CMMC Flowdown Requirements: The Prime-to-Subcontractor Decision Guide (2026)
A prime just sent you a clause, a supplier questionnaire, or a one-line demand: “Be CMMC Level 2 by [date].” Suddenly a 12-person shop is staring down a compliance project nobody budgeted for — and if you’re the prime, the worry runs the other way: am I liable if a supplier fails, and which of my vendors does this even touch?
Here’s the bottom line. CMMC flowdown requirementsmean a Department of Defense prime contractor — and every higher-tier subcontractor above you — must pass the correct Cybersecurity Maturity Model Certification (CMMC) requirement down to any subcontractor whose information systems will process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) in performance of the contract. The level a subcontractor needs is set by the information that flows to them, not by the prime’s level: FCI only maps to Level 1; CUI maps to at least Level 2; and even under a Level 3 prime contract, a CUI-handling subcontractor’s floor is Level 2 with a third-party assessment — not Level 3. Subcontracts solely for commercially available off-the-shelf (COTS) items are excluded (32 CFR § 170.23; DFARS 252.204-7021).
That’s the rule. What trips teams up isn’t the rule — it’s over-applyingit. The fastest way to burn budget and your supplier base is to blast “everyone must be Level 2” down the chain when half those suppliers never touch CUI. Below, we map exactly who needs what, what proof to ask for, what not to demand, and when a third-party assessor is actually required. We read the controlling regulation and the current clause text ourselves to build it.
Fast answer: what CMMC requirement flows down?
A subcontractor falls under CMMC flowdown only when it will process, store, or transmit FCI or CUI on its own systems in performance of a DoD subcontract. FCI-only work requires CMMC Level 1 (annual self-assessment); CUI work requires at least Level 2; CUI under a Level 2 (C3PAO) or Level 3 prime contract requires Level 2 with a third-party assessment. The legal basis is 32 CFR § 170.23, and the contract mechanism is DFARS 252.204-7021, effective November 10, 2025.
View at ecfr.gov| If the subcontractor handles… | Minimum CMMC status | Assessment type | What the prime must do |
|---|---|---|---|
| No FCI or CUI (and no access to covered systems) | No CMMC flowdown from the data trigger | None | Document why no covered information flows |
| FCI only | Level 1 | Annual self-assessment + annual affirmation | Request Level 1 status/affirmation evidence |
| CUI, prime contract allows self-assessment | Level 2 (Self) | Triennial self-assessment + annual affirmation | Request CMMC status evidence + scope |
| CUI, prime contract requires Level 2 (C3PAO) | Level 2 (C3PAO) | Third-party assessment every 3 years | Request CMMC UID + status + assessment scope |
| CUI under a Level 3 (DIBCAC) prime contract | Level 2 (C3PAO) minimum | Third-party assessment (not Level 3 by default) | Do not assume Level 3 unless DoD says so |
| Cloud or external IT provider touching CUI | Scope-dependent | Scope-dependent | Verify cloud authorization + responsibility split |
Not sure which row a specific supplier fits? The CMMC Flowdown Level Finder lets you classify the relationship before you request quotes or demand Level 2.
Use the Flowdown Level Finder →
What CMMC flowdown requirements actually mean
CMMC flowdown is the contractual obligation that requires a prime or higher-tier subcontractor to pass the correct CMMC requirement to subcontractors that process, store, or transmit FCI or CUI. The core rule is not “every subcontractor inherits the prime’s level” — the required level depends on the information and systems each subcontractor will touch.
View at ecfr.govStrip away the acronyms and flowdown is simple: when the government puts a cybersecurity requirement in a prime contract, that requirement has to travel into the subcontracts where sensitive information actually goes. CMMC is the framework DoD uses to confirm that defense contractors protect two kinds of information — FCI (Federal Contract Information: non-public information generated for or provided under a contract) and CUI (Controlled Unclassified Information: information the government requires to be safeguarded under law or policy). The program rule lives at 32 CFR Part 170, which became effective December 16, 2024. The contract clause that carries it lives at DFARS 252.204-7021 (Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements), whose current version is dated November 2025.
Two parts of that clause do the work. Paragraph (d) requires the contractor to “consult 32 CFR 170.23 related to the flowdown of the CMMC requirements, and flow down the correct CMMC level to subcontracts.” Paragraph (f) requires the contractor to insert the substanceof the clause into qualifying subcontracts and, before awarding any subcontract, to ensure the subcontractor holds a current CMMC status “appropriate for the information that is being flowed down.” We pulled that language directly from the clause on Acquisition.gov on June 17, 2026.
The key word is appropriate. Flowdown is not a copy-paste of the prime’s certification onto every vendor. It’s a routing decision driven by data.
What flowdown is not
- It is not“every supplier must be Level 2.” Many of your suppliers may need nothing from the CMMC data trigger.
- It is not“subcontractors need the same level as the prime.” A Level 3 prime does not make a CUI sub Level 3 (more on this below).
- It is not only a paperwork drill. The sub must actually hold the status before covered information moves.
- It is not a reason to send CUI to a supplier before confirming their status and scope.
That’s the whole tension on this page: getting flowdown right usually means flowing down less than the instinct says.
Which subcontractors are actually in scope?
A subcontractor is in scope when it will process, store, or transmit FCI or CUI on contractor information systems in performance of the DoD contract or subcontract, at any tier of the supply chain. If no covered information is shared and the subcontractor never touches covered systems, the correct move is to document that determination — not to reflexively require Level 2.
View at ecfr.govScope comes down to three tests. Run a supplier through all three.
Test 1 — The data test: none, FCI, CUI, CDI, or SPD
- None. The supplier never receives or touches covered information. No CMMC data trigger.
- FCI.Federal Contract Information — non-public, contract-generated information. Maps to Level 1. See our FCI vs. CUI explainer for the full distinction.
- CUI. Controlled Unclassified Information. Maps to at least Level 2.
