CMMC Ready Now
Compliance Guide

CMMC Flow-Down Requirements: What You Owe Your Subcontractors, and What You Must Verify

If you give Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to a subcontractor, you owe them three things. First, the right clauses. Second, a clear statement of what information they will receive. Third, the CMMC level that information requires. Before award, you also owe the government a check that the subcontractor has a current CMMC status at that level. This post walks through each obligation and cites the regulation behind it.

Which Clauses Actually Flow Down to Subcontractors?

Four clause families matter. Each has its own flow-down trigger.

  • FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. Paragraph (c) requires you to flow the clause down to subcontracts where the subcontractor may have FCI on or passing through its information system. That includes commercial products and services but excludes commercially available off-the-shelf (COTS) items. Its 15 basic safeguarding requirements are the basis of CMMC Level 1. Examples are AC.L1-B.1.I (limit system access to authorized users) and AC.L1-B.1.III (verify and control connections to external systems).
  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. Paragraph (m) requires the clause in subcontracts that involve covered defense information or operationally critical support, including commercial items. It must be included without alteration, except to identify the parties. That is stricter than most flow-down language.
  • DFARS 252.204-7019 and 252.204-7020, NIST SP 800-171 DoD Assessment Requirements. Clause 7020 requires you to flow it to applicable subcontractors (excluding COTS). It also bars you from awarding a covered subcontract unless the subcontractor has a current assessment on record, as covered below.
  • DFARS 252.204-7021, Contractor Compliance with the CMMC Level Requirements. Paragraph (c) requires you to include the substance of the clause in subcontracts where the subcontractor will process, store or transmit FCI or CUI. That includes commercial products and services, but not COTS. Before award, you must also confirm the subcontractor has a current CMMC status at the level appropriate for the information you are flowing down.

The difference between 7012 and 7021 matters. Clause 7012 must go down word for word, while 7021 requires its “substance.” Many primes paste both in verbatim, which meets either standard.

How Do I Decide What CMMC Level My Subcontractor Needs?

The answer is in 32 CFR 170.23(a). It sets the subcontractor's minimum level based on the information you flow to them, not on your own level:

  1. FCI only flows down: the subcontractor needs at least a CMMC Level 1 self-assessment.
  2. CUI flows down and your contract requires a Level 2 self-assessment: the subcontractor needs at least a Level 2 self-assessment.
  3. CUI flows down and your contract requires a Level 2 certification assessment (C3PAO): the subcontractor needs a Level 2 C3PAO assessment.
  4. Your contract requires Level 3: the subcontractor needs at least a Level 2 C3PAO assessment if CUI flows to them. It needs Level 3 only if it receives CUI that is covered by the Level 3 requirement.

The takeaway is that your information decisions set your supplier's burden. If a machine shop only needs a dimensioned drawing that is properly marked as FCI (not CUI), it falls under rule 1. If you send the same shop the full CUI technical data package, it falls under rule 2 or 3. That choice belongs to you, so make it deliberately and document it.

What Do I Owe My Subcontractor Before They Start Work?

Beyond the clause text, your subcontractor needs enough information to comply. In practice, that means:

  • A clear statement of what is FCI and what is CUI. A subcontractor can't scope its environment if it doesn't know what it will be holding. Mark CUI before it leaves your hands, in line with MP.L2-3.8.4 (mark media with necessary CUI markings and distribution limitations).
  • Only the CUI they actually need. Under AC.L2-3.1.3, you must control the flow of CUI in accordance with approved authorizations. Sharing only what the work requires keeps your subcontractor's scope small and your own obligations easier to defend.
  • A secure transfer method. Sending CUI to a subcontractor is a CUI flow you must protect. The relevant requirements are SC.L2-3.13.8 (cryptographic protection of CUI in transit), MP.L2-3.8.5 (control access to media during transport) and AC.L2-3.1.20 (verify and control connections to external systems). Your System Security Plan, required by CA.L2-3.12.4, should describe where CUI goes once it leaves your boundary.
  • The incident reporting chain. Under DFARS 252.204-7012(m)(2), subcontractors must report cyber incidents directly to DoD through the DIBNet portal and also to the prime (or the next higher tier). They must give you the incident report number as soon as practicable. Your own incident handling under IR.L2-3.6.2 (track, document and report incidents) should plan for receiving those reports.
  • The CMMC level required and the reason for it. Tell the subcontractor which rule in 32 CFR 170.23(a) applies to them and what information caused it.

Clause 7012(m)(2) also requires a subcontractor to notify you when it asks the DoD CIO to vary from a NIST SP 800-171 requirement. Make sure your subcontractors know that this reporting duty runs both ways.

What Do I Have to Verify Before Awarding a Subcontract?

Two checks must happen before award, not after.

Under DFARS 252.204-7020, if the subcontractor must implement NIST SP 800-171 under 7012, you may not award the subcontract unless it has completed at least a Basic NIST SP 800-171 DoD Assessment within the last three years. The assessment must be posted in the Supplier Performance Risk System (SPRS). The subcontractor can grant you access to its record, or it can confirm its status to you.

