The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC Flowdown Requirements: The Prime-to-Subcontractor Decision Guide (2026)

By The Defense Compliance Report Editorial Team— an independent trade publication on CMMC 2.0 and DIB compliance.

Last verified:

The Defense Compliance Report is not affiliated with, endorsed by, or sponsored by the U.S. Department of Defense, the Cyber AB, DCMA DIBCAC, NIST, or any U.S. government agency. This page is informational and is not legal, contractual, or compliance advice.

A prime just sent you a clause, a supplier questionnaire, or a one-line demand: “Be CMMC Level 2 by [date].” Suddenly a 12-person shop is staring down a compliance project nobody budgeted for — and if you’re the prime, the worry runs the other way: am I liable if a supplier fails, and which of my vendors does this even touch?

Here’s the bottom line. CMMC flowdown requirementsmean a Department of Defense prime contractor — and every higher-tier subcontractor above you — must pass the correct Cybersecurity Maturity Model Certification (CMMC) requirement down to any subcontractor whose information systems will process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) in performance of the contract. The level a subcontractor needs is set by the information that flows to them, not by the prime’s level: FCI only maps to Level 1; CUI maps to at least Level 2; and even under a Level 3 prime contract, a CUI-handling subcontractor’s floor is Level 2 with a third-party assessment — not Level 3. Subcontracts solely for commercially available off-the-shelf (COTS) items are excluded (32 CFR § 170.23; DFARS 252.204-7021).

That’s the rule. What trips teams up isn’t the rule — it’s over-applyingit. The fastest way to burn budget and your supplier base is to blast “everyone must be Level 2” down the chain when half those suppliers never touch CUI. Below, we map exactly who needs what, what proof to ask for, what not to demand, and when a third-party assessor is actually required. We read the controlling regulation and the current clause text ourselves to build it.

Fast answer: what CMMC requirement flows down?

32 CFR § 170.23; DFARS 252.204-7021 (NOV 2025)

A subcontractor falls under CMMC flowdown only when it will process, store, or transmit FCI or CUI on its own systems in performance of a DoD subcontract. FCI-only work requires CMMC Level 1 (annual self-assessment); CUI work requires at least Level 2; CUI under a Level 2 (C3PAO) or Level 3 prime contract requires Level 2 with a third-party assessment. The legal basis is 32 CFR § 170.23, and the contract mechanism is DFARS 252.204-7021, effective November 10, 2025.

View at ecfr.gov
If the subcontractor handles…Minimum CMMC statusAssessment typeWhat the prime must do
No FCI or CUI (and no access to covered systems)No CMMC flowdown from the data triggerNoneDocument why no covered information flows
FCI onlyLevel 1Annual self-assessment + annual affirmationRequest Level 1 status/affirmation evidence
CUI, prime contract allows self-assessmentLevel 2 (Self)Triennial self-assessment + annual affirmationRequest CMMC status evidence + scope
CUI, prime contract requires Level 2 (C3PAO)Level 2 (C3PAO)Third-party assessment every 3 yearsRequest CMMC UID + status + assessment scope
CUI under a Level 3 (DIBCAC) prime contractLevel 2 (C3PAO) minimumThird-party assessment (not Level 3 by default)Do not assume Level 3 unless DoD says so
Cloud or external IT provider touching CUIScope-dependentScope-dependentVerify cloud authorization + responsibility split

C3PAO = Certified Third-Party Assessment Organization, the firms authorized to perform CMMC Level 2 certification assessments. DIBCAC = the Defense Industrial Base Cybersecurity Assessment Center, the DoD body that conducts Level 3 assessments.

Not sure which row a specific supplier fits? The CMMC Flowdown Level Finder lets you classify the relationship before you request quotes or demand Level 2.

Use the Flowdown Level Finder →

What CMMC flowdown requirements actually mean

32 CFR § 170.23

CMMC flowdown is the contractual obligation that requires a prime or higher-tier subcontractor to pass the correct CMMC requirement to subcontractors that process, store, or transmit FCI or CUI. The core rule is not “every subcontractor inherits the prime’s level” — the required level depends on the information and systems each subcontractor will touch.

View at ecfr.gov

Strip away the acronyms and flowdown is simple: when the government puts a cybersecurity requirement in a prime contract, that requirement has to travel into the subcontracts where sensitive information actually goes. CMMC is the framework DoD uses to confirm that defense contractors protect two kinds of information — FCI (Federal Contract Information: non-public information generated for or provided under a contract) and CUI (Controlled Unclassified Information: information the government requires to be safeguarded under law or policy). The program rule lives at 32 CFR Part 170, which became effective December 16, 2024. The contract clause that carries it lives at DFARS 252.204-7021 (Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements), whose current version is dated November 2025.

Two parts of that clause do the work. Paragraph (d) requires the contractor to “consult 32 CFR 170.23 related to the flowdown of the CMMC requirements, and flow down the correct CMMC level to subcontracts.” Paragraph (f) requires the contractor to insert the substanceof the clause into qualifying subcontracts and, before awarding any subcontract, to ensure the subcontractor holds a current CMMC status “appropriate for the information that is being flowed down.” We pulled that language directly from the clause on Acquisition.gov on June 17, 2026.

The key word is appropriate. Flowdown is not a copy-paste of the prime’s certification onto every vendor. It’s a routing decision driven by data.

What flowdown is not

That’s the whole tension on this page: getting flowdown right usually means flowing down less than the instinct says.

Which subcontractors are actually in scope?

