CUI Flow-Down for Subcontractors: What Primes Will Ask

How primes pass CUI and CMMC requirements down to subcontractors, what questions to expect, and how small firms can respond with confidence.

3 min readBy Ironfield Cyber Team

If your company supplies, builds or services anything for a prime contractor on federal work, the security expectations may arrive in your next subcontract. The prime is accountable to the government, and the government expects protections to extend down the chain wherever sensitive information goes. For small subcontractors, the result is often a surprise: a questionnaire, a contract clause and a request for evidence.

This post explains what flow-down means, what primes tend to ask and how to prepare.

What flow-down means

Flow-down is the practice of passing contractual requirements from a prime contractor to its subcontractors. When a federal contract includes cybersecurity clauses, such as those related to safeguarding covered defense information or CMMC, the prime generally must include appropriate requirements in subcontracts where the subcontractor will handle the relevant information.

Under CMMC 2.0, the required level for a subcontractor depends on the type of information it processes, stores or transmits. If a subcontractor handles only federal contract information, Level 1 may apply. If it handles controlled unclassified information, Level 2 is typically relevant, which is based on NIST SP 800-171. The DFARS acquisition rule for CMMC took effect on November 10, 2025, and contract requirements are being phased in, so expect these conversations to become more common.

First question: do you actually receive CUI?

Not every subcontract involves CUI. Drawings, specifications, technical data and schedules may or may not be marked as controlled. Ask the prime to confirm in writing:

  1. Whether the work involves FCI, CUI or neither
  2. What CMMC level is required for your role
  3. Which clauses apply
  4. How CUI will be marked, delivered and returned or destroyed

Do not guess. Overstating your scope increases cost, and understating it risks noncompliance.

What primes commonly ask

Expect requests along these lines:

  • A completed security questionnaire
  • Your current CMMC status or self-assessment score, where applicable
  • A description of where you would store and process CUI
  • Whether you use cloud services and which ones
  • Whether your IT support is outsourced, and to whom
  • Evidence of multifactor authentication, encryption and logging
  • Your incident response plan and how quickly you would notify the prime
  • Policies for personnel, access and training
  • How you will handle your own subcontractors who touch the data

Preparing a response

Define the boundary

Identify the people, systems and locations that would handle CUI. Keep the number small. A separate, controlled environment for CUI work often costs less than bringing the whole company into scope.

Gather basic evidence

Prepare a simple package: an inventory of in-scope systems, a network overview, policies, training records and screenshots of key settings. Having it ready shortens review.

Be honest about gaps

Primes generally prefer a subcontractor with an honest plan to one that claims perfection. If you have gaps, document them with timelines in a plan of action and milestones. Be mindful that the rules limit what can remain open at a formal assessment, so confirm requirements with the prime and review the current program rules.

Coordinate with your IT provider and cloud services

If someone else hosts or manages your systems, find out whether they can meet the required controls and support your evidence needs. Some cloud services are authorized for handling federal data, while others are not. Verify before you put CUI in them.

Handling your own suppliers

If you pass CUI to a supplier, such as a machine shop, engineer or software vendor, you are the one responsible for flowing the requirements down. Create a short list of recipients, determine what each receives and update your subcontract templates with appropriate language. Keep copies of what you send and when.

Practical protection of CUI in daily work

  • Keep CUI in the designated location, not in personal email or on USB drives
  • Limit access to people who need it for the contract
  • Mark and label according to the contract's instructions
  • Use approved methods to transmit files
  • Train the team on what CUI looks like and where it may and may not go
  • Report suspected incidents immediately to the designated contact

Common mistakes

  • Signing flow-down clauses without understanding them
  • Storing CUI in general shared folders
  • Assuming that the IT provider takes care of compliance without verification
  • Waiting for a bid to start preparing
  • Forgetting to ask the prime about incident reporting timelines

How Ironfield Cyber helps

Ironfield Cyber helps subcontractors define their CUI scope, answer prime questionnaires accurately and build the controls that back up their answers. If a flow-down clause has just landed on your desk, we can help you read it and plan the response.