- CDI. Covered Defense Information under DFARS 252.204-7012: unclassified controlled technical information, or other information described in the CUI Registry, that requires safeguarding or dissemination controls and is either (1) marked or identified in the contract and provided to the contractor by or on behalf of DoD, or (2) collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of contract performance. When CDI is in play, 7012 and 7021 obligations can apply at the same time.
- SPD.Security Protection Data — information generated by the tools and providers that protect the CUI environment (security logs, configurations, vulnerability data). SPD is not, by itself, a CMMC flowdown trigger, but it can pull an IT or security provider into your assessment scope and evidence even when that provider never sees a single drawing.
Test 2 — The system test: process, store, or transmit
The trigger is whether the supplier handles covered information on its own systems. Examples that count: emailing CUI, storing CUI drawings, running an IT system that protects the CUI boundary, or administering the tenant where CUI lives. A supplier that only viewsCUI inside a prime-controlled portal — with no download, no local storage — may sit in a different scoping position. Treat that as a scoping question to document carefully, not a loophole to assume.
Test 3 — The tier test: it does not stop at Tier 1
CMMC applies “throughout the supply chain at all tiers” where FCI or CUI is processed, stored, or transmitted (32 CFR § 170.23(a)). If your Tier 1 sub passes CUI to a heat treater or a specialty-process shop, the requirement follows the data down to that lower tier too.
The original part here:we’ve turned the rule into a clean three-test filter — data → system → tier— so you can sort an entire vendor list without guessing. Most competing pages tell you “CMMC flows down.” Few hand you the filter that tells you when it doesn’t.
What CMMC level does each subcontractor need? (the decision matrix)
A subcontractor's required CMMC status is determined by the information it receives and the prime contract's required assessment type: FCI-only → Level 1 (Self); CUI → Level 2 (Self) minimum; CUI where the prime requires Level 2 (C3PAO) → Level 2 (C3PAO); and CUI where the prime requires Level 3 (DIBCAC) → Level 2 (C3PAO) minimum, unless DoD gives contract-specific flowdown guidance.
View at ecfr.govThis is the section to bookmark. We built the matrix below by combining six things competitors usually scatter across separate pages: the supplier’s data trigger, the minimum CMMC status, the assessment type, the evidence to request, what notto over-require, and the provider category that fits if help is needed — each anchored to a primary source.
The Prime-to-Subcontractor CMMC Flowdown Decision Matrix
| Supplier situation | Data trigger | Minimum CMMC status | Assessment type | Evidence to request | Do not over-require | Best-fit provider category | Source |
|---|---|---|---|---|---|---|---|
| Supplier receives no FCI/CUI; no covered-system access | None | No CMMC flowdown from the data trigger | None | A documented no-FCI/no-CUI determination | Don’t demand Level 2 because the prime is Level 2 | Scoping advisor only if genuinely unsure | 32 CFR § 170.23 |
| Supplier receives FCI only | FCI | Level 1 | Annual self-assessment + annual affirmation | Level 1 status/affirmation, CAGE code, scope | Don’t require the full 110 Level 2 controls unless CUI is actually involved | Level 1 / basic-safeguarding readiness | 32 CFR § 170.23(a)(1); FAR 52.204-21 / 52.240-93 |
| Supplier handles CUI, prime self-asserts | CUI | Level 2 (Self) minimum | Triennial self-assessment + annual affirmation | CMMC status evidence, affirmation, scope description | Don’t accept a generic “we’re compliant” letter as proof | Readiness / RPO, MSP/MSSP, GRC evidence tool | 32 CFR § 170.23(a)(2) |
| Supplier handles CUI, prime requires Level 2 (C3PAO) | CUI | Level 2 (C3PAO) | Third-party assessment every 3 years | CMMC UID, status, assessment scope, affirmation | Don’t treat an older NIST 800-171 self-assessment score as the same as a Level 2 (C3PAO) status | C3PAO when assessment-ready; readiness first if not | 32 CFR § 170.23(a)(3) |
| Supplier handles CUI under a Level 3 (DIBCAC) prime contract | CUI | Level 2 (C3PAO) minimum | Third-party assessment | Level 2 (C3PAO) status + scope | Don’t assume every sub must be Level 3 | Level 2 (C3PAO) readiness/assessment path | 32 CFR § 170.23(a)(4) |
| Lower-tier sub receives FCI/CUI from a Tier 1 sub | FCI/CUI | Same logic follows the data | Depends on data + contract | Lower-tier flowdown evidence + supplier-list controls | Don’t stop flowdown at Tier 1 if lower tiers touch covered info | Supplier-risk / GRC workflow + contract support | 32 CFR § 170.23(a) |
| Cloud Service Provider (CSP) stores/processes/transmits CDI or CUI for the covered environment | CDI (under DFARS 7012) and/or CUI (under CMMC scoping) | Scope-dependent | DFARS 7012 cloud obligations for CDI; CMMC scoping impact for CUI | FedRAMP Moderate authorization/equivalency, service boundary, incident-reporting support, shared-responsibility matrix | Don’t assume standard commercial cloud is enough | FedRAMP / GCC High / GovCloud / CUI-enclave advisor | DFARS 252.204-7012; 32 CFR Part 170 |
| MSP / MSSP / ESP supports the CUI environment | FCI/CUI triggers flowdown; SPD affects scope | Depends on the data it touches | Depends on whether it handles FCI/CUI vs. only SPD/services | Service role, admin access, SPD handling, shared-responsibility matrix | Don’t ignore privileged security providers just because they never see drawings | CMMC-focused MSP/MSSP / vCISO / scoping | 32 CFR § 170.23; 32 CFR Part 170 (ESP/SPD scoping) |
| Subcontract solely for COTS items | COTS / none | No CMMC flowdown obligation under 7021 | None | COTS / no-data documentation | Don’t create supplier burden where there’s no data trigger | None, absent a contract-specific issue | DFARS 252.204-7021(f)(1) |
Now the four CUI scenarios, in plain terms.
- Level 1 (FCI only). Fifteen basic safeguarding requirements, self-assessed, affirmed annually. This is the substance behind FAR 52.204-21 (see the clause section for the 2026 renumbering). A capable FCI-only shop can usually handle this without paying anyone.
