.
  5. Inadequate CUI access controls. Root cause: CUI drawings accessible on shared network drives without authentication. Mitigation: implement multi-factor authentication on all devices accessing CUI technical data, including quality tablets and CNC programming terminals.

Metrics That Signal Audit Readiness

Five operational metrics provide early warning of audit risk before an auditor arrives on the floor. Together, they form a diagnostic framework that covers process stability, quality control effectiveness and operational discipline, the three dimensions auditors evaluate during floor walks.

  • First-pass yield (FPY): The percentage of parts that pass inspection on the first attempt without rework. Declining FPY signals process instability that auditors will probe through corrective action records.
  • Nonconformance (NC) rate: The frequency of documented nonconforming material events per production period. This metric complements FPY by capturing issues that escape initial inspection. A rising NC rate without corresponding corrective actions is a direct audit finding under AS9100D Clause 10.2.
  • FAI acceptance rate: The percentage of first article inspections accepted without rejection or resubmission. Low acceptance rates indicate systemic issues in process control or drawing interpretation.
  • On-time delivery (OTD): The percentage of shipments delivered on or before the contractual due date. Auditors use OTD trends as a proxy for production control maturity.
  • Calibration compliance rate: The percentage of measurement devices with current, in-date calibration records at any given time. A rate below 100 percent creates an immediate finding in most defense audits.

Advanced Considerations for Digital and Model-Based Programs

Mature programs with established production baselines face a different audit challenge that centers on digital controls and model-based documentation.

Model-based definition readiness requires that 3D annotated models carry the same revision control, access restrictions and traceability linkages as traditional 2D drawings. Auditors verify that CNC programs derived from model-based datasets reference the correct model revision and that change history is documented.

CMMC Level 2 requires documentation of every human-made change to compliance configurations and every intentional policy change, including the rationale and impact. For mature programs, CNC program version control logs and digital traveler change histories function as audit artifacts, not just internal records.

Digital process control systems must also demonstrate continuous enforcement of security controls rather than point-in-time compliance. Auditors reviewing mature programs request logs that show ongoing monitoring, not only a current-state snapshot.

Frequently Asked Questions

How long does a full AS9100D surveillance audit typically take for a machining supplier?

Surveillance audit duration depends on the scope of the quality management system, the number of employees and the complexity of processes in scope. Most machining suppliers with a defined production scope undergo a one- to two-day surveillance audit. The 48-hour simulation in this guide matches that window so every major audit domain receives attention before the actual event.

What is the difference between a CMMC Level 2 self-assessment and a third-party C3PAO assessment?

A self-assessment allows the contractor to evaluate its own compliance against all 110 NIST SP 800-171 Revision 2 controls and submit results to the Supplier Performance Risk System. A third-party assessment requires a Certified Third-Party Assessment Organization to independently verify the same controls and issue a certification. Self-assessments became required for applicable contracts as of November 10, 2025. Third-party C3PAO assessments become mandatory for Level 2 CUI solicitations beginning November 10, 2026. Both require the same evidence artifacts, the difference lies in who reviews them.

What documents should be immediately accessible during an ITAR compliance review?

Auditors conducting an ITAR review request the company’s ITAR registration, a list of all USML-controlled articles and technical data in scope, access control records that show who is authorized to handle controlled data, export license records or license exemption justifications and records of any disclosures to foreign nationals. Records must be retained for a minimum of five years after the final transaction. Physical and digital access logs for CUI drawings and technical data are also standard requests during a defense floor walk.

How does a Plan of Action and Milestones affect a CMMC Level 2 audit outcome?

Under CMMC Level 2, Plans of Action and Milestones apply only to low-weight controls and must be closed within 180 days of conditional certification. Most controls require full implementation before certification. A Plan of Action and Milestones does not excuse a control gap during an audit, it documents a remediation commitment with a defined timeline. Auditors verify that open items remain on track and that no high-weight controls stay unimplemented. Machining suppliers benefit from resolving all critical control gaps before the audit rather than relying on Plan of Action and Milestones coverage.

When does an engineering change require a new First Article Inspection?

AS9102 and most defense contract quality requirements specify that a partial or full re-FAI is required when a drawing revision changes a dimension, tolerance, material or special process that the original FAI previously verified. The determination of whether a change triggers a re-FAI should be documented in the engineering change order workflow. Auditors request evidence that this determination occurred and that the appropriate FAI action followed. Undocumented change-to-FAI impact assessments appear as recurring findings in defense machining audits.

Conclusion

A structured 48-hour internal simulation addresses the three root causes of defense machining audit failures, traceability chain breaks, calibration control gaps and incomplete special-process documentation. The seven-step process in this guide mirrors the actual audit flow for AS9100D, ITAR and CMMC Level 2 requirements, giving supplier quality engineers and program managers a repeatable framework for audit readiness. Precision Advanced Manufacturing operates under AS9100D, ISO 9001:2015 and ITAR-registered quality systems, with full material traceability and documentation built into every production program.

Defense programs benefit from machining partners whose compliance infrastructure already operates at audit-ready levels, request a quote from Precision Advanced Manufacturing to discuss program requirements and audit readiness support.