APTSecurity Management

Do I Need CMMC? A Checklist for Subcontractors

Cody D. Martin//Updated August 9, 2026

CMMC applies if you hold a DoD contract or subcontract containing DFARS 252.204-7021. If you handle only Federal Contract Information you are Level 1. If you handle Controlled Unclassified Information you are Level 2. Your contract clauses decide it, not your company size.

Most companies asking this question are subcontractors who received a flow down and are not sure what it means. Five questions get you an answer.

1. Do you have a DoD contract or subcontract?

Directly, or as a subcontractor at any tier. If you sell to a prime who sells to the Department of Defense, you are in the supply chain even if you have never spoken to a contracting officer.

No to this? CMMC does not apply. Other frameworks might.

2. Which clauses are in the contract?

This is the question that actually decides it. Read the whole contract, including attachments and the statement of work, not just the cover page.

Clause What it means
FAR 52.204-21 You handle FCI. Basic safeguarding applies
DFARS 252.204-7012 You handle CUI. NIST SP 800-171 applies
DFARS 252.204-7019 / 7020 SPRS score posting and assessment access
DFARS 252.204-7021 The CMMC clause

Nothing on this list? Ask your prime in writing. Absence of a clause is not the same as absence of an obligation, and a prime who forgot to flow it down has a problem that will become yours.

3. What government data do you actually touch?

Two categories matter.

Federal Contract Information is information provided by or generated for the government under a contract, not intended for public release. Emails with a contracting officer, delivery schedules, invoices with contract detail. Most suppliers have this.

Controlled Unclassified Information is information a law or policy requires you to safeguard. In defense work the common category is Controlled Technical Information: drawings, specifications, process sheets, research data.

One trap: CUI is often marked, but not always. An unmarked document can still be CUI if it falls into a registered category. Absence of a stamp proves nothing.

4. Which level does that point to?

  • FCI only points to Level 1. Fifteen requirements, annual self assessment
  • CUI points to Level 2. One hundred and ten practices aligned to NIST SP 800-171, plus an SSP, a POA&M, an SPRS score and annual affirmation

5. What did the July 2026 suspension change for you?

Less than the headlines suggest.

Phase 2 was suspended on 13 July 2026, freezing Level 2 third party assessment and Level 3. The regulation itself was not repealed. DFARS 252.204-7012 and 7021 remain in force, so if you handle CUI you still self assess, still maintain an SSP and POA&M, still post a score, and still affirm annually.

During the suspension a contract can specify only Level 1 (Self) or Level 2 (Self).

If you are still unsure

Ask your prime, in writing. They are responsible for telling you what data flows down and which clauses apply. Written questions get written answers, which is what you want on file.

Ask the contracting officer. They can clarify what a contract involves. Asking early is much cheaper than guessing.

Do the scoping properly. It is the single most expensive thing to get wrong. An oversized boundary means paying to secure systems that never needed it. An undersized one means an assessment that fails on scope before it reaches a control.

There is a free readiness check that walks these questions if you would rather work through it yourself first.

  • CMMC
  • DFARS
  • subcontractors
  • FCI
  • CUI

More on compliance