- Level 2 Self (CUI, prime self-asserts).All 110 NIST SP 800-171 Revision 2 security requirements, organized into 14 control families, self-assessed every three years with an annual affirmation. No outside assessor — but the implementation is the real work and the real cost. See the full CMMC Level 2 requirements.
- Level 2 C3PAO (CUI, prime requires certification). Same 110 requirements, but verified by an authorized C3PAO every three years. This is where the budget conversation gets serious.
- Level 3 (DIBCAC).Requires a Final Level 2 (C3PAO) status first, plus selected requirements from NIST SP 800-172 (February 2021), assessed by DCMA DIBCAC. Rare for subcontractors — and, critically, not the default flowdown level even under a Level 3 prime.
Honest admission: a good flowdown plan shrinks your bill
We’ll say the thing most compliance vendors won’t. The best CMMC flowdown plan usually reduces the number of suppliers who need to pay for CMMC help. That’s not a bug. That’s the point. A defensible plan protects FCI and CUI without turning every vendor relationship into an unnecessary Level 2 project — and over-flowing Level 2 onto suppliers who never touch CUI is one of the most expensive, avoidable mistakes we see primes make.
Here’s the hopeful flip side: once you classify by data flow, the list almost always gets smaller and clearer. Some suppliers need nothing. Some need Level 1. A focused few need Level 2 self-assessment or a C3PAO. And the handful that truly need help are easy to route to the right kind of provider — instead of paying for the wrong one. That’s a far less frightening picture than “everyone, six figures, now.”
If your supplier list just got hit with blanket Level 2 language — or you’re a sub who got that letter — classify it before you spend a dollar. Tell us your contract level, supplier types, CUI scope, and deadline, and we’ll help you identify source-checked provider categories for the relationships that actually need action.
Which DFARS clauses and provisions matter for CMMC flowdown
A qualifying CUI subcontract carries more than the CMMC clause. DFARS 252.204-7021 flows down CMMC status and affirmation; DFARS 252.204-7012 separately flows down CUI safeguarding and 72-hour incident reporting 'without alteration'; and DFARS 252.204-7025 is the solicitation provision that sets the required level before award.
View at acquisition.govThis is where a lot of pages are quietly out of date or, in the other direction, overstated. Let’s be precise, because clause numbers are exactly the kind of detail you don’t want to get wrong in a solicitation.
| Clause / provision | What it is | Flowdown relevance |
|---|---|---|
| DFARS 252.204-7025 | Solicitation provision (Notice of CMMC Level Requirements) | Tells offerors the required CMMC level and makes status a condition of award eligibility — it is not itself a flowdown clause |
| DFARS 252.204-7021 | Contract clause (NOV 2025) | The core CMMC flowdown clause: current status, annual affirmation, and subcontract flowdown |
| DFARS 252.204-7012 | Contract clause | Safeguards CDI, requires 72-hour incident reporting, sets external-cloud requirements; flows down “without alteration” where CDI is involved |
| DFARS 252.204-7019 | Solicitation provision (NIST 800-171 assessment notice) | Still codified; in practice superseded by the 2026 deviation and the CMMC framework |
| DFARS 252.204-7020 | Contract clause (government Medium/High NIST 800-171 assessments) | Still codified; the 2026 deviation uses a renumbered version (see below) |
| FAR 52.204-21 | FAR clause (15 basic safeguarding requirements for FCI) | The Level 1 anchor; the 2026 deviation uses a renumbered version (see below) |
7012 vs 7021: two different flowdowns that often travel together
This distinction matters and signals whether a source actually read the clauses. DFARS 252.204-7012flows down “without alteration, except to identify the parties,” into subcontracts for operationally critical support or where performance involves CDI (DFARS 252.204-7012(m)). DFARS 252.204-7021flows down “the substance of this clause.” On a CUI subcontract that involves CDI, bothapply — the sub owes 800-171 safeguarding and 72-hour incident reporting under 7012, and the correct CMMC status under 7021. CMMC did not replace 7012. It sits on top of it.
What the 2026 FAR overhaul changed — and what’s still on the books
On February 1, 2026, DoD issued a class deviation (DoD Class Deviation 2026-O0025) under the Revolutionary FAR Overhaul that created a new FAR Part 40 and DFARS Part 240for information security and supply-chain requirements, renumbered several cybersecurity clauses, and removed the standalone “basic” NIST SP 800-171 self-assessment because CMMC now covers that ground. Here’s the part most pages get wrong in one direction or the other: this was done by class deviation, ahead of formal rulemaking, so both numbering systems are live right now.
| Codified DFARS/FAR (still in the CFR and on Acquisition.gov) | 2026 class-deviation (RFO) reference — use when the solicitation directs it |
|---|---|
| FAR 52.204-21 — Basic Safeguarding (FCI); prescribed in FAR Part 4 | FAR 52.240-93 — same 15 requirements, moved under FAR Part 40 |
| DFARS 252.204-7019 — NIST 800-171 assessment notice; prescribed at DFARS 204.7304(d) | Eliminated under the deviation (the “basic self-assessment” concept is removed) |
| DFARS 252.204-7020 — NIST 800-171 DoD Assessments; prescribed at DFARS 204.7304(e) | DFARS 252.240-7997 — Medium/High government assessments, prescribed at DFARS 240.370-5; “basic” self-assessment removed |
| DFARS 252.204-7012 — Safeguarding CDI / incident reporting | Unchanged by the deviation |
| DFARS 252.204-7021 — CMMC | Unchanged by the deviation |
As of the May 7, 2026 DFARS change set, Acquisition.gov and the eCFR still show DFARS 252.204-7019 and 252.204-7020, and DFARS 204.7304 still prescribes them — because the deviation has not yet been codified through rulemaking. The practical rule for a live procurement is simple: follow the clause numbers and text in your actual solicitation, and re-check Acquisition.gov before you rely on a number. And don’t read “7019 is going away” as “the assessment requirement is gone” — the clause numbers changed; the safeguarding and assessment expectations did not.
Are COTS items, commercial products, and commercial services treated the same?
