Home / Blog / CMMC Flow-Down Requirements
CMMC and Government Compliance

CMMC Flow-Down Requirements: What Prime Contractors, Subcontractors, and Vendors Need to Know

CMMC obligations do not stop with the prime contractor. When subcontractors and vendors process, store, or transmit FCI or CUI, applicable requirements follow that information through the defense supply chain.

By Fletcher Technology GroupPublished Jul 23, 2026Updated Jul 23, 202618 min read

Cybersecurity obligations in a Department of Defense contract do not stop with the prime contractor.

When a prime shares Federal Contract Information or Controlled Unclassified Information with a subcontractor, supplier, consultant, managed service provider, or other third party, the applicable safeguarding requirements follow that information into the downstream environment.

This is commonly described as the CMMC flow-down requirement or flow-down trigger.

When a downstream organization must process, store, or transmit protected contract information to perform its work, that organization must satisfy the CMMC level and assessment type applicable to that information and subcontract.

There is an important qualification. It is not always correct to say that every vendor must hold the prime contractor's exact CMMC level. The downstream requirement depends on whether the third party receives FCI, CUI, or neither; which CMMC level and assessment type are required by the prime contract; what information is necessary for subcontract performance; what type of provider is involved; whether an exception applies; and whether the DoD provides contract-specific flow-down instructions.

For most organizations in the Defense Industrial Base, the largest operational impact will be at CMMC Level 2, because Level 2 applies to CUI and uses the 110 requirements in NIST Special Publication 800-171 Revision 2.

The Three CMMC Levels

The CMMC model contains three progressively stronger levels.

CMMC levelInformation and risk contextSecurity baselineAssessment model
Level 1Federal Contract Information15 basic safeguarding requirements from FAR 52.204-21Annual self-assessment and affirmation
Level 2Controlled Unclassified Information110 requirements from NIST SP 800-171 Revision 2Self-assessment or C3PAO assessment, as specified by the contract
Level 3CUI requiring enhanced protection against advanced threatsLevel 2 plus 24 selected requirements from NIST SP 800-172DCMA DIBCAC assessment

What Fills the Level 3 Blank?

A common shorthand is:

FCI = CMMC Level 1
CUI = CMMC Level 2
_____ = CMMC Level 3

There is no separate federal information classification that fills the blank. Level 3 still protects CUI. It applies when the DoD requires enhanced protection for designated programs, technologies, or systems exposed to advanced persistent threats.

FCI = CMMC Level 1

CUI = CMMC Level 2

Designated CUI requiring enhanced protection
against advanced persistent threats = CMMC Level 3

Regulatory Status as of July 23, 2026

Time-sensitive CMMC notice

On July 13, 2026, the Department announced the immediate suspension of the planned CMMC Phase II requirements that had been scheduled for November 10, 2026. The Department also stated that Phase I self-assessment requirements remain in place while it conducts a broader program review.

That pause affects the phased expansion of CMMC requirements. It does not erase existing contractual safeguarding duties imposed through clauses such as FAR 52.204-21 and DFARS 252.204-7012.

Contractors should verify the current solicitation, awarded contract, task or delivery order, contract modifications, subcontract language, DFARS clauses, and official DoD CMMC guidance. The controlling requirement is the language incorporated into the applicable contract or subcontract.

Content review reminder: this regulatory-status section should be reviewed within 60 days of publication and whenever the DoD updates CMMC implementation guidance.

What Is Federal Contract Information?

Federal Contract Information, or FCI, is information provided by or generated for the Federal Government under a contract to develop or deliver a product or service that is not intended for public release. It excludes information the Government has already made public and simple transactional information used to process payments.

Examples may include nonpublic contract schedules, internal performance reports, project communications, work instructions, contract-related email, nonpublic deliverable information, and internal status information generated for contract performance.

When FCI resides in or transits through a contractor-owned or contractor-operated information system, FAR 52.204-21 requires 15 basic safeguarding controls. Those safeguards form the basis of CMMC Level 1.

What Is Controlled Unclassified Information?

