Do CMMC Requirements Flow Down to Subcontractors During the Pause?

The direct answer: yes, CMMC requirements still flow down to subcontractors during the pause, and the pause does not release you from anything your prime has already written into a subcontract. Two separate tracks are running at once. The regulatory track is what the government requires, and on July 13, 2026 the Department of War, as DoD is now styled, suspended only one piece of it: the Phase 2 escalation that would have made third-party certification a condition of award. The contractual track is what your prime requires of you, and that track is governed by your subcontract, not by a Pentagon memo. Primes are still demanding Level 2 certification, current SPRS scores, and current affirmations from subs at every tier, and they are entitled to.
Status verified August 27, 2026. This page is updated when the regulatory status changes.
Why the two tracks diverged
Before July, the two tracks pointed the same direction, so nobody had to distinguish them. A prime demanding Level 2 certification by November 10, 2026 was simply passing along the government's own deadline. When the suspension memoranda froze that milestone along with Phases 3 and 4 and all future implementation dates, the regulatory track stopped moving and the contractual track did not. That is the whole source of the confusion. We cover what the suspension did and did not touch in detail in our status page on the Phase 2 suspension.
The short version for flow-down purposes: this is an administrative pause on assessment escalation, not a repeal. The 32 CFR Part 170 program rule is still on the books. DFARS 252.204-7021 still appears in solicitations and subcontracts. Phase 1, live since November 10, 2025, is explicitly unaffected. So the government is still requiring self-assessment, SPRS posting, and annual affirmation from every tier that touches covered data, while it reconsiders whether and how third-party assessment should apply.
What still flows down, unchanged
Flow-down under CMMC has never been tied to contract size or tier depth. It follows the data. If a prime hands you Federal Contract Information or Controlled Unclassified Information, the corresponding obligations come with it, whether you are a first-tier supplier or a third-tier machine shop that has never spoken to a contracting officer. None of that changed in July.
Also unchanged: the annual affirmation of continuous compliance by a named Affirming Official under 32 CFR 170.22. A current affirmation remains a prerequisite to award and to option exercise, and a false one is treble-damages exposure under the False Claims Act, which the Department of Justice continues to pursue through its Civil Cyber-Fraud Initiative. That liability sits with the person who signs, and it does not move to your prime or to any advisor. DFARS 252.204-7012 also continues in full force, including the 72-hour incident reporting duty to DIBNet, and 7019 and 7020 still govern SPRS posting and government verification access.
Level 1 or Level 2: the determination most subs get wrong
The most common error in the small supplier base is assuming that any DoD subcontract means Level 2. It does not. The level is set by the data you receive.
Federal Contract Information is non-public information generated for or provided under the contract that is not intended for public release. Purchase orders, delivery schedules, and routine specifications often fall here. FCI-only work is Level 1, which is a basic-safeguarding self-assessment plus an annual affirmation. Controlled Unclassified Information is the escalation: controlled technical drawings, engineering specifications, export-controlled data, and similar categories carrying a CUI marking. CUI puts you at Level 2 and the baseline is the 110 controls of NIST SP 800-171 Revision 2, not Revision 3, because the May 2024 class deviation to DFARS 252.204-7012 still pins compliance to Rev 2.
Get this determination in writing from your prime before you scope anything. A prime that cannot tell you which data category it is sending has handed you an unpriced compliance obligation, and you are the one who will affirm to it. If your work does land at Level 2, the practical build is covered in our Level 2 requirements guide for small businesses, and the controls that consistently break small shops are in the hardest CMMC requirements for small manufacturers.
Two tracks, side by side
| Obligation | Regulatory track (government) | Contract track (your prime) |
|---|---|---|
| Level 1 or Level 2 self-assessment | Required, Phase 1 unaffected by the pause | Routinely required, often with score minimums |
| Current SPRS score posted | Required under DFARS 7019 and 7020 | Commonly demanded as a condition of PO release |
| Annual affirmation by named official | Required, 32 CFR 170.22, FCA exposure | Often requested as evidence with the score |
| C3PAO Level 2 certification | Suspended as of July 13, 2026 | Still demanded by many primes, enforceable if signed |
| 72-hour incident reporting | Required, DFARS 7012, unaffected | Some primes impose a shorter window by contract, so check your clause |
Read the right column carefully. A prime is free to impose terms stricter than the regulatory floor, and several are doing so deliberately: to manage their own liability, and to avoid being caught flat-footed if assessments resume. The pause is not a defense against a clause you signed.
Holding a flow-down letter you are not sure how to answer?
An advisor can read the clause against your actual data scope, show you what the pause changed and what it did not, and recommend a defensible response for your team to approve.
What a flow-down letter actually obligates you to do
Treat the letter as a proposed contract amendment, not a notice. Six things typically sit inside it, and each is separately enforceable once you sign. First, confirmation of the data category you receive, which sets your level. Second, a scoping statement covering the systems, people, and facilities that touch that data. Third, a current SPRS self-assessment score on the negative 203 to 110 scale. Fourth, an annual affirmation of continuous compliance by a named executive. Fifth, documented POA&M items with closure dates for anything not fully implemented. Sixth, and this is the clause to negotiate, a commitment to hold third-party certification by a stated date.