32 CFR § 170.23(a)

A subcontractor is in scope when it will process, store, or transmit FCI or CUI on contractor information systems in performance of the DoD contract or subcontract, at any tier of the supply chain. If no covered information is shared and the subcontractor never touches covered systems, the correct move is to document that determination — not to reflexively require Level 2.

View at ecfr.gov

Scope comes down to three tests. Run a supplier through all three.

Test 1 — The data test: none, FCI, CUI, CDI, or SPD

Test 2 — The system test: process, store, or transmit

The trigger is whether the supplier handles covered information on its own systems. Examples that count: emailing CUI, storing CUI drawings, running an IT system that protects the CUI boundary, or administering the tenant where CUI lives. A supplier that only viewsCUI inside a prime-controlled portal — with no download, no local storage — may sit in a different scoping position. Treat that as a scoping question to document carefully, not a loophole to assume.

Test 3 — The tier test: it does not stop at Tier 1

CMMC applies “throughout the supply chain at all tiers” where FCI or CUI is processed, stored, or transmitted (32 CFR § 170.23(a)). If your Tier 1 sub passes CUI to a heat treater or a specialty-process shop, the requirement follows the data down to that lower tier too.

The original part here:we’ve turned the rule into a clean three-test filter — data → system → tier— so you can sort an entire vendor list without guessing. Most competing pages tell you “CMMC flows down.” Few hand you the filter that tells you when it doesn’t.

What CMMC level does each subcontractor need? (the decision matrix)

32 CFR § 170.23(a)(1)–(4)

A subcontractor's required CMMC status is determined by the information it receives and the prime contract's required assessment type: FCI-only → Level 1 (Self); CUI → Level 2 (Self) minimum; CUI where the prime requires Level 2 (C3PAO) → Level 2 (C3PAO); and CUI where the prime requires Level 3 (DIBCAC) → Level 2 (C3PAO) minimum, unless DoD gives contract-specific flowdown guidance.

View at ecfr.gov

This is the section to bookmark. We built the matrix below by combining six things competitors usually scatter across separate pages: the supplier’s data trigger, the minimum CMMC status, the assessment type, the evidence to request, what notto over-require, and the provider category that fits if help is needed — each anchored to a primary source.

The Prime-to-Subcontractor CMMC Flowdown Decision Matrix

Supplier situationData triggerMinimum CMMC statusAssessment typeEvidence to requestDo not over-requireBest-fit provider categorySource
Supplier receives no FCI/CUI; no covered-system accessNoneNo CMMC flowdown from the data triggerNoneA documented no-FCI/no-CUI determinationDon’t demand Level 2 because the prime is Level 2Scoping advisor only if genuinely unsure32 CFR § 170.23
Supplier receives FCI onlyFCILevel 1Annual self-assessment + annual affirmationLevel 1 status/affirmation, CAGE code, scopeDon’t require the full 110 Level 2 controls unless CUI is actually involvedLevel 1 / basic-safeguarding readiness32 CFR § 170.23(a)(1); FAR 52.204-21 / 52.240-93
Supplier handles CUI, prime self-assertsCUILevel 2 (Self) minimumTriennial self-assessment + annual affirmationCMMC status evidence, affirmation, scope descriptionDon’t accept a generic “we’re compliant” letter as proofReadiness / RPO, MSP/MSSP, GRC evidence tool32 CFR § 170.23(a)(2)
Supplier handles CUI, prime requires Level 2 (C3PAO)CUILevel 2 (C3PAO)Third-party assessment every 3 yearsCMMC UID, status, assessment scope, affirmationDon’t treat an older NIST 800-171 self-assessment score as the same as a Level 2 (C3PAO) statusC3PAO when assessment-ready; readiness first if not32 CFR § 170.23(a)(3)
Supplier handles CUI under a Level 3 (DIBCAC) prime contractCUILevel 2 (C3PAO) minimumThird-party assessmentLevel 2 (C3PAO) status + scopeDon’t assume every sub must be Level 3Level 2 (C3PAO) readiness/assessment path32 CFR § 170.23(a)(4)
Lower-tier sub receives FCI/CUI from a Tier 1 subFCI/CUISame logic follows the dataDepends on data + contractLower-tier flowdown evidence + supplier-list controlsDon’t stop flowdown at Tier 1 if lower tiers touch covered infoSupplier-risk / GRC workflow + contract support32 CFR § 170.23(a)
Cloud Service Provider (CSP) stores/processes/transmits CDI or CUI for the covered environmentCDI (under DFARS 7012) and/or CUI (under CMMC scoping)Scope-dependentDFARS 7012 cloud obligations for CDI; CMMC scoping impact for CUIFedRAMP Moderate authorization/equivalency, service boundary, incident-reporting support, shared-responsibility matrixDon’t assume standard commercial cloud is enoughFedRAMP / GCC High / GovCloud / CUI-enclave advisorDFARS 252.204-7012; 32 CFR Part 170
MSP / MSSP / ESP supports the CUI environmentFCI/CUI triggers flowdown; SPD affects scopeDepends on the data it touchesDepends on whether it handles FCI/CUI vs. only SPD/servicesService role, admin access, SPD handling, shared-responsibility matrixDon’t ignore privileged security providers just because they never see drawingsCMMC-focused MSP/MSSP / vCISO / scoping32 CFR § 170.23; 32 CFR Part 170 (ESP/SPD scoping)
Subcontract solely for COTS itemsCOTS / noneNo CMMC flowdown obligation under 7021NoneCOTS / no-data documentationDon’t create supplier burden where there’s no data triggerNone, absent a contract-specific issueDFARS 252.204-7021(f)(1)

CSP = Cloud Service Provider. MSP/MSSP = Managed (Security) Service Provider. ESP = External Service Provider — any outside provider that touches your CUI environment or the data that protects it. RPO = Registered Provider Organization, a Cyber AB-listed consulting/readiness provider. vCISO = virtual Chief Information Security Officer.