No. DFARS 252.204-7021 excludes subcontracts and other contractual instruments that are solely for COTS items from the CMMC subcontract flowdown obligation. But the clause does flow into subcontracts for commercial products and commercial services where the subcontract contains a requirement to process, store, or transmit FCI or CUI.
View at acquisition.govThe COTS carve-out is narrow and item-based, not a blanket “commercial” exemption. A subcontract for a commercial product or commercial service that involves CUI still carries flowdown. Two separate questions decide it: (1) is the subcontract solely for COTS items, and (2) will the supplier process, store, or transmit FCI or CUI? If the answer to (1) is yes, the 7021 flowdown obligation doesn’t attach. If the answer to (2) is no, there’s no CMMC data trigger under 32 CFR § 170.23 regardless of how the item is labeled.
Can a prime just require every supplier to be Level 2?
Answer capsule:A prime can set stricter business terms in its own supplier program, but the regulatory CMMC flowdown minimum follows the information shared and the contract’s required assessment type — not a blanket policy. Defaulting every supplier to Level 2 is administratively simpler, but it over-scopes vendors that never touch CUI, raises costs, and can push small businesses out of the supply chain when CUI isn’t actually in play.
You canimpose a stricter floor as a matter of business risk tolerance, and plenty of large primes do, because uniform requirements are easier to manage across thousands of suppliers. But “easier to manage” and “correct” aren’t the same thing, and a blanket Level 2 mandate has real costs: it inflates supplier pricing, slows awards, and — for the small specialty shops the DIB depends on — can make a contract uneconomical. GAO put hard numbers on the strain: as of December 2025, only 92 C3PAOs were authorized to perform Level 2 certification assessments against a defense supply chain of roughly 200,000 companies(GAO-26-107955, March 2026). Pushing suppliers toward third-party certification they don’t actually need wastes a scarce resource.
The disciplined move is to classify first, then require only what the data demands. That protects the information and the supplier base.
How does a prime verify a subcontractor’s CMMC status if it can’t see SPRS?
Primes need a documented evidence process because SPRS — the DoD database that holds CMMC status — is not a public supplier-verification directory, and DoD will not give primes direct access to a subcontractor's SPRS data. Subcontractors may share SPRS screenshots or certifications with primes for verification, while DFARS 252.204-7021 still makes the prime responsible for ensuring the sub has appropriate current status before award.
View at acquisition.govThis is the operational gap that catches primes off guard. You’re accountable for not flowing CUI to a non-compliant sub — and you can’t simply look up the sub’s score. DoD confirmed in the rule’s responses that it will not share subcontractor CMMC information with prime contractors; instead, subcontractors may provide SPRS screenshots or certifications to primes for verification (DFARS final rule, Federal Register, Sept. 10, 2025). So you have to build verification into your supplier process.
There’s a real legal-risk dimension behind this. The annual affirmation is signed by an “affirming official” — a senior company representative attesting continuous compliance in SPRS. False cybersecurity representations can create False Claims Actrisk when they’re tied to government contract payment, award, or compliance. The Department of Justice’s Civil Cyber-Fraud Initiative specifically uses the False Claims Act to pursue contractors and grantees that knowingly provide deficient cybersecurity, knowingly misrepresent their cybersecurity practices, or knowingly violate obligations to monitor and report cyber incidents. That risk runs to the sub making the claim and to a prime that knowingly relies on a supply chain it has misrepresented as compliant.
The supplier evidence packet (request this — and no more)
| Supplier level/status | Evidence to request | What to verify | What not to ask for by default |
|---|---|---|---|
| No FCI/CUI | Data-flow memo or no-covered-info representation | That no covered data is processed/stored/transmitted | A full System Security Plan (SSP) |
| Level 1 | Level 1 self-assessment / affirmation evidence | CAGE code, scope, date, affirming official | Level 2 control evidence |
| Level 2 (Self) | CMMC Level 2 (Self) status, affirmation, scope | Status, CAGE, environment boundary, scope | The full SSP unless contract/risk justifies it |
| Level 2 (C3PAO) | CMMC UID, status, C3PAO assessment scope, affirmation | Final vs Conditional status, expiration, scope | Raw assessment artifacts unless needed |
| CSP / ESP | Authorization/equivalency, shared-responsibility matrix, service boundary | Whether the service handles CUI or SPD | A generic “compliance” badge |
A note on restraint: asking for a supplier’s full SSP “just to be safe” is a mistake. It’s a sensitive document, and casually collecting it across dozens of suppliers creates disclosure risk you now own. Request targeted status evidence first.
What is a CMMC UID, and what should the prime ask for?
A CMMC Unique Identifier (CMMC UID) is the identifier SPRS assigns to a specific CMMC assessment for a contractor information system. DFARS 252.204-7025 requires offerors to provide a CMMC UID for each information system that will process, store, or transmit FCI or CUI, so for a Level 2 (C3PAO) subcontractor, the UID plus the assessment scope and current status is the cleanest evidence a prime can request.
When you’re verifying a certified sub, don’t settle for “we’re certified.” Ask for the CMMC UID, the assessment scope it covers, the status (Conditional vs Final), and the expiration window. The UID ties the claim to a specific assessment and a specific system boundary — which is what you actually need to confirm the right environment is covered for the work you’re flowing down.
Handle screenshots like records
Any SPRS screenshot you accept should be date-stamped, tied to the supplier’s CAGE code and assessment scope, redacted where appropriate, stored in your supplier-risk records, and re-requested on renewal and on the annual affirmation cycle. A screenshot from 14 months ago proves nothing about today.
Questionnaire language you can adapt
“Will your organization process, store, or transmit FCI or CUI for this subcontract? If yes, identify the system boundary, CAGE code, current CMMC status and assessment type, CMMC UID (if applicable), affirmation date, and whether any lower-tier subcontractor will receive FCI or CUI.”
That single question forces the data-flow answer that drives everything else. If you’d rather build this into a documented, repeatable supplier-verification process instead of a one-off email, we can point you to the provider categories that do exactly that.
