Assessment Scope Guide · Ground Vehicle

CMMC for Ground Vehicle Manufacturers and Tier 2 Suppliers: Navigating Flow-Down Requirements

Prime contractor supply chain audits are no longer theoretical. Sub-tier suppliers to JLTV, AMPV, and Abrams programs are receiving compliance questionnaires and contract amendments that carry real consequences for non-compliance.

Last updated: January 8, 2026

Flow-down reality What triggers obligations CUI in ground vehicle Tier 2 exposure Prime audit prep SPRS and affirmation FAQ

The Flow-Down Situation Tier 2 Suppliers Are Waking Up To

Ground vehicle suppliers have spent years watching CMMC from a comfortable distance. The program applied to prime contractors, they reasoned, and maybe to Tier 1 suppliers who held direct government contracts. Tier 2 and Tier 3 suppliers who received subcontracts from primes assumed the obligation stopped at the prime contractor level.

That assumption was always legally incorrect, and the supply chain is catching up to the reality. DFARS 252.204-7012, which establishes the underlying cybersecurity and CUI protection requirements that CMMC now enforces, has always required primes to flow the clause down to subcontractors at all tiers who will receive, process, store, or transmit Covered Defense Information. The clause itself does not contain a tier limit.

What has changed is enforcement. Prime contractors for major ground vehicle programs are now conducting supply chain cybersecurity audits, requiring SPRS score submissions, and including CMMC compliance requirements as terms in subcontract renewals. Suppliers who cannot demonstrate compliance are losing access to new task orders. Some have been removed from approved vendor lists.

Timeline pressure
CMMC Level 2 certification requirements are being phased into defense contracts on a rolling basis. Contracts issued or renewed after a certain phase-in date will require certification as a condition of award. For ground vehicle subcontractors, the pressure point is subcontract renewal, and those renewals are already happening with new compliance language included.

What Actually Triggers Your CMMC Obligation

The threshold question for any Tier 2 or Tier 3 supplier is whether your subcontract involves Covered Defense Information. The DFARS definition is technical: CDI means unclassified Controlled Technical Information or other information requiring safeguarding or dissemination controls pursuant to applicable law, regulation, or policy that is collected, developed, received, transmitted, used, or stored by or on behalf of a contractor in support of the performance of a contract.

For ground vehicle suppliers, the practical test is simpler. Do you receive technical drawings, specifications, test procedures, or performance requirements from your prime that describe any component of a defense vehicle system? Do you generate production records, inspection reports, or certifications that reference those components? If yes to either question, you are almost certainly handling CDI and your subcontract almost certainly flows DFARS 252.204-7012 to you, whether your subcontract explicitly says so or not.

The legal principle is that a prime contractor cannot use a subcontractor to perform work that the prime is contractually required to protect, without flowing the protection obligation down. If the prime is required to protect CUI under its government contract, and you are performing work that generates or touches that CUI, you have inherited the obligation.

Reading Your Subcontract

The most reliable indicator is whether your subcontract explicitly includes DFARS 252.204-7012 by clause reference. If it does, you have a clear written obligation. If it does not, review the clauses by reference section and any compliance certification requirements in the contract. Many prime contractors flow the obligation through general cybersecurity compliance requirements or supply chain security addenda rather than by specific DFARS clause citation. The functional obligation exists regardless of how the prime chooses to document it.

If you genuinely cannot determine whether you have CUI obligations from the face of your subcontract, contact your prime's supply chain compliance team and ask directly. Document the inquiry and the response. This creates a paper trail that demonstrates good-faith compliance effort, which is relevant if a question arises later.

What CUI Looks Like in a Ground Vehicle Supply Chain

Ground vehicle programs generate a specific profile of CUI that differs meaningfully from aviation or naval programs. Understanding what categories appear in your environment helps focus the scoping exercise.

Vehicle System Technical Data

Engineering drawings and models for armor configurations, powertrain systems, suspension components, and hull structures received from primes under government contracts are CUI. This is the most straightforward category. If the drawing came from a prime on a defense program and it describes how a vehicle or its components are built, it is CUI.

Performance and Test Specifications

Ballistic protection specifications, blast resistance parameters, mobility performance requirements, and vehicle signature management specifications are typically Export Controlled and CUI. These documents often arrive as procurement specifications attached to purchase orders, and suppliers sometimes treat them as generic technical requirements rather than controlled information.

Supplier-Generated Production Data

This is the category that surprises Tier 2 suppliers most often. The inspection records, material certifications, first article reports, and conformance documentation you generate for your defense program parts are CUI. You created them, but the obligation to protect them derives from the contract under which the work was performed. A supplier who receives a specification, manufactures to it, and generates conformance documentation has created CUI even if they never received a single drawing directly from the government.

Electronic Data Interchange and Portal Access

Prime contractor supplier portals increasingly serve as the mechanism for transmitting technical data, receiving purchase orders, and submitting inspection and certification documentation. If you access a prime's supplier portal and that portal contains CUI, your workstations and the network they run on are in scope for CMMC. The data is in your environment for as long as it is in your browser cache, your download folder, and any local storage you created while working with it.

CUI Category Ground Vehicle Examples Where It Typically Lives
Controlled Technical Information Armor drawings, powertrain specs, hull models PDM, shared drive, email attachments
Export Controlled Ballistic specs, signature management data Received via email or supplier portal
Supplier-generated conformance data First article reports, certs of conformance QMS, shared drive, email
Procurement information Contract-specific part numbers, quantities ERP, email

Why Tier 2 Suppliers Are More Exposed Than They Realize

Tier 1 suppliers to major ground vehicle programs have compliance teams, legal counsel, and years of experience managing DFARS obligations. Tier 2 and Tier 3 suppliers frequently have none of those resources. They are often small machine shops, specialty fabricators, or component manufacturers who won subcontracts based on technical capability and price, without a full understanding of the compliance strings attached.