Controlled Unclassified Information, or CUI, is unclassified information that requires safeguarding or dissemination controls under applicable law, regulation, or Government-wide policy.

CUI is not classified information, but it requires substantially stronger protection than ordinary business information.

Examples in DoD contracting may include controlled technical information, engineering drawings, technical specifications, maintenance procedures, test results, vulnerability information, export-controlled technical data, program documentation, certain acquisition information, personally identifiable information, and other categories identified in the National Archives CUI Registry.

When a contractor information system processes, stores, or transmits covered defense information under DFARS 252.204-7012, the organization is generally required to implement the applicable requirements of NIST SP 800-171. CMMC Level 2 is the assessment framework used to verify that implementation.

Where the Flow-Down Requirement Comes From

The flow-down obligation is established through multiple FAR, DFARS, and CMMC provisions.

FAR 52.204-21: Basic Safeguarding of FCI

FAR 52.204-21 applies when FCI resides in or transits through a contractor information system. Its subcontract paragraph requires the contractor to include the substance of the clause in applicable subcontracts when the subcontractor may have FCI residing in or transiting through its information system. The clause applies to commercial products and commercial services, but excludes commercially available off-the-shelf items.

If a subcontractor will receive FCI through its own information system, the FCI safeguarding requirements must be flowed down.

Under CMMC, a subcontractor that handles only FCI and no CUI requires CMMC Level 1 status.

DFARS 252.204-7012: Safeguarding Covered Defense Information

DFARS 252.204-7012 is the central DoD clause for protecting covered defense information on contractor systems. It addresses adequate security, NIST SP 800-171 implementation, cyber incident reporting, malicious software submission when applicable, preservation of evidence, DoD forensic support, cloud service provider requirements, and subcontractor flow-down.

Paragraph (m) requires the contractor to include the clause in subcontracts or similar contractual instruments for operationally critical support or when subcontract performance will involve covered defense information.

DFARS 252.204-7021: The CMMC Contract Clause

DFARS 252.204-7021 is the clause used to specify the required CMMC level and assessment type. The contracting officer inserts CMMC Level 1 Self, Level 2 Self, Level 2 C3PAO, or Level 3 DIBCAC.

The clause requires the contractor to maintain the required CMMC status, consult 32 CFR 170.23 and flow down the correct level, complete annual affirmations, ensure applicable subcontractors and suppliers complete affirmations, insert the substance of the clause into applicable subcontracts, and verify the subcontractor's appropriate current CMMC status before subcontract award.

32 CFR 170.23: The Flow-Down Matrix

CMMC applies throughout the supply chain at all tiers when contractor systems will process, store, or transmit FCI or CUI in performance of the DoD contract or subcontract.

Information and prime-contract requirementMinimum downstream requirement
Subcontractor handles FCI onlyCMMC Level 1 Self
Subcontractor handles CUI and no higher assessment type is specifiedCMMC Level 2 Self
Prime contract requires Level 2 C3PAO and subcontractor handles CUICMMC Level 2 C3PAO
Prime contract requires Level 3 and subcontractor handles CUICMMC Level 2 C3PAO, unless the DoD or subcontract requires more

The DoD may also provide contract-specific flow-down guidance.

The Critical Correction: Same Level Is Not Always the Rule

A common industry statement is: if the prime is Level 2, every vendor must be Level 2; if the prime is Level 3, every vendor must be Level 3. That is too broad.

The correct rule is that each subcontractor must have the CMMC level and assessment type appropriate to the information and work being flowed down.

Example 1: Level 2 Prime, Vendor Receives No FCI or CUI

A Level 2 prime purchases ordinary office furniture from a commercial vendor. The vendor receives only public or simple transactional information and does not access FCI or CUI. The vendor does not automatically require CMMC Level 2 merely because its customer is a Level 2 prime.

Example 2: Level 2 Prime, Subcontractor Receives Only FCI

A prime awards administrative work that requires nonpublic FCI but no CUI. The subcontractor may require CMMC Level 1, depending on the subcontract and the information involved.

