CMMC Assessment Checklist
Download our CMMC assessment checklist!
Quick answer: Prime contractors are legally responsible for ensuring their subcontractors meet applicable CMMC compliance requirements. Under 32 CFR § 170.23, primes must identify which subcontractors handle FCI or CUI, flow the correct CMMC level down through contract language, and verify compliance using tools like SPRS scores and the CCRA questionnaire. Getting this wrong can trigger False Claims Act liability.
Securing your own systems is only half the job. If you're a prime contractor in the Defense Industrial Base, your CMMC compliance obligations extend to every supplier who touches sensitive defense information. A single unprepared subcontractor can jeopardize an entire contract award—and expose your organization to serious legal risk.
This responsibility isn't theoretical. Since November 10, 2025, CMMC requirements have been appearing in new Department of Defense solicitations, and major primes like Boeing, Lockheed Martin, and RTX are already assessing their supply chains independently of the government schedule. Understanding how compliance flows down through your subcontractors is now essential to protecting your programs.
This post breaks down why prime contractors carry this burden, what contract language you need, how to verify subcontractor readiness, and how to support smaller suppliers who may lack in-house compliance expertise.
The legal foundation for CMMC compliance predates the certification program itself. DFARS 252.204-7012 has required DoD contractors to implement NIST SP 800-171 and protect Covered Defense Information since 2017. What changed recently is enforcement and verification.
32 CFR Part 170, which took effect December 16, 2024, established the CMMC framework, defined its certification levels, and codified flow-down obligations. Specifically, 32 CFR § 170.23 requires primes to determine the correct CMMC level for each subcontractor based on the data being shared, then flow that requirement down contractually.
There are two compelling reasons primes cannot ignore this duty:
Put simply, a non-compliant subcontractor can sink an entire contract bid. If a prime needs a certified supply chain to win a DoD contract and one supplier isn't certified, the whole bid is at risk.
Accurate, standardized contract language is the backbone of flow-down compliance. Primes must ensure the right clauses appear—without alteration—in every relevant subcontract.
Three DFARS clauses are central to CMMC compliance:
Contractors should also account for FAR 52.204-21, which sets basic safeguarding requirements for Federal Contract Information. Under DFARS 252.204-7019/-7020, subcontractors must have a current NIST 800-171 assessment posted in SPRS before award.
The most common flow-down failure is inconsistent or missing contract language, which leaves subcontractors unaware of their obligations. Standardizing your subcontract templates—and clearly defining CUI handling requirements—closes that gap.
Inserting a clause is not the same as confirming compliance. Primes need verifiable evidence that their subcontractors have the controls in place. Several mechanisms have become standard across the Defense Industrial Base.
The DoD's Supplier Performance Risk System (SPRS) tracks each supplier's NIST SP 800-171 assessment score by CAGE code. Prime contractors can access these scores directly. Importantly, CMMC certification status in SPRS is only visible to the supplier and the DoD—primes cannot view it themselves, which is why they lean on additional verification methods.
The Cybersecurity Compliance and Risk Assessment (CCRA) is a standardized questionnaire developed by the Defense Industrial Base Sector Coordinating Council and delivered through Exostar. Containing up to 60 questions drawn from NIST SP 800-171, the CCRA lets suppliers complete one assessment and share results with every prime that accepts it on a reciprocal basis—including Lockheed Martin, Boeing, RTX, Northrop Grumman, and General Dynamics. It gives primes independently collected evidence of what controls are actually in place.
Many primes embed compliance verification into their onboarding and renewal processes. RTX, for example, requires suppliers to declare their CMMC certification status on its Annual Supplier Registration form. General Dynamics Mission Systems requires annual supplier certification of CMMC compliance as a condition of future purchase orders, with a minimum SPRS score of 88 and no waivers.
To validate readiness thoroughly, primes should request documentation, such as each supplier's System Security Plan (SSP), Plan of Action and Milestones (POA&M), and current SPRS score.
Smaller and mid-tier suppliers often lack the cybersecurity or legal resources to meet CMMC compliance requirements on their own. Since these suppliers are frequently the most vulnerable link, supporting them protects your programs as much as theirs.
Consider these strategies:
Primes that invest in their suppliers' readiness now reduce the risk of scrambling to replace a non-compliant vendor later.
The consequences of neglecting flow-down CMMC compliance are significant and already active. They include:
Prime enforcement is not waiting for the government's phased rollout. Lockheed Martin has warned that suppliers without a green CCRA rating "may evoke program mitigation actions to reduce or eliminate dependencies on suppliers who are under-prepared." The direction across the Defense Industrial Base is unmistakable: primes are de-risking their supply chains, and non-compliant subcontractors are the risk being managed.
CMMC compliance is a shared responsibility that reaches every tier of your operation. The primes who succeed treat flow-down not as a contractual formality, but as a core part of their cybersecurity and program-risk strategy.
Start with three practical steps. First, map the flow of CUI across your supply chain to identify which subcontractors fall under DFARS 7012 and at what CMMC level. Second, standardize your subcontract language so every relevant clause appears without alteration. Third, put a verification process in place—using SPRS scores, the CCRA, and documented SSPs and POA&Ms—to confirm readiness rather than assume it.
The window to act is already open. Building a compliant, resilient supply chain today is the surest way to protect your eligibility for defense work tomorrow.
Contact us today to learn more about achieving compliance and securing your contracts, or request a quote to start strengthening your supply chain now.
Both parties share responsibility. The prime contractor must determine the correct CMMC level for each subcontractor under 32 CFR § 170.23, flow that requirement down contractually, and verify compliance. Each subcontractor is responsible for achieving and maintaining the certification level assigned to it.
It depends on the data they handle. Subcontractors handling Federal Contract Information (FCI) require Level 1. Those processing, storing, or transmitting Controlled Unclassified Information (CUI) almost certainly require Level 2. The specific level is communicated through the contract, typically via DFARS 252.204-7025.
Level 2 C3PAO certification generally takes 6 to 12 months to achieve. With a current 6-to-7-month backlog to schedule a certified third-party assessor, subcontractors who delay may struggle to meet contract deadlines.
Yes. A prime that knowingly awards work to a non-compliant subcontractor and misrepresents supply chain compliance can face liability under the False Claims Act, along with the loss of contracts and renewal opportunities.
Primes typically combine several methods: reviewing SPRS assessment scores, issuing the CCRA questionnaire through Exostar, requiring annual supplier certifications, and requesting documentation such as System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).