DFARS Readiness Checklists and guides for DFARS readiness.

Guides / October 07, 2026

What Does DFARS Flow-Down Mean for My Subcontractors?

Your prime just forwarded a DFARS clause and asked you to sign by Friday.

This article explains what that signature obligates you to do. It covers which clauses flow down, what the prime must do, and what you must deliver. Nothing here replaces legal counsel for your specific contract.

What flow-down actually is

Flow-down is a clause that passes requirements from one contract into the next. Your prime holds a contract with the government. Your subcontract holds your agreement with the prime. Flow-down copies specified clauses word for word into that subcontract. The duties then bind every tier they reach.

Acronyms, spelled out: DFARS means Defense Federal Acquisition Regulation Supplement. CMMC means Cybersecurity Maturity Model Certification. CDI means Covered Defense Information. CUI means Controlled Unclassified Information. FCI means Federal Contract Information. SPRS means the Supplier Performance Risk System. NIST SP 800-171 is the federal standard for protecting CUI on nonfederal systems. DIBNet is the DoD portal for reporting cyber incidents.

Which clauses flow down

DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," flows down verbatim. The prime must include it in subcontracts for operationally critical support or where performance will involve CDI. DFARS 204.7304 The flow-down paragraph reaches subcontracts for commercial products and services, but not those solely for COTS items. DFARS 252.204-7012 A subcontractor that receives 7012 owes the same duties as the prime. It must provide adequate security for CDI on its covered systems. It must rapidly report cyber incidents affecting CDI, within 72 hours of discovery. DFARS 252.204-7012 It must pass DoD-assigned incident report numbers up the chain to the prime. DFARS 252.204-7012

DFARS 252.204-7019, "Notice of NIST SP 800-171 DoD Assessment Requirements," is a notice, not a standing duty. It requires a current assessment to be considered for award. Current means not more than three years old, posted in SPRS. DFARS 204.7304 DFARS 252.204-7020, "NIST SP 800-171 DoD Assessment Requirements," carries the ongoing obligation. The prime must verify that subcontractors have current SPRS assessment results before awarding a subcontract. DFARS 252.204-7020 COTS-only solicitations are exempt from 7020. DFARS 252.204-7020

DFARS 252.204-7021, "Cybersecurity Maturity Model Certification (CMMC) Requirements," flows down to qualifying subcontractors. It reaches subcontractors that will process, store, or transmit FCI or CUI. The prime must ensure each subcontractor holds the appropriate CMMC level before awarding the subcontract. DFARS 252.204-7021 The levels are set by 32 CFR 170.23. A subcontractor handling only FCI needs CMMC Status of Level 1 (Self). A subcontractor handling CUI needs CMMC Status of Level 2 (Self) at minimum. If the prime contract requires Level 2 (C3PAO), the subcontractor needs Level 2 (C3PAO). If the prime contract requires Level 3 (DIBCAC), the subcontractor needs Level 2 (C3PAO). 32 CFR 170.23

What the prime must do, in order

First, the prime maps which subcontractors will touch FCI, CUI, or CDI. Second, it inserts the required clauses verbatim into each subcontract. Editing 7012 down violates the prime's own contract. Third, it verifies each subcontractor's SPRS assessment or CMMC status before awarding the subcontract. Fourth, if a subcontractor refuses the terms, the prime must not share CDI with that subcontractor. DFARS 252.204-7012 Fifth, the prime minimizes CDI shared with each subcontractor to what performance actually requires. DFARS 252.204-7012

What subcontractors must deliver

A subcontractor that receives these clauses owes concrete evidence, not promises. It needs a System Security Plan describing how each NIST SP 800-171 requirement is met. It needs a POA&M, a Plan of Action and Milestones, covering every unmet requirement. It needs a current SPRS assessment posted within the last three years. It needs a working incident reporting path that meets the 72-hour deadline. It must preserve affected media and monitoring data for at least 90 days. DFARS 252.204-7012 Any external cloud provider storing CDI must meet security requirements equivalent to the FedRAMP Moderate baseline. DFARS 252.204-7012 Under CMMC, each subcontractor submits its own assessment and affirmation information in SPRS. 32 CFR Part 170

Common prime-subcontractor friction points

One, the subcontractor cannot negotiate 7012 out of the deal. The clause travels with the contract. Two, primes often add private terms on top: deadlines, audit rights, indemnification, or notice of status changes. Those private terms survive any DoD program change. Three, the 72-hour incident clock starts with the subcontractor's discovery. It must notify the prime and file its own DoD report, then share the DoD report number upward. Four, confusion about the CMMC Phase 2 pause causes missed obligations. The Department paused its own third-party certification timeline. It did not pause your customer's contract terms. DFARS 7012, NIST 800-171, SPRS scoring, annual affirmations, and every flowed-down subcontract clause remain in force.

Practical next steps

Read your actual subcontract, not a summary of it. Highlight every DFARS number it names. List which data types you will handle: FCI only, or CUI. Match that list to the required CMMC level and the SPRS assessment you need. Build your System Security Plan and POA&M around NIST SP 800-171 before the prime asks. Test your 72-hour incident reporting path now, including the DoD portal access you will need. Confirm in writing with your prime which level they require of you, since their private terms control. Reconfirm before every subcontract award, because clause sets change between contracts.

PolicyCortex builds compliance automation evaluated against NIST 800-53 and NIST 800-171. Learn more at https://policycortex.com.

Sources