CMMC is no longer a future topic for defense contractors. The DFARS acquisition rule took effect on November 10, 2025, and the program is phasing into contracts over several years. That means the paperwork landing on your desk, from a prime or directly from an agency, may now include CMMC language that someone at your company has to read and understand before signing.
Most owners and project managers are not trained to parse these clauses, and most legal reviews focus on price, schedule and indemnity. The cyber terms deserve the same attention, because they can create obligations that take months to meet.
Find the required level first
The solicitation or subcontract should state which CMMC level applies. Level 1 covers Federal Contract Information (FCI) and uses a basic set of safeguarding practices. Level 2 covers Controlled Unclassified Information (CUI) and aligns with NIST SP 800-171. If the document is silent or vague, ask in writing. Do not assume the lowest level.
Also note whether the requirement is a self-assessment or a third-party assessment. The rule phases these in, so the answer can depend on the contract and the timing. Get the requirement in writing from the contracting officer or your prime.
Clauses and phrases that deserve a second look
Flow-down language
Primes are expected to pass cyber requirements to subcontractors that handle FCI or CUI. Look for phrases such as "flow down," "applicable to all subcontractors," or references to DFARS safeguarding clauses. If your scope never touches CUI, say so clearly and ask the prime to confirm the correct level for your role.
Affirmation and certification
CMMC involves a company affirmation of compliance. A senior official signs it, which creates real accountability. Make sure the person who signs understands what the company has actually implemented, not what the company hopes to implement.
Incident reporting
Contracts typically require reporting cyber incidents within a short window. Check the timeline and who you must notify. Then confirm your own team could meet it. If you cannot detect an incident in time to report it, the clause is a risk even if you never have an incident.
Cloud and service providers
If CUI will live in a cloud service, such as a file sharing platform or a project portal, the provider may need to meet specific requirements. Ask your vendors early, since some will not support the contract's needs at all.
Questions to put to the prime or contracting officer
- Which CMMC level applies to our scope, and is it a self-assessment or a third-party assessment?
- Will we receive or create CUI? If so, which categories, and how will it be marked?
- What is the incident reporting timeline and the reporting contact?
- Does the contract require us to use a specific portal or system for CUI?
- When must our status be recorded in the government's tracking system, and by whom?
- Do our own subcontractors need to meet requirements, and who verifies that?
Written answers matter. Verbal assurances from a project manager rarely survive a later audit.
Practical steps before you sign
- Map your data. Identify where FCI and any CUI would be stored, sent and printed. Email, shared drives, laptops and mobile devices all count.
- Check your current posture. Compare your safeguards to the requirement. Gaps found now are cheaper than gaps found after award.
- Budget the work. Remediation can include MFA, encryption, logging, device management and documentation. Time matters as much as money, so build it into your schedule.
- Assign an owner. Compliance without a named owner drifts. Pick someone responsible for the system security plan and the evidence behind it.
- Plan for subs and vendors. If you pass CUI to a subcontractor, your contract may make you responsible for what they do with it.
A hypothetical example
Consider a hypothetical 40-person mechanical contractor that wins a small subcontract at a military facility. The subcontract mentions CMMC but does not state a level. The owner signs, assuming it is minor. Months later the prime sends drawings marked as CUI and asks for confirmation of safeguards. The contractor now has to scramble to protect data it already received, on systems not built for it. A single clarifying email before signing would have set the right expectations and the right budget.
Where to get help
You do not need to become a compliance expert to read these clauses, but you do need someone who can translate them into actions for your environment. Ironfield Cyber helps contractors review CMMC language, map where FCI and CUI actually live, and build a realistic plan. If a solicitation is on your desk, we are glad to look at it with you before you commit.