Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
SUBCONTRACTOR DUE DILIGENCE

What a Small Subcontractor Should Ask a Prime About CMMC Requirements Before Signing

Before signing, a subcontractor should clarify the protected data, clauses, CMMC status, approved systems, evidence expectations, incident duties, and cost impact.

Before signing, a small subcontractor should force the CMMC requirement into concrete terms. Ask what FCI/CUI will flow, which clauses will be in the subcontract, what CMMC level/status is required, when it must be current, and which systems or services the prime expects the subcontractor to use.

In practice, the question that matters for a small defense contractor is narrower: does the requirement map to a specific control inside the FCI/CUI boundary, is an owner assigned, and is there current evidence it is actually operating?

The rule in plain English

Do not accept 'you need CMMC' as a complete requirement. The solicitation and subcontract language should identify the contractual basis and the data/work scope that drives it.

Also ask whether the prime will provide marked CUI, customer-furnished systems, collaboration portals, or technical data through methods that change the planned boundary.

How to implement it without overbuilding

Review the draft subcontract with IT/compliance before price and schedule are fixed. Identify requirements that force cloud migration, new tooling, enclave expansion, or third-party assessment cost.

Clarify incident-reporting coordination and whether the prime expects supplier questionnaires or evidence beyond government-required status.

What evidence to keep

Keep the draft/final clause set, written answers from the prime, data-flow assumptions, pricing assumptions, and accepted exceptions.

Use those records to update scope if the prime later changes how information is delivered.

Where teams get into trouble

The biggest mistake is pricing the work before understanding the cyber scope. Another is letting sales promise a CMMC level that the actual environment or contract path does not support.

Small-contractor walkthrough

A small subcontractor receives a draft subcontract that says 'CMMC Level 2' but does not explain what CUI will be provided or which system must handle it. Those questions should be resolved before the company prices cloud migration or commits to a delivery schedule.

For readiness, choose a normal business example rather than a perfect demonstration environment.

For the subcontractor, unresolved handoffs should become written pre-award questions: who sends CUI, through which portal or service, which system is approved to receive it, whether a downstream supplier may be used, and who must approve a change. Those answers are more valuable than a generic supplier-security checklist because they define the actual work the company is pricing.

  • Ask what data will flow.
  • Ask which clauses apply.
  • Confirm required CMMC status.
  • Clarify systems/cloud expectations.

Ask what information will actually reach your system

Before accepting a prime's statement that 'you need Level 2,' ask what FCI or CUI the subcontractor will process, store, or transmit in performance. Under 32 CFR 170.23, that data path controls the regulatory minimum: FCI-only maps to Level 1 (Self), CUI maps to at least Level 2 (Self), and a prime Level 2 (C3PAO) requirement drives the CUI subcontractor to at least Level 2 (C3PAO).

Ask for representative information types, expected CUI categories or markings, delivery methods, prime portals, collaboration tools, and whether the subcontractor will generate controlled information. These answers let a small company design scope before award rather than discovering that drawings or test results have already entered ordinary email and file shares.

Separate the legal minimum from the prime's supplier policy

A prime can negotiate supplier requirements that are more conservative than the regulatory minimum. Ask which obligation comes from 32 CFR/DFARS and which is a commercial condition of doing business. Get the clause, required level and assessment type, date status must be current, and any additional customer or export-security requirement in writing.

If the prime requests Level 2 (C3PAO) for apparently FCI-only work, do not simply assume the request is illegal or automatically required. Ask whether CUI will flow later, whether program-specific guidance applies, or whether the prime is imposing a higher contractual supplier standard. The answer changes price, schedule, and bid/no-bid decisions.

Questions about system, UID, tools, and future changes

Confirm the contracting legal entity, CAGE code, information system used for performance, CMMC UID/status the subcontractor expects to rely on, and whether the prime requires a particular portal, cloud environment, or transfer service. Also ask how the prime expects supplier status evidence to be presented and protected.

Put change handling into the subcontract: new data type, new work package, new prime tool, different assessment type, or downstream subcontracting should trigger a review. A pre-signing email is not enough if later program staff cannot tell which system was approved for the work.

  • Data received/generated.
  • Required clause, level, and assessment type.
  • System/CMMC UID used for performance.
  • Prime-mandated tools and transfer methods.
  • Change-notification and downstream-flowdown duties.

Turn unanswered prime questions into explicit bid assumptions

If the prime cannot yet identify the CUI flow, required assessment type, or mandated platform, put that uncertainty in the pricing and schedule assumptions. State what environment the bid assumes and what change would require repricing or a revised delivery date.

This protects a small subcontractor from agreeing to an undefined Level 2 burden and later absorbing an unexpected cloud migration, assessment, or tool requirement without a contractual discussion.

WORKING CHECKLIST

A short working check

  • Ask what data will flow.
  • Ask which clauses apply.
  • Confirm required CMMC status.
  • Clarify systems/cloud expectations.
  • Price compliance impact.
  • Document incident/reporting contacts.

Common questions

Can a prime impose stricter requirements?

A subcontract can include negotiated security obligations beyond a baseline, so read the actual subcontract and price the obligation.

Should we ask for sample CUI before signing?

Ask for enough description to scope the work without creating unnecessary controlled-data exposure.

What if the prime says Level 2 but no CUI is expected?

Ask for the contractual and data basis and resolve the mismatch before signing.

Can compliance cost be built into the proposal?

Commercial treatment depends on the procurement, but you should at least understand the cost before committing.

Can a prime require more than the regulatory minimum?

A prime may impose additional contractual supplier conditions, but the subcontractor should distinguish those terms from the minimum CMMC flowdown in 32 CFR 170.23.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.