Get matched with source-checked provider options →
What should a CMMC flowdown letter or subcontract clause include?
Answer capsule:A CMMC flowdown letter should never just say “be CMMC compliant.” It should identify the information type, the required level and assessment type, the evidence required before award, the annual affirmation expectation, lower-tier flowdown obligations, change-notification requirements, and whether DFARS 252.204-7012 cyber-incident and cloud obligations also apply. Use counsel-approved language for the actual subcontract instrument.
We see a lot of flowdown letters. The bad ones all share a tell: they’re vague. The good ones are specific enough that the supplier knows exactly what to do and the prime has a defensible record.
Minimum components of a usable flowdown letter:
- Contract or solicitation reference number
- The applicable DFARS/FAR clauses
- Whether FCI or CUI (or CDI) is shared
- The required CMMC level
- The assessment type (self vs C3PAO)
- The evidence deadline (before award)
- The lower-tier flowdown obligation
- The annual affirmation requirement
- A duty to notify if status changes
- A named point of contact
Bad flowdown language:
“Supplier must be CMMC compliant.”
Better flowdown language (sample structure, not legal advice):
“Supplier will process, store, or transmit CUI in performance of this subcontract and must maintain CMMC Level 2 [Self / C3PAO, as applicable] status for the assessment scope used to perform the work; provide evidence of current status and annual affirmation before award and upon renewal; and flow down applicable requirements to any lower-tier subcontractor that will process, store, or transmit FCI or CUI.”
That’s a reusable asset — the contrast itself teaches you how to fix your own letter. Have counsel finalize the binding clause.
What does CMMC flowdown actually cost you?
Cost tracks the flowed-down level. DoD's rulemaking models a Level 2 self-assessment cycle at over $37,000 for a small entity and a Level 2 (C3PAO) cycle at about $104,670 over three years for a small entity (roughly $118,000 for a larger entity). Those figures cover the assessment and affirmations — not the cost of implementing NIST SP 800-171 in the first place, which is a separate and often larger expense.
View at ecfr.govLet’s put the budget conversation where it belongs — early — so the value can build from there. The table separates DoD’s official rulemaking estimate from real-world market and planning ranges, because they answer different questions.
| Your flowed-down level | DoD rulemaking estimate (small entity) | What that estimate covers / excludes | Market & planning reality |
|---|---|---|---|
| Level 1 (Self) — FCI only | Modeled as low; primarily internal time | Self-assessment + affirmation; assumes the 15 FCI safeguards are in place | Planning estimates commonly run from the low thousands up to ~$15,000, mostly internal effort |
| Level 2 (Self) — CUI, prime self-asserts | Over $37,000 over the 3-year cycle | Triennial self-assessment + affirmations; assumes NIST SP 800-171 R2 is already implemented | Implementation/remediation is the real number and is separate — often $20,000–$150,000+ depending on starting maturity |
| Level 2 (C3PAO) — CUI + certification required | ~$104,670 over 3 years (~$101,752 assessment + initial affirmation, plus two annual affirmations); ~$118,000 for a larger entity | Third-party assessment + affirmations; assumes 800-171 R2 already implemented; excludes remediation | Market C3PAO assessment fees alone commonly run ~$30,000–$150,000; all-in (with implementation) often $50,000–$150,000+ |
| Level 3 (DIBCAC) — most sensitive CUI (rare for subs) | Government-assessed; DoD expects it to affect only a small subset of the DIB | Requires a Final Level 2 (C3PAO) status first, plus selected NIST SP 800-172 requirements | Engineering costs are substantial and methodology-dependent; flowdown rarely places a subcontractor here |
Here’s the insight that the headline numbers hide: DoD’s estimate is for the assessment, not for getting your environment ready in the first place. The big swing for most subcontractors is the cost to implement and remediate against NIST SP 800-171 — and the single biggest lever on that cost isn’t negotiating an assessor’s day rate. It’s scope.Every system that touches CUI has to meet all 110 Level 2 requirements, so consolidating CUI into a defined enclave — a limited, controlled set of systems where the sensitive data lives — shrinks how much of your environment carries the full burden.
That’s the honest, reader-first reason to talk to a readiness or enclave provider: not to sell you more, but to make the assessment smaller. If your prime is flowing down CUI and you’re starting from a standard commercial setup, readiness comes before any assessment — and under the Cyber AB CMMC Assessment Process (CAP), C3PAOs must attest to and manage conflicts of interest, so the firm that prepares you generally should not be the one that certifies you. See what a Level 2 readiness program actually involves before you spend.
Want a full breakdown by CMMC Level 2 cost drivers? That page separates assessment fees, implementation, enclave, and managed support line by line.
What if a subcontractor isn’t CMMC-ready before award?
Answer capsule:If a subcontractor isn’t ready, the first question is whether the FCI/CUI flow can be eliminated, reduced, isolated, or delayed. If the supplier truly must handle CUI, route it to readiness and scoping help before any formal assessment — and keep readiness separate from the C3PAO assessment, because under the Cyber AB CAP a C3PAO must manage conflicts of interest with the organizations it assesses.
This is the panic scenario, and there are four real options. Work them in order.
- Remove the supplier from the CUI flow.Redact CUI from bid packages, use no-download portals or prime-controlled environments, or shift the sensitive work to a supplier that’s already compliant. The cheapest CUI to protect is the CUI you never send.
- Isolate the work in an enclave.A dedicated CUI environment — often built on Microsoft GCC High, AWS GovCloud, or a purpose-built CUI collaboration tool — keeps the requirement contained to a small boundary.
- Readiness first, assessment later. Registered Provider Organizations (RPOs), CMMC-focused MSPs/MSSPs, vCISOs, and documentation/GRC providers build the environment and the evidence. A C3PAO comes after, for the formal assessment. The market data backs this sequencing: in Alluvionic’s 2025 State of CMMC report, a survey of C3PAOs performing Level 2 assessments, only about 25% of contractors arrived genuinely well prepared, and roughly half of assessors reported delaying or turning away clients due to readiness gaps. Showing up unready wastes money and time.
