With the rapid development of cloud manufacturing technology and the new generation of artificial intelligence technology, the new cloud manufacturing system (NCMS) built on the connotation of cloud manufacturing 3.0 presents a new business model of “Internet of everything, intelligent leading, data driving, shared services, cross-border integration, and universal innovation”. The network boundaries are becoming increasingly blurred, NCMS is facing security risks such as equipment unauthorized use, account theft, static and extensive access control policies, unauthorized access, supply chain attacks, sensitive data leaks, and industrial control vulnerability attacks. Traditional security architectures mainly use information security technology, which cannot meet the active security protection requirements of NCMS. In order to solve the above problems, this paper proposes an integrated cloud-edge-terminal security system architecture of NCMS. It adopts the zero trust concept and effectively integrates multiple security capabilities such as network, equipment, cloud computing environment, application, identity, and data. It adopts a new access control mode of “continuous verification + dynamic authorization”, classified access control mechanisms such as attribute-based access control, role-based access control, policy-based access control, and a new data security protection system based on blockchain, achieving “trustworthy subject identity, controllable access behavior, and effective protection of subject and object resources”. This architecture provides an active security protection method for NCMS in the digital transformation of large enterprises, and can effectively enhance network security protection capabilities and cope with increasingly severe network security situations.