Now the four CUI scenarios, in plain terms.

Honest admission: a good flowdown plan shrinks your bill

We’ll say the thing most compliance vendors won’t. The best CMMC flowdown plan usually reduces the number of suppliers who need to pay for CMMC help. That’s not a bug. That’s the point. A defensible plan protects FCI and CUI without turning every vendor relationship into an unnecessary Level 2 project — and over-flowing Level 2 onto suppliers who never touch CUI is one of the most expensive, avoidable mistakes we see primes make.

Here’s the hopeful flip side: once you classify by data flow, the list almost always gets smaller and clearer. Some suppliers need nothing. Some need Level 1. A focused few need Level 2 self-assessment or a C3PAO. And the handful that truly need help are easy to route to the right kind of provider — instead of paying for the wrong one. That’s a far less frightening picture than “everyone, six figures, now.”

If your supplier list just got hit with blanket Level 2 language — or you’re a sub who got that letter — classify it before you spend a dollar. Tell us your contract level, supplier types, CUI scope, and deadline, and we’ll help you identify source-checked provider categories for the relationships that actually need action.

Map My Flowdown Path →

Provider-matching forms on this site may generate referral or lead-routing compensation. This page does not currently contain named provider rankings, endorsements, or "best provider" awards. If named provider reviews are published later, sponsored, affiliate, partner, or referral relationships will be labeled on the relevant provider card or review. See our Methodology and Editorial & Advertising Policy for details.

Which DFARS clauses and provisions matter for CMMC flowdown

DFARS 252.204-7021; DFARS 252.204-7012; DFARS 252.204-7025

A qualifying CUI subcontract carries more than the CMMC clause. DFARS 252.204-7021 flows down CMMC status and affirmation; DFARS 252.204-7012 separately flows down CUI safeguarding and 72-hour incident reporting 'without alteration'; and DFARS 252.204-7025 is the solicitation provision that sets the required level before award.

View at acquisition.gov

This is where a lot of pages are quietly out of date or, in the other direction, overstated. Let’s be precise, because clause numbers are exactly the kind of detail you don’t want to get wrong in a solicitation.

Clause / provisionWhat it isFlowdown relevance
DFARS 252.204-7025Solicitation provision (Notice of CMMC Level Requirements)Tells offerors the required CMMC level and makes status a condition of award eligibility — it is not itself a flowdown clause
DFARS 252.204-7021Contract clause (NOV 2025)The core CMMC flowdown clause: current status, annual affirmation, and subcontract flowdown
DFARS 252.204-7012Contract clauseSafeguards CDI, requires 72-hour incident reporting, sets external-cloud requirements; flows down “without alteration” where CDI is involved
DFARS 252.204-7019Solicitation provision (NIST 800-171 assessment notice)Still codified; in practice superseded by the 2026 deviation and the CMMC framework
DFARS 252.204-7020Contract clause (government Medium/High NIST 800-171 assessments)Still codified; the 2026 deviation uses a renumbered version (see below)
FAR 52.204-21FAR clause (15 basic safeguarding requirements for FCI)The Level 1 anchor; the 2026 deviation uses a renumbered version (see below)

7012 vs 7021: two different flowdowns that often travel together

This distinction matters and signals whether a source actually read the clauses. DFARS 252.204-7012flows down “without alteration, except to identify the parties,” into subcontracts for operationally critical support or where performance involves CDI (DFARS 252.204-7012(m)). DFARS 252.204-7021flows down “the substance of this clause.” On a CUI subcontract that involves CDI, bothapply — the sub owes 800-171 safeguarding and 72-hour incident reporting under 7012, and the correct CMMC status under 7021. CMMC did not replace 7012. It sits on top of it.

What the 2026 FAR overhaul changed — and what’s still on the books

On February 1, 2026, DoD issued a class deviation (DoD Class Deviation 2026-O0025) under the Revolutionary FAR Overhaul that created a new FAR Part 40 and DFARS Part 240for information security and supply-chain requirements, renumbered several cybersecurity clauses, and removed the standalone “basic” NIST SP 800-171 self-assessment because CMMC now covers that ground. Here’s the part most pages get wrong in one direction or the other: this was done by class deviation, ahead of formal rulemaking, so both numbering systems are live right now.

Codified DFARS/FAR (still in the CFR and on Acquisition.gov)2026 class-deviation (RFO) reference — use when the solicitation directs it
FAR 52.204-21 — Basic Safeguarding (FCI); prescribed in FAR Part 4FAR 52.240-93 — same 15 requirements, moved under FAR Part 40
DFARS 252.204-7019 — NIST 800-171 assessment notice; prescribed at DFARS 204.7304(d)Eliminated under the deviation (the “basic self-assessment” concept is removed)
DFARS 252.204-7020 — NIST 800-171 DoD Assessments; prescribed at DFARS 204.7304(e)DFARS 252.240-7997 — Medium/High government assessments, prescribed at DFARS 240.370-5; “basic” self-assessment removed
DFARS 252.204-7012 — Safeguarding CDI / incident reportingUnchanged by the deviation
DFARS 252.204-7021 — CMMCUnchanged by the deviation

As of the May 7, 2026 DFARS change set, Acquisition.gov and the eCFR still show DFARS 252.204-7019 and 252.204-7020, and DFARS 204.7304 still prescribes them — because the deviation has not yet been codified through rulemaking. The practical rule for a live procurement is simple: follow the clause numbers and text in your actual solicitation, and re-check Acquisition.gov before you rely on a number. And don’t read “7019 is going away” as “the assessment requirement is gone” — the clause numbers changed; the safeguarding and assessment expectations did not.

