CMMC · Common question
Is CMMC required for prime contractors and their subcontractors?
Short answer
Yes. CMMC 2.0 flows down from prime contractors to every subcontractor that touches Federal Contract Information (FCI, Level 1) or Controlled Unclassified Information (CUI, Level 2). If your contract references DFARS 252.204-7012, you almost certainly need CMMC.
CMMC 2.0 is a mandatory cybersecurity framework for the DoD supply chain — and it flows down. When a prime contractor is awarded a contract requiring CMMC, that requirement propagates to every subcontractor that handles the same information. There's no 'small enough to skip' threshold.
The level required depends on the information you touch:
Level 1 (17 controls, self-attestation): required if you handle Federal Contract Information (FCI) — essentially any non-public contract data. About 220,000 companies in the DoD supply chain are at this level.
Level 2 (110 controls mapped to NIST 800-171, third-party assessment): required if you handle Controlled Unclassified Information (CUI). Any contract referencing DFARS clause 252.204-7012 is a strong signal you're at Level 2.
Level 3 (NIST 800-172 additions, DIBCAC assessment): required for a small number of high-priority programs. Most SMBs will never see this level.
As of 2025, the CMMC rule is final and phasing in through 2026. New DoD contracts progressively require certification, and primes are already flowing the requirement down aggressively — often before their own contract technically mandates it. Waiting for the contract to demand CMMC is waiting too long.
Related
Still have questions?
Book a 20-minute walkthrough.
