If you're a subcontractor and a prime just emailed you asking about your CMMC status, you're not alone. The question showing up across the defense supply chain right now is simple: am I actually required to do this?

The answer is: it depends — but there's a straightforward rule that answers it. Your CMMC level is determined by the type of government information your prime passes to you in performance of the subcontract, not by the prime's own certification level and not by the dollar value of the work.

Here's the complete picture.

The Core Rule: Your Data Determines Your Level

CMMC has three levels. Which one applies to a subcontractor is determined by a single question: what information will you receive, process, store, or transmit while performing this subcontract?

Information you handle CMMC Level required What that means
No FCI or CUI — pure labor, materials, manufacturing with no government data involved None CMMC does not apply to you on this subcontract
FCI only — Federal Contract Information (non-public info generated under the contract, like work orders, delivery schedules) Level 1 17 basic cybersecurity controls, annual self-assessment in SPRS
CUI — Controlled Unclassified Information (technical drawings, specs, ITAR-controlled data, export-controlled info) Level 2 110 NIST SP 800-171 controls; third-party C3PAO assessment required beginning November 2026
ℹ️ FCI vs. CUI — the most common confusion. FCI is basic contract information like purchase orders, statements of work, and delivery confirmations. CUI is more sensitive — think engineering drawings, technical specifications, defense-related research data, or anything marked with a CUI designation block. If you're not sure which one you're handling, this guide on CUI identification walks through it.

What Is CMMC Flow-Down?

Flow-down is the legal mechanism that brings CMMC requirements to subcontractors. Under 32 CFR § 170.23, prime contractors are required to:

  1. Identify every subcontractor that will receive FCI or CUI in performance of the contract
  2. Determine the appropriate CMMC level based on what information that sub will actually handle
  3. Include the correct CMMC contract clause in the subcontract
  4. Verify that subcontractors have a current CMMC certificate or self-assessment at the required level before award — and on an ongoing basis

This is not optional for primes. A prime that knowingly uses a non-compliant subcontractor on a CMMC-covered contract — and misrepresents its supply chain compliance to the government — faces liability under the False Claims Act. That's why primes are pushing hard on this right now: their legal exposure doesn't end at their own front door.

Your CMMC level is based on the data your prime actually shares with you — not the prime's own certification level and not the value of the subcontract.

The November 2026 Deadline and What It Means for Subs

CMMC is being rolled out in phases. Here's where things stand as of June 2026:

Phase Date What's required
Phase 1 November 10, 2025 (active now) Level 1 self-assessments and Level 2 self-assessments in SPRS for applicable contracts
Phase 2 November 10, 2026 Level 2 C3PAO assessments required on CUI contracts — self-assessment alone no longer sufficient for most CUI work
Phase 3 ~2027 (DoD discretion) Level 3 requirements for highest-priority CUI programs

For subcontractors handling CUI, the Phase 2 deadline is the critical one. After November 10, 2026, solicitations for CUI work will require a Level 2 certificate issued by an authorized C3PAO — not a self-assessment score, a certificate. A C3PAO assessment typically takes six to twelve months from start to finish, which means subs who haven't started are running short on time.

⚠️ Don't wait for your subcontract to say "CMMC required." Many primes are requiring compliance ahead of the government deadline as a condition of their own supply chain management. Boeing, Lockheed Martin, RTX, and other large primes began assessing sub compliance in early 2026. If you're bidding on prime work through 2026 and beyond, assume you'll need to show a CMMC status.

What If You Don't Handle CUI — Just FCI?

Level 1 is meaningfully lighter than Level 2. The 17 Level 1 controls (drawn from FAR 52.204-21) cover basic cybersecurity hygiene that most legitimate small businesses already have in place:

Level 1 requires an annual self-assessment posted to the Supplier Performance Risk System (SPRS) and a senior official affirmation — not a third-party audit. If you're handling FCI but not CUI, this is your target.

Know your level before your prime asks

CMMC Map walks you through whether you handle CUI or FCI, maps your requirements, and builds the documentation to prove it — so you're not scrambling when the subcontract clause arrives.

Start Your Free 7-Day Trial

Practical Steps for Subcontractors Right Now

Step 1: Read the subcontract clause

Look for DFARS clause 252.204-7012 (Safeguarding Covered Defense Information) or 252.204-7021 (CMMC Requirements). These clauses and the information they require to flow down define whether CMMC applies to your work and at what level. If neither clause appears and your prime is telling you CMMC is required, ask them to show you where in the subcontract it's required.

Step 2: Determine what information you actually touch

Don't assume — confirm. Ask your prime directly: "What type of government information will you share with us in performance of this subcontract? Is it FCI, CUI, or both?" A good prime will tell you. If they won't or can't answer, that's a red flag about whether they understand their own compliance obligations.

Step 3: Get your SPRS score on record

Even if you're not sure what's coming, posting a current self-assessment score to SPRS (with a senior official affirmation) shows good faith and gives the prime something to verify. If you handle FCI and score 110 on the 17 Level 1 controls, you can post that today. If you handle CUI, your SPRS score reflects your current NIST 800-171 implementation — even if it's not 110 yet.

Step 4: If CUI is involved, start your Level 2 readiness work now

A Level 2 C3PAO assessment covers 110 controls across all 14 NIST 800-171 practice families. Most small organizations need six to twelve months to prepare — and that's before you factor in the C3PAO scheduling backlog as November 2026 approaches. If you've been putting this off, starting now may still give you enough runway.

✅ CUI safety note: As you gather documentation and evidence for your CMMC readiness work, do not paste or upload CUI into any compliance tool, AI assistant, or cloud platform that doesn't have a formal CMMC-compliant environment and data handling agreement. Using non-CUI example content or redacted versions is always the safer approach.

Can a Prime Ring-Fence You to Avoid Triggering CMMC?

Sometimes, yes. If a prime can restructure the subcontract so that you genuinely don't receive any FCI or CUI — you're manufacturing a part to a public drawing, for example, with no government-marked information involved — then CMMC may not apply to that specific scope of work. This is called scope reduction, and it's a legitimate strategy primes use for simpler supply relationships.

What's not legitimate: a prime claiming a subcontractor is outside scope while actually sharing CUI with them anyway. That's the scenario that exposes a prime to False Claims Act liability, which is why sophisticated primes take sub-level scoping seriously.

What Happens If You Can't Comply?

If a subcontractor handling CUI cannot achieve CMMC Level 2 compliance, the prime contractor faces a hard choice: restructure the scope so you receive no CUI, find a compliant alternative sub, or risk the contract. In most cases the prime will find a different sub. That's the market reality of November 2026 enforcement — non-compliant CUI subs become a liability primes can't carry.

That's not a reason to panic. It's a reason to know your status now, before a prime is forced to make that call without you in the room.