CMMC Compliance for Subcontractors

CMMC compliance for subcontractors

If you are a subcontractor on a U.S. defense contract, CMMC does not automatically mean โ€œget Level 2 certified.โ€ The first question is much narrower: Will your subcontract require your systems to process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI)?

If you handle only FCI, the regulatory path is generally CMMC Level 1. If you handle CUI, Level 2 is the minimum. If neither type of information reaches your systems, CMMC flowdown may not apply to that subcontract at all. Your first practical action is therefore not buying compliance software or calling an assessor. It is mapping exactly what information the prime intends to give you and where that information will travel.

There is also an important 2026 wrinkle. The Department suspended the planned transition to CMMC Phase 2 on July 13, 2026. Phase 1 remains in effect, so Level 1 and Level 2 self-assessment requirements continue where applicable, while the planned expansion of mandatory third-party Level 2 assessments is paused. The Department’s current CMMC program page should be checked before relying on an old November 2026 deadline.

CMMC compliance for subcontractors

Does CMMC Apply to Your Subcontract?

CMMC follows protected contract information through the defense supply chain. It does not follow company size, subcontract value, or the prime contractor’s anxiety level.

Under 32 CFR ยง 170.23, CMMC requirements apply throughout the supply chain at all tiers when a subcontractor will process, store, or transmit FCI or CUI on contractor information systems while performing the subcontract.

That creates a useful three-question gate:

  • Will we receive or generate nonpublic federal contract information?
  • Does any of that information qualify as CUI?
  • Will it touch our own information systems, endpoints, cloud services, email, file storage, production systems, or service providers?

If the answer to all three is no, do not volunteer the entire company for a compliance project simply because the prime mentions CMMC in conversation. Ask the prime to identify the information and contractual requirement being flowed down.

If the answer is yes, the information type becomes the main decision hinge.

Which CMMC Level Does a Subcontractor Need?

The subcontractor’s required level is driven primarily by the information it handles, not simply by copying the prime contractor’s level.

Subcontractor situationRegulatory CMMC floorWhat that means
No FCI or CUI on contractor systemsNo CMMC level solely from ยง 170.23Document the boundary and confirm the subcontract does not require covered information to reach your systems.
FCI onlyLevel 1 (Self)Basic safeguarding requirements apply to the FCI environment.
CUILevel 2 (Self)The CUI environment must meet the Level 2 requirements.
CUI and associated prime contract requires Level 2 (C3PAO)Level 2 (C3PAO)The rule ordinarily flows down the certification assessment requirement.
CUI and associated prime contract requires Level 3At least Level 2 (C3PAO)Level 3 does not automatically cascade to every CUI subcontractor.

The last two rows describe the rule’s normal flowdown structure. Current implementation policy matters, however. The July 2026 suspension keeps the program in Phase 1 and directs acquisition activities to use Level 1 or Level 2 self-assessment requirements during the suspension rather than moving into the planned Phase 2 C3PAO expansion.

This is why a 2026 subcontractor should read both the regulation and the actual subcontract. A clause drafted before the suspension, a pending modification, and a new procurement issued after the suspension may not look identical on paper.

The Flowdown Rule Primes and Subcontractors Need to Apply

DFARS 252.204-7021 turns CMMC from a framework into a contract-performance issue. The clause requires contractors to flow the appropriate CMMC requirement into covered subcontracts and, before subcontract award, ensure the subcontractor has the appropriate current CMMC status for the information being shared.

You can review the operative language in DFARS 252.204-7021.

The practical consequence is easy to miss: flowdown follows data at every tier. A first-tier subcontractor can become responsible for flowing requirements to its own suppliers when those suppliers need FCI or CUI to perform their work.

Imagine a machine shop receives a CUI drawing and sends that drawing to a heat-treatment company. The prime-to-sub relationship is no longer the end of the chain. The first subcontractor has created another covered information flow that must be analyzed.

Conversely, if the heat-treatment company can perform its task using an ordinary part number, dimensions that are not CUI, or another appropriately sanitized work instruction, pushing the entire CUI package downstream may create compliance scope without adding operational value.