Example 3: Level 2 C3PAO Prime, Machine Shop Receives CUI

A prime sends controlled technical drawings to a machine shop so it can manufacture a component. The machine shop will process and store CUI. The minimum downstream requirement is CMMC Level 2 C3PAO, and the applicable clauses must be included before the CUI is released.

Example 4: Level 3 Prime, Subcontractor Receives CUI

A prime contract requires Level 3. The prime sends CUI to a subcontractor. Under the baseline rule in 32 CFR 170.23, the subcontractor's minimum is Level 2 C3PAO, not automatically Level 3. The DoD may impose Level 3 through contract-specific guidance when the subcontract involves the higher-risk portion of the program.

Example 5: Managed Service Provider Supports the CUI Environment

An MSP administers identity, endpoints, firewalls, logging, backups, or other security capabilities for the prime's CUI enclave. The provider may or may not receive the content of CUI documents. However, it may process Security Protection Data or provide security functions to the assessed environment. That can place the provider's services within the prime's CMMC assessment scope as an External Service Provider.

The Flow-Down Trigger Is the Information and the Work

The flow-down trigger is not simply the existence of a purchase order or vendor relationship.

Will the third party process, store, or transmit protected contract information in its systems to perform the work?

Decision path
1Will the third party receive contract information?
2Is it public, transactional, FCI, CUI, or CDI?
3Match the required CMMC level and assessment type.
4Verify status, scope, clauses, and approved systems.
5Document the decision before award and release.

No protected information

No CMMC flow-down solely because of the vendor relationship.

FCI only

Flow FAR 52.204-21 and require Level 1 when applicable.

CUI or CDI

Flow DFARS 252.204-7012 and the applicable CMMC clause.

Data minimization can materially reduce cost and risk. If a vendor can perform its work without receiving CUI, the prime should design the process accordingly.

Where Should Contractors Look in the Contract?

Cybersecurity obligations may appear in several parts of a solicitation, prime contract, task order, subcontract, or modification.

Section C: Description, Specifications, or Statement of Work

Section C may identify the work the contractor will perform, technical data and deliverables, required access to DoD systems, operationally critical support, data-handling requirements, and cybersecurity functions.

Section H: Special Contract Requirements

Section H may contain program-specific cybersecurity, CUI, incident-reporting, access, or handling requirements that go beyond standard clauses.

Section I: Contract Clauses

Section I is where incorporated FAR and DFARS clauses are commonly listed. Look for FAR 52.204-21, DFARS 252.204-7008, DFARS 252.204-7012, DFARS 252.204-7019, DFARS 252.204-7020, DFARS 252.204-7021, agency-specific security clauses, cloud-computing requirements, and export-control obligations.

Section J: Attachments

Section J may contain Contract Data Requirements Lists, Data Item Descriptions, CUI handling instructions, security plans, program protection plans, incident procedures, network or system requirements, and security classification guidance for classified portions of the work.

Sections L and M During Solicitation

Before award, Section L may include instructions requiring the offeror to provide CMMC or cybersecurity information. Section M may explain how cybersecurity status affects eligibility or evaluation.

Not every acquisition uses the Uniform Contract Format, and requirements may also appear in task orders, purchase orders, statements of work, master agreements, and contract modifications. The contract must be reviewed as a complete package.

What the Prime Contractor Must Do

The Government establishes the requirement in the prime contract. The prime is then responsible for translating the requirement into the supply chain.

1. Identify FCI and CUI

The prime must understand which information is protected and where it will move. This requires coordination among contracts, program management, engineering, IT, cybersecurity, procurement, legal counsel, export compliance, and supply-chain management.

2. Determine What Each Third Party Actually Needs

Before sending information downstream, determine what task the third party will perform, which information is necessary, whether it is FCI, CUI, covered defense information, export-controlled, public, or transactional, and whether the work can be performed in a controlled portal or enclave.

3. Assign the Correct CMMC Requirement

Use the contract, 32 CFR 170.23, and program guidance to determine the required level and assessment type. Do not copy the prime's level into every purchase order without analysis, and do not lower the requirement merely because a preferred supplier is not ready.

4. Verify Status Before Award

When DFARS 252.204-7021 applies, the prime must ensure that the subcontractor has the appropriate current CMMC status before awarding the subcontract or other contractual instrument.