Are COTS items, commercial products, and commercial services treated the same?

DFARS 252.204-7021(f)(1)

No. DFARS 252.204-7021 excludes subcontracts and other contractual instruments that are solely for COTS items from the CMMC subcontract flowdown obligation. But the clause does flow into subcontracts for commercial products and commercial services where the subcontract contains a requirement to process, store, or transmit FCI or CUI.

View at acquisition.gov

The COTS carve-out is narrow and item-based, not a blanket “commercial” exemption. A subcontract for a commercial product or commercial service that involves CUI still carries flowdown. Two separate questions decide it: (1) is the subcontract solely for COTS items, and (2) will the supplier process, store, or transmit FCI or CUI? If the answer to (1) is yes, the 7021 flowdown obligation doesn’t attach. If the answer to (2) is no, there’s no CMMC data trigger under 32 CFR § 170.23 regardless of how the item is labeled.

Can a prime just require every supplier to be Level 2?

Answer capsule:A prime can set stricter business terms in its own supplier program, but the regulatory CMMC flowdown minimum follows the information shared and the contract’s required assessment type — not a blanket policy. Defaulting every supplier to Level 2 is administratively simpler, but it over-scopes vendors that never touch CUI, raises costs, and can push small businesses out of the supply chain when CUI isn’t actually in play.

You canimpose a stricter floor as a matter of business risk tolerance, and plenty of large primes do, because uniform requirements are easier to manage across thousands of suppliers. But “easier to manage” and “correct” aren’t the same thing, and a blanket Level 2 mandate has real costs: it inflates supplier pricing, slows awards, and — for the small specialty shops the DIB depends on — can make a contract uneconomical. GAO put hard numbers on the strain: as of December 2025, only 92 C3PAOs were authorized to perform Level 2 certification assessments against a defense supply chain of roughly 200,000 companies(GAO-26-107955, March 2026). Pushing suppliers toward third-party certification they don’t actually need wastes a scarce resource.

The disciplined move is to classify first, then require only what the data demands. That protects the information and the supplier base.

How does a prime verify a subcontractor’s CMMC status if it can’t see SPRS?

DFARS final rule, Federal Register Sept. 10, 2025; DFARS 252.204-7021

Primes need a documented evidence process because SPRS — the DoD database that holds CMMC status — is not a public supplier-verification directory, and DoD will not give primes direct access to a subcontractor's SPRS data. Subcontractors may share SPRS screenshots or certifications with primes for verification, while DFARS 252.204-7021 still makes the prime responsible for ensuring the sub has appropriate current status before award.

View at acquisition.gov

This is the operational gap that catches primes off guard. You’re accountable for not flowing CUI to a non-compliant sub — and you can’t simply look up the sub’s score. DoD confirmed in the rule’s responses that it will not share subcontractor CMMC information with prime contractors; instead, subcontractors may provide SPRS screenshots or certifications to primes for verification (DFARS final rule, Federal Register, Sept. 10, 2025). So you have to build verification into your supplier process.

There’s a real legal-risk dimension behind this. The annual affirmation is signed by an “affirming official” — a senior company representative attesting continuous compliance in SPRS. False cybersecurity representations can create False Claims Actrisk when they’re tied to government contract payment, award, or compliance. The Department of Justice’s Civil Cyber-Fraud Initiative specifically uses the False Claims Act to pursue contractors and grantees that knowingly provide deficient cybersecurity, knowingly misrepresent their cybersecurity practices, or knowingly violate obligations to monitor and report cyber incidents. That risk runs to the sub making the claim and to a prime that knowingly relies on a supply chain it has misrepresented as compliant.

The supplier evidence packet (request this — and no more)

Supplier level/statusEvidence to requestWhat to verifyWhat not to ask for by default
No FCI/CUIData-flow memo or no-covered-info representationThat no covered data is processed/stored/transmittedA full System Security Plan (SSP)
Level 1Level 1 self-assessment / affirmation evidenceCAGE code, scope, date, affirming officialLevel 2 control evidence
Level 2 (Self)CMMC Level 2 (Self) status, affirmation, scopeStatus, CAGE, environment boundary, scopeThe full SSP unless contract/risk justifies it
Level 2 (C3PAO)CMMC UID, status, C3PAO assessment scope, affirmationFinal vs Conditional status, expiration, scopeRaw assessment artifacts unless needed
CSP / ESPAuthorization/equivalency, shared-responsibility matrix, service boundaryWhether the service handles CUI or SPDA generic “compliance” badge

SSP = System Security Plan, the document describing how an organization meets each security requirement. POA&M = Plan of Action and Milestones, the remediation plan for gaps.

A note on restraint: asking for a supplier’s full SSP “just to be safe” is a mistake. It’s a sensitive document, and casually collecting it across dozens of suppliers creates disclosure risk you now own. Request targeted status evidence first.

What is a CMMC UID, and what should the prime ask for?