That leads to one of the most useful CMMC cost-control rules for small subcontractors: minimize unnecessary FCI and CUI distribution before you try to secure an unnecessarily large environment.

Your 15-Minute Subcontract Scope Check

Before accepting a CMMC requirement, sit down with the subcontract, a blank sheet of paper, and whoever actually understands your IT environment. You are trying to draw the information path, not an impressive network diagram.

  1. Identify the information. Write down whether the prime expects to send FCI, CUI, both, or neither.
  2. Identify the source. Email, supplier portal, file transfer, collaboration platform, API, engineering repository, physical media, or another method.
  3. Identify every landing point. Laptop, workstation, server, cloud storage, mailbox, backup, mobile device, manufacturing system, printer, or file share.
  4. Identify every security-supporting service. Identity provider, endpoint management, security monitoring, backup, remote administration, MSP, MSSP, or other external provider.
  5. Identify every downstream recipient. Suppliers, consultants, fabricators, software developers, logistics providers, testing laboratories, and lower-tier subcontractors.
  6. Mark what can be removed. Ask whether each person and system genuinely needs the covered information.

This exercise often saves more money than the first compliance-tool demo. Scope is the trunk of the tree; licensing, documentation, evidence collection, monitoring, and assessment effort grow from it.

What Level 1 Means for an FCI-Only Subcontractor

Level 1 is designed around the basic safeguarding requirements associated with FCI. Under the current Phase 1 program, Level 1 uses an annual self-assessment, with the applicable result and affirmation maintained through SPRS.

Level 1 is smaller than Level 2, but it is not a declaration that your company โ€œuses antivirus and passwords.โ€ The relevant safeguards must actually be implemented in the systems that process, store, or transmit FCI.

Another useful distinction is that Level 1 does not permit a POA&M as a substitute for missing requirements. If Level 1 is the required status, the required safeguards need to be met rather than parked on a future-work list.

For a small FCI-only supplier, this makes aggressive scope control especially valuable. If only two managed workstations and one controlled cloud workflow need FCI, there is little reason to casually spread contract documents across personal mailboxes, consumer file-sharing accounts, and every employee laptop.

CMMC compliance for subcontractors

What Level 2 Means When Your Subcontract Includes CUI

Level 2 is the meaningful jump. It applies when contractor systems process, store, or transmit CUI and is built around the 110 security requirements of NIST SP 800-171 Revision 2 under the current CMMC program.

There is a version trap here. NIST has superseded Revision 2 with Revision 3 for its broader publication program, but CMMC Phase 1 currently continues to use the Revision 2 requirement set. The archived NIST SP 800-171 Revision 2 publication therefore remains operationally relevant to CMMC even though it is no longer NIST’s newest revision.

If your security team is also adopting Revision 3 for other reasons, keep a crosswalk. Do not silently swap the CMMC evidence set to Revision 3 and assume the contractual assessment requirement changed with NIST’s publication lifecycle.

Level 2 also changes the evidence problem. A policy saying โ€œmultifactor authentication is requiredโ€ is weaker than evidence showing MFA is configured, enforced, monitored, and applied to the accounts and access paths within scope. If MFA is one of your larger implementation gaps, the MFA rollout guide can help separate deployment mechanics from policy language.

Current Phase 1 Level 2 self-assessment status is generally valid for three years, subject to annual affirmation requirements. Limited POA&M use is possible under the rule, but it is not a license to postpone an unfinished environment indefinitely. Conditional status requires permitted gaps to be closed within the applicable 180-day window.

Build an Evidence Map Before You Buy More Security Tools

CMMC readiness becomes much easier to manage when each requirement has four owners instead of one vague โ€œcompliance owner.โ€

Evidence questionWhat you need to identify
Who owns the requirement?The person accountable for maintaining it.
What implements it?Technology, configuration, process, physical control, or combination.
What proves it?Configuration export, policy, log, ticket, screenshot, record, interview, or other assessment evidence.
How often can it drift?The event or schedule that should trigger re-verification.

This exposes an expensive category error: a tool is not the same thing as a control, and a control is not the same thing as evidence.

A SIEM license may help collect audit records. It does not decide what must be logged, configure every source, review the logs, maintain retention, investigate failures, document ownership, or prove the process is operating as described.