That sixth item is where the pause matters commercially. A certification-by-date commitment made when the government had a November 10, 2026 milestone is now a commitment to a date the government itself has abandoned. That is a legitimate basis to ask your prime to tie the date to resumption of the federal requirement rather than to a fixed calendar date. Ask in writing, before signature. After signature you are asking for a favor rather than negotiating a term.
The assessor market is a real variable now
The capacity picture inverted overnight, and it cuts both ways for a sub deciding what to do. Before the pause, roughly 111 authorized C3PAOs and about 3,200 qualified Level 2 assessors faced more than 100,000 companies that would have needed certification. That shortage was itself part of the case for pausing. Since the pause, assessors have reported contract cancellations and layoffs across more than 100 assessment organizations, with per-assessment costs rising on thin volume.
So the calculus is not simply "cancel and save money." If third-party assessment returns in any form, a shrunken assessor base meets the same enormous queue, and the companies that already hold or complete an assessment are positioned to win awards while their competitors wait. If your prime is contractually requiring certification regardless, that decision is largely made for you. The stated driver behind the pause was small-business cost burden, with the Department of War CIO citing SBA data suggesting the coming phases could cost the defense industrial base more than $7 billion a year, so a materially cheaper path is plausible. Plausible is not the same as decided.
What to do in the next 30 days
Keep your Phase 1 posture current, because it is still legally required and it is the foundation of any outcome the reform review produces. That means a live SSP against NIST SP 800-171 Rev 2, an accurate SPRS score, POA&M items with real closure dates, and an affirmation your named official can defend under oath. Get your data-category determination in writing from every prime. Inventory which of your subcontracts already contain certification commitments and which are still in negotiation, and treat those two piles differently. If you support federal work across multiple frameworks, our defense and government practice maps these obligations against the rest of your program so you are not maintaining CMMC evidence in isolation.
What to watch next
Three dates. On or about September 13, 2026, the 60-day CMMC Reform Task Force report is due to the Department of War CIO; the public RFI feeding it closed August 14, 2026. Formal determinations are not expected before mid-October 2026, and analysts consider late 2026 or early 2027 realistic. Watch also for a final rule on the May 2026 proposed DFARS FOCI amendment, which would extend foreign ownership disclosure to uncleared contractors and subcontractors at any tier above $5 million, DoD estimates more than 37,000 affected entities, including over 21,000 small businesses. Its comment period closed in early July 2026 and no final rule has issued. Until those land, the answer for subcontractors does not change: the regulatory track is paused at the assessment step, the contract track never stopped, and your signature is what binds you.
Frequently Asked Questions
Do CMMC requirements still flow down to subcontractors during the pause?
Yes. The July 13, 2026 suspension froze the Phase 2 escalation to third-party C3PAO assessment, not the flow-down structure. CMMC obligations still reach any subcontractor at any tier that receives Federal Contract Information or Controlled Unclassified Information. Phase 1 self-assessments, SPRS score posting, and the annual affirmation by a named Affirming Official under 32 CFR 170.22 remain mandatory, and DFARS 252.204-7021 still appears in new subcontracts.
My prime still requires CMMC certification even though DoD paused it. Do I have to comply?
If it is written into your subcontract, yes. A Pentagon policy memo suspends a government requirement. It does not amend a private agreement between you and your prime. Primes are free to impose security terms stricter than the regulatory floor, and many are doing exactly that to manage their own liability and to avoid a scramble if assessments resume. Your obligation is whatever the executed subcontract says, so read the clause before you rely on the pause.
Am I CMMC Level 1 or Level 2 as a subcontractor?
It depends on what data you receive, not on how big the contract is. If you only handle Federal Contract Information, meaning non-public information generated for or provided under the contract, you are Level 1. If you receive Controlled Unclassified Information such as controlled technical drawings, specifications, or export-controlled data, you are Level 2 and you assess against the 110 controls of NIST SP 800-171 Revision 2. Many small manufacturers assume Level 2 when their actual scope is Level 1.
My prime sent a CMMC flow-down letter. What do I actually have to do?
Start by establishing which data you actually handle, because that sets your level: federal contract information puts you at Level 1, controlled unclassified information at Level 2. Then read what the letter demands against what your subcontract already says, since a request and a signed clause are different obligations. Confirm your SPRS score is current and your affirmation has not lapsed, then respond in writing with your posture and any dated plan of action items.
What does a CMMC flow-down letter actually obligate me to do?
Read it as a contract amendment, not a notice. Typically it asks you to confirm the data type you receive, scope the systems that touch it, post a current SPRS self-assessment score on the negative 203 to 110 scale, record an annual affirmation of continuous compliance by a named executive, maintain documented POA&M items, and in some cases commit to certification by a date. Each of those is separately enforceable once you sign.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.