A CMMC Unique Identifier (CMMC UID) is the identifier SPRS assigns to a specific CMMC assessment for a contractor information system. DFARS 252.204-7025 requires offerors to provide a CMMC UID for each information system that will process, store, or transmit FCI or CUI, so for a Level 2 (C3PAO) subcontractor, the UID plus the assessment scope and current status is the cleanest evidence a prime can request.

When you’re verifying a certified sub, don’t settle for “we’re certified.” Ask for the CMMC UID, the assessment scope it covers, the status (Conditional vs Final), and the expiration window. The UID ties the claim to a specific assessment and a specific system boundary — which is what you actually need to confirm the right environment is covered for the work you’re flowing down.

Handle screenshots like records

Any SPRS screenshot you accept should be date-stamped, tied to the supplier’s CAGE code and assessment scope, redacted where appropriate, stored in your supplier-risk records, and re-requested on renewal and on the annual affirmation cycle. A screenshot from 14 months ago proves nothing about today.

Questionnaire language you can adapt

“Will your organization process, store, or transmit FCI or CUI for this subcontract? If yes, identify the system boundary, CAGE code, current CMMC status and assessment type, CMMC UID (if applicable), affirmation date, and whether any lower-tier subcontractor will receive FCI or CUI.”

That single question forces the data-flow answer that drives everything else. If you’d rather build this into a documented, repeatable supplier-verification process instead of a one-off email, we can point you to the provider categories that do exactly that.

Get matched with source-checked provider options →

What should a CMMC flowdown letter or subcontract clause include?

Answer capsule:A CMMC flowdown letter should never just say “be CMMC compliant.” It should identify the information type, the required level and assessment type, the evidence required before award, the annual affirmation expectation, lower-tier flowdown obligations, change-notification requirements, and whether DFARS 252.204-7012 cyber-incident and cloud obligations also apply. Use counsel-approved language for the actual subcontract instrument.

We see a lot of flowdown letters. The bad ones all share a tell: they’re vague. The good ones are specific enough that the supplier knows exactly what to do and the prime has a defensible record.

Minimum components of a usable flowdown letter:

Bad flowdown language:

“Supplier must be CMMC compliant.”

Why it fails: no level, no data type, no assessment type, no evidence standard, no lower-tier handling. The supplier can’t act on it, and you can’t enforce it.

Better flowdown language (sample structure, not legal advice):

“Supplier will process, store, or transmit CUI in performance of this subcontract and must maintain CMMC Level 2 [Self / C3PAO, as applicable] status for the assessment scope used to perform the work; provide evidence of current status and annual affirmation before award and upon renewal; and flow down applicable requirements to any lower-tier subcontractor that will process, store, or transmit FCI or CUI.”

That’s a reusable asset — the contrast itself teaches you how to fix your own letter. Have counsel finalize the binding clause.

What does CMMC flowdown actually cost you?

32 CFR Part 170 final rule; regulatory flexibility analysis

Cost tracks the flowed-down level. DoD's rulemaking models a Level 2 self-assessment cycle at over $37,000 for a small entity and a Level 2 (C3PAO) cycle at about $104,670 over three years for a small entity (roughly $118,000 for a larger entity). Those figures cover the assessment and affirmations — not the cost of implementing NIST SP 800-171 in the first place, which is a separate and often larger expense.

View at ecfr.gov

Let’s put the budget conversation where it belongs — early — so the value can build from there. The table separates DoD’s official rulemaking estimate from real-world market and planning ranges, because they answer different questions.

Your flowed-down levelDoD rulemaking estimate (small entity)What that estimate covers / excludesMarket & planning reality
Level 1 (Self) — FCI onlyModeled as low; primarily internal timeSelf-assessment + affirmation; assumes the 15 FCI safeguards are in placePlanning estimates commonly run from the low thousands up to ~$15,000, mostly internal effort
Level 2 (Self) — CUI, prime self-assertsOver $37,000 over the 3-year cycleTriennial self-assessment + affirmations; assumes NIST SP 800-171 R2 is already implementedImplementation/remediation is the real number and is separate — often $20,000–$150,000+ depending on starting maturity
Level 2 (C3PAO) — CUI + certification required~$104,670 over 3 years (~$101,752 assessment + initial affirmation, plus two annual affirmations); ~$118,000 for a larger entityThird-party assessment + affirmations; assumes 800-171 R2 already implemented; excludes remediationMarket C3PAO assessment fees alone commonly run ~$30,000–$150,000; all-in (with implementation) often $50,000–$150,000+
Level 3 (DIBCAC) — most sensitive CUI (rare for subs)Government-assessed; DoD expects it to affect only a small subset of the DIBRequires a Final Level 2 (C3PAO) status first, plus selected NIST SP 800-172 requirementsEngineering costs are substantial and methodology-dependent; flowdown rarely places a subcontractor here

DoD figures are from the 32 CFR Part 170 final rule and its regulatory flexibility analysis. They are rulemaking estimates, not market quotes, and DoD states actual C3PAO pricing is driven by market forces and the size and complexity of the environment under assessment.

Here’s the insight that the headline numbers hide: DoD’s estimate is for the assessment, not for getting your environment ready in the first place. The big swing for most subcontractors is the cost to implement and remediate against NIST SP 800-171 — and the single biggest lever on that cost isn’t negotiating an assessor’s day rate. It’s scope.Every system that touches CUI has to meet all 110 Level 2 requirements, so consolidating CUI into a defined enclave — a limited, controlled set of systems where the sensitive data lives — shrinks how much of your environment carries the full burden.