Verification evidence may include required CMMC level and assessment type, CMMC UID, SPRS status, annual affirmation status, assessment expiration date, CAGE code, supplier representations, system and enclave scope, and procurement approval record.

The prime should verify that the status applies to the information system the subcontractor will actually use. A status held by one corporate division does not automatically cover every subsidiary, location, network, or system.

5. Include the Correct Clauses

Applicable FAR and DFARS language must be incorporated into the subcontract, purchase order, master services agreement, or similar instrument. The contract should also define the information being shared, required level and assessment type, incident-reporting paths, further flow-down requirements, secure transfer expectations, evidence rights, and remedies for noncompliance.

6. Control the Release of Information

Protected information should not be released merely because a subcontract has been signed. Before sharing FCI or CUI, confirm that the required clauses are in place, the supplier has the correct status, the approved system or enclave is identified, recipients are authorized, secure transfer methods are available, export restrictions are addressed, and markings are present.

7. Monitor Ongoing Compliance

CMMC status is not a one-time onboarding checkbox. The prime should monitor annual affirmations, assessment validity, material supplier-system changes, cyber incident notifications, lower-tier flow-down, data-access changes, contract modifications, corrective actions, and supplier ownership or location changes.

What the Subcontractor Must Do

A subcontractor cannot assume that CMMC is solely the prime contractor's problem.

Before accepting work, the subcontractor should determine whether FAR 52.204-21, DFARS 252.204-7012, or DFARS 252.204-7021 is included; whether the work involves FCI or CUI; which assessment type is required; which systems will be used; whether cloud and service providers meet applicable requirements; whether lower-tier suppliers will receive protected information; and whether it can satisfy cyber incident-reporting duties.

The subcontractor must then flow applicable requirements to its own lower-tier suppliers. The chain does not stop at Tier 1.

Why Level 2 Will Affect Most CUI Contractors

CMMC Level 2 aligns with the 110 requirements in NIST SP 800-171 Revision 2 across 14 security families: Access Control, Awareness and Training, Audit and Accountability, Security Assessment, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, System and Communications Protection, and System and Information Integrity.

For a small manufacturer, engineering consultant, laboratory, staffing provider, or specialty vendor, receiving a single controlled drawing can bring the systems used to handle that drawing into the CMMC assessment scope.

That scope may include email, user identities, workstations, file servers, cloud storage, backups, remote-access tools, security platforms, network devices, administrative systems, External Service Providers, and physical locations.

This is why the prime must identify flow-down obligations before award and before data exchange. A supplier may require substantial time and investment to establish an appropriate CUI environment.

A Supplier Questionnaire Is Not the Same as Verification

Questionnaires are useful for due diligence, but they do not replace the CMMC status required by the contract.

The following are not interchangeable: "CMMC ready," NIST SP 800-171 implementation, an SPRS score, Level 1 self-assessment, Level 2 self-assessment, Level 2 C3PAO status, and Level 3 DIBCAC status.

A supplier's marketing statement is not proof of contract eligibility.

COTS and Other Important Qualifications

DFARS 252.204-7021 excludes commercially available off-the-shelf items from its subcontract flow-down paragraph. FAR 52.204-21 also excludes COTS items from its subcontract flow-down requirement.

That exception should not be applied casually. A commercial product or service is not automatically a COTS item. The legal definition and the facts of the acquisition matter.

A company also does not avoid flow-down merely by describing itself as a consultant, staffing company, software provider, or commercial vendor. The real questions are what is being purchased, what information the third party will receive, what systems will handle it, and which clauses apply.

External Service Providers and Cloud Providers

Some third parties support the CUI environment rather than receiving a conventional subcontract deliverable. Examples include managed service providers, managed security service providers, security operations centers, identity providers, backup providers, cloud hosting providers, email security providers, endpoint-management providers, and vulnerability-management providers.

An External Service Provider that processes Security Protection Data or performs security functions may be included in the contractor's CMMC assessment scope.

