For defense contractors and their subcontractors, CMMC has moved from a future plan to a contract reality. Two rules matter. The Department of Defense's program rule, published at 32 CFR Part 170, took effect on December 16, 2024. The companion acquisition rule, which amends the DFARS in 48 CFR, took effect on November 10, 2025, and that is the one that begins placing CMMC requirements into solicitations and contracts, in phases.
If you are a subcontractor, you may not deal with the government directly, but requirements can still reach you through your prime. This post explains the mechanics in plain terms.
What the acquisition rule does
The program rule describes how CMMC works, including levels and assessments. The acquisition rule is the piece that connects that program to contracts. Under it, DoD contracting officers can include a required CMMC level in solicitations and contracts, and contractors must meet that level to be eligible for award where it applies.
The rollout is phased rather than all at once, so you will not see the requirement in every contract on the same day. Which requirement applies to you depends on the contract you are bidding or performing.
How it reaches subcontractors
The requirement flows down. A prime contractor that must meet a particular CMMC level generally must make sure subcontractors who handle the relevant information meet an appropriate level too. The key question is what information you handle.
- If you handle Federal Contract Information, the baseline level of requirements applies.
- If you handle controlled unclassified information, a higher level applies, aligned with NIST SP 800-171.
- If you handle neither, flow-down may not apply to you in that way.
Do not assume. Ask your prime in writing what information they expect you to receive and which CMMC level, if any, they believe applies to your role.
Questions to ask your prime
- Does this contract involve CUI, and will we receive any?
- What CMMC level do you expect us to hold, and by when?
- Will you accept our current self-assessment, or do you need evidence of a third-party assessment?
- Can the scope of CUI shared with us be minimized?
- What will you require in our subcontract?
What to do now
Step 1: Determine your data
Identify what contract information you handle. Walk through where drawings, specifications, emails, and attachments tied to defense work are stored, and who touches them. Many companies find the answer is narrower than they feared, which reduces cost.
Step 2: Run an honest gap assessment
For Federal Contract Information, review the basic safeguarding practices. For CUI, assess against NIST SP 800-171. Record where you are strong and where you fall short.
Step 3: Write it down
Assessments rely on documentation. A system security plan describes how you meet requirements, and a plan of action and milestones lists gaps you intend to close, subject to the program's rules about what may remain open. Build these documents early.
Step 4: Limit your scope
Keeping CUI in a controlled environment, rather than across your entire company, can reduce the number of systems, users, and devices an assessor will examine. This is often the most effective way to control cost.
Step 5: Plan your assessment path
Depending on the required level, you may be able to self-assess, or you may need an assessment by a certified third-party assessment organization. Ask your prime and consider lead times, since assessor availability and preparation can take months.
Mistakes to avoid
- Waiting for a contract to demand compliance before starting
- Assuming your IT provider has already handled it without evidence
- Treating the effort as a one-time project instead of a continuing practice
- Signing a flow-down clause without understanding it
- Overstating your compliance in affirmations, which carries serious legal risk
A hypothetical example
Consider a hypothetical 35-person fabrication shop that supplies parts to a prime on a defense program. A careful review could show that only two employees and one file share handle information the prime marked as controlled. Building a small secured environment around those users and that data may be much more practical than upgrading every system in the shop.
Where Ironfield Cyber helps
Ironfield Cyber helps defense subcontractors understand their obligations, scope their environments, and prepare documentation and controls aligned with NIST SP 800-171. If your prime has started asking about CMMC, we can help you work out what actually applies to you and build a practical plan.