CMMC ANSWER ENGINE

How do CMMC requirements flow down to my subcontractors?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-16
Quick answer. Each subcontractor must meet the CMMC level appropriate for the FCI or CUI it will process, store, or transmit (Level 1 for FCI only, Level 2 for CUI per the Defense OIG test, Level 3 if designated). The prime verifies each subcontractor's CMMC Status before sharing CUI. DFARS 252.204-7012 flows down separately. The biggest cost-savings opportunity in supply-chain compliance is stopping CUI flow to suppliers who never needed it. Subcontractor access to a prime's enclave reduces but does not eliminate the subcontractor's own CMMC obligations.

Flow-down is the mechanism by which CMMC requirements reach beyond the prime contractor and into the supply chain. The CMMC 101 (Nov 2025) brief is explicit: "Subcontractors are subject to flow-down requirements." 32 CFR Part 170 § 170.23 establishes the framework, and DFARS 252.204-7012 flows down separately and concurrently.

The principle

A subcontractor that will process, store, or transmit FCI or CUI in performance of the prime's contract must meet the appropriate CMMC level for the data they will handle. The level determination follows the same logic as for the prime:

  • FCI only: Level 1 (Self-Assessment).
  • CUI in the NARA Registry but not in the Defense OIG: Level 2 (Self-Assessment).
  • CUI in the Defense OIG: Level 2 (Certification by C3PAO).
  • Program Manager designates as Level 3: Level 3 (Certification by DIBCAC).

Sort suppliers by CUI need before sending CUI to them

The biggest cost-savings opportunity in supply-chain compliance is the supplier who was receiving CUI through habit or laziness but never actually needed it to do their job. A productive supply-chain scoping exercise sorts your suppliers into three categories:

Supplier typeWhat they needCMMC implication
No CUI access requiredSpecifications, drawings, or instructions that contain no CUI, or that you can decontrol before sharing.Level 1 (FCI handling) sufficient.
Limited CUI access requiredSome CUI is operationally necessary, but volume and category can be minimized.Level 2 required, but boundary can be tightly scoped.
Full CUI access requiredCUI is fundamental to the work they perform.Level 2 (or 3) required; full scoping needed.

Procurement (not compliance) has the operational levers to reshape what flows to suppliers. Procurement controls what gets attached to purchase orders, what gets shared in RFQs, what gets sent to process providers. A procurement team that understands CUI scoping principles can stop flowing CUI to suppliers who do not need it, simply by being more thoughtful about what gets attached to which order.

The process-provider example

You need to send a part to a process provider for stress relief, plating, heat treatment, or similar. Two approaches:

  1. Send the customer's drawing. The drawing is CUI, the provider now handles CUI, the provider needs Level 2 certification. Default failure mode.
  2. Send a process traveler. A short, contractor-generated instruction sheet identifying the part, the process required (for example, "1mm coating per specification XYZ"), and any required quality requirements. If the traveler does not contain CUI, the process provider does not need to handle CUI.

The second approach requires that your engineers understand which elements of a drawing are regulated and which are not. The investment pays back in reduced supply-chain compliance footprint. Important caveat: stripping the customer's name off a drawing and sending it onward does not decontrol it. The customer's name was not what made it CUI; the regulated technical content was. A process traveler is decontrolled because it contains different (non-regulated) information, not because it is a sanitized version of the original drawing.

The enclave-access myth

A common pattern: a prime builds an enclave for handling CUI and offers subcontractors remote access as a way of reducing the subcontractor's compliance burden. The pitch is intuitive ("just use our environment"), but it does not eliminate the subcontractor's own CMMC obligations.

Even if a subcontractor accesses CUI exclusively through a prime's enclave and never takes possession of digital copies, the subcontractor is still performing on a subcontract that involves CUI. Under DFARS, "involves CUI" includes accessing it, viewing it, and being in situations where someone could observe a screen displaying it. The subcontractor typically still has to address:

  • Physical security requirements. Controlling the environment in which personnel access the prime's enclave.
  • Personnel screening. Background screening for personnel with CUI access.
  • Awareness and training. CUI-handling training for personnel with access.
  • Incident handling. Obligations to respond to and report potential CUI exposures.
  • Media protection. Restrictions on photography, screen recording, and physical media in the access environment.

What enclave access does enable is a substantially narrower CMMC Level 2 certification for the subcontractor. By eliminating many of the IT-system obligations (no local storage, no local processing, no local transmission), the subcontractor's certification can focus on a much smaller subset of 800-171 requirements (typically physical, personnel, and operational controls). This is real value, but it is not "no certification needed."

Be wary of advisors who tell subcontractors that prime-enclave access eliminates their CMMC obligations. It reduces and reshapes those obligations but does not eliminate them. A subcontractor who relies on that misframing and skips certification will discover the gap during prime audits or end-customer compliance reviews, when remediation is expensive.

