← Blog

What CMMC Flowdown Actually Means for Companies Seeking Certification

Jonathan Mandell, Founder, Docubark · Aug 20, 2026

If you supply the defense industrial base, you have probably received an email or a subcontract clause telling you that CMMC “flows down” to you. It usually arrives without much explanation, and it often comes with a deadline. This post explains what flowdown actually is, where the obligation comes from, how it decides which level you need, and what changed in July 2026 that you need to understand before you spend a dollar on it.

The short version

Flowdown is the mechanism that pushes cybersecurity requirements from a prime contractor down to its subcontractors. The government contracts with a prime. The prime cannot simply absorb the requirement and shield everyone beneath it. If the prime hands you information that has to be protected, you inherit the obligation to protect it, and you have to prove it. That is flowdown.

The key point most companies miss: CMMC does not automatically apply to every subcontractor. It flows down only when you actually handle protected information in performing the work. What you handle determines whether the requirement reaches you at all, and if it does, at what level.

Where the obligation comes from

Flowdown is not a courtesy or a preference the prime invented. It sits in the contract, and it traces back to a few specific sources:

  • 32 CFR Part 170, the CMMC program rule, establishes the program and the flowdown responsibility. Section 170.23 is the part that spells out what primes owe their subcontractors.
  • DFARS 252.204-7021 requires the prime to hold the required CMMC status at award and to flow the requirement down to subs handling covered information.
  • DFARS 252.204-7012 is the older, foundational clause. It has been in defense contracts since 2017 and requires safeguarding covered defense information under NIST SP 800-171, plus incident reporting. If you do DoD work touching CUI, this clause is almost certainly already in your contract.
  • FAR 52.204-21 sets the 15 basic safeguarding requirements for Federal Contract Information, which underpin CMMC Level 1.

When a prime sends you a flowdown clause, it is passing along an obligation it is contractually bound to enforce. It is not optional on their end either.

Your level is set by your data, not your size or role

This is the single most useful thing to understand. Your required CMMC level is determined by the type of information that flows to you in the performance of the subcontract:

  • You handle only Federal Contract Information (FCI), not CUI. You need Level 1, a self-assessment against the 15 FAR safeguarding requirements, affirmed annually.
  • You handle Controlled Unclassified Information (CUI). You need Level 2, which means all 110 controls from NIST SP 800-171 Revision 2.

Level 2 can be satisfied by a self-assessment or by a third-party assessment from a C3PAO, depending on what the specific contract calls for. A subcontractor’s level can be lower than the prime’s. If the prime holds a Level 2 (C3PAO) certification but only passes you FCI, you land at Level 1. The determining factor is never your job title or business function. It is whether your systems process, store, or transmit the covered data.

Practically, this means the first thing to do when a flowdown notice arrives is to figure out exactly what data you receive and where it lives in your environment. That answer sets everything else.

What the prime is actually required to do

Flowdown is not a one-way handoff. The prime carries continuing obligations that affect you directly:

  • Verify before award. A prime cannot award you a subcontract until you have a current CMMC status posted in the Supplier Performance Risk System (SPRS) at the required level. No status in SPRS, no award.
  • Withhold information until you qualify. A prime is not supposed to share CUI with a subcontractor that has not met the required level. In plain terms: no certification, no data, no work.
  • Collect annual affirmations. Compliance is not a one-time event. Primes must confirm that subcontractors continue to meet the required level, affirmed at least annually.

This is why primes are increasingly sending questionnaires and flowdown forms asking detailed questions about your information systems and security practices. They are documenting your posture because they are on the hook for it.

What changed in July 2026, and what did not

Here is the part you cannot afford to get wrong, because a lot of secondhand advice is now out of date.

On July 13, 2026, the Department of War (the renamed Department of Defense) suspended CMMC Phase 2, the phase that was scheduled to begin November 10, 2026 and would have made third-party C3PAO assessment a condition of award for most Level 2 contracts. The suspension also paused Phases 3 and 4 and pending implementation milestones. A CMMC Reform Task Force was given 60 days to review the program, with recommendations expected around mid-September 2026. As of this writing, no new Phase 2 timeline has been announced.

Now read carefully what was not suspended:

  • Phase 1 self-assessment requirements remain fully in effect. Level 1 and Level 2 self-assessments still appear in contracts as conditions of award.
  • SPRS scores and annual affirmations remain required. You still have to post and maintain your score. Submitting an inaccurate one still carries False Claims Act exposure.
  • DFARS 252.204-7012 is untouched. The underlying obligation to safeguard covered information under NIST SP 800-171 has not moved.
  • Your prime’s flowdown clause still binds you. The Pentagon paused a government verification mechanism. It did not release you from a contract you already signed. Many primes are continuing to require and verify compliance on their own schedule, independent of the government’s timeline. Some large primes were already running 12 months ahead of the rollout before the pause.

The honest read is that the pause changed how compliance is verified, not what you are required to do. The technical work of securing your systems to the NIST standard is the same whether the eventual verification is a self-assessment or a third-party audit. Companies that treat the suspension as a reason to stop are betting on an outcome the task force has not delivered, while their contractual obligations and their prime’s expectations stay exactly where they were.

What to do now

  1. Inventory your contracts and pipeline. Identify which involve FCI and which involve CUI. Option periods in 2026 and 2027 are often your nearest hard deadlines, because status has to be current before an option can be exercised.
  2. Determine your level from your data. FCI-only means Level 1. CUI means Level 2. Do not guess. The classification depends on the program and the data markings.
  3. Scope your environment deliberately. Every system that touches CUI falls inside the assessment boundary. The smaller you can make that boundary, the fewer controls you have to implement and document, and the cheaper and faster certification becomes. Keeping CUI out of general-purpose commercial tools is one of the most effective ways to shrink scope.
  4. Run a gap assessment against NIST SP 800-171 Rev 2 and post an accurate SPRS score. Accuracy matters more than the number, given the liability attached to it.
  5. Track your own subcontractors. If you pass covered information further down the chain, you become the party responsible for flowing requirements down and verifying them. Flowdown is fundamentally a third-party risk problem, and it does not stop at your door. Knowing which of your vendors and subs touch that data, and confirming their status before you share anything, is now part of your compliance obligation, not an afterthought. This is exactly the work a third-party risk management platform like DocuBark is built for: mapping which vendors handle CUI, sending and scoring the right level of questionnaire, and keeping the annual affirmations current so you can prove the chain below you is covered.

The bottom line

Flowdown means the government’s cybersecurity requirements follow the data, wherever it goes, through every tier of the supply chain. Your level is set by what you handle, the obligation is written into your contract, and the July 2026 suspension changed the verification calendar without lifting the underlying duty to protect the information. The companies that stay ready, rather than waiting for the final program design, are the ones that will still be eligible to bid when the picture clarifies.

Flowdown does not stop at your door. If you pass FCI or CUI to vendors and subcontractors below you, you own the job of flowing requirements down to them and verifying they meet them. DocuBark is built for exactly that workflow: mapping which of your vendors touch covered information, sending and scoring the right level of assessment, and keeping their statuses and annual affirmations current so you can prove the chain below you is covered. See how it works.

Book a Demo