CMMC Flowdown Requirements for Defense Subcontractors
Defense subcontractors are being removed from teams quietly and without warning. Not because they failed a proposal review. Not because their pricing was out of range. Because a prime contractor reviewed their compliance posture and decided the risk was not worth carrying.
CMMC flowdown is the mechanism driving this shift. Prime contractors who hold DoD contracts subject to CMMC requirements are legally obligated to flow those requirements down to subcontractors who will handle Controlled Unclassified Information in the performance of the work. The obligation is not discretionary. What is discretionary is how aggressively primes choose to enforce it and how early in the teaming process they ask the question.
For subcontractors who have not been paying attention, that question is arriving earlier than expected. The firms that cannot answer it are finding themselves replaced before the proposal is submitted.
How Flowdown Works Under DFARS
The legal foundation for CMMC flowdown is DFARS 252.204-7021, the clause that implements CMMC Level 2 requirements in DoD contracts. That clause does not only apply to the prime contractor. It requires primes to include the substance of the clause in all subcontracts and other contractual instruments that involve performance of work that requires handling CUI.
This is mandatory flowdown. The prime does not have the option to decide whether to pass CMMC requirements to a sub. If the sub will handle CUI as part of the subcontract, the prime must include the CMMC clause. The sub is then legally bound by the same CMMC requirements as the prime for the portion of work it performs.
DFARS 252.204-7012, the clause covering adequate security for covered defense information and cyber incident reporting, also flows down. Subcontractors who receive covered defense information are required to provide adequate security on their information systems and report cyber incidents to the DoD within 72 hours. Both clauses together create a compliance framework that extends through the entire supply chain, not just to the prime.
What varies is the CUI scope. Not every subcontract involves CUI. A subcontractor providing a purely commercial product or service that does not require access to technical data, export-controlled information, or other CUI categories may not fall within scope. But the determination of whether CUI is involved is made based on what the sub will actually do in performance, not based on their historical relationship with the prime or their industry category.
What Primes Are Adding Beyond the Legal Minimum
The DFARS flowdown requirements define the legal floor. Many prime contractors are operating well above it.
As CMMC enforcement has accelerated, large prime contractors have been revising their subcontractor qualification processes. Cybersecurity questionnaires that were once a formality have become substantive evaluations. Some primes are requiring subcontractors to demonstrate active SPRS records, minimum SPRS scores, or documented CMMC Level 2 status before they will consider them for teaming. Others are incorporating cybersecurity representations into teaming agreements and NDAs, creating contractual obligations that attach before a proposal is even written.
The practical effect is that CMMC compliance has become a qualification criterion at the teaming stage, not the contract award stage. Subcontractors who have not done this work cannot answer a prime's cybersecurity questionnaire accurately. The firms that are winning teaming spots are the ones that can answer quickly, accurately, and with documentation to back it up.
Primes are doing this for a straightforward reason: their own contract eligibility depends on the security posture of their supply chain. If a subcontractor handling CUI is compromised, the prime bears reporting obligations, reputational consequences, and potential contract liability. Vetting the sub's compliance posture before award is basic risk management.
The Specific Obligations Subcontractors Need to Understand
Subcontractors who receive a subcontract containing DFARS 252.204-7021 are bound by the same CMMC Level 2 requirements as the prime for the systems and work covered by that subcontract. The DoD's CMMC program overview outlines the full framework. In practice, that means:
- Maintaining an SPRS record that reflects a current assessment, either a self-assessment for lower-risk programs or a C3PAO third-party assessment for programs requiring independent validation
- Affirming CMMC status annually in SPRS through a senior company executive
- Implementing all applicable NIST SP 800-171 controls on systems that process, store, or transmit CUI in connection with the subcontract
- Maintaining a System Security Plan that documents the boundary of those systems and the controls in place
- Reporting cyber incidents involving covered defense information to the DoD within 72 hours under DFARS 252.204-7012
- Flowing CMMC requirements further down to any lower-tier subcontractors who will also handle CUI
The scope of these obligations is limited to the CUI that the subcontractor handles in connection with the specific subcontract. A subcontractor's entire information environment does not necessarily fall within scope. But the scoping determination requires deliberate analysis. It is not automatically limited to a single system or project folder simply because the work is defined as limited in scope.
How Subcontractors Are Getting Cut Out
The supply chain displacement happening right now is not usually the result of a formal compliance audit. It is the result of a question that gets asked during teaming discussions, before the proposal goes in, and the answer is not good enough.
The cybersecurity questionnaire gap
Prime contractors are distributing cybersecurity questionnaires to prospective teaming partners with increasing frequency and specificity. These questionnaires ask about SPRS scores, CMMC assessment status, System Security Plan completion, POA&M management, and incident response capabilities. Subcontractors who have not done this work cannot answer these questions accurately. Subcontractors who guess or inflate their answers create legal exposure for themselves and a reliability problem for the prime.
