Skip to content
    August 16, 2026| Top Floor Team| 9 min read

    CMMC Flow-Down: What Primes Can and Cannot Require of Subs

    The CMMC level that reaches a subcontractor is set by the information the prime actually shares. Federal Contract Information alone means Level 1 and the 15 requirements of FAR 52.204-21. Controlled Unclassified Information means at least Level 2 and the 110 requirements of NIST SP 800-171 Rev 2. A prime cannot make you Level 2 by regulation simply because the prime is Level 2, though a prime can ask for more by contract, and since the July 13, 2026 suspension of CMMC Phases 2 through 4 the questionnaires we have read have not slowed down. Before you attest to anything, get one fact in writing: what data will you receive? That single answer sets your level, your scope, your cost, and your False Claims Act exposure.

    If you are reading this with a supplier questionnaire open, the order of operations is: establish the data, then answer, then negotiate. The rest of this is how to do each part without over-committing.

    Key takeaways

    • The level that reaches a subcontractor is set by the information the prime actually shares. FCI alone means Level 1; CUI means at least Level 2.
    • Neither DFARS 252.204-7012 nor 252.204-7021 says a subcontractor inherits the prime's level. The flow-down is keyed to the information involved in the subcontracted effort.
    • A prime can still require more by contract. That is a commercial position, not a legal one, and it is a negotiation about price and scope rather than a compliance obligation.
    • Get one fact in writing before you attest to anything: what data will you receive, and will any of it reside on your systems? That answer sets your level, your scope, your cost and your False Claims Act exposure.
    • You are a prime to somebody too, and the cheapest control is often not to share. A redacted drawing, or a supplier working inside your environment, removes a compliance relationship instead of managing it.

    Where the obligation actually comes from

    Two clauses do the work, and they are different instruments.

    DFARS 252.204-7012 is the safeguarding clause. It requires adequate security on covered contractor information systems, implementation of NIST SP 800-171, cyber incident reporting to the Department within 72 hours of discovery, media preservation, and malicious software submission. It flows down to subcontractors when the subcontracted effort involves covered defense information.

    DFARS 252.204-7021 is the CMMC clause. It obliges the contractor to have the CMMC level required by the contract, and it requires flow-down to subcontractors at the level appropriate to the information being shared.

    Notice what neither clause says. Neither one says a subcontractor inherits the prime's level. The flow-down is keyed to the information involved in the subcontracted effort, which is why the data question decides everything.

    Regulation versus contract, and why the distinction is worth money

    A prime is free to write requirements into a purchase order that exceed the regulation. Some do, for reasons that are often defensible: a prime may not want to track which of 900 suppliers received what, so it applies one standard to everyone. That is a commercial position, not a legal one.

    The distinction matters because the two have different remedies. If a prime asserts that the regulation requires you to be Level 2, and the data you receive is FCI only, that assertion is checkable and often resolved by pointing at the flow-down language. If a prime says its own supplier policy requires Level 2 regardless, you are in a negotiation about price, timeline, and whether the work is worth it.

    So the useful reply is never a flat refusal. It is: here is what we understand we will receive, here is the level that follows from it, and if you require more than that, let us talk about scope and schedule.

    The four questions to answer before you answer them

    What data will we receive, specifically? Not "may involve CUI". Ask for the categories and the delivery mechanism. Drawings by email is a different problem from read-only access in the prime's own environment.

    Will any CUI reside on our systems? This is the scoping question in disguise. If you only ever view CUI inside the prime's portal and never store or process it locally, your boundary is very different from a shop that receives files. Get it in writing, because it is also the cheapest scope reduction available.

    What level does the contract itself name? Read the flow-down clause in the subcontract rather than the questionnaire. Questionnaires are drafted by supplier-management teams; clauses are drafted by contracts teams, and they are the ones that bind.

    When is the requirement effective? Since November 10, 2025 Phase 1 has required a CMMC level to be met at award for applicable solicitations. The Phase 2 trigger that would have generalized third-party certification assessments was suspended on July 13, 2026, so a prime asserting a hard November 2026 certification deadline is working from a schedule that no longer exists. What the suspension did and did not change covers the detail.

    Answering the questionnaire without over-committing

    Three rules, learned the expensive way.

    Answer the question asked, in the tense it is asked. "Do you implement multifactor authentication for network access?" is a present-tense question about your current state. "Yes, in progress" is not an answer. Either it is implemented or it is not, and a plan with a date is a better answer than a soft yes.

    Never let a sales or account team submit it alone. The person who wants the order is not the right person to characterize your control environment. In our experience this is the single most common source of inaccurate supplier attestations, and it is fixable with one review step.

    Keep the evidence with the answer. If you say your SPRS score is a given number as of a given date, keep the assessment behind it. A questionnaire response is a representation, and representations to a prime under a federal contract can travel.

