A CMMC flow-down letter can look like a routine contract requirement, but a single requirement can determine whether your company needs a Level 1 or Level 2 assessment before moving forward. Since CMMC implementation began for new DoW contracts on November 10, 2025, subcontractors handling FCI or CUI need to understand exactly what is being flowed down.
This guide explains what to do when a prime contractor sends a CMMC flow-down requirement in 2026, including how to identify whether FCI or CUI is involved, determine the applicable CMMC level, review assessment expectations, evaluate your current security posture, and clarify requirements with the prime contractor. It also explains the current Phase 2 status and what remains applicable today.
Also Read: CMMC Level 1 vs Level 2, Which Applies to You?
CMMC Flow-Down Requirements: 7 Steps to Take When a Prime Contractor Contacts You
- Review the CMMC Flow-Down Requirement: Read the contract language carefully to understand what cybersecurity obligations the prime is passing down to your organization.
- Determine Whether the Contract Involves FCI or CUI: Identify whether your organization will handle Federal Contract Information (FCI), Controlled Unclassified Information (CUI), or both, as this directly affects the applicable CMMC requirements.
- Identify the CMMC Level Required: Confirm whether the contract calls for CMMC Level 1 or Level 2 based on the type of information involved and the requirements specified in the contract.
- Map the Requirement to Your Systems and Processes: Identify the systems, applications, users, networks, and processes that will store, process, or transmit the information covered by the flow-down.
- Assess Your Current CMMC Readiness: Compare your existing security controls and practices against the applicable CMMC requirements to identify gaps that could affect contract readiness.
- Prepare the Required Documentation and Evidence: Organize policies, procedures, assessment results, system documentation, and other evidence needed to demonstrate that applicable security requirements are being addressed.
- Confirm Requirements with the Prime Contractor and Plan Next Steps: Clarify outstanding requirements, timelines, assessment expectations, and responsibilities with the prime before committing to the applicable compliance obligations.
What Changed for CMMC Flow-Downs in 2026?
For solicitations issued on or after February 1, 2026, two CMMC-related clause numbers changed. FAR 52.204-21 became FAR 52.240-93, and DFARS 252.204-7020 became DFARS 252.240-7997. On July 13, 2026, the Department of War (DoW) also suspended CMMC Phase 2. These changes make it important for subcontractors to review the specific clause language included in the applicable contract or subcontract when evaluating a CMMC flow-down requirement.
For subcontractors, the requirement is more specific than simply asking for a "CMMC certificate." Before awarding a covered subcontract, the prime must ensure that the subcontractor has a current CMMC certificate or current CMMC status at the level appropriate for the information being flowed down. The clause must also be flowed into covered subcontracts and other contractual instruments when they require the subcontractor to process, store, or transmit FCI or CUI. COTS items are excluded from this particular flow-down requirement.
What to Check in 2026
| What It Means for a Subcontractor | CMMC Level |
|---|---|
| Confirm the level specified by the prime's contract or subcontract. | |
| Information Type | Determine whether the work involves FCI, CUI, or both. |
| Contract Language | Look for the applicable CMMC clause and specific flow-down requirements. |
| Current Status | Ensure the required CMMC status is current before subcontract award. |
| System Scope | Identify which systems will process, store, or transmit the covered information. |
| SPRS / UID | Maintain the applicable CMMC information and status required by the contract. |
Also Read: What Is CMMC and Do You Need It?
What to Check When a Prime Contractor Sends a CMMC Request
Before responding to the prime, check:
- Information Involved: Determine whether the subcontract requires your organization to handle FCI, CUI, or both. The type of information involved helps determine which CMMC requirements may apply.
- Required CMMC Level: Confirm the CMMC level specified by the prime and ensure your organization's current status meets the requirement. Do not assume that every subcontractor automatically requires the same level as the prime.
- System Scope: Identify the specific systems, applications, endpoints, or environments that will process, store, or transmit the covered information. This helps establish which systems need to be included in your CMMC scope.
- Contract Language: Review the subcontract for the applicable CMMC clause and flow-down provisions. The contractual language should clarify what requirements the prime expects your organization to meet. FAR 52.204-21 paragraph (c) requires the prime contractor to include the substance of the clause in subcontracts where the subcontractor will handle FCI.
- Current CMMC Status: Verify that your organization's CMMC status is current and corresponds to the level required for the subcontract. If the prime requests supporting information, make sure the information you provide reflects your current status.
- SPRS Information: Confirm the applicable CMMC UID and assessment information associated with the in-scope environment. This allows the prime to verify the required status through the appropriate DoW system.
- Annual Affirmation: Check that the required affirmation of continuous compliance remains current. An outdated affirmation can create an issue even when the underlying security controls remain implemented.