Likewise, buying a โ€œCMMC platformโ€ may organize requirements and evidence beautifully while leaving endpoint configuration, identity, encryption, network segmentation, incident response, physical protection, backups, and supplier management untouched.

What to Request From the Prime Before Subcontract Award

A subcontractor cannot scope responsibly if the prime provides nothing except โ€œyou need CMMC.โ€ Ask for enough information to understand the obligation without requesting CUI before your environment is ready to receive it.

  • The CMMC level and assessment type required by the subcontract.
  • Whether the work involves FCI, CUI, or both.
  • The categories or types of CUI expected, where relevant.
  • The DFARS and FAR clauses being flowed down.
  • The approved information-transfer method.
  • Any prime-specific security or reporting requirements.
  • Whether lower-tier suppliers are expected to receive covered information.
  • Whether the requirement has been updated following the July 2026 Phase 2 suspension.

If the prime cannot explain why Level 2 is required, do not treat that uncertainty as proof that Level 2 is unnecessary. Treat it as a contract-clarification problem. The objective is to identify the actual information flow and controlling clause before information changes hands.

What Evidence a Prime May Reasonably Ask You to Provide

DFARS 252.204-7021 places pre-award responsibility on the higher-tier contractor to ensure that a covered subcontractor has the appropriate current CMMC status. The rule does not give primes a magical dashboard containing every supplier’s internal compliance details.

Expect a prime or higher-tier subcontractor to ask for information sufficient to validate your status and scope without needing your entire security program handed over wholesale.

  • Your applicable CMMC status or certificate information.
  • Relevant SPRS-generated information or evidence of the required assessment status.
  • Confirmation that annual affirmation requirements remain current.
  • The environment or business unit covered by the status when scope could otherwise be ambiguous.
  • Notification if your status changes in a way that affects subcontract performance.

Be cautious with requests for raw vulnerability data, privileged architecture information, credentials, full internal audit exports, or unrestricted copies of sensitive security documentation. Verification should prove the required condition without creating a new security problem in the prime’s inbox.

Cloud Services, MSPs, and External Providers Can Expand the Boundary

A small subcontractor can outsource technology, but not accountability.

If an external service becomes part of how your organization processes, stores, transmits, or protects covered information, that relationship needs to be analyzed as part of the CMMC environment. Cloud services that handle CUI also interact with separate DFARS cloud-security requirements, including the FedRAMP Moderate equivalency requirement in applicable circumstances.

Before treating an MSP, MSSP, cloud provider, backup provider, or managed identity service as your compliance shortcut, ask four questions:

  • Does the provider process or store CUI, or merely support a system that does?
  • Which CMMC requirements depend on the provider?
  • What evidence will the provider make available to support your assessment?
  • Which responsibilities remain yours under the contract and customer responsibility model?

A provider that says โ€œwe are CMMC readyโ€ without defining the service boundary is selling a sentence. You need an architecture and responsibility model.

DIY, Compliance Software, or Professional Help?

The right choice depends less on employee count than on scope complexity and internal expertise.

ApproachBest fitMain limitation
DIYSmall, well-understood environment with capable internal IT/security staffInternal teams can underestimate evidence, scoping, and contractual details.
Compliance softwareTeams that understand the controls but need repeatable evidence, task, policy, and status managementSoftware usually does not implement the technical environment for you.
Consultant or MSPOrganizations with material implementation gaps or limited internal expertiseQuality varies, and outsourced work still needs an internal owner.
Independent assessment providerWhen the contract and current CMMC implementation actually require third-party assessmentAn assessor validates compliance; it should not be confused with your implementation team.

During the current Phase 1 suspension of Phase 2 progression, do not buy a C3PAO engagement merely because an old implementation timeline told you November 10, 2026 was an automatic deadline. First verify the current solicitation, subcontract, Department policy, and required status.

Professional readiness help may still be justified long before any external assessment if you cannot define the CUI boundary, interpret flowdowns, implement the 110 Level 2 requirements, build an SSP that matches reality, or determine how an external provider fits into scope.