    The False Claims Act exposure here is not theoretical. The Department of Justice's Civil Cyber-Fraud Initiative has pursued contractors over cybersecurity representations. It does not require a breach; it requires a claim for payment and an untrue statement.

    You are a prime to somebody too

    Almost nobody in this chain is only a subcontractor. If you send drawings to a machine shop, technical data to a calibration lab, or system access to a software contractor, the same rule runs onward: the level that applies to your supplier is set by the information you share with them, and DFARS 252.204-7012 flows down where the subcontracted effort involves covered defense information.

    Two consequences follow, and the second one saves real money.

    First, a supplier who holds your CUI becomes part of how your CUI is protected. Your System Security Plan has to describe that external relationship, and your assessment scope reaches the interface even though it does not reach their internal systems. Sharing CUI is not a way of moving a problem outside your boundary.

    Second, and this is the lever most buyers miss: the cheapest control is often not to share. A redacted drawing, a dimensioned subset that omits the controlled attributes, or an arrangement where the supplier works inside your environment rather than receiving files, removes an entire compliance relationship rather than managing it. We have watched organizations shrink a supplier CMMC problem substantially by changing what leaves the building instead of by pushing certification demands down a chain of small shops that cannot absorb them.

    That is also the more persuasive answer when your own prime is pressing you. A conversation about which data actually needs to move is a conversation both sides benefit from, and it is more productive than a conversation about who pays for a certification.

    When to say no

    Here is the against-interest part.

    If a prime demands Level 2 certification for a relationship that will send you no CUI, and will not put the data determination in writing, the honest cost of compliance may exceed the value of the work. We have advised small suppliers to decline exactly that, and to say so plainly: we handle FCI, we meet Level 1, we are happy to be assessed on that basis, and we cannot justify a 110-requirement program for this scope.

    If the work is worth it anyway, price it. A Level 2 program is a real project with real capital in it, and a supplier who absorbs that cost silently to keep a purchase order is subsidizing the prime's risk management.

    And if a consultancy quotes you a full Level 2 readiness program before reading the flow-down clause and establishing what data you receive, get a second opinion. That is a scope conclusion drawn before the scoping question was asked.

    Where Top Floor fits

    The first thing our CMMC practice does with a flow-down demand is the boring part: read the subcontract clause, establish the data, and work out which level genuinely applies. Often the answer is a smaller project than the questionnaire implies, and occasionally it is a conversation with the prime rather than a project at all.

    For suppliers who need someone to own the response across many primes, that is standing work rather than a project, which is what a virtual CISO engagement or compliance as a service is for. Answering forty questionnaires consistently is its own discipline, and inconsistency across them is a risk in itself.

    How to decide this week

    Email the prime one question in writing: what categories of information will we receive under this subcontract, and will any of it reside on our systems?

    Read the actual flow-down clause in the subcontract, not the supplier questionnaire, and note the level it names.

    Then map the level to the work: if the honest answer is Level 1, respond on that basis with your FAR 52.204-21 position, and put any excess demand back on the table as a commercial question rather than a compliance one.

    Frequently asked questions

    Can a prime contractor require me to be CMMC Level 2?

    By regulation, the level that flows down follows the information the prime shares with you: Federal Contract Information alone means Level 1, and Controlled Unclassified Information means at least Level 2. A prime cannot make you Level 2 simply by being Level 2 itself. A prime can still impose a higher standard as a matter of contract, which some do to simplify supplier management, but that is a commercial requirement to be negotiated rather than a regulatory one to be accepted.

    Did the CMMC Phase 2 suspension stop primes asking for certification?

    Not in what we have seen. The July 13, 2026 suspension paused Phases 2 through 4 of the contractual rollout, but Phase 1 self-assessment obligations remain in force and prime supplier programs generally have their own timelines. If a prime asserts a November 2026 third-party certification deadline, that specific trigger was suspended, and it is fair to ask what the requirement is now based on.

    What should I do when a prime sends a CMMC questionnaire?

    Establish the data before you answer. Ask in writing what categories of information you will receive and whether any of it will reside on your systems, then read the flow-down clause in the subcontract rather than relying on the questionnaire. Answer in the present tense about your actual current state, keep the supporting evidence with the response, and have someone other than the account team review it before it goes back.

    Does DFARS 252.204-7012 flow down to subcontractors?

    Yes. The safeguarding clause flows down to subcontractors when the subcontracted effort involves covered defense information, and it carries the same obligations: implementation of NIST SP 800-171 on covered systems, cyber incident reporting to the Department within 72 hours of discovery, media preservation, and malicious software submission. It is a separate instrument from the CMMC clause at DFARS 252.204-7021 and was not affected by the July 2026 phase suspension.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.