- Timing: Clarify when the prime needs CMMC status verified, particularly if the request is connected to subcontract award or a new flow-down requirement. This gives your team time to resolve any gaps before the contractual deadline.
FCI vs. CUI: Determine What Your Contract Covers
The type of information handled under a DoD contract can influence the CMMC level that applies. FCI is information not intended for public release that is provided by or generated for the Government under a contract, while CUI requires additional safeguarding or dissemination of controls under applicable law, regulation, or government-wide policy.
| Factor | FCI | CUI |
|---|---|---|
| Meaning | Information not intended for public release that is provided by or generated for the Government under a contract. | Government information requiring safeguarding or dissemination controls under applicable authority. |
| CMMC Relevance | Associated with Level 1 basic safeguarding requirements. | Associated with Level 2 broad protection requirements. |
| CMMC Requirements | 15 requirements from FAR 52.204-21. | 110 requirements based on NIST SP 800-171 Rev. 2. |
| Typical CMMC Status | Final Level 1 (Self) | Level 2 status may be Self or C3PAO, depending on the contract. |
| Assessment Frequency | Annual self-assessment. | Self-assessment every three years for Level 2 Self, with annual affirmation. |
| POA&M | Not permitted. | Permitted under defined CMMC conditions. |
| Contract Impact | The applicable contract must specify the required CMMC level. | The applicable contract determines the required Level 2 assessment type and status. |
Also Read: How to Complete Your CMMC Level 1 Self Assessment
Documents and Evidence to Prepare for the Prime
When a prime contractor requests CMMC information, having the right evidence ready can make subcontractor onboarding much smoother. The current DFARS CMMC clause requires applicable contractors and subcontractors to maintain the appropriate CMMC status and annual affirmation, while CMMC status is tied to the specific information systems that process, store, or transmit FCI or CUI.
The most useful evidence package should typically include:
- CMMC Status & UID: Current CMMC status and the applicable CMMC UID(s) associated with in-scope systems.
- Assessment Results: Current self-assessment results entered into SPRS, where applicable.
- Annual Affirmation: Evidence that the affirming official has completed the required annual affirmation of continuous compliance.
- System Scope: Documentation identifying the systems and environments covered by the CMMC status.
- Policies & Procedures: Final versions of relevant security policies, procedures, and processes.
- System & Network Diagrams: Diagrams showing relevant systems, boundaries, connections, and data flows.
- Control Evidence: Configuration records, access information, training records, logs, or other evidence supporting implemented requirements.
For Level 1, the DoW Assessment Guide specifically identifies policies, processes, procedures, training materials, planning documents, and system, network, and data-flow diagrams as examples of evidence that may be examined. It also emphasizes that evidence can involve examination, interviews, and testing, so a document alone may not always demonstrate that a safeguard is actually implemented.
The goal is not to send the prime every security document your organization owns. Prepare a focused evidence package that demonstrates the required CMMC status, scope, assessment, affirmation, and implementation of applicable safeguards, while protecting sensitive internal security information from unnecessary disclosure.
Common Gaps That Can Delay CMMC Readiness
CMMC Level 1 readiness often slows down because organizations focus on implementing controls but overlook scope, evidence, ownership, and consistency. Common gaps include unclear identification of systems handling FCI, outdated policies or network diagrams, incomplete access records, missing evidence of system configurations, and controls that exist on paper but are not consistently implemented. The Level 1 Assessment Guide emphasizes that assessment evidence can include documentation, interviews, and technical testing, so having a policy alone may not demonstrate that a requirement is met.
Organizations should pay particular attention to:
- Unclear FCI Scope: Not knowing which systems and assets fall within the assessment boundary can lead to incomplete assessments.
- Incomplete Evidence: Missing policies, procedures, diagrams, records, or technical evidence can make otherwise implemented controls difficult to demonstrate.
- Outdated Documentation: Final documentation should reflect the organization's current environment rather than an older network or operating model.
- Unassigned Ownership: Requirements without clear control owners can become difficult to maintain and validate.
- Configuration Gaps: Security settings may differ between documented requirements and actual system configurations.
- Inconsistent Practices: Controls need to operate consistently rather than only during assessment or preparation.
Moving Ahead
CMMC flow-down requirements can create unnecessary confusion when subcontractors treat a prime contractor's request as a standalone compliance requirement. A clearer approach is to trace the requirement back to the contract, identify the information and systems involved, verify the applicable CMMC level, and confirm that your status and evidence align. Keeping these details current also makes future prime requests easier to handle and helps prevent avoidable delays during subcontractor onboarding.
Also Read: What CMMC Means for DoD Subcontractors