Yes. CMMC "flows down" through the entire DoD supply chain, meaning subcontractors must meet the same compliance level the prime contract requires, regardless of your company's size or how many tiers removed you are from the Department of War. There is no size exemption and no tier exemption. If your prime handles CUI and passes any of it to you, drawings, specs, part numbers tied to a DoD program, you're contractually and legally in scope, even as a second- or third-tier supplier.
How CMMC "Flows Down" Through the Supply Chain
Flow-down is the legal mechanism, defined in DFARS 252.204-7021 and 32 CFR 170.23, that extends CMMC requirements from the prime contractor to every tier of the supply chain where CUI is present. A third-tier subcontractor receiving technical data from a second-tier sub carries the same NIST SP 800-171 obligation as a direct subcontractor. CUI doesn't become less sensitive just because it passed through more hands before reaching your systems.
Prime contractors must also flow down three related DFARS clauses:
- DFARS 252.204-7012: requires NIST SP 800-171 compliance
- DFARS 252.204-7019: requires a current NIST SP 800-171 self-assessment score
- DFARS 252.204-7021: requires the applicable CMMC certification level
The 3 Signs You're a Subcontractor in Scope
- You process, store, or transmit CUI, such as drawings, specifications, or part numbers tied to a specific DoD program
- Your contract references DFARS 252.204-7012, 7019, or 7021, even in boilerplate language you may not have read closely
- Your prime has sent you a flow-down clause, supplier security questionnaire, or CMMC certification request
Major primes including Boeing, Lockheed Martin, RTX, and General Dynamics are already assessing their supply chains directly and treating CMMC certification as a condition of new contract awards, rather than waiting for a formal DoD audit.
What Level Do You Actually Need?
Most subcontractors fall into Level 1 or Level 2, depending on the type of data they touch. If you only handle Federal Contract Information (FCI), such as basic order details, Level 1 self-assessment is likely enough. If you handle CUI in any form, expect Level 2 and its full 110 NIST SP 800-171 controls. Level 3 is reserved for the most critical programs facing advanced persistent threats, representing less than 1% of the entire Defense Industrial Base.
The Gap Between "We're Compliant" and "We Can Prove It"
This is where many subcontractors get caught off guard. Industry research shows 69% of contractors claim DFARS compliance through self-assessment, but only 30% have completed the medium- or high-level assessments that would actually validate their security posture. Assuming you're covered because "IT handles that" is very different from having a documented System Security Plan (SSP) and current SPRS score that would hold up if your prime, or the DoD, asked to see it.
What Happens If You Ignore Flow-Down Requirements
- Loss of your current subcontract if your prime cuts non-compliant vendors from active programs
- Disqualification from future solicitations that require a current SPRS score as a condition of award
- Liability exposure for your prime, who is ultimately responsible for verifying your compliance
A scramble under deadline pressure instead of a planned 12-18 month implementation timeline
How Small Subcontractors Can Get Compliant Without an In-House Compliance Team
Most small manufacturers and suppliers don't have a dedicated compliance department, and they don't need one. A turnkey bootcamp and coaching model walks you through scoping your CUI, closing the gaps against NIST 800-171, and documenting everything in an SSP and POA&M, without pulling your team off production for months at a time.
Why Subcontractors Work With Justice IT Consulting
- Registered Practitioner Organization (RPO) with Certified CMMC Professionals (CCPs) and Registered Practitioners (RPs) on staff
- We hold our own CMMC Level 2 certification
- 4-time Top 250 MSSP in the world, 3-time Top 500 MSP in the world
- Our team includes an Amazon Best-Selling Author on CMMC compliance and hosts The CMMC Compliance Guide Podcast
- Family-owned, DFW-based, 60+ five-star Google reviews
Not sure if your subcontract puts you in scope for CMMC? Contact Justice IT Consulting for a straight answer and a clear next step.