A cloud service provider that processes, stores, or transmits CUI must meet the cloud-security requirements imposed by DFARS 252.204-7012, including the applicable FedRAMP Moderate or equivalent-security requirements.

The contractor should document the service provided, whether the provider handles CUI, whether it handles Security Protection Data, which controls the provider supports, inherited controls, shared responsibilities, required evidence, and the customer responsibility matrix.

Common Flow-Down Mistakes

Sending CUI Before the Supplier Is Ready

Schedule pressure does not override the contract.

Assuming an NDA Satisfies CMMC

An NDA addresses confidentiality. It does not implement NIST SP 800-171 or establish a CMMC status.

Flowing the Prime's Level to Every Vendor

The downstream requirement should be based on the information and work.

Failing to Flow Requirements to Lower Tiers

CMMC applies throughout the supply chain when FCI or CUI is involved.

Accepting "CMMC Ready" as Evidence

Readiness is not a current CMMC status.

Verifying the Company but Not the System Scope

The assessed environment must be the environment used for the subcontract.

Ignoring Service Providers

An MSP, cloud provider, or security platform can materially affect the CMMC scope.

Treating CUI Identification as an IT-Only Task

Contracts and program personnel must determine what is being shared and why.

Failing to Update Purchase-Order Templates

Legacy procurement templates may omit current clauses, verification requirements, and lower-tier flow-down language.

A Practical Prime-Contractor Flow-Down Process

  1. Review the prime contract. Identify applicable FAR, DFARS, agency, program, data, and cybersecurity requirements.
  2. Identify the information required for the subcontract. Determine whether it is FCI, CUI, covered defense information, public, or transactional.
  3. Determine the required CMMC level and assessment type. Use 32 CFR 170.23 and contract-specific guidance.
  4. Classify the third-party relationship. Determine whether it is a subcontractor, supplier, COTS vendor, cloud provider, or External Service Provider.
  5. Verify status and scope. Complete verification before award and before releasing protected information.
  6. Insert the required clauses. Include further flow-down obligations.
  7. Approve the transfer method. Define users, systems, encryption, markings, and retention.
  8. Maintain evidence. Retain classification decisions, contract reviews, supplier verification, and approvals.
  9. Revalidate periodically. Review affirmations, status, scope, and data access at least annually and when conditions change.
  10. Stop the flow when compliance fails. Suspend protected-data exchange and use the contractual escalation process.

The Business Impact for Prime Contractors

A prime can build a strong internal CMMC enclave and still expose the program through an unmanaged supply chain. Potential consequences include ineligible subcontract awards, unauthorized CUI disclosure, cyber incident exposure, contractual remedies, schedule delays, supplier replacement, False Claims Act risk, reputational damage, loss of future eligibility, and increased assessment findings.

The Business Opportunity for Subcontractors

CMMC readiness is not only a compliance expense. For subcontractors and vendors, an appropriate Level 2 environment can become a competitive differentiator. A supplier capable of receiving CUI may be eligible for work that unprepared competitors cannot accept.

A mature supplier should be able to clearly state which CMMC status it holds, which systems and locations are covered, what information it can receive, which secure transfer methods it supports, which shared responsibilities apply, when its status expires, and how it manages lower-tier suppliers.

The Bottom Line

The cybersecurity obligation follows the protected information.

FCI
-> FAR 52.204-21
-> CMMC Level 1

CUI
-> DFARS 252.204-7012
-> NIST SP 800-171
-> CMMC Level 2

Designated CUI requiring enhanced protection
-> Level 2 foundation
-> 24 selected NIST SP 800-172 requirements
-> CMMC Level 3

For subcontractors and vendors, the requirement is not based solely on the prime's corporate CMMC level. It is based on the information and contractual work being flowed down.

CMMC is not only an internal cybersecurity program. It is a supply-chain eligibility requirement.

Frequently Asked Questions

Do all vendors working with a CMMC Level 2 prime need Level 2?

No. A vendor does not automatically need Level 2 solely because it sells to a Level 2 prime. The requirement depends on whether the vendor will process, store, or transmit FCI or CUI and what the subcontract requires.

What CMMC level is required for FCI?