That’s the honest, reader-first reason to talk to a readiness or enclave provider: not to sell you more, but to make the assessment smaller. If your prime is flowing down CUI and you’re starting from a standard commercial setup, readiness comes before any assessment — and under the Cyber AB CMMC Assessment Process (CAP), C3PAOs must attest to and manage conflicts of interest, so the firm that prepares you generally should not be the one that certifies you. See what a Level 2 readiness program actually involves before you spend.

Want a full breakdown by CMMC Level 2 cost drivers? That page separates assessment fees, implementation, enclave, and managed support line by line.

What if a subcontractor isn’t CMMC-ready before award?

Answer capsule:If a subcontractor isn’t ready, the first question is whether the FCI/CUI flow can be eliminated, reduced, isolated, or delayed. If the supplier truly must handle CUI, route it to readiness and scoping help before any formal assessment — and keep readiness separate from the C3PAO assessment, because under the Cyber AB CAP a C3PAO must manage conflicts of interest with the organizations it assesses.

This is the panic scenario, and there are four real options. Work them in order.

  1. Remove the supplier from the CUI flow.Redact CUI from bid packages, use no-download portals or prime-controlled environments, or shift the sensitive work to a supplier that’s already compliant. The cheapest CUI to protect is the CUI you never send.
  2. Isolate the work in an enclave.A dedicated CUI environment — often built on Microsoft GCC High, AWS GovCloud, or a purpose-built CUI collaboration tool — keeps the requirement contained to a small boundary.
  3. Readiness first, assessment later. Registered Provider Organizations (RPOs), CMMC-focused MSPs/MSSPs, vCISOs, and documentation/GRC providers build the environment and the evidence. A C3PAO comes after, for the formal assessment. The market data backs this sequencing: in Alluvionic’s 2025 State of CMMC report, a survey of C3PAOs performing Level 2 assessments, only about 25% of contractors arrived genuinely well prepared, and roughly half of assessors reported delaying or turning away clients due to readiness gaps. Showing up unready wastes money and time.
  4. Replace or delay the supplier.If a critical supplier can’t reach the required status before award and no scoping alternative exists, the prime may need a different award strategy. That’s a hard conversation, but it beats an award-blocking surprise or an FCA problem.

If a key supplier isn’t ready, don’t guess between remediation, enclave, assessment, or replacement. Share the supplier’s role, the data flow, the required level, and your award deadline, and we’ll help you find the provider category that fits the situation.

Find the Right CMMC Path →

How do MSPs, MSSPs, CSPs, GRC tools, and other external providers affect flowdown?

32 CFR § 170.23; DFARS 252.204-7012; 32 CFR Part 170 (ESP/SPD scoping)

External providers can change CMMC scope even when they're not traditional manufacturing subcontractors. A Cloud Service Provider that stores, processes, or transmits covered defense information brings DFARS 252.204-7012 cloud requirements into play, and a CSP used for CUI must meet FedRAMP Moderate (or equivalent) under CMMC scoping. An MSP or other External Service Provider that handles CUI can fall under flowdown, while one that only handles Security Protection Data affects assessment scope rather than triggering flowdown on its own.

View at ecfr.gov

The blind spot here is assuming “they’re just IT” or “it’s just software,” so they don’t count. They can.

ProblemBest-fit categoryWhat they should doWhat they should not do
“We don’t know if CUI flows to this supplier”Scoping / readiness advisorMap the data flow and boundarySell full Level 2 before scoping
“Our supplier uses commercial email/cloud for CUI”Enclave / GCC High / GovCloud providerBuild a controlled CUI environmentClaim the tool alone equals certification
“We need evidence from 80 suppliers”GRC / supplier-risk workflowTrack and organize evidenceReplace control implementation
“A small supplier needs to get Level 2 ready”RPO / MSP / MSSP / vCISO / readinessImplement and document controlsBlur managed IT with formal assessment
“A supplier is ready for third-party assessment”C3PAOPerform the formal Level 2 assessmentRemediate, then assess the same engagement

Does CMMC flow down to lower-tier subcontractors?

32 CFR § 170.23(a)

Yes. CMMC flows down to lower-tier subcontractors whenever FCI or CUI is passed beyond the first subcontract tier. The prime and each higher-tier subcontractor should document lower-tier data flows, set evidence expectations, and assign responsibility for confirming current CMMC status before covered information is shared.

View at ecfr.gov

Flowdown follows the data, not the org chart. A Tier 1 machine shop that sends CUI drawings to a heat treater has just created a Tier 2 obligation. A software subcontractor that subcontracts testing involving CUI has done the same. So has an MSP that leans on a lower-tier SOC provider.

What a prime should require from its Tier 1 subs:

The risk if you skip this: CUI quietly leaks to a lower-tier shop with no controls, and the breach at that shop becomes, functionally, a breach of your program.

Does a Level 3 prime contract mean every subcontractor needs Level 3?

32 CFR § 170.23(a)(4)

No. Under 32 CFR § 170.23(a)(4), if a subcontractor will process, store, or transmit CUI and the prime contract requires Level 3 (DIBCAC), the subcontractor's minimum is Level 2 (C3PAO) — not Level 3 — unless DoD provides contract-specific flowdown guidance.

