When you handle CUI under a DoD contract, your security obligations don’t stop with your organization. The security requirements that apply to you also apply to your subcontractors, suppliers, and any other vendor you share CUI with in the course of executing your contract.
This is CUI flowdown, and understanding it matters whether you're a prime trying to manage supply chain risk or a subcontractor who just received a request for proof of CMMC compliance you weren't expecting.
Why CUI flowdown exists
The defense supply chain is a complex multi-tier network. of prime contractors, subcontractors, suppliers, and service providers, and sensitive defense information moves through all of it.
A prime contractor might handle CUI directly under a DoD contract, then share technical drawings, specifications, or other sensitive data with a subcontractor to perform part of the work. That subcontractor may share some of it with their own suppliers. At each step, the same sensitive information that triggered a compliance obligation at the prime level moves further from the original contract and deeper into organizations that may never have dealt directly with the DoD.
This is exactly where adversaries look for gaps. A sophisticated attacker doesn't necessarily try to breach a large prime contractor with mature security controls when a smaller subcontractor two tiers down has access to the same technical data and far fewer resources dedicated to protecting it. The value of CUI, and the risk of its exposure, doesn't diminish as it moves down the supply chain.
As Rob Joyce noted at the Secureframe National Cybersecurity Summit, “The adversary doesn't care about your headcount. They care about which path to CUI is the easiest path to get into their objective. Today, that path runs through the supplier with the part-time MSP because the CUI is the same, but the defense isn't."
Flowdown requirements exist to close that gap by ensuring every organization in the supply chain that handles CUI is subject to the same baseline protection requirements, regardless of their size, tier, or whether they have a direct contract with the DoD.
The regulatory basis for CUI flowdown
Two regulatory instruments drive CUI flowdown obligations for defense contractors.
DFARS 252.204-7012 requires prime contractors to include the clause in subcontracts where performance involves Covered Defense Information. When that clause appears in your prime contract, you're obligated to pass it down to your subcontractors if they'll handle the same information. This means the same NIST SP 800-171 requirements, 72-hour cyber incident reporting obligations, and FedRAMP Moderate equivalent cloud service standards that apply to you also apply to them. And if your subcontractors have their own subcontractors handling CDI, the clause flows down again.
32 CFR §170.23 adds a second layer: it specifies the minimum CMMC level required for each subcontract based on the type of information being shared. This is where CMMC, the verification mechanism for CUI protection, enters the supply chain picture.

How CMMC levels flow down the supply chain
The CMMC level a subcontractor needs isn't determined by what level their prime has achieved. It's determined by what information the prime is actually sharing with them.
- The prime contract requires Level 2, but the subcontractor only touches FCI. The subcontractor's minimum requirement is still Level 1, not Level 2. CMMC level follows the information, not the prime's certification level. A subcontractor can't be required to achieve a higher level than the sensitivity of the information they actually handle justifies.
- The prime contract requires Level 2, and CUI flows down to the subcontractor. The subcontractor's minimum requirement is Level 2.
- The prime contract requires Level 3, and CUI flows down to the subcontractor. The minimum flowdown requirement for subcontractors is still Level 2, not Level 3. The DoD has made a deliberate risk-based decision not to mandate Level 3 flowdown to subcontractors unless explicitly directed by the contract.

Prime contractor obligations
Prime contractors carry significant obligations when it comes to their subcontractors' CUI compliance, and many underestimate how operationally demanding those obligations are.
Before awarding a subcontract that involves CUI, you're required to verify that the subcontractor has a current CMMC certificate or self-assessment at the required level. That means the compliance burden isn't just your own organization; it's every vendor you plan to share CUI with. You also need to include the right DFARS clauses (7012, 7020, and 7021) in subcontracts where CDI or CUI is involved, confirm that subcontractors affirm continuous compliance at least annually, and stop sharing CUI with any subcontractor who can't demonstrate they've met the required level.
That last point carries real consequences. Sharing CUI with a non-compliant subcontractor isn't just a supply chain risk; it's a breach of your own contract obligations and potential False Claims Act exposure if you're certifying compliance while knowingly working with vendors who aren't meeting their requirements.
Primes like Lockheed Martin and General Dynamics are already enforcing this proactively. They're requiring subcontractors to demonstrate compliance now, before CMMC enforcement deadlines, because a subcontractor compliance gap can delay or disqualify the prime's own certification.
Recommended reading
Why Prime Contractors Are Already Enforcing CMMC Level 2
Read MoreWhat this means if you're a subcontractor
If you're a subcontractor receiving CUI from a prime, you're subject to essentially the same core obligations as the prime, scoped to the information and systems involved in your work. You need to implement NIST SP 800-171 controls on any system that processes, stores, or transmits the CUI you've received, report cyber incidents within 72 hours, flow requirements further down to any of your own subcontractors who will handle the CUI, and maintain a current SPRS score.
The most common and costly mistake subcontractors make is assuming these requirements will only be enforced for large companies or prime contractors. They won't be. DoD enforces flowdown uniformly regardless of company size or tier, and primes are increasingly making compliance a condition of subcontract award, which means non-compliance doesn't just create legal risk; it can cost you the contract before you even knew you were at risk of losing it.
A note on paper CUI
Organizations that handle CUI exclusively in paper form, with no digital systems that process, store, or transmit it, may have a more limited scope, per Cyber AB FAQ C-Q11. However, compliance obligations under NIST SP 800-171 and DoDI 5200.48 still apply.
More importantly: this exception disappears the moment paper CUI enters a digital system. Scanning a drawing, photographing a document, uploading it to a shared drive, or emailing it as an attachment all bring your information systems into CMMC assessment scope.
This matters because building a compliant CUI environment isn't a quick process. Implementing 110 security controls, documenting each one in a System Security Plan, and maintaining evidence across your technology environment takes months even before a self-assessment starts. An organization that digitizes even a single piece of CUI without having begun that process is suddenly facing a significant compliance gap with real timeline pressure.
Proposed changes under the FAR Overhaul
The proposed FAR Overhaul (FAR Case 2026-001, June 2026) would strengthen and formalize the flowdown mechanism through a new Standard Form (SF XXX). Under the proposed rule, prime contractors would be required to include their own SF XXX in subcontracts involving CUI, specifying which categories of CUI are being shared, where it will reside, and what safeguarding and reporting requirements apply.
This would replace the current approach, where subcontractors often have to piece together their CUI obligations from clause language, and give them a clearer, standardized picture of what's required for each subcontract.
Recommended reading
CMMC Requirements for Subcontractors: Understanding How CMMC Flows Down the Defense Supply Chain
Read More