The missing SPRS record
An SPRS record is required for contractors subject to DFARS 252.240-7997 when their subcontract involves CUI. If a subcontractor's SPRS record is blank, expired, or reflects a score well below the threshold for conditional Level 2 status, that is a visible and verifiable compliance gap. Primes who check SPRS before finalizing their team will see it.
The contract flowdown trap
Some subcontractors accept subcontract terms that include DFARS compliance clauses without fully understanding what they are agreeing to. The clause is in the boilerplate. They sign. They perform the work. Then, when the prime asks for a CMMC status update before option year renewal, or when a program office requests compliance verification, they realize their systems do not meet the requirements they contractually committed to. At that point, the path forward involves either rapid remediation, a significant contract risk conversation with the prime, or both.
The supply chain tier problem
Compliance gaps do not only affect direct subcontractors to large primes. They affect companies several tiers down the supply chain. A precision machining firm, a specialized testing laboratory, or a software maintenance contractor may receive a subcontract from a mid-tier integrator who holds a prime contract with DoD. If CUI flows through to that lower-tier sub, the compliance obligation flows with it. The fact that the sub does not have a direct relationship with the DoD agency does not change the regulatory requirement.
What Subcontractors Need to Do Now
The supply chain compliance environment is not getting easier. The firms that establish a defensible CMMC posture now will hold their teaming relationships. The ones that treat this as someone else's problem will continue to lose spots on proposals they should be winning. Atlantic Digital's industry partner network includes subcontractors at every tier of the defense supply chain working through exactly this process.
Audit your existing subcontracts for DFARS clauses
Review every active subcontract for the presence of DFARS 252.204-7012 and 252.204-7021. If those clauses are present, the work you perform under those subcontracts may already carry CMMC obligations. Understanding the existing scope of your compliance requirements is the first step before addressing gaps.
Establish or update your SPRS record
If you do not have a current SPRS record, you cannot demonstrate compliance to a prime contractor or a contracting officer. Completing a self-assessment and uploading your results to SPRS is the minimum viable step. The assessment must be accurate, the score must reflect your actual implementation status, and the affirmation must be signed by a qualified senior executive.
Define your CUI boundary
Scope is everything in CMMC compliance. Work with a CMMC strategy advisor to define precisely which of your information systems are within scope for CUI based on your actual subcontract work. A narrow, well-defined boundary that is rigorously defended is better than a broad boundary that is poorly managed. Get the scoping right first before investing in controls that may not be required.
Prepare for the questionnaire
Develop a standard set of answers to the cybersecurity questionnaire questions your primes are likely to ask. These answers need to be accurate, supported by documentation, and deliverable quickly. A prime that asks on Tuesday and does not hear back by Friday has their answer. Preparation is a competitive advantage.
Frequently Asked Questions
As a subcontractor, am I subject to CMMC if I do not have a direct contract with DoD?
Yes, if your subcontract requires you to handle CUI and your prime contractor flows down DFARS 252.204-7021, you are subject to the same CMMC Level 2 requirements as the prime for that portion of work. The requirement applies based on the nature of the information you handle, not on whether you have a direct contractual relationship with a DoD agency.
How do I know if my subcontract work actually involves CUI?
Review the subcontract statement of work and any contract data requirements lists associated with the effort. Look for references to technical data, export-controlled information, proprietary government information, or any information marked with a CUI designation. If you are uncertain, ask the prime contractor directly. The prime has an obligation to tell you whether CUI will be involved in your performance and, if so, to include the appropriate flowdown clauses.
Can I lose an existing subcontract if I am not CMMC compliant?
A prime contractor who discovers that a subcontractor handling CUI does not meet CMMC requirements has a compliance problem of their own. Depending on the contract terms and the nature of the gap, this can lead to remediation requirements, contract modifications, or in serious cases, termination of the subcontract. The risk is real and is being actively managed by primes as CMMC enforcement matures.
Do I need a C3PAO assessment as a subcontractor or will a self-assessment work?
Whether you need a self-assessment or a C3PAO third-party assessment depends on the specific requirements of the prime contract and the solicitation. Many subcontracts under programs that allow self-assessment at the prime level will also allow self-assessment for subs. However, programs that require C3PAO certification at the prime level will generally require the same for subcontractors who handle CUI. Review the prime's subcontract terms and, when in doubt, ask directly.
Contact us today to learn more about how Atlantic Digital helps defense subcontractors establish CMMC compliance, build defensible SPRS records, and maintain their teaming relationships as flowdown enforcement tightens across the supply chain.