View at ecfr.gov

This is one of the most-misstated points in the whole topic, and getting it right is a trust signal. Many pages assume the sub inherits the prime’s level, so they tell a Level 3 prime’s suppliers they all need Level 3. The regulation says otherwise. Read literally, even when the prime carries the most demanding status in the program, a CUI subcontractor is held to a Level 2 (C3PAO) floor. DoD can issue specific guidance that changes the picture for a particular contract (32 CFR § 170.23(b)), so check your contract — but Level 3 is not the default that cascades to every vendor.

If a prime is pushing Level 3 across the board, that’s a flag to slow down and confirm what the contract actually requires.

When do CMMC flowdown requirements start applying?

32 CFR § 170.3(e)

The CMMC program rule (32 CFR Part 170) became effective December 16, 2024, and DoD's phased implementation began November 10, 2025, when the DFARS rule took effect. As of June 17, 2026, Phase 1 is active (Level 1 and Level 2 self-assessments); Phase 2 is scheduled to begin November 10, 2026, when Level 2 (C3PAO) certification requirements become more common where applicable.

View at ecfr.gov

DoD is rolling CMMC into contracts over four phases across three years (32 CFR § 170.3(e)). The timeline matters, but remember the operative trigger is always the clause in your solicitation or contract and the information flowed to you.

DateMilestoneWhy it matters
Oct. 15, 202432 CFR Part 170 final rule publishedEstablished the CMMC program rule
Dec. 16, 202432 CFR Part 170 effectiveProgram rule took effect
Nov. 10, 2025DFARS rule effective; Phase 1 beginsCMMC starts appearing in contracts via DFARS 252.204-7021
Nov. 10, 2025 – Nov. 9, 2026Phase 1Level 1 and Level 2 self-assessments emphasized
Nov. 10, 2026Phase 2 scheduledLevel 2 (C3PAO) certification becomes a more common condition of award
Nov. 10, 2027Phase 3 scheduledLevel 3 (DIBCAC) added as a condition of award where applicable
Nov. 10, 2028Phase 4 / full implementation scheduledCMMC requirements apply broadly across applicable contracts

Here’s the scarcity that’s real, not manufactured. If your CUI work will require a Level 2 (C3PAO) certification for a Phase 2 award, the runway is finite: Phase 2 is roughly five months out as of this writing, there were only 92 authorized C3PAOsas of December 2025 (GAO-26-107955), and assessments commonly take months to schedule once you’re ready. Readiness takes longer than scheduling. The math favors starting now. See our CMMC deadlines and phases guide for the full timeline.

What are the biggest CMMC flowdown mistakes?

Answer capsule:The most common and costly flowdown mistakes are over-flowing Level 2 to suppliers that don’t touch CUI, under-flowing to lower-tier suppliers that do, confusing an old NIST 800-171 score with a CMMC status, ignoring CSP/ESP scope, failing to collect annual affirmation evidence, and using vague subcontract language. The fix is the same in every case: classify the data flow first, then request evidence matched to the required status.

MistakeWhy it mattersFix
Blanket Level 2 for every supplierInflates cost; can shrink your supplier baseClassify by data flow
No lower-tier controlsCUI can leak past Tier 1Require lower-tier flowdown evidence
Accepting “we’re compliant”Doesn’t verify current statusRequest status, scope, and affirmation evidence
Treating an old NIST 800-171 self-assessment score as a CMMC certificationDifferent evidence; different obligationsMatch evidence to the required status
Ignoring CSP/ESP rolesCloud and admin providers can change scopeBuild a shared-responsibility map
Confusing NIST 800-171 Rev. 3 with the CMMC baselineCMMC Level 2 currently maps to Rev. 2Cite the current rule baseline
Requesting full SSPs casuallySensitive document; disclosure riskAsk for targeted evidence first

One clarification worth nailing down, because it confuses even experienced teams: CMMC Level 2 currently incorporates NIST SP 800-171 Revision 2, not Revision 3, under the active CMMC rule. NIST issued Rev. 3 in 2024, but GAO confirmed DoD has not incorporated it into CMMC as of its March 2026 report. Don’t let a vendor scope you to Rev. 3 controls the program doesn’t yet require.

Who should help: readiness provider, MSP/MSSP, GRC tool, enclave provider, or C3PAO?

Answer capsule:Most CMMC flowdown problems are scoping, readiness, evidence, and supplier-risk problems before they are formal-assessment problems. Engage a C3PAO when a supplier is assessment-ready or the question is formal certification; use readiness, MSP/MSSP, enclave, or GRC categories when the problem is implementation, CUI isolation, documentation, or ongoing evidence — and keep readiness/remediation separate from the formal assessment.

There’s a logical order to provider categories, and matching the category to the actual problem is most of the value.

Your situationBest categoryWhyNext step
“We don’t know which suppliers touch CUI”Scoping / readiness advisorData-flow classification comes firstMap my supplier scope
“Our supplier uses commercial email/cloud for CUI”Enclave / GCC High / GovCloudThe environment may need redesignCompare secure-collaboration options
“We need evidence from dozens of suppliers”GRC / supplier-risk workflowThis is an evidence-tracking problemBuild a supplier evidence workflow
“A small supplier needs to get Level 2 ready”RPO / MSP / MSSP / vCISO / readinessImplementation and documentation firstFind readiness support
“A supplier is ready for third-party assessment”C3PAOFormal Level 2 (C3PAO) assessmentCompare the assessment path
“We got Level 2 flowdown but only view CUI in a portal”Scoping advisor firstThe boundary may change the requirementReview portal-only scope

When you reach the assessment stage, you can confirm a C3PAO’s authorization directly in the Cyber AB Marketplace — the official directory of authorized assessors and listed professionals (more than 5,300 organizations and individuals as of January 2026, per GAO-26-107955). We point you there because it’s neutral and verifiable; notably, the Cyber AB’s own process states that neither the Cyber AB nor DoD personnel recommend or facilitate introductions to specific C3PAOs, which is part of why an independent mapping of provider categories is useful in the first place.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.

