Hull, drivetrain, armor, and vehicle systems suppliers supporting Abrams, Bradley, JLTV, and next-gen programs are handling technical CUI on the shop floor with no compliance infrastructure. Flow-down obligations don't wait for you to be ready.
DFARS 252.204-7012 requires primes to flow cybersecurity and CUI protection obligations down to every subcontractor who handles Covered Defense Information, at every tier. There is no lower limit. A Tier 3 components supplier to a JLTV Tier 1 has the same legal obligation as the prime. Prime contractors for major ground vehicle programs are now conducting supply chain audits, requiring SPRS score submissions, and writing CMMC compliance into subcontract renewals. Suppliers who cannot demonstrate compliance are losing access to new task orders.
Drawings and models for armor, powertrain, hull, and suspension components received under DoD contracts are CUI. The systems where they live are in your assessment boundary.
Ballistic protection specs, blast resistance parameters, and mobility requirements arriving as procurement attachments are CUI, not generic purchase order terms.
Inspection records, material certifications, and first article reports you generate for defense program parts are CUI even though you created them.
Workstations used to access prime supplier portals that contain CUI are in scope. Data in browser cache, download folders, and local storage is CUI in your environment.
Ground vehicle prime contractors are auditing supply chains now. Suppliers without a compliance program documented and defensible are the ones removed from vendor lists. Talk to us about where you stand.
Prime contractor supply chain audits vary in depth, from self-certification questionnaires to on-site reviews by the prime's security team. Regardless of format, the foundation of a defensible response is documentation. A supplier who has done the work but cannot demonstrate it receives the same outcome as one who hasn't. At minimum, a ground vehicle Tier 2 supplier needs a System Security Plan, a documented SPRS score with methodology, access control evidence, and a written cybersecurity policy covering the 14 CMMC domains. 1TEN generates all of it from guided interviews conducted entirely on-premises.
Your honest score calculated from actual implementation, not a template estimate, ready for submission and prime audit review.
Generated from your implementation data. Describes your CUI boundary, in-scope systems, and how each of the 110 requirements is met.
Written policies across all 14 CMMC domains, tailored to your environment, not generic templates that assessors immediately recognize as boilerplate.
Gaps documented with milestone plans, responsible owners, and completion tracking so you can show progress to primes and assessors over time.
1TEN tracks your control posture across all 110 NIST SP 800-171 requirements and generates C3PAO-ready documentation automatically.
Request a Demo