CMMC Requirements for DoD Subcontractors in 2026
What changed, how CMMC reaches subcontractors, why FCI and CUI matter, and what to verify before accepting a DoD subcontract.
CMMC is now a live subcontract review issue, not a future planning topic. The current DFARS rules allow DoD solicitations and contracts to require a specific Cybersecurity Maturity Model Certification level, and the subcontract flowdown depends on the information and systems used to perform the subcontract.
For a subcontractor, the most important questions are not simply “Do we need CMMC?” They are: what information will we receive, which systems will process it, what CMMC level is required for those systems, and does the prime's subcontract language match that requirement?
The current 2026 DFARS framework
DFARS 252.204-7021 now requires the contracting officer to insert a specified CMMC level when the clause is used. The available levels in the current clause include Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), and Level 3 (DIBCAC).
Under DFARS 204.7504, through November 9, 2028, the clause is used when the program office or requiring activity determines that a specific CMMC level is required, subject to the stated exception. The rule then broadens on and after November 10, 2028 for covered contractor information systems that process, store, or transmit FCI or CUI.
CMMC can flow down to subcontractors
The current DFARS clause expressly addresses subcontractors and suppliers. If a subcontract or other contractual instrument will require processing, storing, or transmitting Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), the prime must flow down the substance of the clause as required by DFARS 252.204-7021.
Before subcontract award, the prime must also ensure the subcontractor has the current CMMC certificate or status appropriate for the information being flowed down, based on the requirements in 32 CFR 170.23. The clause also requires annual affirmations of continuous compliance for applicable subcontractor information systems.
- Will your company receive or generate FCI, CUI, or both?
- Which of your information systems will process, store, or transmit that information?
- What CMMC level does the prime say is required for the subcontract?
- Does the solicitation or subcontract identify the applicable DFARS cybersecurity clauses?
- Does the subcontract require a level higher than the information being flowed down appears to require? If so, ask the prime to explain the basis.
- Will any lower-tier supplier receive FCI or CUI from you?
- Are annual affirmation, SPRS, assessment, incident-reporting, and other cybersecurity duties clearly assigned?
FCI and CUI are not the same thing
The current DFARS clause defines FCI as nonpublic information provided by or generated for the Government under a contract to develop or deliver a product or service, excluding public information and simple transactional information. CUI is information that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy.
That distinction matters because the required CMMC level and the security controls can depend on the type of information involved. We will cover this in a separate dedicated guide so this page stays focused on the subcontract requirement itself.
CMMC does not replace DFARS 252.204-7012
CMMC sits alongside other DoD cybersecurity requirements. DFARS 204.7302 states that contractors and subcontractors must provide adequate security on covered contractor information systems, and contractors required to implement NIST SP 800-171 under DFARS 252.204-7012 also have DoD assessment requirements.
In other words, a subcontractor should review the full cyber clause set, not just the CMMC acronym. The existing SubPreCheck guide on DFARS cybersecurity and data-rights risk points provides the broader context.
Watch for blanket cyber language
A prime may use a standard subcontract template across many suppliers. That can create a mismatch between the clause package and the actual information being shared. Before pricing or accepting compliance obligations, ask the prime to identify the FCI/CUI flow, the required CMMC level, and the systems that will be in scope.
The goal is not to avoid valid cybersecurity requirements. It is to understand the requirement before you commit to the cost, staffing, systems, representations, and lower-tier obligations that come with it.
CMMC is also a flowdown question
CMMC belongs inside the same clause-review process as other FAR and DFARS obligations. Ask where the requirement comes from, what triggers it, what level applies, and whether you must pass it to suppliers. See our guides to FAR and DFARS flowdowns and mandatory vs. prime-added flowdowns.
Official references
Review the current DFARS 204.7504, DFARS 252.204-7021, and DFARS 204.7302 on Acquisition.gov.
Check the Cyber Language Before You Commit
SubPreCheck can surface CMMC, DFARS, CUI, FCI, NIST, and lower-tier language in the package and organize the questions that need follow-up.
View Sample ReportSee Review PlansThis article is general educational information, not legal, cybersecurity, or certification advice. Confirm current DoD requirements and the exact solicitation or subcontract before relying on a CMMC level.