Nexeris

CMMC Flow-Down Requirements: What Subcontractors Need to Know Before Your Prime Asks

When a prime contractor holds a DoD contract that includes DFARS 252.204-7012 or a CMMC requirement, that obligation does not stay with the prime. It flows down, contractually, to every subcontractor that touches Controlled Unclassified Information (CUI). You do not wait for your prime to ask. By the time they do, you are already behind on your compliance timeline, and so are they.

This guide is written for program managers, IT directors, and compliance leads at Tier 2 and Tier 3 defense subcontractors who have received, or expect to receive, a CMMC compliance requirement from their prime. It covers the legal mechanism behind CMMC flow-down requirements for subcontractors, which level applies to your work, what documentation primes are requesting in 2026, and four concrete steps to take right now.

What Does “CMMC Flow-Down” Actually Mean?

Flow-down is the mechanism by which the federal government’s contractual requirements pass from a prime contractor to its subcontractors. For CMMC, the operative clause is DFARS 252.204-7012(m), which requires prime contractors to include the clause, verbatim, in all subcontracts where the subcontractor will process, store, or transmit CUI, or provide operationally critical support.

This is not a best-practice recommendation. It is a contract obligation. A prime that fails to flow down the clause is in breach of its prime contract. A subcontractor that receives the clause and does not comply is in breach of its subcontract. The downstream consequence is loss of subcontract eligibility, not just a compliance finding.

The CMMC program rule reinforces this obligation directly. Under 32 CFR § 170.23 (Application to Subcontractors), a prime must flow the correct CMMC level down to any subcontractor that will process, store, or transmit FCI or CUI, and DFARS 252.204-7021 requires the prime to confirm the subcontractor holds the appropriate CMMC status before subcontract award. The specific clauses and levels that apply to your work depend on your contract, so confirm them with your contracting officer or legal counsel. For more detail on the prime-level obligations under the incident-reporting clause, see our DFARS 252.204-7012 compliance guide.

Prime-to-Sub Flow-Down: Obligation Mapping
Prime Contract Clause Sub Obligation Triggered Consequence of Non-Compliance
DFARS 252.204-7012(m) Include clause in all CUI-touching subcontracts; meet NIST 800-171 Rev 2 requirements Subcontract termination for default; prime’s contract at risk
DFARS 252.204-7021 (CMMC clause) Hold a valid CMMC certificate at the required level at time of subcontract award Ineligibility for subcontract award; prime cannot execute CUI work
DD Form 254 (Contract Security Classification Specification) Implement classified/CUI handling requirements per the form’s exhibits Security violation; loss of facility clearance eligibility

Which CMMC Level Applies to Your Subcontract?

The CMMC level that applies to a subcontractor is determined by the type of information handled in the subcontract scope, not by the prime’s certification level. A prime certified at Level 2 can have subs operating at Level 1 if those subs only handle Federal Contract Information (FCI), not CUI.

  • CMMC Level 1 applies to subcontractors handling only FCI: information provided by or generated for the government under a contract and not intended for public release. Per 32 CFR § 170.14, Level 1 covers the 15 basic safeguarding requirements drawn from FAR 52.204-21, met through an annual self-assessment.
  • CMMC Level 2 applies to subcontractors that receive, generate, process, store, or transmit CUI. Per 32 CFR § 170.14(c)(3) and DoD Class Deviation 2024-O0013, Level 2 maps directly to all 110 security requirements in NIST SP 800-171 Rev 2 (not Rev 3, which has not yet been adopted for CMMC). Most contracts requiring Level 2 certification will require a valid CMMC certificate issued by a C3PAO; a subset of lower-priority programs may remain eligible for self-assessment under 32 CFR Part 170. Confirm the assessment path required by your specific solicitation.
  • CMMC Level 3 applies to a narrow set of programs involving CUI deemed critical to national security. Standard commercial subcontracts rarely trigger Level 3. If it applies to your work, you will know explicitly from your contracting officer.
CMMC Level Determination for Subcontractors
Information Type in Your Scope CMMC Level Required Assessment Type Assessment Cadence
FCI only (no CUI) Level 1 Annual self-assessment Annually; affirmed in SPRS
CUI (any category) Level 2 Third-party C3PAO assessment (most contracts) or self-assessment (select programs) Every 3 years (C3PAO); annually (self)
CUI critical to national security (specified by CO) Level 3 DCMA DIBCAC-led government assessment Every 3 years

One point that repeatedly catches subcontractors: receiving CUI incidentally, say a prime emails you a controlled drawing to answer a technical question, still triggers Level 2 obligations if that CUI lives anywhere in your environment. Scope is determined by where CUI goes, not by whether you requested it.

How Do You Know If You Handle CUI?

