Skip to content

cybersecurity

CMMC for Subcontractors: What Tier 2 DoD Vendors Need to Know

CMMC flow-down requirements apply to subcontractors who handle CUI, not just prime contractors. Here is how DoD subcontractors determine their required level, what primes expect, and how Hampton Roads supply chain companies get to readiness.

By Wakeem Williams
Subcontractor reviewing CMMC flow-down requirements for DoD work
Photo: Vanessa Garcia / Pexels

If you are a subcontractor to a DoD prime, CMMC requirements may already apply to your business. Whether they do depends on one thing: whether you touch Controlled Unclassified Information as part of your work. If you do, the flow-down requirements in your subcontract carry the same legal weight as the prime’s prime contract clause.

This article is for Tier 2 and Tier 3 vendors who are not prime contractors but are part of a defense supply chain. You know CMMC is coming. You are trying to figure out exactly what applies to you, what your prime expects, and what the path forward actually looks like. Especially if you are in Newport News, Hampton, or anywhere else in Hampton Roads where the defense industrial base runs deep.

What Flow-Down Requirements Are

When the DoD includes DFARS 252.204-7021 in a contract, that clause requires the prime contractor to achieve a specified CMMC level before performing work that involves CUI. The clause also requires primes to pass that obligation down the supply chain.

That is the flow-down. Every subcontractor who receives, transmits, generates, or processes CUI in support of the prime’s scope is covered. The prime cannot simply wall off compliance at their own boundary and call it done. The DoD designed the program this way deliberately: a prime’s security posture is only as strong as the weakest link in the subcontract chain.

What the flow-down does NOT do is automatically require a subcontractor to achieve the same level as the prime. The prime has some discretion. If a sub only handles certain types of CUI and not the full scope of the prime’s CUI environment, the prime may specify a lower required level in the subcontract. If the sub handles no CUI at all, CMMC may not apply to them under that contract.

This matters because many subcontractors assume they either need everything the prime needs or nothing at all. Reality is more nuanced, and getting it wrong in either direction is expensive.

How a Subcontractor Determines Their Required Level

The prime contractor is your primary source of truth here. When DFARS 252.204-7021 flows down to a subcontract, the prime is responsible for communicating the required CMMC level to the sub. That communication should be in the subcontract itself.

If your subcontract does not specify a CMMC level, or if the language is ambiguous, do not guess. Ask the prime program manager or contracting officer directly: “What CMMC level is required under this subcontract?” and “Does my scope of work involve CUI?” Get the answer in writing.

The general logic is straightforward:

If your work involves CUI, you are almost certainly looking at CMMC Level 2 and the full 110-control requirement from NIST SP 800-171 Rev 2.

If your work involves Federal Contract Information but not CUI (think: basic procurement data, administrative information, non-sensitive technical deliverables), Level 1 with its 17 basic safeguarding controls may be the requirement.

If you genuinely handle no government information in your scope, CMMC may not apply. But confirm this with the prime. Do not self-determine based on your own read of your work scope.

To understand the CUI definitions that drive these determinations, the CUI explainer is worth reading before your next conversation with your prime.

What Primes Actually Expect from Their Subs

The formal requirement is CMMC level compliance. The practical expectation, increasingly, is documentation that proves you are on the path before work begins.

Large defense primes have started requesting these before awarding subcontracts:

A current SPRS score. The Supplier Performance Risk System score is the number a contractor generates through a formal NIST SP 800-171 assessment. It ranges from -203 (every control missing) to 110 (all controls implemented). Primes pull SPRS scores to screen their supply chains. A missing score or a score well below zero signals risk to the prime’s own compliance posture.

A System Security Plan. The SSP is the document that describes your system boundary, the CUI in scope, your people and roles, and how each NIST 800-171 control is addressed in your environment. Primes may not read your SSP cover to cover, but they will ask whether you have one. If you say no, you have just told them you are not compliant.

A Plan of Action and Milestones. If you have control gaps, the POA&M documents what they are, what you are doing to close them, and by when. Primes understand that most organizations have open items. A credible POA&M signals maturity. No POA&M signals either overconfidence or inattention.

Evidence of scheduled or completed C3PAO assessment (where required). For contracts involving prioritized CUI programs, the prime cannot take your word for it. They need third-party verification. If your prime is under that requirement, they will ask you to provide proof that you have scheduled or completed your own C3PAO assessment.

Newport News Shipbuilding, Huntington Ingalls, and the broader Hampton Roads defense contractor ecosystem are all navigating this simultaneously. Primes with dozens of subcontractors are starting to standardize what they ask for and when. The subs who have their paperwork in order before they are asked for it win work. The ones who scramble after a prime makes it a condition of award lose time they do not have.

Common Gaps in Subcontractor Environments

Small subcontractors tend to have a predictable set of compliance gaps. Understanding them ahead of your formal gap assessment helps you prioritize resources.

No System Security Plan. Many small businesses handle CUI on shared drives, personal laptops, or in cloud tools without ever defining where CUI lives or how it is protected. Writing an honest SSP requires defining your system boundary precisely, which is harder than it sounds. It also reveals gaps you did not know you had.

No multi-factor authentication on remote access. NIST 800-171 control 3.5.3 requires MFA for all remote access to systems containing CUI. This is not optional, and it is not satisfied by a password alone. Small subs running VPNs without MFA, or using remote desktop tools with single-factor logins, fail this control immediately.

No audit logging. Controls in the Audit and Accountability family require logging of user activity and security events, retaining those logs long enough to be useful, and protecting them from tampering. Many small businesses have no logging infrastructure at all.