- Replace or delay the supplier.If a critical supplier can’t reach the required status before award and no scoping alternative exists, the prime may need a different award strategy. That’s a hard conversation, but it beats an award-blocking surprise or an FCA problem.
If a key supplier isn’t ready, don’t guess between remediation, enclave, assessment, or replacement. Share the supplier’s role, the data flow, the required level, and your award deadline, and we’ll help you find the provider category that fits the situation.
How do MSPs, MSSPs, CSPs, GRC tools, and other external providers affect flowdown?
External providers can change CMMC scope even when they're not traditional manufacturing subcontractors. A Cloud Service Provider that stores, processes, or transmits covered defense information brings DFARS 252.204-7012 cloud requirements into play, and a CSP used for CUI must meet FedRAMP Moderate (or equivalent) under CMMC scoping. An MSP or other External Service Provider that handles CUI can fall under flowdown, while one that only handles Security Protection Data affects assessment scope rather than triggering flowdown on its own.
View at ecfr.govThe blind spot here is assuming “they’re just IT” or “it’s just software,” so they don’t count. They can.
- Cloud Service Providers. Two related requirements, kept distinct. Under DFARS 252.204-7012, an external cloud service that stores, processes, or transmits covered defense informationmust meet FedRAMP Moderate (or equivalent) and support the clause’s incident-reporting and records obligations. Separately, under 32 CFR Part 170’s CMMC scoping, a CSP used to process, store, or transmit CUIis also expected to meet FedRAMP Moderate or equivalent. Standard commercial cloud is not automatically enough — which is exactly why GCC High and GovCloud come up.
- Managed (Security) Service Providers and other ESPs. Start with the data. If the ESP will process, store, or transmit FCI or CUI for the subcontract, flowdown can apply under 32 CFR § 170.23 and DFARS 252.204-7021. If it doesn’t receive FCI/CUI but provides services used to meet your CMMC requirements or handles Security Protection Data (admin accounts, security logs, configurations, vulnerability data), it may still affect your assessment scope, your Customer Responsibility Matrix, your evidence, and your shared-responsibility documentation. A privileged provider that never sees a drawing can still matter to your assessment.
- GRC and evidence platforms.Tools that store your SSP, POA&M, control evidence, and asset inventories aren’t automatically out of scope just because they’re software — and no software, by itself, makes you compliant. GRC is a supporting layer that organizes evidence; it is not the whole CMMC solution.
| Problem | Best-fit category | What they should do | What they should not do |
|---|---|---|---|
| “We don’t know if CUI flows to this supplier” | Scoping / readiness advisor | Map the data flow and boundary | Sell full Level 2 before scoping |
| “Our supplier uses commercial email/cloud for CUI” | Enclave / GCC High / GovCloud provider | Build a controlled CUI environment | Claim the tool alone equals certification |
| “We need evidence from 80 suppliers” | GRC / supplier-risk workflow | Track and organize evidence | Replace control implementation |
| “A small supplier needs to get Level 2 ready” | RPO / MSP / MSSP / vCISO / readiness | Implement and document controls | Blur managed IT with formal assessment |
| “A supplier is ready for third-party assessment” | C3PAO | Perform the formal Level 2 assessment | Remediate, then assess the same engagement |
Does CMMC flow down to lower-tier subcontractors?
Yes. CMMC flows down to lower-tier subcontractors whenever FCI or CUI is passed beyond the first subcontract tier. The prime and each higher-tier subcontractor should document lower-tier data flows, set evidence expectations, and assign responsibility for confirming current CMMC status before covered information is shared.
View at ecfr.govFlowdown follows the data, not the org chart. A Tier 1 machine shop that sends CUI drawings to a heat treater has just created a Tier 2 obligation. A software subcontractor that subcontracts testing involving CUI has done the same. So has an MSP that leans on a lower-tier SOC provider.
What a prime should require from its Tier 1 subs:
- A list of lower-tier suppliers that will receive FCI or CUI
- An evidence process at each tier
- A lower-tier flowdown clause in their subcontracts
- Change notification when status shifts
- A prohibition on sharing CUI with unapproved lower-tier suppliers
The risk if you skip this: CUI quietly leaks to a lower-tier shop with no controls, and the breach at that shop becomes, functionally, a breach of your program.
Does a Level 3 prime contract mean every subcontractor needs Level 3?
No. Under 32 CFR § 170.23(a)(4), if a subcontractor will process, store, or transmit CUI and the prime contract requires Level 3 (DIBCAC), the subcontractor's minimum is Level 2 (C3PAO) — not Level 3 — unless DoD provides contract-specific flowdown guidance.
View at ecfr.govThis is one of the most-misstated points in the whole topic, and getting it right is a trust signal. Many pages assume the sub inherits the prime’s level, so they tell a Level 3 prime’s suppliers they all need Level 3. The regulation says otherwise. Read literally, even when the prime carries the most demanding status in the program, a CUI subcontractor is held to a Level 2 (C3PAO) floor. DoD can issue specific guidance that changes the picture for a particular contract (32 CFR § 170.23(b)), so check your contract — but Level 3 is not the default that cascades to every vendor.
If a prime is pushing Level 3 across the board, that’s a flag to slow down and confirm what the contract actually requires.
When do CMMC flowdown requirements start applying?
The CMMC program rule (32 CFR Part 170) became effective December 16, 2024, and DoD's phased implementation began November 10, 2025, when the DFARS rule took effect. As of June 17, 2026, Phase 1 is active (Level 1 and Level 2 self-assessments); Phase 2 is scheduled to begin November 10, 2026, when Level 2 (C3PAO) certification requirements become more common where applicable.