CUI is defined in the National Archives CUI Registry under 32 CFR Part 2002. It is not classified information. It is unclassified information the government has determined requires safeguarding. For defense contractors, common CUI categories include: export-controlled technical data (EAR/ITAR), controlled technical information (CTI), naval nuclear propulsion information, and procurement-sensitive data. See our guide on What Is CUI? A Defense Contractor’s Guide for a full breakdown by category.

The practical scoping exercise has three steps:

  1. Review your DD Form 254. The Contract Security Classification Specification attached to your subcontract will identify whether classified or controlled information is involved in the performance work statement. If there is a DD Form 254, assume CUI is in scope until you can confirm otherwise.
  2. Review the performance work statement and attachments. Look for language referencing technical data packages, controlled drawings, export licenses, or proprietary government information. Any of these signal CUI.
  3. Map where that data goes in your environment. Email, file shares, CAD workstations, cloud storage, VPN endpoints: wherever CUI lands or transits becomes part of your assessed environment.

The most common mis-scoping error is treating email as out of scope. If a prime sends CUI to a shared mailbox, that mailbox, and the mail server behind it, is part of your CUI boundary. An assessor will ask for it.

What Documentation Will Your Prime Request?

Across our subcontractor engagements, primes are consistently requesting three documents before awarding or renewing subcontracts that involve CUI: a System Security Plan, a current SPRS score, and, increasingly, a C3PAO assessment letter.

  • System Security Plan (SSP). The SSP documents how your organization implements each of the 110 NIST 800-171 Rev 2 requirements. It is not a form fill. It is a control-by-control narrative of how you actually operate: your technical configurations, policies, personnel procedures, and third-party dependencies. Primes use the SSP to evaluate whether your security posture is real or documented-only. A Free SSP Template is a starting point, but it requires substantive customization to reflect your actual environment.
  • SPRS Self-Assessment Score. The Supplier Performance Risk System score ranges from -203 to +110 per the DoD NIST SP 800-171 Assessment Methodology (version 1.2.1), with +110 representing full implementation of all 110 NIST 800-171 controls. Primes pull this score from the SPRS database as a pre-award check. An unsubmitted or deeply negative score is a subcontract eligibility red flag, not a compliance timeline issue.
  • Plan of Action and Milestones (POA&M). Any control not yet implemented must be documented in a POA&M with a remediation timeline. An open POA&M is not automatically disqualifying, but primes are reading them carefully. For example, a POA&M with dozens of open items and no realistic closure dates signals a program that is not progressing.
Prime Subcontractor Document Review: What Gets Scrutinized
Document What Primes Evaluate Red Flags That Stall Award
System Security Plan (SSP) Control coverage, specificity of implementation descriptions, evidence references Generic language, template-only responses, missing controls
SPRS Score Current score; trend if rescored; submission date Score not submitted; score below -100 with no remediation plan
POA&M Number of open items, remediation timelines, milestone completion rates Large number of open items with no progress; items open for >12 months without closure activity
C3PAO Assessment Letter Valid certification at correct level; assessment date within 3-year window Self-assessment only (when third-party is required by contract)

For help structuring your policy documentation before the SSP narrative, see the Free CMMC Policy Templates covering all 14 CMMC Level 2 policy domains.

What Is the November 2026 Deadline and Why Does It Matter for Subs?

Under the CMMC final rule (32 CFR Part 170, effective December 16, 2024), DoD is phasing CMMC requirements into solicitations on a rolling basis. Most Level 2 contracts will require a C3PAO assessment, and the timing of that requirement is now the critical planning variable. Phase 2 of the rollout begins November 10, 2026, when DoD intends to make Level 2 C3PAO certification a condition of award across the bulk of solicitations involving CUI. Per DoD CMMC program office announcements, implementation timelines are subject to revision, so verify current phase dates against those announcements before your proposal planning.

Primes are also moving the requirement earlier than the contract mandates. To protect their own award eligibility, they are asking key subcontractors to hold a valid CMMC certificate before the prime’s proposal submission date, not before the contract award date. That shifts a late-2026 compliance deadline into a Q1 to Q2 2026 requirement for many subs.

C3PAO scheduling activity suggests assessment queues are booking out further than most subcontractors expect. A subcontractor beginning readiness in mid-2026 is unlikely to complete a C3PAO assessment in time for a Q3 2026 prime proposal submission. Readiness-to-assessment cycles, covering gap assessment, remediation, SSP build, and C3PAO scheduling, have typically run six to twelve months, depending on the organization’s starting maturity.

For a structured timeline on what that preparation looks like, the CMMC Audit Preparation: A 90-Day Roadmap outlines the three phases primes and subs use to get to assessment-ready.

Four Steps Subcontractors Should Take Right Now

These steps are sequenced for a subcontractor that has not yet started a formal CMMC program. If you are already partway through, use this as a gap check.

