Want to learn more about services? Book a free introductory call - "Here"
Does CMMC Apply to You?
CMMC obligations depend on what information you handle, not your size or supply-chain tier. Here's how DFARS 252.204-7021 flow-down actually works for subcontractors.
CMMC BLOG
Daniel McLain
8/28/20266 min read
Does CMMC Apply to You? A Straight Answer for Subcontractors Handling DoD Work
If you're a subcontractor and someone just told you "CMMC applies to us now," the honest answer is: maybe, and it depends on what information actually reaches your systems, not on your company's size, your tier in the supply chain, or what level your prime holds. A lot of small businesses either panic and assume the full 110-practice standard applies to them, or assume it doesn't apply at all because they're "just a small sub." Both assumptions get people in trouble.
A quick note on naming: since a September 2025 executive order, the Department of Defense (DoD) has also been using "Department of War" as a secondary title in some official communications, but DoD remains the department's legal name under federal law and in the regulatory text itself, so that's the term we use here.
Here's how to actually figure out where you stand.
The trigger isn't the contract. It's the information.
Cybersecurity Maturity Model Certification (CMMC) requirements don't attach to a company. They attach to information, specifically Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), and to the systems that process, store, or transmit it.
The Federal Acquisition Regulation (FAR), at clause 52.204-21, defines FCI as "information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government," excluding information the government has already made public and simple transactional data like payment processing (FAR 52.204-21, e-CFR). If you're doing DoD work at all, you're almost certainly touching FCI in some form.
CUI is a narrower, more sensitive category: unclassified government information that still requires safeguarding under a law, regulation, or government-wide policy. Technical drawings marked as CUI, export-controlled specifications, and certain program details are common examples in defense manufacturing and engineering work.
Which category you handle, if either, determines which CMMC level applies to you. It has nothing to do with your headcount or how many tiers down the supply chain you sit.
CMMC Level 1 covers FCI. CMMC Level 2 covers CUI.
CMMC Level 1 exists to protect FCI. It's built on the 15 basic safeguarding requirements in FAR 52.204-21, which CMMC restates as 17 individual practices (a few of the FAR requirements get split into two related CMMC practices each, which is why you'll see both numbers used correctly in different places). Level 1 is assessed through an annual self-assessment. There's no third-party audit involved at this level.
CMMC Level 2 exists to protect CUI. It requires implementing all 110 practices in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Revision 2, currently the applicable baseline (a transition to Revision 3 is in progress; we cover that separately since it doesn't change what applies today). Level 2 is assessed either through a self-assessment, done initially and then every three years with annual affirmations in between, or through a certification assessment by a Certified Third-Party Assessment Organization (C3PAO) when the specific contract requires it.
On that last point: the requirement to expand mandatory third-party C3PAO assessments (often called "Phase 2") was suspended by the Department of Defense in July 2026 pending a program review. Self-assessment obligations were not affected by that pause. We've written about what that suspension does and doesn't change in a separate article, so we won't re-cover it here, but if your subcontract specifically calls for a C3PAO assessment, don't assume the pause removes that requirement from your contract. Confirm it with your prime.
There is no CMMC Level 1.5 or partial designation. If you only handle FCI, you're looking at Level 1. If CUI is in the picture, Level 2 is the floor, regardless of how small your CUI footprint is.
The flow-down mechanic: how your specific level actually gets set
The Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7021 is the clause that puts CMMC into a contract. It requires the prime contractor to hold and maintain the CMMC level the contracting officer specified, for every system used in performance of the contract that processes, stores, or transmits FCI or CUI (DFARS 252.204-7021, Acquisition.gov). That's a contractual requirement on the prime, not just background policy.
The same clause is also the flow-down mechanism. It directs the prime to consult 32 CFR 170.23 and flow down "the correct CMMC level" to its subcontracts, and requires the prime to confirm, before awarding a subcontract, that the subcontractor holds a CMMC status appropriate to the information actually being shared with that subcontractor (32 CFR 170.23, e-CFR).