Under DFARS 252.204-7021(c), you must make sure the subcontractor has a current CMMC status at the level the flowed-down information requires. Under 32 CFR Part 170, status depends on both the assessment and an affirmation by a senior official. Level 1 self-assessments and affirmations are annual. Level 2 assessments are valid for three years, and the affirmation must be renewed annually. An assessment with a lapsed affirmation is not a current status.

Keep a record of each check: what you looked at, when you looked and for which subcontract. An assessor, or a contracting officer reviewing your supply chain, will ask how you knew.

Does Flow-Down Apply to Commercial Items, Cloud Providers and IT Service Providers?

Commercial items: yes, generally. FAR 52.204-21, DFARS 7012, 7020 and 7021 all reach commercial products and services when the information triggers apply. The common exclusion is COTS items, meaning products sold in substantial quantities in the commercial marketplace without modification.

Cloud service providers: different rules apply. DFARS 252.204-7012(b)(2)(ii)(D) requires that a cloud service storing, processing or transmitting covered defense information on your behalf meet security requirements equivalent to the FedRAMP Moderate baseline. That obligation is set by the clause itself, not by a CMMC level you assign.

External service providers (ESPs), such as managed IT or security providers: these are handled in the CMMC scoping rules in 32 CFR 170.19, not through the 170.23 flow-down table. If an ESP handles CUI or Security Protection Data for you, its services fall within your assessment scope. How deep an assessor will go depends on the facts of the arrangement, so document it carefully rather than assume a particular result.

What Happens to Flow-Down While the CMMC Rollout Is Still Phasing In?

The obligations in FAR 52.204-21, DFARS 252.204-7012 and DFARS 252.204-7020 don't depend on the CMMC phase-in. If they are in your contract, they apply now and they flow down now.

For DFARS 252.204-7021, the trigger is whether the clause and a CMMC level appear in your contract. 32 CFR 170.3(e) describes a phased implementation. The schedule for the later phases is not settled, and Phase 2 is currently suspended, so don't build supplier plans around a fixed date. The more durable approach is to ask now which of your subcontractors receive FCI only and which receive CUI. You need that answer whatever the timing turns out to be.

If you want help scoping FCI versus CUI assets and boundaries, need a refresher on SPRS scores and the NIST SP 800-171 Basic Assessment, or want to know whether every subcontractor needs Level 2, those posts go deeper on each piece.

Mapping Which Subcontractors Get FCI or CUI?

CMMC Ready Now can walk you through the 32 CFR 170.23 analysis for your supply chain.

Book a Free Call with Rick

Frequently Asked Questions

Do I have to flow DFARS 252.204-7012 down to every subcontractor?

No. Under paragraph (m), 7012 flows down only to subcontracts involving covered defense information or operationally critical support. When it applies, it must be included without alteration except to identify the parties. A subcontractor that never receives covered defense information and provides no operationally critical support does not get the clause.

Does my subcontractor need the same CMMC level as me?

Not necessarily. Under 32 CFR 170.23(a), the subcontractor's minimum level depends on what information you flow to them. If they receive only FCI, they need Level 1 even if you hold Level 2. If you hold Level 3, a subcontractor receiving CUI needs at least a Level 2 C3PAO assessment, and Level 3 only if it receives CUI covered by the Level 3 requirement.

What must a prime verify before awarding a subcontract that involves CUI?

Under DFARS 252.204-7020, the subcontractor must have at least a Basic NIST SP 800-171 DoD Assessment completed within the last three years and posted in SPRS. Under DFARS 252.204-7021(c), it must also have a current CMMC status at the appropriate level. Both checks happen before award.

Can I reduce my subcontractor's CMMC burden?

Yes, by limiting what you share. If a subcontractor only needs information that is FCI and not CUI, 32 CFR 170.23(a) sets their minimum at Level 1. Controlling CUI flow is a requirement in its own right under AC.L2-3.1.3, so sharing the minimum also strengthens your own compliance.

Who does a subcontractor report a cyber incident to?

Under DFARS 252.204-7012(m)(2), subcontractors report cyber incidents directly to DoD through DIBNet and also to the prime contractor or next higher tier. They must give the prime the incident report number as soon as practicable. Reporting only to the prime is not enough.

Are COTS suppliers subject to CMMC flow-down?

Generally no. FAR 52.204-21, DFARS 252.204-7020 and DFARS 252.204-7021 exclude subcontracts for commercially available off-the-shelf items from their flow-down requirements. Commercial products and services that are not COTS can still be covered when FCI or CUI is involved.

Sources

  • 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program, including 170.3, 170.19 and 170.23 (ecfr.gov)
  • FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (acquisition.gov)
  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (acquisition.gov)
  • DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements (acquisition.gov)
  • DFARS 252.204-7021, Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements (acquisition.gov)
  • NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (csrc.nist.gov)