Guide

CMMC Requirements for Subcontractors (2026) — Do I Need CMMC?

Last updated: 2026-03-02

Do Subcontractors Need CMMC? How the Flow-Down Works What Subcontractors Are Actually Required to Do What Primes Are Responsible For The Certification Is Organization-Specific

Do Subcontractors Need CMMC?

The short answer is: it depends on whether you handle Controlled Unclassified Information. If your work under a DoD prime contract involves receiving, generating, processing, storing, or transmitting CUI — technical drawings, specifications, program data, export-controlled information — then yes, CMMC applies to you. The obligation is not limited to prime contractors. It flows through every tier of the supply chain where CUI is present.

This is the question thousands of defense subcontractors are grappling with right now. Many have been operating under DoD primes for years, receiving technical data packages and delivering components or services, without ever formally addressing cybersecurity compliance. The enforcement record makes clear that this gap has real consequences — and that "my prime didn't tell me" is not a defense that has held up in court.

The Three-Question Test
Ask yourself three questions: (1) Do I receive technical drawings, specifications, or program information from a DoD prime? (2) Does my subcontract or the work itself involve information marked CUI, FOUO, or with a distribution statement? (3) Does my prime's contract with the DoD contain DFARS 252.204-7012? If the answer to any of these is yes — or if you don't know — assume CMMC applies and verify with your prime.

Subcontractors who do not handle CUI — for example, a commercial off-the-shelf component supplier who provides standard catalog items with no program-specific technical data involved — are generally not subject to CMMC requirements. The line is drawn at CUI, not at the fact of doing business with a DoD prime.

How the Flow-Down Works

DFARS 252.204-7012 contains an explicit flow-down obligation. Prime contractors whose DoD contracts include this clause are required to include the substance of the clause in all subcontracts where the subcontractor will process, store, or transmit covered defense information, or operate information systems that provide security protection for such information.

This is not a courtesy or a best practice. It is a contract requirement. A prime who fails to flow down DFARS 7012 to a CUI-handling subcontractor is in breach of their own DoD contract. And a subcontractor who receives CUI but has not been given the flow-down language is still bound by the obligation that attaches to the information itself — the absence of proper paperwork does not eliminate the underlying requirement.

What primes must flow downThe requirement to implement all 110 NIST SP 800-171 controls on systems handling CUI, maintain a current SPRS score, report cyber incidents to the DoD within 72 hours, and — once DFARS 252.204-7021 is present in the prime's contract — hold a valid CMMC Level 2 certification from an authorized C3PAO.
When it appliesThe flow-down is triggered by the presence of CUI in the subcontract scope. It is not triggered by dollar value, contract type, or the subcontractor's size. A $50,000 subcontract involving technical drawings for a defense system carries the same CMMC obligation as a $50 million one.
At every tierThe obligation does not stop at the first-tier subcontractor. A sub-subcontractor who receives CUI from the first-tier sub carries the same obligations. There is no tier at which the requirement evaporates. Every organization in the chain that touches CUI must comply.
Even without explicit languageIf you receive CUI from a prime contractor, the handling obligation attaches to that information regardless of whether your subcontract explicitly references DFARS 7012 or CMMC. The safe assumption for any defense subcontractor receiving technical data is that the requirement applies until you have confirmed with your prime that CUI is not involved.

What Subcontractors Are Actually Required to Do

Once you have determined that you handle CUI under a DoD subcontract, your obligations parallel those of a prime contractor. The fact that you are a subcontractor does not reduce the technical requirements — it only changes who you are accountable to for meeting them.

