A dated record of what defense primes have publicly required of their suppliers on CMMC: letters, surveys, portal mandates, contract terms, and purchase order conditions, tracked against the Phase 2 date.
Dates shown are the most concrete public requirement or deadline for each prime. Two more converge on the Phase 2 line itself: Leonardo DRS has reportedly told suppliers to hold Level 2 certification by November 10, 2026, and GE Aerospace's contract terms require certification within one year of the CMMC rules taking effect, which lands at the same point. Lockheed Martin does not appear as a single marker because its posture is continuous: readiness declared non negotiable in mid 2025, a green CCRA rating pushed as the readiness bar in September 2025, and a Cybersecurity Compliance Attestation required in Exostar as of December 1, 2025, with a warning that any lapse in CMMC status directly affects the ability to receive subcontracts. Details for every company are in the table below.
| Prime | Dated public actions | What it means for suppliers | Source |
|---|---|---|---|
| L3Harris | Apr 6, 2026Supplier letter stating suppliers are expected to be certified by July 30, 2026. All suppliers receiving CUI at any tier must be certified if required by the prime contract, including small businesses and foreign suppliers. COTS only suppliers per FAR 2.101 are excluded. | The most concrete deadline any major prime has issued. If you supply L3Harris and handle CUI, July 30, 2026 is your operative date, not November 10. | Industry documented |
| HII | Sep 30, 2024 and Sep 11, 2025Supplier letters, hosted on HII's own site, requiring suppliers to provide current CMMC status evidence from SPRS, with the 2025 letter requesting responses by September 30, 2025. Published timelineHII's public CMMC timeline shows Level 2 certifications beginning around Q4 2025 and Level 3 certifications around Q4 2026, roughly a year ahead of the government schedule. | HII suppliers are effectively already operating under Phase 2 conditions, and HII is one of the few primes that publishes its actual supplier letters. | Prime published |
| Elbit Systems of America | Nov 5, 2025Open letter declaring CMMC Level 1 the minimum requirement to continue doing business with Elbit, directing CUI handling suppliers toward Level 2. Jan 9, 2026Open letter from the VP of Supply Chain stating buyers will not issue purchase orders to suppliers who fail contractual CMMC flowdown requirements, noting it "only took 32 days to receive a solicitation requiring Level 2 certification" after Phase 1 opened, and directing suppliers to engage a C3PAO now. Feb 9, 2026Open letter announcing Elbit is actively building a network of Level 2 certified suppliers and inviting certified suppliers to submit evidence. | Purchase orders are already conditioned on compliance, and all three letters are posted on Elbit's own site. Certified competitors are being actively recruited. | Prime published |
| Lockheed Martin | Sep 29, 2025Supplier article directing suppliers with yellow or red Exostar CCRA risk ratings to close POA&Ms, positioning a green CCRA as the Level 2 readiness indicator. Dec 1, 2025Supplier notice requiring all active suppliers to document CMMC status through the Cybersecurity Compliance Attestation in Exostar, warning that any lapse in required CMMC status directly affects the ability to receive DoD subcontracts. 2024 to 2025, reportedIndustry sources also describe a December 2024 memo, a June 30, 2025 notice declaring Level 2 compliance non negotiable with outreach to low scoring suppliers, and C3PAO language in some FY2026 contracts. | Compliance is a standing condition of continued business, tracked through Exostar. Low scores draw direct outreach. | Both tiers |
| RTX | Dec 2025Supplier reps and certs form, published on rtx.com, with a dedicated DFARS 252.204-7021 section requiring disclosure of current and intended CMMC status, SPRS recording, annual affirmation, and Level 2 C3PAO where the prime contract requires it. Applies across Raytheon, Collins Aerospace, and Pratt & Whitney. Mar 2026, reportedNotice requiring suppliers to complete a CMMC status survey by March 17, 2026, with weekly follow up for non responders and a warning that C3PAO availability may make 2026 certification unachievable for those not yet scheduled. | Status reporting is mandatory at annual registration and monitored between cycles. RTX itself has told suppliers the assessor calendar may already be closed for 2026. | Both tiers |
| Northrop Grumman | 2025Supplier announcement, hosted on Northrop's own CDN, stating that neither contracting officers nor prime contractors may waive or deviate from CMMC requirements and that primes may not award purchase orders to noncompliant subcontractors. Industry sources date the distribution to December 2025. OngoingSuppliers must provide SPRS scores and answer cybersecurity questions at onboarding and renewal. Northrop co-developed the CCRA questionnaire used across the industry through Exostar. | The clearest public statement that relationship history cannot protect a noncompliant supplier. The prime has no legal authority to waive the requirement. | Both tiers |