View at ecfr.govDoD is rolling CMMC into contracts over four phases across three years (32 CFR § 170.3(e)). The timeline matters, but remember the operative trigger is always the clause in your solicitation or contract and the information flowed to you.
| Date | Milestone | Why it matters |
|---|---|---|
| Oct. 15, 2024 | 32 CFR Part 170 final rule published | Established the CMMC program rule |
| Dec. 16, 2024 | 32 CFR Part 170 effective | Program rule took effect |
| Nov. 10, 2025 | DFARS rule effective; Phase 1 begins | CMMC starts appearing in contracts via DFARS 252.204-7021 |
| Nov. 10, 2025 – Nov. 9, 2026 | Phase 1 | Level 1 and Level 2 self-assessments emphasized |
| Nov. 10, 2026 | Phase 2 scheduled | Level 2 (C3PAO) certification becomes a more common condition of award |
| Nov. 10, 2027 | Phase 3 scheduled | Level 3 (DIBCAC) added as a condition of award where applicable |
| Nov. 10, 2028 | Phase 4 / full implementation scheduled | CMMC requirements apply broadly across applicable contracts |
Here’s the scarcity that’s real, not manufactured. If your CUI work will require a Level 2 (C3PAO) certification for a Phase 2 award, the runway is finite: Phase 2 is roughly five months out as of this writing, there were only 92 authorized C3PAOsas of December 2025 (GAO-26-107955), and assessments commonly take months to schedule once you’re ready. Readiness takes longer than scheduling. The math favors starting now. See our CMMC deadlines and phases guide for the full timeline.
What are the biggest CMMC flowdown mistakes?
Answer capsule:The most common and costly flowdown mistakes are over-flowing Level 2 to suppliers that don’t touch CUI, under-flowing to lower-tier suppliers that do, confusing an old NIST 800-171 score with a CMMC status, ignoring CSP/ESP scope, failing to collect annual affirmation evidence, and using vague subcontract language. The fix is the same in every case: classify the data flow first, then request evidence matched to the required status.
| Mistake | Why it matters | Fix |
|---|---|---|
| Blanket Level 2 for every supplier | Inflates cost; can shrink your supplier base | Classify by data flow |
| No lower-tier controls | CUI can leak past Tier 1 | Require lower-tier flowdown evidence |
| Accepting “we’re compliant” | Doesn’t verify current status | Request status, scope, and affirmation evidence |
| Treating an old NIST 800-171 self-assessment score as a CMMC certification | Different evidence; different obligations | Match evidence to the required status |
| Ignoring CSP/ESP roles | Cloud and admin providers can change scope | Build a shared-responsibility map |
| Confusing NIST 800-171 Rev. 3 with the CMMC baseline | CMMC Level 2 currently maps to Rev. 2 | Cite the current rule baseline |
| Requesting full SSPs casually | Sensitive document; disclosure risk | Ask for targeted evidence first |
One clarification worth nailing down, because it confuses even experienced teams: CMMC Level 2 currently incorporates NIST SP 800-171 Revision 2, not Revision 3, under the active CMMC rule. NIST issued Rev. 3 in 2024, but GAO confirmed DoD has not incorporated it into CMMC as of its March 2026 report. Don’t let a vendor scope you to Rev. 3 controls the program doesn’t yet require.
Who should help: readiness provider, MSP/MSSP, GRC tool, enclave provider, or C3PAO?
Answer capsule:Most CMMC flowdown problems are scoping, readiness, evidence, and supplier-risk problems before they are formal-assessment problems. Engage a C3PAO when a supplier is assessment-ready or the question is formal certification; use readiness, MSP/MSSP, enclave, or GRC categories when the problem is implementation, CUI isolation, documentation, or ongoing evidence — and keep readiness/remediation separate from the formal assessment.
There’s a logical order to provider categories, and matching the category to the actual problem is most of the value.
| Your situation | Best category | Why | Next step |
|---|---|---|---|
| “We don’t know which suppliers touch CUI” | Scoping / readiness advisor | Data-flow classification comes first | Map my supplier scope |
| “Our supplier uses commercial email/cloud for CUI” | Enclave / GCC High / GovCloud | The environment may need redesign | Compare secure-collaboration options |
| “We need evidence from dozens of suppliers” | GRC / supplier-risk workflow | This is an evidence-tracking problem | Build a supplier evidence workflow |
| “A small supplier needs to get Level 2 ready” | RPO / MSP / MSSP / vCISO / readiness | Implementation and documentation first | Find readiness support |
| “A supplier is ready for third-party assessment” | C3PAO | Formal Level 2 (C3PAO) assessment | Compare the assessment path |
| “We got Level 2 flowdown but only view CUI in a portal” | Scoping advisor first | The boundary may change the requirement | Review portal-only scope |
When you reach the assessment stage, you can confirm a C3PAO’s authorization directly in the Cyber AB Marketplace — the official directory of authorized assessors and listed professionals (more than 5,300 organizations and individuals as of January 2026, per GAO-26-107955). We point you there because it’s neutral and verifiable; notably, the Cyber AB’s own process states that neither the Cyber AB nor DoD personnel recommend or facilitate introductions to specific C3PAOs, which is part of why an independent mapping of provider categories is useful in the first place.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
What we actually verified
Answer capsule:This page is built from primary sources, not paraphrase. Below is exactly what we checked, where, and when — so you can verify every regulatory claim yourself before you act on it.
- DFARS 252.204-7021 (NOV 2025)— the current clause text, including paragraph (d) flowdown and paragraph (f) Subcontracts — read on Acquisition.gov, June 17, 2026.
- 32 CFR § 170.23 (Application to subcontractors), including the § 170.23(a)(4) Level 3 → Level 2 (C3PAO) floor — read on eCFR (current as of June 2026), June 17, 2026.
- Phase schedule — 32 CFR § 170.3(e); Phase 1 effective November 10, 2025, Phase 2 scheduled November 10, 2026, Phase 3 November 10, 2027, Phase 4 November 10, 2028— eCFR and DoD CIO CMMC materials.
- The 2026 FAR overhaul (clause numbering)— confirmed that the codified DFARS still contains 252.204-7019 and 252.204-7020, with DFARS 204.7304 still prescribing them in the current text (DFARS change set dated May 7, 2026), while DoD Class Deviation 2026-O0025 (effective February 1, 2026) moves these requirements into FAR Part 40 / DFARS Part 240 with renumbered clauses (FAR 52.240-93; DFARS 252.240-7997, prescribed at DFARS 240.370-5). 7012 and 7021 are unchanged. Verified on Acquisition.gov and eCFR, June 17, 2026.
