Supplier Profiles and Flow-Down Tracking
Each supplier record captures the vendor name, services provided, whether CUI is shared with the vendor, the applicable DFARS clauses flowed down in the contract, contract expiration date, and current CMMC compliance status. Supporting documentation. Supplier self-assessments, flow-down confirmation letters, and NDAs. Can be attached directly to the supplier record.
DFARS 252.204-7012 requires prime contractors to flow cybersecurity obligations down to subcontractors who handle Covered Defense Information. The module tracks which clauses are in each supplier contract and flags relationships where flow-down documentation is missing, expired, or where the supplier's CMMC status is unverified. These are the gaps that create liability during a prime's supply chain audit or a C3PAO assessment.
Vendor Risk Ratings and Assessment Preparation
Each supplier is assigned a risk rating based on the sensitivity of the CUI they handle, the access they have to your systems, and their documented compliance posture. High-risk suppliers. Those with system access or who handle the most sensitive data. Receive greater scrutiny in the register and drive more detailed documentation requirements.
C3PAO assessors examine supply chain risk management as part of the Security Assessment (CA) and broader organizational risk controls. Arriving at an assessment with a populated supplier register, documented flow-down status, and attached compliance documentation for each high-risk vendor demonstrates a level of supply chain awareness that most small contractors cannot match. It changes the assessor's question from "do you know who your vendors are" to "walk me through your highest-risk supplier relationship."
What You See Inside
- *Supplier records capturing vendor name, services, CUI sharing status, applicable DFARS clauses, contract expiration, and CMMC compliance status
- *Flow-down clause tracking. Which DFARS and CMMC obligations are in each supplier contract
- *Compliance status field. Not Required, Self-Attested, C3PAO Certified, or Unknown. Per supplier
- *Risk rating per supplier. High, Medium, or Low. Based on CUI sensitivity and system access
- *Document attachments per supplier. Self-assessments, flow-down letters, NDAs, supplier agreements
- *Missing flow-down flag. Relationships where required clauses are absent or documentation is unattached
- *Contract expiration tracking. Renewal dates surfaced before they lapse and flow-down obligations need to be re-established
- *Supplier register section included in SSP Export. Assessors receive the vendor list as part of the system security plan package
Supplier Record Fields
| Field | Purpose |
|---|---|
| Vendor name and services | Identifies the supplier and the nature of their engagement |
| CUI shared | Whether CUI is transmitted to or accessible by this vendor. The trigger for flow-down obligations |
| System access | Whether the vendor has access to in-scope systems. Affects risk rating and maintenance log integration |
| DFARS clauses flowed | Which specific clauses (7012, 7019, 7020, 7021) are included in the supplier contract |
| CMMC compliance status | Not Required / Self-Attested / C3PAO Certified / Unknown. Per supplier |
| Risk rating | High / Medium / Low. Based on CUI sensitivity and access level |
| Contract expiration | Renewal date with advance alert to ensure flow-down obligations are re-established |
| Supporting documents | Attachments: self-assessments, flow-down confirmation letters, NDAs, supplier agreements |
What this replaces
- *No supplier register at all. The most common situation, and the one that creates the most assessor scrutiny
- *Vendor contact lists in procurement systems with no compliance status, risk rating, or flow-down documentation
- *Flow-down clauses included in contracts but no documentation that the vendor acknowledged or is meeting the obligation
- *No visibility into which vendor contracts have expired. Flow-down obligations lapsed without anyone noticing
- *Supporting compliance documents for vendors scattered across email, shared drives, and paper files with no connection to the supplier record
Practices Satisfied
| Practice ID | Description |
|---|---|
| SR Domain | Supply chain risk management practices. Identifying, assessing, and responding to risks associated with third-party vendors who handle CUI or access CUI systems. |
| CA.L2-3.12.1 | Periodically assess the security controls in organizational systems. Supplier compliance status is part of the organizational control environment subject to periodic review. |
Related Modules
Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.