The prime's responsibility

The prime contractor is responsible for ensuring each subcontractor that will receive FCI or CUI under the prime's contract holds the appropriate CMMC Status before the data is shared. Practically:

  1. Identify which subcontractors will receive FCI or CUI under the contract.
  2. For each, determine the CMMC level required based on what they will receive (after applying the decontrol and minimization analysis above).
  3. Have each subcontractor send proof of their current CMMC Status. In practice this means a screenshot of their SPRS record (for Level 1 self-assessments and Level 2 self-assessments) or their CMMC eMASS record (for Level 2 certifications and Level 3). Primes do not have visibility into other contractors' SPRS or eMASS records directly, so the sub providing the screenshot is the operational verification path.
  4. Include CMMC requirements in the subcontract through the appropriate flow-down clauses.
  5. Maintain documentation of the flow-down, including the subcontractor's status screenshot and the date it was provided.

DFARS 252.204-7012 flow-down

Independently of CMMC, DFARS clause 252.204-7012 contains its own flow-down language. When 7012 is in the prime's contract, the prime must include the substance of 7012 in any subcontracts where the subcontractor will use covered defense information in performance of the contract. This includes:

  • The NIST SP 800-171 implementation requirement.
  • The cloud computing services requirement (FedRAMP Moderate Equivalent for CUI).
  • The cyber incident reporting requirement (DIBNet within 72 hours of discovery).
  • The damage assessment cooperation requirement.

DFARS 252.204-7020 also flows down assessment-cooperation requirements when applicable.

What the prime can verify and what it cannot

Primes do not have direct access to other contractors' SPRS or eMASS records. The practical verification path is for the subcontractor to send the prime a screenshot of their own SPRS or eMASS record.

Prime can verifyPrime cannot verify directly
A SPRS or eMASS screenshot the subcontractor provides showing their current CMMC Status.The subcontractor's SPRS or eMASS record directly. Primes can only see their own.
A screenshot or attestation of the subcontractor's annual affirmation.The internal control implementation details of the subcontractor.
That the appropriate flow-down clauses are in the subcontract.The technical effectiveness of subcontractor controls.
The date the screenshot was captured (use it as the reference point for the next verification cycle).That the subcontractor's environment exactly matches the SPRS posture.

The CMMC ecosystem relies on the affirmation and assessment regime to ensure the subcontractor's stated status is accurate; the prime's responsibility is to obtain and retain the evidence the subcontractor provides, not to re-assess the subcontractor.

Multi-prime alignment for small subcontractors

A specialist subcontractor (for example, a small machine shop) typically serves multiple primes. If one prime is willing to flow paper-only CUI to keep the subcontractor's scope minimal, but nine others demand digital flow, the subcontractor's effective scope is driven by the most demanding prime. The strategic move for a small subcontractor is to align primes around a common minimal-scope handling pattern: a clear articulation of the subcontractor's scope decision (for example, "paper-only CUI, all digital handling occurs in your environments"), buy-in from all primes who flow CUI to the subcontractor, and documentation that survives prime-level audits. Without multi-prime alignment, the subcontractor's compliance footprint is set by the worst-case prime.

Common errors

  • Sharing CUI with a subcontractor before verifying their CMMC Status. Once CUI is on the subcontractor's environment, the prime cannot retroactively impose protections.
  • Assuming all subcontractors need the same level as the prime. The level depends on what the subcontractor will actually handle. A subcontractor that will not receive CUI may only need Level 1 even if the prime is Level 2.
  • Flowing CUI to a supplier who could have done the work with decontrolled data. The process-provider example above is the single largest cost-savings opportunity in supply-chain compliance.
  • Telling subcontractors that prime-enclave access eliminates their CMMC obligations. It reduces and reshapes them; it does not eliminate them.
  • Confusing CMMC flow-down with DFARS 7012 flow-down. Both apply, and they are related but distinct mechanisms.
  • Assuming you can pull a subcontractor's status from SPRS yourself. Primes do not have access to other contractors' SPRS or eMASS records. The verification has to come from the subcontractor in the form of a SPRS or eMASS screenshot they send you. Ask for it; do not assume you can look it up.
  • Failing to refresh the screenshot on subcontractor renewal. CMMC Statuses have validity windows: Final Level 1 (Self) requires annual self-assessment and affirmation; Final Level 2 (Self-Assessment) is annual; Final Level 2 (C3PAO Certification) is valid for 3 years with annual affirmations during that period. Get a fresh screenshot before each renewal or new task order. The screenshot you collected at award is stale within a year.
  • Forgetting that subcontractor systems providing security functions to the prime's CUI environment are SPAs in the prime's scope, not just separately CMMC-obligated entities.

Sources

  • CMMC 101 Brief (Nov 2025). Subcontractor flow-down requirements. link
  • 32 CFR Part 170, § 170.23 Subcontractor flow-down. link
  • 32 CFR Part 2002, CUI Program. The two-part federal definition that underwrites scoping decisions. link
  • DFARS 252.204-7012. Flow-down language for CDI safeguarding and cyber incident reporting. link
  • DFARS 252.204-7020. Flow-down language for assessment cooperation. link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170); CMMC 101 Nov 2025 brief; DFARS 252.204-7012 / -7020; 32 CFR Part 2002 (CUI Program)

Track every subcontractor's CMMC Status.

The CMMC Compliance Engine includes the VRQ-01_Vendor_Risk_Register for tracking subcontractor CMMC Status, affirmation expirations, and the data categories each receives under your contract.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.