CMMC 2.0 for Subcontractors: What Flows Down to You

If your contractor holds defense work, CMMC requirements may reach you as a subcontractor. Here is what flows down, what CUI means, and how to prepare.

3 min readBy Ironfield Cyber Team

Many construction and energy firms discover they are in the defense supply chain only when a prime contractor sends a questionnaire. If you build, maintain, or supply anything connected to Department of Defense work, cybersecurity requirements may flow down to you through your contracts. Understanding the basics early gives you time to prepare instead of scrambling.

What CMMC is

The Cybersecurity Maturity Model Certification program is how the Department of Defense verifies that contractors protect sensitive unclassified information. The program rule, codified at 32 CFR Part 170, took effect on December 16, 2024. A separate acquisition rule is needed before the requirements start appearing in contracts, so timing depends on when solicitations include them.

CMMC 2.0 has three levels. Level 1 covers basic safeguarding of Federal Contract Information and relies on a short list of fundamental practices with annual self-assessment. Level 2 covers Controlled Unclassified Information and aligns with the practices in NIST SP 800-171. Depending on the contract, Level 2 may be a self-assessment or require a third-party assessment. Level 3 applies to the most sensitive programs and is rarely relevant to small firms.

Why it can reach subcontractors

Requirements flow down. If a prime contractor shares FCI or CUI with you, they are expected to make sure you protect it at an appropriate level, and the level you need depends on the type of information you handle, not on your company size.

What counts as CUI in construction

CUI is information the government says needs protection even though it is not classified. In the built environment, this can include certain drawings, facility layouts, utility and security system details, and specifications for sensitive installations. Your contract or the prime contractor should identify what is marked or designated. If you are unsure, ask in writing.

Practical first steps

1. Find out what you actually handle

Ask your prime what information, if any, is FCI or CUI, and what level they expect. Do not assume. Many subcontractors handle little or none and need only basic safeguards.

2. Define your scope

The most useful decision you can make is limiting where sensitive information lives. A small, controlled enclave of systems and users is easier and cheaper to secure than your entire company. Decide which people, devices, and cloud services will touch protected data, and keep it away from everything else.

3. Run a gap assessment against NIST SP 800-171

The standard contains 110 security requirements across families such as access control, awareness and training, audit and accountability, configuration management, incident response, and system protection. Score your current state honestly, and document what is missing.

4. Build the documentation

Assessors look for written evidence. You will generally need a system security plan describing your environment and how each requirement is met, and a plan of action for open items. Policies, procedures, and records of training and access reviews all count.

5. Close the technical gaps

Common items include multi-factor authentication, encryption, logging and monitoring, patching, controlled use of removable media, and secure configuration of cloud services. Email and file storage need particular attention, since that is where CUI usually sits.

Common mistakes

  • Waiting until a contract requires it. Preparation takes months.
  • Treating compliance as a one-time project rather than an ongoing practice.
  • Putting CUI in ordinary email or consumer file-sharing tools.
  • Pulling the whole company into scope when a smaller boundary would do.
  • Writing policies that do not match what staff actually do.

A word on cloud services

If you use a cloud platform for CUI, verify that it meets the necessary requirements. Not every commercial service is appropriate, and the details depend on the type of data and the contract. Ask vendors specific questions and get answers in writing.

Getting ready with Ironfield Cyber

Ironfield Cyber helps defense-adjacent contractors understand which requirements apply, scope their environment, and prepare documentation and technical controls. If a prime has asked about your cybersecurity posture, we can help you read the request and plan a realistic path.