- Prime/sub verification— DoD will not share subcontractor SPRS data with primes; subcontractors may share SPRS screenshots/status for verification — DFARS final rule responses (Federal Register, Sept. 10, 2025).
- False Claims Act— risk framing tied to the DOJ Civil Cyber-Fraud Initiative (knowingly deficient cybersecurity, knowing misrepresentation of cybersecurity practices, knowing failure to report incidents).
- CMMC ecosystem capacity— 92 authorized C3PAOs (Dec. 2025); 5,300+ marketplace listings (Jan. 2026); ~200,000 DIB companies — GAO-26-107955, March 12, 2026.
- Cost figures— Level 2 (C3PAO) ~$104,670 over three years for a small entity (~$118,000 larger); Level 2 (Self) over $37,000 for a small entity — 32 CFR Part 170 final rule and its regulatory flexibility analysis. These are rulemaking estimates that assume NIST SP 800-171 R2 is already implemented; actual C3PAO pricing is market-driven.
- Baseline — CMMC Level 2 incorporates NIST SP 800-171 Revision 2(110 requirements, 14 families); Rev. 3 issued but not incorporated as of GAO’s March 2026 report. Level 3 uses selected NIST SP 800-172 (Feb 2021) requirements and a Final Level 2 (C3PAO) prerequisite — NIST CSRC, 32 CFR Part 170, and GAO.
- Conflict-of-interest framing— under the Cyber AB CMMC Assessment Process (CAP), C3PAOs must attest to and manage conflicts of interest.
How we built the decision matrix
The matrix is an editorial decision framework built from primary regulatory sources — it is not a substitute for legal or contractual advice. The regulatory facts come from 32 CFR Part 170, the DFARS clauses, the Federal Register, DoD CMMC materials, NIST, and GAO. The judgments — which provider category fits which problem, when to start with scoping versus a C3PAO, what evidence packet is reasonable, and when a blanket Level 2 approach is operationally harmful — are clearly labeled as our editorial conclusions based on those verified facts.
CMMC flowdown requirements: FAQ
- Does CMMC flow down to subcontractors?
- Yes. CMMC applies to subcontractors throughout the supply chain at all tiers when they process, store, or transmit FCI or CUI on contractor information systems in performance of a DoD contract or subcontract (32 CFR § 170.23(a)). Subcontracts solely for COTS items sit outside the flowdown obligation.
- Do all subcontractors need CMMC Level 2?
- No. FCI-only subcontractors map to Level 1. CUI-handling subcontractors map to Level 2 at minimum, with the assessment type (self vs C3PAO) set by the prime contract and any contract-specific guidance (32 CFR § 170.23(a)).
- Does a Level 3 prime contract mean subcontractors need Level 3?
- Not automatically. Under 32 CFR § 170.23(a)(4), CUI-handling subcontractors under a Level 3 prime contract need Level 2 (C3PAO) at minimum, unless DoD provides contract-specific flowdown guidance.
- Can a prime see a subcontractor’s SPRS score or CMMC status?
- Generally no. SPRS is not a public supplier-verification portal, and DoD will not give primes direct access to subcontractor data. Per the DFARS final rule, subcontractors may share SPRS screenshots or certifications with primes for verification.
- What evidence should a subcontractor provide?
- Evidence should match the required status: a no-covered-info determination, Level 1 affirmation evidence, Level 2 (Self) status, or Level 2 (C3PAO) CMMC UID and status — plus the assessment scope, CAGE-code alignment, and annual affirmation date where applicable.
- Are COTS suppliers exempt from flowdown?
- DFARS 252.204-7021(f)(1) excludes subcontracts solely for commercially available off-the-shelf items from the CMMC subcontract flowdown obligation. Subcontracts for commercial products or services are not exempt if they involve processing, storing, or transmitting FCI or CUI.
- Does DFARS 252.204-7012 still matter under CMMC?
- Yes. DFARS 252.204-7012 remains in force for covered defense information safeguarding, 72-hour cyber-incident reporting, and external cloud requirements. CMMC sits on top of those obligations; it does not erase them.
- What changed with DFARS 7019 and 7020 in 2026?
- A February 1, 2026 class deviation reorganized cybersecurity clauses into FAR Part 40 / DFARS Part 240 and removed the standalone “basic” self-assessment. The renumbered clauses (FAR 52.240-93; DFARS 252.240-7997) apply where the deviation directs, but 7019 and 7020 remain in the codified DFARS pending rulemaking, so you may see both numbering systems. Follow the clause text in your actual solicitation.
- Is NIST SP 800-171 Revision 3 the current CMMC Level 2 baseline?
- No, not under the current rule. CMMC Level 2 incorporates NIST SP 800-171 Revision 2 unless and until DoD amends the rule. GAO confirmed Rev. 3 was issued but not incorporated as of March 2026.
- Can a supplier use a prime-controlled portal to avoid CUI scope?
- Sometimes scope changes when a supplier doesn’t process, store, or transmit CUI on its own systems — but this requires careful documentation of the access model, download controls, roles, and assessment boundary. Treat it as a scoping question, not a shortcut.
- When should a supplier talk to a C3PAO?
- When it’s approaching formal Level 2 (C3PAO) assessment readiness or needs to understand assessment logistics. If the supplier still lacks scoping, controls, an SSP, a POA&M, evidence, or a sound environment design, readiness help comes first.
- What should a small supplier do first after getting a Level 2 flowdown letter?
- Ask what FCI or CUI you’ll actually receive and whether you’ll handle it on your own systems. Then confirm the required level and assessment type, pin down the deadline, and decide whether to scope CUI out, build an enclave, start readiness, or decline the work.
Your next step
You came here to end the confusion and make a decision. Here’s the simplest path forward.
If you only handle FCI, or your subcontract is solely for COTS items, you likely don’t need to pay anyone — document your determination and move on. If you know you need readiness, compare the provider categories that fit. And if you’re still not sure which provider type fits your situation, let us do the matching.
Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options.