Implement NIST SP 800-171All 110 security requirements across 14 domains must be implemented on every system that processes, stores, or transmits CUI in your environment. This is the same technical bar that prime contractors must meet. There is no reduced version of NIST 800-171 for subcontractors.
Maintain a current SPRS scoreSubcontractors subject to DFARS 252.204-7019 must self-assess their NIST SP 800-171 implementation and submit the score to SPRS. The score must reflect your actual implementation posture — not your aspirational one. An inflated score is False Claims Act exposure regardless of whether you are a prime or a sub.
Build and maintain an SSPA System Security Plan documenting how each of the 110 requirements is implemented in your specific environment. Your prime may request a copy as part of supply chain risk management. Your C3PAO will use it as the primary artifact in your assessment.
Obtain CMMC Level 2 certificationOnce DFARS 252.204-7021 is flowed down through your prime's contract, you must hold a valid CMMC Level 2 certification from an authorized C3PAO as a condition of continuing to perform work. Self-attestation is not sufficient. The certification is specific to your organization and your systems — you cannot rely on your prime's certification.
Report cyber incidents within 72 hoursIf a cyber incident occurs on your systems that affects CUI received from a prime, you must report to the DoD within 72 hours through the DIBNet portal — and notify your prime immediately. Failure to report is a contract violation independent of the underlying incident.
Flow down to your own subsIf you subcontract any of your work to lower-tier suppliers who will handle CUI, you must flow the same obligations down to them. You become the prime relative to your own supply chain.

What Primes Are Responsible For

Prime contractors face a dual exposure problem when it comes to subcontractor compliance. They are responsible for meeting their own CMMC obligations, and they are responsible for ensuring that CUI they share with subcontractors is adequately protected at those downstream organizations. A breach at a subcontractor can create liability for the prime if the prime failed to properly flow down requirements or failed to exercise reasonable oversight.

The practical implication is that primes need a supply chain cybersecurity program, not just their own compliance posture. This means identifying which subcontractors handle CUI, ensuring flow-down language is in every applicable subcontract, obtaining compliance representations from subcontractors, and periodically verifying that those representations are accurate.

The Liability Gap Primes Often Miss
A prime contractor with a perfect CMMC Level 2 certification can still face False Claims Act exposure if they shared CUI with a subcontractor who was not compliant and represented to the DoD that their supply chain was adequately protected. The certification covers your systems. It does not certify the security posture of your subcontractors. That requires separate diligence.

What a comprehensive prime subcontractor compliance program looks like in practice:

CUI inventory by subcontractDocument which subcontractors receive CUI, what categories, and through what channels. This inventory determines which subs are in scope for CMMC flow-down and which are not.
Flow-down in every applicable subcontractDFARS 252.204-7012 language and, where required, CMMC certification requirements must be explicitly included in every subcontract where CUI is involved. Do not rely on blanket compliance clauses that do not specifically address cybersecurity.
Compliance representationsRequire subcontractors to represent that they have implemented NIST SP 800-171, maintain a current SPRS score, and hold the required CMMC certification level. Obtain these representations in writing, periodically renewed.
Verification rightsReserve the contractual right to verify a subcontractor's compliance posture — through SPRS score review, SSP review, or independent assessment. You may never exercise the right, but having it creates accountability.
Incident notification obligationsRequire subcontractors to notify you immediately of any cyber incident affecting CUI they received from you. Your own 72-hour DoD reporting clock may depend on information that originates at a subcontractor.
Certification failure consequencesDefine in the subcontract what happens if a subcontractor fails to achieve or maintain CMMC certification. Can you replace them mid-contract? Can you withhold payment? Do you have step-in rights? These are questions better addressed before an incident than during one.

The Certification Is Organization-Specific

One of the most common misconceptions among defense subcontractors is that a prime's CMMC certification covers their work. It does not. CMMC certification is issued to a specific organization for its specific systems and environment. It is not transferable, sharable, or extendable to other organizations in the supply chain.

If you are a subcontractor and CUI touches your systems — your servers, your workstations, your cloud storage, your email — you need your own CMMC certification. The prime's C3PAO assessment covered the prime's environment. It said nothing about yours.

This is why the supply chain compliance problem is significant in scale. There are estimated to be more than 80,000 organizations in the DoD supply chain. A fraction of them are prime contractors. The vast majority are subcontractors at various tiers. Each one that handles CUI needs its own certification. The C3PAO industry is not currently sized to assess that volume, which is precisely why lead times are extending and the November 2026 Phase 2 deadline requires action now rather than later.

What “Covered by the Prime” Actually Means
There is one narrow scenario where a subcontractor's systems may be considered within the prime's CMMC boundary: if the subcontractor's personnel work exclusively on the prime's systems, in the prime's environment, without any CUI touching systems the subcontractor owns or operates. This is an enclave model and requires explicit boundary documentation. If CUI ever touches a system your organization owns or controls — including your email, your laptop, your VPN endpoint — you are outside the prime's boundary and you need your own certification.