Flat networks with no CUI segmentation. If every device in your office can reach every other device, and CUI lives somewhere on that network, you have a problem under the System and Communications Protection family. Segmenting the environment to limit CUI access is an infrastructure project, not a policy update.

No documented incident response plan. When something goes wrong, DFARS 252.204-7012 requires reporting covered cyber incidents to the DoD within 72 hours. Subcontractors without a documented incident response plan often discover this requirement only when they need to use it, which is the worst time to discover it.

These gaps are fixable. None of them are rare edge cases. Almost every small subcontractor we have assessed in Hampton Roads has at least two or three of them.

The Path to Readiness

Start with an honest gap assessment. Not a self-administered checklist, but a structured review against all 110 NIST SP 800-171 controls that produces a scored SPRS number and a prioritized list of open items. Without that baseline, you are spending remediation budget without knowing whether you are spending it in the right places.

The SSP comes next. The SSP is not a compliance artifact you produce after fixing everything. It is a living document you build as you work through remediation, reflecting your actual environment at each point in time. Many organizations make the mistake of writing the SSP last. That approach means your remediation decisions are made without a clear record of what system they apply to.

Remediation follows the gap list. Prioritize based on severity. Controls that fail at high weight under the CMMC assessment methodology affect your SPRS score more than lower-weight controls. If you have a limited runway before a prime asks for proof, know which controls move the needle most.

For subcontractors uncertain whether their path requires a C3PAO third-party assessment or self-assessment, the answer depends on the contract designation. Ask your prime. If the contract involves prioritized CUI, plan for a third-party assessment and factor in both the timeline (C3PAOs book out months in advance) and the cost (assessments typically range from $30,000 into six figures depending on environment size and complexity).

The CMMC requirements overview for Hampton Roads contractors covers the program structure if you want the broader context on all three levels before digging into specifics.

Hampton Roads Defense Supply Chain Reality

Hampton Roads sits at the center of one of the densest defense contractor ecosystems in the country. Newport News Shipbuilding, the Norfolk Naval Station, Langley Air Force Base, and the dozens of commands based in the region create a subcontract supply chain with thousands of small vendors.

The companies in that supply chain range from engineering firms and IT services companies to precision manufacturers and staffing firms with cleared personnel. Many of them have handled CUI for years under DFARS 252.204-7012 without ever completing a formal NIST 800-171 assessment. CMMC changes that, because it requires proof rather than self-representation.

The timeline pressure is real. CMMC clauses are appearing in new contracts now and will be routine in most DoD contracts by 2028. Subcontractors who start their readiness programs in 2025 or 2026 have time to do this correctly. Subcontractors who wait until a prime makes it a condition of award will be scrambling with far less room for error.

Where Helix Stax Fits

Helix Stax works with small Hampton Roads defense subcontractors on CMMC readiness and NIST 800-171 compliance. That includes gap assessments against all 110 controls, SPRS scoring, SSP development, and practical remediation planning.

To be direct about scope: our practice is built around CMMC Level 2 readiness and NIST 800-171 implementation. We do not have Level 3 engagements in our portfolio. If your contract involves Level 3 (CUI requiring enhanced protection, Advanced Persistent Threat alignment), you should be working with a firm that has that track record specifically.

If you are at the beginning of figuring out what applies to your subcontract and where your gaps are, the Free IT Assessment is a straightforward starting point. You walk away with a clearer picture of your current posture before any prime starts asking questions.

The earlier you start, the more options you have. Once a prime makes CMMC compliance a condition of subcontract award and gives you a 90-day window, your options narrow considerably.

Questions

Frequently asked questions about Helix Stax managed IT services

Yes, if the subcontractor handles FCI or CUI under a contract that includes CMMC requirements. The requirement flows down from the prime through subcontract language. The required level depends on the information the subcontractor receives, stores, processes, or transmits, not simply its tier.

Most subcontractors handling only FCI need Level 1. Subcontractors handling CUI usually need Level 2 with 110 NIST SP 800-171 practices. For the broader Hampton Roads contractor view, see our CMMC requirements guide at /blog/cmmc-requirements-small-hampton-roads-contractors/ before planning remediation work internally.

CMMC flows down through subcontract clauses. If a prime includes CMMC requirements in the subcontract, lower-tier subcontractors must meet the level tied to their data access. A lower-tier supplier that never receives CUI may have a lower obligation than one that processes CUI directly.

Yes. Once CMMC requirements appear in a covered contract, a prime may have to verify subcontractor compliance before allowing CUI or FCI work. A subcontractor without the required status, SPRS record, or assessment evidence can be removed from consideration even if its technical work is strong.

Primes are directly accountable to the contracting officer and must flow requirements down. Subcontractors must meet the level that matches their own scope and report evidence to the prime. The same data rules apply, but the reporting path and contract accountability differ.

Primes usually verify through SPRS records, subcontract documentation, and evidence of self-assessment or C3PAO assessment where required. Some primes ask for an SSP, POA&M status, or proof of scheduled assessment. They carry risk if they let noncompliant subcontractors handle CUI.

CMMC requirements began phasing into DoD contracts in 2025, with broader implementation expected through 2028. Subcontractors should not wait for a prime to ask. A current SPRS score, defined CUI scope, and remediation plan make the next subcontract conversation easier.

A failed assessment means the subcontractor does not receive certification for that level. The company can remediate gaps and schedule follow-up review, but it cannot claim the level while deficiencies remain. A prime may need another supplier for CUI-handling work during that period.

Suppliers providing only commercial off-the-shelf products with no CUI access are generally outside CMMC scope for that work. Customization, integration, support, or access to government information can change the answer. Confirm the subcontract scope with the prime before assuming an exemption.