Merit3D

AS9100 REV D · ISO 9001:2015 · ITAR REGISTERED · MADE IN PRICE, UTAH 833-341-2335  ·  SALESSUPPORT@MERIT3D.COM

Certification Has Become the Floor for Defense AM. Here’s What That Looks Like.

Meltio rolled out a slate of U.S. defense partnerships in June — Force Automation, Snowbird Technologies, Phillips Corporation, Fastech — built explicitly around ITAR registration and cybersecurity compliance as the shared foundation. The framing in the announcement was telling. The partners weren’t being selected purely for their AM expertise. They were being selected because they already had the certification stack to operate inside the U.S. defense supply chain.

That’s the shift. The certifications used to be how an additive shop differentiated itself from prototyping competitors. In 2026 they’re the floor everybody has to clear before the conversation starts.

The stack, in plain language

“Certified for defense” isn’t one credential. It’s an interlocking set, each addressing a different lane of the supply chain.

AS9100D is the aerospace and defense quality management system standard — built on ISO 9001 but with additional rigor on risk management, configuration control, counterfeit-parts prevention, and product safety. Primes like Boeing, Lockheed Martin, Northrop Grumman, and RTX require AS9100 from any supplier touching production aircraft or defense parts.

ITAR registration is the State Department requirement for any U.S. entity that manufactures, exports, or brokers items on the U.S. Munitions List. Registration itself is annual and not particularly hard, but the operational compliance — controlling who can see what data, where the data lives, who runs the machines — is where shops get bogged down.

NIST SP 800-171 and CMMC are the cybersecurity layer. NIST 800-171 sets the 110 controls a contractor needs to handle Controlled Unclassified Information. CMMC, the Cybersecurity Maturity Model Certification, is the DoD’s assessment framework that verifies a contractor actually meets them — Level 2 for most non-classified defense work. Compliance affects how networks are segmented, how email is configured, who has administrative rights to which servers, and how data flows between the CAD seat and the print queue.

DFARS 252.204-7012 is the contract clause that makes 800-171 and CMMC binding on anything DoD-funded.

That’s the floor. None of it has anything to do with how well a shop prints.

Why the floor moved

Two pressures pushed the certification floor up. The first is DoD’s supply-chain security agenda, which intensified after a string of cybersecurity incidents and which DoD has been steadily formalizing through CMMC rollout and updated DFARS clauses. The second is the maturation of AM itself. When additive was a prototyping novelty, certified shops were rare and valuable. Now that AM is supplying production parts to actual fleets — the C-17 microvane rollout, Norsk Titanium on Airbus and Boeing, Beehive Industries scaling drone-engine production against a $29.7 million Air Force contract — the certification stack has to be there as a baseline. Procurement officers aren’t excited to find a certified AM shop. They expect it.

The Meltio partnerships are the explicit version of this shift. Meltio could have selected partners on AM capability alone. The announcement instead names ITAR and cybersecurity compliance frameworks as the actual selection criteria. Capability is assumed; compliance is the filter.

The trap shops walk into

The reflexive answer for an AM shop chasing defense work is, “We’ll certify when we win the work.” That used to be plausible — primes would sometimes carry a promising vendor through certification as part of a development program. It’s not plausible anymore.

AS9100 typically takes twelve to eighteen months from a standing start, assuming the shop already runs a quality management system disciplined enough to be auditable. CMMC Level 2 assessment runs in parallel and can take six months on its own, plus the months of remediation before the assessment is even winnable. ITAR registration is fast administratively, but the operational compliance — restricting data access, training staff, locking down the network — takes longer than people expect and never quite gets to done.

A shop that starts certifying after winning a defense award is going to ship the first parts before its quality management system is auditable. That’s how customers get burned, and it’s how the procurement office stops returning calls.

What this looks like from our end

Merit3D is AS9100D-certified and ITAR-registered, and our cybersecurity posture is grinding toward NIST SP 800-171 / CMMC-aligned controls. We made that investment ahead of needing it. It was expensive in time, in process discipline, and in the kind of small-business overhead that doesn’t look like manufacturing work until you need it to be there. We made it anyway because the shape of the AM industry was already telling us where the floor was moving.

The Meltio announcement, read carefully, says the same thing to anyone else paying attention. The AM shops that get to participate in defense supply chains in the next five years are the ones whose certifications are already standing.

The good news in this for Merit3D’s customers is that the floor we’ve already built is the floor they need their AM vendor on. The harder news for the broader industry is that the gap between “we could do that work” and “we are eligible to do that work” widened this year, and it’s not narrowing back.


Ready to see what your part would cost? Upload a CAD file for an instant estimate, see what we run on our capabilities and materials pages, or talk to a real person about your project.

Leave a Comment

Your email address will not be published. Required fields are marked *