CMMC Flowdown

CMMC flows down with your data. Manage the vendors it reaches.

The moment you pass Federal Contract Information or CUI to a subcontractor or vendor, confirming they meet the right level — and keeping that current — becomes your responsibility. Docubark turns that into a single, trackable workflow: which vendors touch covered data, what level each one needs, and whether their affirmations are up to date.

Flowdown doesn't stop at your own certification

CMMC requirements travel with the data. When protected information moves from one company to the next, the duty to safeguard it moves too. So the moment your organization shares FCI or CUI with a supplier, manufacturing partner, or downstream sub, you inherit the job of pushing the requirement down to them and confirming they meet it — an obligation written into the contract chain through 32 CFR Part 170, DFARS 252.204-7021 and -7012, and FAR 52.204-21.

It doesn't reach every vendor, though — only the ones that actually handle the covered data. That makes the first move clear: figure out which suppliers touch FCI or CUI, because that single answer decides who is in scope and at what level.

A vendor's level is set by the data it touches

Not the vendor's size, not its role in your program — only whether its systems process, store, or transmit the covered information you share.

Level 1 — the vendor handles FCI only

Federal Contract Information

A self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21, affirmed each year.

Level 2 — the vendor handles CUI

Controlled Unclassified Information

The full set of 110 controls from NIST SP 800-171 Revision 2 — met by self-assessment or a C3PAO assessment, depending on the contract.

Because the level tracks the data, two vendors in the same program can land in different places — one at Level 1, one at Level 2 — based solely on what you pass to each.

The July 2026 pause didn't lift your vendor obligations

In July 2026 the government suspended CMMC Phase 2 — the stage that would have required third-party (C3PAO) verification for most Level 2 contracts — and paused the later phases pending a reform review. It's easy to read that as a reason to slow down. It isn't.

Still fully in effect:

  • Self-assessment requirements — Level 1 and Level 2 self-assessments still show up in contracts as conditions of award.
  • SPRS scores and annual affirmations — still required, and an inaccurate score still carries False Claims Act exposure.
  • DFARS 252.204-7012 — the duty to safeguard covered information under NIST SP 800-171 never moved.
  • Your responsibility for the chain below you — confirming the vendors you share covered data with are covered is still your job.

What changed is how compliance gets verified someday — not what you owe today. The vendors handling your CUI need to be secured to the same standard either way.

One workflow for CMMC across your vendors

Flowdown is a third-party risk problem, and Docubark runs it as one — from mapping the chain to keeping it audit-ready.

  • Map your vendors by the data they touch — flag which receive FCI and which receive CUI.
  • Assign each vendor a required level automatically: Level 1 for FCI, Level 2 for CUI.
  • Send the right-level assessment and collect the evidence, then score and chase what’s missing.
  • Gate covered data on status — confirm a vendor qualifies before anything is shared.
  • Keep annual affirmations and evidence current, with one audit-ready record per vendor.

The result: a live view of which vendors are covered, which aren't yet, and what's coming due — instead of a folder of email threads and a spreadsheet nobody trusts.

Building the program, step by step

1

Find the vendors in scope

List every supplier and subcontractor that receives protected information, and mark which handle FCI versus CUI. Vendors that never touch covered data stay out of scope.

2

Set each vendor’s level from its data

FCI-only vendors need Level 1; CUI vendors need Level 2 (the full NIST SP 800-171 Rev 2 control set). The classification follows the data markings, so tie the level to what each vendor actually receives.

3

Assess at the right depth

Send a Level 1 or Level 2 questionnaire to match — no over-asking low-risk vendors, no under-asking the ones handling CUI — and collect the supporting evidence in one place.

4

Verify before you share

Confirm a vendor meets its required level before covered information changes hands. Status first, data second.

5

Keep the chain current

Compliance is not a one-time event. Track affirmations on an annual cadence and keep every vendor’s record ready to show, so proving the chain below you is covered is a report, not a fire drill.

Frequently asked questions

Does CMMC flow down to every vendor? +

No. The requirement reaches a vendor or subcontractor only when they actually receive and handle the protected information tied to the work. A supplier that never touches FCI or CUI is out of scope. That is why the first step is identifying which of your vendors handle covered data — the rest follows from that.

What level does each vendor need? +

It depends entirely on the data they receive. A vendor that only handles Federal Contract Information (FCI) needs Level 1 — a self-assessment against 15 basic safeguarding requirements. A vendor that handles Controlled Unclassified Information (CUI) needs Level 2, which covers all 110 controls in NIST SP 800-171 Revision 2. A vendor’s level is never set by its size or role, only by the data it touches.

Do I have to verify a vendor before sharing CUI with them? +

Yes. If you pass covered information down the chain, you take on responsibility for confirming the receiving vendor meets the required level before you share anything — and for keeping that confirmation current over time. Verifying status up front, not after the fact, is the core of managing flowdown.

Did the July 2026 pause change what I owe for my vendor chain? +

No. The suspension paused third-party (C3PAO) verification of CMMC Phase 2. It did not lift self-assessment requirements, SPRS scores, annual affirmations, or DFARS 252.204-7012. Your responsibility to confirm the vendors below you are covered still stands — the pause changed the verification calendar, not the underlying duty.

How does Docubark help with CMMC flowdown? +

Docubark gives you one place to run flowdown across your vendor base: map which vendors and subs handle FCI versus CUI, send and score the right-level assessment for each, verify status before covered data changes hands, and keep annual affirmations and evidence current and audit-ready — instead of tracking it all in email and spreadsheets.

Know your CMMC chain is covered.

Book a 30-minute demo and we'll show how Docubark maps your vendors to FCI and CUI, assesses each at the right level, and keeps the affirmations current — all in one place.

This page is general information about CMMC flowdown, not legal advice. Regulations, timelines, and program details change; confirm your specific requirements with your contracting officer or counsel. References reflect publicly available information as of 2026.