Timeline and Deadlines for Subcontractors

CMMC is being phased into DoD solicitations in four phases. For subcontractors, the relevant deadline is Phase 2, beginning November 2026, when the requirement becomes standard in new solicitations for contracts involving CUI. At that point, primes bidding on new CUI contracts will need to demonstrate that their subcontractors who handle CUI are CMMC-certified — or will be before work begins.

The practical timeline for a subcontractor starting today:

Now — Month 2Determine whether CMMC applies. Review your subcontracts for DFARS 7012 flow-down language. Ask your prime directly if CUI is involved. Conduct a gap assessment against NIST SP 800-171 and calculate your actual SPRS score. Submit an accurate score to SPRS if you have not done so.
Month 2 — Month 5Remediate identified gaps. Implement missing controls. Migrate to FedRAMP Moderate cloud services if needed. Build your System Security Plan. Build your POA&M for any remaining gaps. Begin engaging C3PAOs for pre-assessment readiness reviews — as of March 2026, booking lead times were running 3 to 6 months, though windows have been lengthening as Phase 2 approaches, so confirm current availability directly with a C3PAO.
Month 5 — Month 8Complete remediation. Finalize documentation. Conduct internal mock assessment. Book your C3PAO assessment. Assessment itself typically takes 2 to 5 on-site days plus 6 to 10 weeks for the full engagement including evidence review and report finalization.
Before November 2026Hold a valid CMMC Level 2 certification. Notify your primes. Update your SPRS record. Be positioned to represent compliance in any new solicitation your prime is pursuing under Phase 2 requirements.

This timeline is tight but achievable for organizations starting now. It is not achievable for organizations that wait until late 2026 to begin.

What Happens to Subcontractors Who Are Not Compliant

Non-compliant subcontractors face consequences on two tracks: from their prime and from the government directly.

From the prime: As CMMC requirements flow into subcontracts, primes will be required to ensure their subcontractors are certified. A subcontractor who cannot demonstrate CMMC compliance will face removal from the subcontract team — either replaced by a compliant sub or removed from the work scope. For subcontractors whose revenue is significantly tied to one or a few DoD primes, this is an existential business risk. The prime cannot put their own contract award at risk for a non-compliant sub.

From the government: Subcontractors are not shielded from direct False Claims Act exposure simply by virtue of being a sub. If a subcontractor submits claims or invoices under a government contract while knowingly misrepresenting their cybersecurity compliance posture, the FCA applies to them directly. The DOJ has pursued contractors at various levels of the supply chain, and the whistleblower mechanism — which produced four of the five major CMMC enforcement settlements — is available to employees at any level of the organization.

The Business Risk Is Concrete
Defense subcontractors should think about CMMC compliance the same way they think about quality certifications like AS9100 or ITAR registration. Primes require it. Without it, you cannot participate. The difference is that CMMC carries criminal and civil enforcement exposure that quality certifications do not. The downside of non-compliance is not just lost business — it is potential treble damages and per-claim FCA penalties applied to every invoice submitted during the period of non-compliance.

Special Situations

Several common subcontractor scenarios create specific questions about CMMC applicability that do not have obvious answers.