A subcontractor that processes, stores, or transmits FCI and no CUI requires CMMC Level 1 status under the CMMC flow-down rule.

What CMMC level is required for CUI?

CMMC Level 2 is the minimum level for a subcontractor handling CUI. The contract determines whether the required assessment type is Level 2 Self or Level 2 C3PAO.

Does a subcontractor under a Level 3 prime automatically need Level 3?

No. Under 32 CFR 170.23, a subcontractor handling CUI under a Level 3 prime contract requires at least Level 2 C3PAO status. The DoD or subcontract may impose Level 3 when appropriate.

Is Level 3 associated with a different data classification?

No. Level 3 still applies to CUI. It adds enhanced security requirements for designated critical or higher-risk environments.

Which clause requires CMMC flow-down?

DFARS 252.204-7021 requires the contractor to consult 32 CFR 170.23, flow down the correct CMMC level, insert the clause into applicable instruments, and verify the subcontractor's status before award.

Which clause requires NIST SP 800-171?

DFARS 252.204-7012 requires applicable covered contractor information systems to implement NIST SP 800-171 and includes subcontract flow-down and cyber incident-reporting obligations.

Does an NDA satisfy the CMMC requirement?

No. An NDA does not replace required safeguards, assessment status, contract clauses, or system scope.

Does flow-down apply below first-tier subcontractors?

Yes. The CMMC rule applies throughout the supply chain at all tiers when contractor systems process, store, or transmit FCI or CUI.

Does the July 2026 Phase II suspension eliminate existing safeguarding obligations?

No. Phase I self-assessment requirements remain in place, and existing FAR and DFARS obligations continue to apply when incorporated into a contract. Contractors should monitor official guidance because the program is under active review.

How Fletcher Technology Group Can Help

Fletcher Technology Group helps defense contractors design, implement, and document secure environments for CMMC and NIST SP 800-171.

Our services include CMMC Level 1 and Level 2 readiness assessments, FCI and CUI environment scoping, NIST SP 800-171 gap assessments, System Security Plan development, POA&M management, CMMC enclave architecture, Microsoft Azure Government and Microsoft 365 GCC High architecture, Active Directory and Microsoft Entra ID security, technical control implementation, supplier and External Service Provider scoping, evidence development, pre-assessment technical validation, and governance documentation.

Need to scope CMMC flow-down risk?

We can help you identify where FCI and CUI move, assign the right downstream requirements, and build a defensible supplier-verification process.

Related content

Legal and Regulatory Disclaimer

Educational information only

This article provides general educational information and does not constitute legal advice, a binding contract interpretation, or a guarantee of CMMC eligibility or certification.

CMMC, FAR, DFARS, NIST, export-control, program, and contract requirements must be evaluated against the current solicitation, contract, subcontract, data, architecture, and official guidance.

Organizations should coordinate with qualified legal counsel, contracting professionals, cybersecurity personnel, and the applicable contracting officer when determining specific obligations.

Technical and Regulatory References

  1. 32 CFR Part 170 - Cybersecurity Maturity Model Certification Program
  2. 32 CFR 170.14 - CMMC Model
  3. 32 CFR 170.23 - Application to Subcontractors
  4. FAR 15.204-1 - Uniform Contract Format
  5. FAR 52.204-21 - Basic Safeguarding of Covered Contractor Information Systems
  6. DFARS 252.204-7008 - Compliance with Safeguarding Covered Defense Information Controls
  7. DFARS 252.204-7012 - Safeguarding Covered Defense Information and Cyber Incident Reporting
  8. DFARS 252.204-7019 - Notice of NIST SP 800-171 DoD Assessment Requirements
  9. DFARS 252.204-7020 - NIST SP 800-171 DoD Assessment Requirements
  10. DFARS 252.204-7021 - Contractor Compliance with CMMC Level Requirements
  11. DFARS Subpart 204.75 - Cybersecurity Maturity Model Certification
  12. DoD CIO - Cybersecurity Maturity Model Certification
  13. NIST SP 800-171 Revision 2
  14. NIST SP 800-172
  15. National Archives CUI Registry