Is Your DFARS Subcontract Still Subject to CMMC? A 3-Point Self-Check

Reports to: 
02
Location: 

Is Your DFARS Subcontract Still Subject to CMMC? A 3-Point Self-Check

The short answer, for almost every subcontractor: yes, technically. Flow-down obligations do not disappear, even after the Department of War’s CMMC Phase II suspension announcement on July 13, 2026.  Flow-down obligations are the CMMC and DFARS (Defense Federal Acquisition Regulation Supplement) requirements your prime is required to pass down into your subcontract. As a subcontractor, even if you do not deal with the DoW directly, your obligations come from the subcontract with your prime. This contract has the answers on what is still required, and there are 3 self-checks to start with.

Who Is This Written For?

This is written for subcontractors trying to determine whether the suspension changed anything for their specific contract. It cannot tell you what your contract legally means but is designed to show you what to look for, so you know what to ask your prime or your attorney.

How CMMC, NIST 800-171, and DFARS Fit Together

NIST SP 800-171 (National Institute of Standards and Technology) is the technical standard that DFARS 252.204-7012 requires you to follow, and CMMC certification verifies that you're meeting it. Even with CMMC's third-party verification paused, a government-led spot check would still test your NIST 800-171 controls.

The regulatory language can be a lot to digest. A driver's license works about the same way. The law (DFARS 252.204-7012) requires you to meet a driving standard (NIST SP 800-171) before you're allowed on the road. The road test (CMMC certification) is what normally proves you meet it. If a state paused the formal road test but troopers could still pull drivers over to check they're following the rules (a government-led spot check), the law and the standard would not go anywhere, testing would just look different for a while.

Check 1: Does Your Contract Reference DFARS 252.204-7012 or 252.204-7021?

252.204-7012 is the safeguarding clause, requiring you to protect covered defense information (CUI, Controlled Unclassified Information) according to the NIST SP 800-171 security controls and to report cyber incidents. It's been in effect for years; the suspension didn't touch it.

252.204-7021 is the CMMC clause that specifies the required assessment level.

Check your contract for both clause numbers. Finding 7012 alone usually means you have that safeguarding obligation without a formal certification requirement yet. Finding 7021 too means the contract names a specific assessment level, filled in directly within the clause.

Where to look: RFQs, IDIQs, and RFPs often list these DFARS clauses directly within the requirements sections rather than as a separate attachment, so start there. It can be tricky to find, since subcontracts aren't organized the same way across primes. Look in the terms and conditions, a flow-down exhibit, or a reference back to the prime contract by clause number.

If you can't find either clause: don't assume that means you're exempt. Older contracts may predate when this language became standard. If you're not sure why it's missing, contact your contracting officer directly and ask them to confirm what applies.

Once you find it, there are four standard options:

  • Level 1 Self-Assessment
  • Level 2 Self-Assessment
  • Level 2 C3PAO Assessment
  • Level 3 DIBCAC Assessment

The July announcement paused the C3PAO and DIBCAC assessment options, not the underlying requirement. Your contract still names a required CMMC level; you just don't have to complete that outside assessment to prove it while the review is underway.

Check 2: Does Your Contract Cite a Specific CMMC Level or Deadline?

Once you've found your required assessment level, check the date attached to it. Level 2's third-party (C3PAO) requirement was set to become mandatory on November 10, 2026. Level 3's government-led (DIBCAC) requirement was set to phase on November 10, 2027. Both got paused along with the rest of the rollout. Level 1 self-assessment was never part of that pause.

One nuance: your subcontract's flow-down obligations can be lower (less stringent) than your prime's. Even if your prime holds Level 3, check your own contract. The regulation sets your minimum at Level 2 with C3PAO assessment, unless it says otherwise. A prime building a full system may need Level 3's scrutiny while a subcontractor supplying one component may only need Level 2, so it is best to not assume your level matches your prime's.

Check 3: Has Your Prime Confirmed Any Change to Your Requirements in Writing?

The suspension only pauses how the DoW verifies compliance internally. It doesn't touch your contract. Your prime's subcontract terms stay the same unless your prime actually changes them. Primes and subcontractors still need to manage flow-down obligations and assurances of compliance, even without mandatory third-party assessments.

Confirm with your prime, preferably in writing, if there have been any amendments to the subcontract.

Most primes have held steady on requiring CMMC Level 2 from their subs, suspension or not. When a sub flags that they don't actually handle or generate CUI, and only deal with FCI (Federal Contract Information), the prime will sometimes come back and adjust that sub's requirement down to CMMC Level 1. It's the prime's call, not something a sub can claim on their own, but it starts with flagging the gap.

If you're still not sure

Some contracts bury this language in places that aren't obvious on a first read. If you've checked and you're still not confident, you may want to bring in your attorney for the legal read, plus a compliance partner like Treeline to discuss the practical next steps on the matter. 

So, still subject to CMMC? Most likely yes, the suspension didn't erase your contract's terms and there are steps you can take now to still get ahead.