COTS suppliersCommercial off-the-shelf product suppliers who provide standard catalog items without receiving any CUI from the prime are generally not subject to CMMC requirements. The key question is whether any program-specific CUI — drawings, specifications, acceptance criteria — flows to the supplier. If the answer is no, CMMC likely does not apply. Confirm this in writing with your prime.
IT and managed service providersMSPs who manage or operate systems that process CUI on behalf of a defense contractor are within scope for CMMC requirements. If your IT provider has access to systems containing CUI — including remote management access, backup systems, or cloud infrastructure — they are handling CUI and must comply. This is one of the most commonly overlooked flow-down scenarios in the defense supply chain.
Engineering and design firmsEngineering subcontractors who receive technical data packages and produce drawings, analyses, or designs for defense programs are almost certainly handling CUI. Controlled Technical Information is the most prevalent CUI category in the defense supply chain and it flows routinely to engineering subs. CMMC applies.
Testing and certification labsLabs that perform acceptance testing, environmental testing, or certification testing for defense components frequently receive technical specifications and test requirements that qualify as CUI. If the test documentation or results reference program-specific technical data, the lab is handling CUI and the obligation applies.
Foreign subcontractorsNon-US subcontractors who handle CUI under DoD prime contracts are not exempt from CMMC requirements. CMMC applies based on where CUI is handled, not where the contractor is incorporated. Foreign subs handling CUI must also navigate ITAR and EAR export control implications, which add additional layers of restriction on top of CMMC requirements.
Single-employee subsCompany size is not a factor. A sole proprietor or single-employee subcontractor who handles CUI carries the same 110-requirement obligation as a 500-person firm. The controls scale in implementation complexity but not in requirement count. Small subcontractors often find that their simplicity is actually an advantage — a smaller environment is easier to scope, document, and assess.

Frequently Asked Questions

Do subcontractors need CMMC certification?

It depends on whether you handle CUI. If your work under a DoD subcontract involves receiving, processing, storing, or transmitting Controlled Unclassified Information, you are subject to CMMC requirements. This applies regardless of your company size, your tier in the supply chain, or whether your subcontract paperwork explicitly references CMMC. Subcontractors who handle only commercial off-the-shelf products with no program-specific CUI involved are generally not required to certify.

Can I rely on my prime's CMMC certification?

No. CMMC certification is organization-specific. It covers the certified organization's systems and environment only. If CUI touches your systems — your servers, your workstations, your email, your cloud storage — you need your own certification from an authorized C3PAO. There is no umbrella or pass-through arrangement under CMMC.

What if my subcontract doesn't mention CMMC?

The absence of CMMC language in your subcontract does not eliminate the obligation if you handle CUI. The requirement flows from the prime's DoD contract. If you receive technical data, drawings, or program information from a prime contractor, assume CUI requirements apply and confirm with your prime. Do not wait for a formal flow-down notice that may never come.

Do sub-subcontractors (tier 3+) need CMMC?

Yes, if they handle CUI. The flow-down applies at every tier where CUI is present. A third-tier subcontractor who receives technical specifications from a second-tier sub carries the same 110-requirement NIST SP 800-171 obligation and the same CMMC certification requirement as a direct subcontractor. There is no tier exemption.

Does my IT provider need CMMC?

If your IT provider manages or has access to systems that contain CUI — including remote management, backup systems, cloud infrastructure, or helpdesk tools that touch CUI systems — they are handling CUI and are subject to CMMC requirements. MSPs supporting defense contractors are one of the most commonly overlooked flow-down scenarios. If your IT provider does not have their own CMMC compliance program, that is a gap in your supply chain.

What is the CMMC deadline for subcontractors?

Phase 2 begins November 2026, at which point new DoD solicitations for CUI contracts will require CMMC Level 2 certification. This applies equally to primes and subcontractors. With C3PAO booking lead times running 3 to 6 months as of March 2026 — and lengthening as Phase 2 approaches — subcontractors who need certification before November 2026 should be initiating the process now. Waiting until mid-2026 creates significant risk of missing the window.

Can a prime be held responsible for its subcontractor's breach?

Yes. Primes are responsible for ensuring that CUI shared with subcontractors is adequately protected. If a subcontractor suffers a CUI breach and the prime failed to properly flow down DFARS 7012 requirements or failed to verify the subcontractor's compliance, the prime may bear responsibility. This is why a supply chain cybersecurity program — not just the prime's own compliance posture — is essential.

We are a small company. Does CMMC still apply?

Yes. Company size is not a factor in CMMC applicability. A sole proprietor who handles CUI has the same 110-requirement obligation as a large defense contractor. The implementation may be simpler — a smaller environment with fewer systems is faster to scope, document, and assess — but the requirement count does not change. Small subcontractors sometimes find the assessment process more straightforward than they expected once the documentation is in order.

Built for the DIB.

1TEN tracks your control posture across all 110 NIST SP 800-171 requirements and generates C3PAO-ready documentation automatically.

Request a Demo