What CMMC Compliance Actually Costs a Subcontractor

There is no defensible universal subcontractor price. Two ten-person companies can have dramatically different budgets if one keeps CUI in a tightly controlled enclave while the other allows it across ordinary email, laptops, cloud drives, remote workers, printers, backups, administrators, and external providers.

A more useful budget model is:

Existing-control gaps + scope reduction or architecture work + implementation + documentation + evidence collection + recurring operations + permitted remediation + required assessment = realistic CMMC budget.

The large cost drivers are usually not the acronym itself. They are the number of in-scope users and assets, identity architecture, endpoint management, logging, secure collaboration, cloud choices, external providers, documentation debt, remediation backlog, and the amount of the existing environment that must be redesigned.

If budgeting is now your next decision, use the separate CMMC compliance cost guide rather than treating a vendor’s assessment fee as the whole project cost.

Five Subcontractor Mistakes That Create Avoidable CMMC Work

1. Assuming every subcontractor needs Level 2. FCI and CUI are different triggers. A supplier that receives neither may sit outside the CMMC flowdown for that work.

2. Copying the prime’s level without checking ยง 170.23. The regulation contains specific subcontractor rules. A Level 3 prime contract, for example, does not automatically make every downstream CUI supplier Level 3.

3. Sending CUI downstream because it is convenient. Every unnecessary recipient can widen both contractual and technical scope.

4. Buying tools before drawing the boundary. You can spend thousands securing systems that never needed covered information while leaving one forgotten file-transfer path inside the real scope.

5. Treating the Phase 2 suspension as cancellation of cybersecurity obligations. The certification rollout changed in July 2026. The obligation to protect covered defense information did not vanish with it.

CMMC compliance for subcontractors

Frequently Asked Questions

Does every small defense subcontractor need CMMC?

No. CMMC applicability depends on the covered information and contract. A subcontractor whose systems process, store, or transmit FCI or CUI can be in scope regardless of company size, while a supplier that receives neither may not have a CMMC requirement for that subcontract.

Does a COTS supplier need CMMC?

CMMC rules contain an exclusion for acquisitions exclusively involving commercially available off-the-shelf items. Do not extend that exception casually to every commercial product or service. DFARS 252.204-7021 can flow to commercial products and commercial services when the relevant subcontract requires processing, storing, or transmitting FCI or CUI, while excluding COTS items as specified by the clause.

What if my prime still asks for a C3PAO assessment in 2026?

Ask which contract requirement controls and whether the instrument has been updated following the July 13, 2026 suspension. Current Department guidance pauses the planned Phase 2 transition and directs use of Level 1 and Level 2 self-assessment requirements during the suspension. Do not ignore the prime’s written subcontract, but do not spend on an obsolete deadline without reconciling it with current policy.

Does Level 2 mean our entire company must be inside the CMMC boundary?

Not necessarily. CMMC scope is tied to the systems and services involved in processing, storing, transmitting, or protecting CUI. A deliberately designed enclave can reduce scope, but shared identity, security, administration, backup, or infrastructure services may still become relevant to the assessment. Boundary reduction must reflect technical reality, not a box drawn around convenient assets.

Can a subcontractor become compliant by buying a CMMC platform?

No. A platform may organize controls, policies, evidence, tasks, and remediation, but compliance depends on the underlying safeguards, documentation, assessment status, affirmations, information flows, and contractual obligations. Software can manage the map; it cannot turn an unimplemented control into an implemented one.

What to Do Before You Accept the Subcontract

Spend ten minutes on one document before you buy anything: create a one-page flow map showing what the prime will send you, whether it is FCI or CUI, which systems will touch it, which outside providers support those systems, and whether anyone farther down your supply chain needs the same information.

Then compare that map with the actual CMMC and DFARS language in the subcontract. If the data classification, required status, and contract language align, you have a defensible starting point for implementation. If they do not, resolve the discrepancy before covered information arrives.

That small sequence prevents two expensive errors at once: building a compliance program for systems that did not need to be in scope, and accepting sensitive defense information into systems that were never ready for it.


Last reviewed: 2026-10

Stay Updated with Kioptrix

Get practical guides, useful resources, and new articles delivered to your inbox.

No spam. Unsubscribe anytime. Read our Privacy Policy.