The exposure has two dimensions. The first is the legal and contractual risk of non-compliance. A subcontractor who is handling CUI without adequate protections is in breach of its subcontract, regardless of whether the prime is actively monitoring compliance. When primes conduct supply chain audits, non-compliant Tier 2 suppliers face the possibility of contract termination or removal from the approved vendor list.

The second dimension is financial. CMMC compliance has real costs. A small supplier that has been winning subcontracts without compliance costs baked into its pricing structure will face margin compression when those costs are finally incurred. Suppliers who build compliance capability early are in a better position to price it into future bids than suppliers who are forced to comply reactively.

False comfort: "We're too small to matter"
The DoD's stated concern is not the size of the contractor. It is the access path. A Tier 3 supplier who handles ballistic protection specifications for an active vehicle program represents a potential access point to sensitive technical data, regardless of how small the company is. Size does not determine risk; access to CUI does.

Preparing for a Prime Contractor Supply Chain Audit

Prime contractor audits of Tier 2 and Tier 3 suppliers vary in depth. Some are questionnaire-based, asking suppliers to self-certify compliance. Others involve on-site visits by the prime's supply chain security team. The most rigorous require evidence submission: policies, procedures, system diagrams, and SPRS score documentation.

Regardless of the audit format, the foundation of a defensible response is documentation. A supplier who has done the compliance work but cannot demonstrate it with documentation will receive the same outcome as a supplier who has not done the work. Documentation is not the bureaucratic burden that suppliers often treat it as. It is the evidence that protects you in an audit.

The Minimum Documentation Set

At minimum, a Tier 2 supplier should be able to produce a System Security Plan that describes the environment where CUI is handled, a SPRS score with the methodology documented, evidence of access control practices for CUI systems (user account management records, access review records), and a written cybersecurity policy covering the 14 CMMC domains at a high level.

Beyond that minimum, the documents that receive the most scrutiny in prime audits are incident response procedures (have you tested them?), configuration management evidence (what is on your network, and is it authorized?), and media management procedures (how do you handle portable storage that contains CUI?).

SPRS Score Submission and the Annual Affirmation

The Supplier Performance Risk System score is a number between negative 203 and positive 110 that represents your assessed compliance with NIST SP 800-171. Every contractor and subcontractor handling CUI under a DoD contract is required to submit this score to the SPRS system and update it when the score changes by more than a specified threshold.

The score itself is self-assessed. You calculate it by reviewing each of the 110 NIST 800-171 requirements and determining whether it is fully implemented, partially implemented, or not implemented. Requirements that are not implemented subtract points from the maximum score of 110 based on the DoD Assessment Methodology weighting. The final score is entered into SPRS along with your CAGE code, the date of the assessment, and the scope of systems assessed.

CMMC Level 2 added a separate requirement: the Senior Official Affirmation. This is an annual attestation, submitted by a company official with authority to bind the organization, affirming that the SPRS score is accurate and that the organization is complying with the requirements of DFARS 252.204-7012. The affirmation is a legal certification. Filing a false affirmation exposes the company and the individual signing it to False Claims Act liability.

For Tier 2 suppliers, the practical implication is that someone with authority at your company needs to understand what they are certifying before they certify it. If your compliance program exists only on paper or your SPRS score does not reflect your actual security posture, the affirmation creates legal exposure. The right approach is to build a compliance program that accurately reflects your environment, score it honestly, and certify the accurate score.

Frequently Asked Questions

My prime contractor told me to submit an SPRS score but has not told me what CMMC level is required. What should I do?

An SPRS score submission is required for NIST 800-171 compliance under DFARS 252.204-7012, independent of CMMC certification level. CMMC Level 2 certification (third-party assessment) is a separate requirement that applies when your contract explicitly requires it. If your prime is asking for an SPRS score, that is the DFARS 252.204-7012 obligation. Ask your prime specifically whether the contracts you hold require CMMC Level 2 certification or whether self-attestation under CMMC Level 1 is sufficient. Get the answer in writing.

We do not receive technical drawings. We only receive purchase orders with part numbers and quantities. Are we in scope?

Possibly, but it depends on what those part numbers reference. If the part numbers are associated with controlled defense articles and your subcontract flows DFARS 252.204-7012, the purchase order data itself may qualify as CUI under procurement and acquisition information categories. More importantly, if you are manufacturing parts to specifications you received at contract award or program kickoff, even if you no longer receive drawings on each purchase order, the specifications you are working from are CUI. The trigger is whether the data in your environment describes a controlled defense item, not whether you receive it on every transaction.

We are both a commercial and defense supplier. Do we have to bring our entire operation into CMMC scope?

Not necessarily, but clean segmentation is required. CMMC scope is defined by where CUI flows. If your defense program data is completely isolated from your commercial operations at the network level, with no shared systems, shared credentials, or shared storage, you may be able to limit your CMMC boundary to the defense-program environment. The segmentation must be real and demonstrable. Assessors will verify it. If the segmentation is not airtight, the entire shared environment is typically placed in scope.

What happens if we fail a prime contractor supply chain audit?

The outcome depends on the prime's policies and the severity of the gaps found. Common consequences include being placed on a corrective action plan with a deadline for remediation, being suspended from receiving new task orders while the plan is being executed, being required to submit a remediation plan and evidence of completion before subcontract renewal, and in cases of material non-compliance, removal from the approved vendor list. The relationships involved are commercial relationships, so the exact consequences are governed by your subcontract terms and the prime's supplier qualification program. What is consistent across programs is that non-compliant suppliers lose competitive position relative to compliant ones.

All 110. Tracked.

1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.

Request a Demo