What we actually verified

Answer capsule:This page is built from primary sources, not paraphrase. Below is exactly what we checked, where, and when — so you can verify every regulatory claim yourself before you act on it.

How we built the decision matrix

The matrix is an editorial decision framework built from primary regulatory sources — it is not a substitute for legal or contractual advice. The regulatory facts come from 32 CFR Part 170, the DFARS clauses, the Federal Register, DoD CMMC materials, NIST, and GAO. The judgments — which provider category fits which problem, when to start with scoping versus a C3PAO, what evidence packet is reasonable, and when a blanket Level 2 approach is operationally harmful — are clearly labeled as our editorial conclusions based on those verified facts.

CMMC flowdown requirements: FAQ

Does CMMC flow down to subcontractors?
Yes. CMMC applies to subcontractors throughout the supply chain at all tiers when they process, store, or transmit FCI or CUI on contractor information systems in performance of a DoD contract or subcontract (32 CFR § 170.23(a)). Subcontracts solely for COTS items sit outside the flowdown obligation.
Do all subcontractors need CMMC Level 2?
No. FCI-only subcontractors map to Level 1. CUI-handling subcontractors map to Level 2 at minimum, with the assessment type (self vs C3PAO) set by the prime contract and any contract-specific guidance (32 CFR § 170.23(a)).
Does a Level 3 prime contract mean subcontractors need Level 3?
Not automatically. Under 32 CFR § 170.23(a)(4), CUI-handling subcontractors under a Level 3 prime contract need Level 2 (C3PAO) at minimum, unless DoD provides contract-specific flowdown guidance.
Can a prime see a subcontractor’s SPRS score or CMMC status?
Generally no. SPRS is not a public supplier-verification portal, and DoD will not give primes direct access to subcontractor data. Per the DFARS final rule, subcontractors may share SPRS screenshots or certifications with primes for verification.
What evidence should a subcontractor provide?
Evidence should match the required status: a no-covered-info determination, Level 1 affirmation evidence, Level 2 (Self) status, or Level 2 (C3PAO) CMMC UID and status — plus the assessment scope, CAGE-code alignment, and annual affirmation date where applicable.
Are COTS suppliers exempt from flowdown?
DFARS 252.204-7021(f)(1) excludes subcontracts solely for commercially available off-the-shelf items from the CMMC subcontract flowdown obligation. Subcontracts for commercial products or services are not exempt if they involve processing, storing, or transmitting FCI or CUI.
Does DFARS 252.204-7012 still matter under CMMC?
Yes. DFARS 252.204-7012 remains in force for covered defense information safeguarding, 72-hour cyber-incident reporting, and external cloud requirements. CMMC sits on top of those obligations; it does not erase them.
What changed with DFARS 7019 and 7020 in 2026?
A February 1, 2026 class deviation reorganized cybersecurity clauses into FAR Part 40 / DFARS Part 240 and removed the standalone “basic” self-assessment. The renumbered clauses (FAR 52.240-93; DFARS 252.240-7997) apply where the deviation directs, but 7019 and 7020 remain in the codified DFARS pending rulemaking, so you may see both numbering systems. Follow the clause text in your actual solicitation.
Is NIST SP 800-171 Revision 3 the current CMMC Level 2 baseline?
No, not under the current rule. CMMC Level 2 incorporates NIST SP 800-171 Revision 2 unless and until DoD amends the rule. GAO confirmed Rev. 3 was issued but not incorporated as of March 2026.
Can a supplier use a prime-controlled portal to avoid CUI scope?
Sometimes scope changes when a supplier doesn’t process, store, or transmit CUI on its own systems — but this requires careful documentation of the access model, download controls, roles, and assessment boundary. Treat it as a scoping question, not a shortcut.
When should a supplier talk to a C3PAO?
When it’s approaching formal Level 2 (C3PAO) assessment readiness or needs to understand assessment logistics. If the supplier still lacks scoping, controls, an SSP, a POA&M, evidence, or a sound environment design, readiness help comes first.
What should a small supplier do first after getting a Level 2 flowdown letter?
Ask what FCI or CUI you’ll actually receive and whether you’ll handle it on your own systems. Then confirm the required level and assessment type, pin down the deadline, and decide whether to scope CUI out, build an enclave, start readiness, or decline the work.

Your next step

You came here to end the confusion and make a decision. Here’s the simplest path forward.

If you only handle FCI, or your subcontract is solely for COTS items, you likely don’t need to pay anyone — document your determination and move on. If you know you need readiness, compare the provider categories that fit. And if you’re still not sure which provider type fits your situation, let us do the matching.

Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options.

Get Matched With Source-Checked Options →

The Defense Compliance Report is the independent CMMC decision layer for defense contractors — mapping contract requirements, FCI/CUI scope, environments, provider categories, costs, and evidence into the next correct step before you hire.

Provider-matching forms on this site may generate referral or lead-routing compensation. This page does not currently contain named provider rankings, endorsements, or "best provider" awards. If named provider reviews are published later, sponsored, affiliate, partner, or referral relationships will be labeled on the relevant provider card or review. See our Methodology and Editorial & Advertising Policy for details.