That "appropriate to the information" phrase is the whole ballgame. Under 32 CFR 170.23, a subcontractor that only handles FCI needs Level 1. A subcontractor handling CUI needs Level 2 at minimum, at whatever assessment type (self-assessment or C3PAO) the flow-down specifies. There's a genuinely useful nuance here too: even when the prime itself holds a Level 3 requirement, a subcontractor is generally still only held to Level 2, because Level 3 assessments are reserved for organizations directly handling the highest-priority programs, not automatically inherited down the chain.
In practical terms: your CMMC obligation is set by what you touch, not by matching your prime's level. A subcontractor that never receives or generates FCI or CUI in performing its piece of the work may not have any CMMC-related obligation from that clause at all.
One more thing worth saying plainly, because contract language and business caution aren't the same thing. What the clause requires is that your prime flow down the level appropriate to your actual information handling. What's simply a sensible practice, not a legal requirement, is getting that determination from your prime in writing rather than assuming it, and reflecting it in your own subcontract review before you rely on it in a proposal or a compliance budget.
A quick example (illustrative, not a rule)
Say a small machine shop is subcontracted to manufacture a component from a technical drawing the prime marks as CUI, and the shop receives, stores, and works from that drawing on its own network. That shop is very likely in Level 2 scope for the systems touching that drawing, because it's processing and storing CUI to perform the work.
Compare that to a staffing firm that places an administrative employee at the prime's own office, working entirely on the prime's systems with no access to FCI or CUI. That firm may not be in CMMC scope at all for that placement, because it isn't itself processing, storing, or transmitting the protected information.
These are illustrations, not universal outcomes. The actual answer always depends on your specific contract, your specific data flow, and what your prime has put in writing. A different drawing, a different access arrangement, or a different subcontract clause can change the answer entirely.
Questions to ask your prime or your contracting officer
Before you spend money on tools, a full System Security Plan (SSP), or an assessment, get clarity on scope. These are the questions worth asking directly, in writing:
What CMMC level, if any, does our subcontract require, and which clause is it tied to?
What specific information (FCI, CUI, or both) will we receive, generate, or store in performing this work?
Which of our systems will actually touch that information, and which are genuinely out of scope?
Is the assessment type specified as self-assessment or C3PAO certification, and has that changed given the current Phase 2 pause?
If our scope is unclear, can we get the CMMC level requirement confirmed in writing before we commit resources?
Getting answers to these isn't a formality. It's the difference between building a compliance program sized to what your contract actually requires and overbuilding (or underbuilding) based on a guess.
What this means for your next step
If you don't yet know whether FCI or CUI reaches your systems, that's the first thing to nail down, not the assessment type, not the SSP, not the tooling. Scope comes first. Everything downstream, your practice count, your assessment path, your timeline, follows from getting that right.
This article is general informational guidance, not legal advice, and it isn't a substitute for reviewing your specific contract and subcontract language. For a determination specific to your contracts, or to prepare for a self-assessment or C3PAO certification assessment, talk to a Registered Practitioner Organization (RPO) or a C3PAO.
Before investing in tools, documentation, or an assessment, make sure you understand what the contract requires and which parts of your environment are actually in scope. ICTS USA can help you evaluate the opportunity, identify the gaps, and determine a practical next step.
Official resources
The Assessment Is Not the First Step
CMMC is not simply an assessment that an organization schedules when a contract requires it.
The organization must first determine what information it handles, identify the systems and service providers in scope, understand the required CMMC level, implement the applicable safeguards, and collect evidence showing that the requirements are operating as intended.
The assessment or self-assessment comes after the scope and security environment have been properly established.
If you’re unsure whether CMMC applies to your organization, start with your contracts, information flows, customers, and systems.
The answer depends on what the contract requires, whether you handle FCI or CUI, and which systems support the work.