  1. Confirm whether CUI flows into your work scope. Pull your DD Form 254 and the performance work statement from your current subcontract. If CUI is referenced, directly or in exhibits, CMMC Level 2 applies. If not, you are likely Level 1 and can proceed with a self-assessment.
  2. Define your CUI boundary. Identify every system, service, and personnel group that touches CUI. This includes cloud storage, endpoint devices, email platforms, collaboration tools, and any third-party services your team uses in performance of the contract. Document this as your System Boundary. It becomes the scope statement in your SSP.
  3. Complete a NIST 800-171 Rev 2 gap assessment and submit your SPRS score. Evaluate your implementation of all 110 controls. Score each as MET, NOT MET, or NOT APPLICABLE. Calculate your SPRS score using the DoD-prescribed formula and submit it in SPRS through PIEE (piee.eb.mil). An unsubmitted score is visible to primes; the absence of a score is itself a flag.
  4. Build your SSP and POA&M before your prime asks. Document your current implementation for each control in the SSP, and create POA&M entries with realistic remediation timelines for the gaps. Subcontractors consistently underestimate the SSP. Written well, it is a control-by-control narrative that stands up to assessor scrutiny; written as a template fill, it becomes the first thing an assessor flags.

Common Questions About CMMC Flow-Down Requirements

Does every subcontractor need CMMC certification?

No. CMMC applies only to subcontractors whose scope involves CUI or FCI. If your subcontract involves only commercial products or services with no government-furnished CUI, CMMC may not apply. The determination depends on your contract language, DD Form 254, and whether CUI flows into your performance environment. When in doubt, review the clauses with your contracting officer or a CMMC advisor.

Can a subcontractor self-assess for CMMC Level 2?

It depends on the contract. The CMMC final rule under 32 CFR Part 170 allows self-assessment for a subset of Level 2 contracts where DoD has determined the information is not critical to national security. However, the majority of CUI-handling subcontracts will require a C3PAO third-party assessment for a valid CMMC Level 2 certificate. Your prime’s subcontract clause or the solicitation’s CMMC requirement section, including the applicable DFARS 252.204-7021 language, will specify which path applies.

What happens if a subcontractor fails to comply with flow-down requirements?

Non-compliance with a DFARS 252.204-7012 flow-down clause is a material breach of your subcontract. Consequences range from cure notices and remediation timelines to subcontract termination for default. Because the prime’s own contract eligibility depends on its subcontractors’ compliance, primes increasingly have no tolerance for subs that cannot demonstrate a credible CMMC program, regardless of the relationship history.

How long does it take a subcontractor to get CMMC Level 2 certified?

In our experience supporting defense subcontractors, the timeline from program start to a valid C3PAO-issued CMMC Level 2 certificate has ranged from six to twelve months, depending on current security maturity and the complexity of the CUI environment. The sequence, gap assessment, remediation, SSP build, POA&M closure, C3PAO scheduling, and assessment, takes longer than most subcontractors expect. Organizations that began in early 2025 are finishing in mid-2026; those beginning now face tight timelines against the Phase 2 requirements arriving in late 2026.

What if the prime hasn’t asked about CMMC yet, do I still need to act?

Yes. DFARS 252.204-7012 is already in your subcontract if the prime’s contract includes it. The obligation exists whether or not the prime has sent a formal request for compliance documentation. Primes that have not yet asked are either behind on their own compliance obligations or are prioritizing higher-risk subs first. Either way, waiting for the ask means starting the compliance timeline late, when assessment queues are already backlogged.

Start with a Scoping Call, Not a Sales Pitch

Working toward your CMMC assessment and need to know where you actually stand? Nexeris builds flow-down compliance programs for defense subcontractors: gap assessments, SSP development, SPRS score submission, and C3PAO readiness work. We are CMMC consultants, not a C3PAO, which means our only interest is getting your program ready to pass, not selling you the assessment.

Zach Tracy, CISSP and CMMC Registered Practitioner, has led CMMC readiness engagements across 40+ contractor assessments. Most engagements start with a scoping conversation to determine what level actually applies to your work and where the real gaps are. Exact scope, cadence, and inclusions are set during that conversation.

Schedule a free consultation. No obligation, no pitch deck.

Zach Tracy, Nexeris founder and CEO

Zach Tracy, CISA, CISSP

Zach Tracy is the CEO and a cybersecurity executive with more than 10 years of experience in security program management and regulatory compliance. He has served as a fractional Chief Information Security Officer for over 40 organizations and has led more than 100 audits across frameworks including SOC 2, CMMC, NIST CSF, ISO 27001, HIPAA, and HITRUST.

Zach specializes in helping defense contractors and regulated organizations build practical, audit-ready security programs that protect contract eligibility and reduce operational risk. He holds CISA, CISSP, CMMC-RP, and ISO 27001 and 9001 Lead Implementer certifications, along with a B.S. in Cybersecurity from Thomas College.

A Marine Corps veteran and former law enforcement officer, Zach brings a mission-focused, disciplined approach to cybersecurity leadership.

Connect with Zach on LinkedIn

Scroll to Top