Physical Security & Access Control

Supplier Management Flow-Down Tracking · Vendor Risk · Compliance Status

Third-party vendors who handle CUI or access CUI systems inherit CMMC compliance obligations from your contracts. The Supplier Management module tracks which vendors have those obligations, whether they're meeting them, and whether your flow-down documentation can survive assessor scrutiny.

SR Domain practices supported
Flow-down Clause tracking built in
Vendor Risk ratings per supplier
The problem this solves
Most defense contractors can name their major vendors. Few can immediately answer which of those vendors handles CUI, which contracts contain DFARS 252.204-7012 flow-down clauses, and what documentation exists confirming each vendor's compliance posture. When a C3PAO assessor asks about supply chain risk management. And they increasingly do. The answer needs to be a documented vendor list with compliance status, not a verbal description of relationships.

Supplier Profiles and Flow-Down Tracking

Each supplier record captures the vendor name, services provided, whether CUI is shared with the vendor, the applicable DFARS clauses flowed down in the contract, contract expiration date, and current CMMC compliance status. Supporting documentation. Supplier self-assessments, flow-down confirmation letters, and NDAs. Can be attached directly to the supplier record.

DFARS 252.204-7012 requires prime contractors to flow cybersecurity obligations down to subcontractors who handle Covered Defense Information. The module tracks which clauses are in each supplier contract and flags relationships where flow-down documentation is missing, expired, or where the supplier's CMMC status is unverified. These are the gaps that create liability during a prime's supply chain audit or a C3PAO assessment.

Dashboard Requirements Evidence POA&M Reports
1TEN Supplier Management interface tracking subcontractor CMMC compliance and CUI flow-down

Vendor Risk Ratings and Assessment Preparation

Each supplier is assigned a risk rating based on the sensitivity of the CUI they handle, the access they have to your systems, and their documented compliance posture. High-risk suppliers. Those with system access or who handle the most sensitive data. Receive greater scrutiny in the register and drive more detailed documentation requirements.

C3PAO assessors examine supply chain risk management as part of the Security Assessment (CA) and broader organizational risk controls. Arriving at an assessment with a populated supplier register, documented flow-down status, and attached compliance documentation for each high-risk vendor demonstrates a level of supply chain awareness that most small contractors cannot match. It changes the assessor's question from "do you know who your vendors are" to "walk me through your highest-risk supplier relationship."

What You See Inside

  • *Supplier records capturing vendor name, services, CUI sharing status, applicable DFARS clauses, contract expiration, and CMMC compliance status
  • *Flow-down clause tracking. Which DFARS and CMMC obligations are in each supplier contract
  • *Compliance status field. Not Required, Self-Attested, C3PAO Certified, or Unknown. Per supplier
  • *Risk rating per supplier. High, Medium, or Low. Based on CUI sensitivity and system access
  • *Document attachments per supplier. Self-assessments, flow-down letters, NDAs, supplier agreements
  • *Missing flow-down flag. Relationships where required clauses are absent or documentation is unattached
  • *Contract expiration tracking. Renewal dates surfaced before they lapse and flow-down obligations need to be re-established
  • *Supplier register section included in SSP Export. Assessors receive the vendor list as part of the system security plan package

Supplier Record Fields

Field Purpose
Vendor name and servicesIdentifies the supplier and the nature of their engagement
CUI sharedWhether CUI is transmitted to or accessible by this vendor. The trigger for flow-down obligations
System accessWhether the vendor has access to in-scope systems. Affects risk rating and maintenance log integration
DFARS clauses flowedWhich specific clauses (7012, 7019, 7020, 7021) are included in the supplier contract
CMMC compliance statusNot Required / Self-Attested / C3PAO Certified / Unknown. Per supplier
Risk ratingHigh / Medium / Low. Based on CUI sensitivity and access level
Contract expirationRenewal date with advance alert to ensure flow-down obligations are re-established
Supporting documentsAttachments: self-assessments, flow-down confirmation letters, NDAs, supplier agreements

What this replaces

  • *No supplier register at all. The most common situation, and the one that creates the most assessor scrutiny
  • *Vendor contact lists in procurement systems with no compliance status, risk rating, or flow-down documentation
  • *Flow-down clauses included in contracts but no documentation that the vendor acknowledged or is meeting the obligation
  • *No visibility into which vendor contracts have expired. Flow-down obligations lapsed without anyone noticing
  • *Supporting compliance documents for vendors scattered across email, shared drives, and paper files with no connection to the supplier record

Practices Satisfied

Practice IDDescription
SR Domain Supply chain risk management practices. Identifying, assessing, and responding to risks associated with third-party vendors who handle CUI or access CUI systems.
CA.L2-3.12.1 Periodically assess the security controls in organizational systems. Supplier compliance status is part of the organizational control environment subject to periodic review.

Related Modules

Risk Register
High-risk supplier relationships can be entered as formal risk register items. Linking supply chain exposure to the organization's risk posture.
Evidence Manager
Supplier compliance documents attached in Supplier Management are also linked in the Evidence Manager to the SR domain requirements they satisfy.
Maintenance Log
Vendor service visits are logged in the Maintenance Log. The supplier record provides context for who was on-site and what system access they had.
SSP Export
The supplier register is included in the SSP Export. Assessors receive the vendor list and compliance status as part of the system security plan package.
See Supplier Management in action.

Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.

Request a demo