| Boeing | 2025Signed supplier letter, hosted on Boeing's supplier portal, urging Level 2 C3PAO preparation where CUI or FCI work requires it. The letter itself is undated; industry sources place it in September 2025. OngoingSupplier portal maintains CMMC email announcements, a preparedness document, ESLC portal instructions, and a cybersecurity supplement to its terms. | No published hard deadline, but requirements are embedded in terms documents and validated through the ESLC system. Silence is not inactivity. | Both tiers |
| General Dynamics | Division specificGD Mission Systems states CMMC compliance will be a condition of contract award and will require suppliers to certify at least annually, as a condition precedent to future purchase orders carrying CMMC requirements. GD Land Systems states Level 1 is the minimum for all suppliers, CUI suppliers need at least Level 2, and certification is required to do business with GDLS and the DoD unless the supplier provides only COTS. GDIT publishes the phased schedule and flowdown clauses in its supplier terms. | Requirements differ by division. If you supply General Dynamics, identify which operating unit holds your contract and check that unit's supplier page. | Prime published |
| GE Aerospace | Dec 19, 2024Enterprise Cyber Flowdowns contract terms requiring sellers to obtain and maintain the contracted CMMC level no later than one year after the CMMC rules go into effect, to notify GE's program cyber lead at least 60 days before any third party assessment, and to deliver a CMMC implementation plan and post assessment POA&M as contract data deliverables. Requirements flow to sub-tier vendors. OngoingSupplier cyber requirements page states suppliers must achieve the necessary CMMC level to remain eligible for DoD related work. | The earliest hard contractual commitment found from any prime, and its one year clause lands almost exactly on the Phase 2 date. The 60 day assessment notice requirement is unique in the public record. | Prime published |
| General Atomics | Nov 14, 2024Supplier day briefing stating that subcontractors handling CUI must demonstrate commitment and capacity to achieve Level 2 compliance by early to mid 2025, and that starting a relationship with a supplier that cannot demonstrate this represents an unacceptable risk to General Atomics. OngoingSupplier cybersecurity portal requires that assessment scores, applicable certifications, and annual affirmations be posted to SPRS before a supplier handles FCI, CUI, or CDI. | SPRS posting is a precondition for receiving covered data at all, not just for new awards. | Prime published |
| Leonardo DRS | OngoingSupplier cybersecurity page states that non COTS DoD suppliers must meet flowed DFARS 252.204-7021 requirements, FCI only suppliers need Level 1, CUI suppliers require Level 2 with C3PAO certification, that Level 2 is a pre-award requirement, and that suppliers should not wait for the contract clause to flow down before starting certification. Oct 2025 and mid 2026, reportedIndustry coverage describes an October 2025 supplier letter telling DFARS 7012 holders to anticipate Level 2 C3PAO requirements within two years, close POA&Ms, and target a 110 score, and a 2026 notice reportedly setting supplier certification expectations at November 10, 2026. | The public page removes all ambiguity: Level 2 certification is pre-award, and waiting for the clause is explicitly discouraged. | Both tiers |
| Honeywell | 2026Third party security requirements document, published on honeywell.com, requiring applicable suppliers to achieve and maintain their contracted CMMC level, notify Honeywell within 30 days of certification or status events, provide compliance evidence within 15 business days on request, and flow requirements to sub-tiers. The document states that "a lapse in CMMC status constitutes a material breach." | The strongest consequence language in the public record. CMMC status is a continuous condition of performance, not a milestone. | Prime published |
| Sierra Nevada Corporation | OngoingSupplier data protection page stating that DFARS 252.204-7021 requires a current CMMC certificate at the contract specified level, maintained throughout performance with annual affirmation, and that lapses or changes in certification status must be reported within 72 hours. | The 72 hour lapse reporting requirement is the tightest status change window published by any prime. | Prime published |
| BPMI (Bechtel Plant Machinery) | FY2027Supplier cybersecurity page stating CMMC requirements will be incorporated into BPMI's fiscal year 2027 terms and conditions, and that starting in FY2027 suppliers must confirm and provide evidence of Level 2 certification status, including the certificate with CMMC UID and CAGE codes or an SPRS report, to be eligible for contract awards. U-NNPI suppliers additionally remain under NN-801 Revision 5. | The clearest example of a prime pinning the requirement after the Phase 2 date, on its own fiscal calendar. Naval nuclear suppliers carry NN-801 obligations on top. | Prime published |
| Parsons | Nov 2025 and Mar 2026, reportedIndustry sources describe two supply chain notices and a CMMC readiness survey due March 3, 2026. Parsons' own public supplier pages carry general cybersecurity and DFARS content without the survey or deadline. | Readiness data collection is underway per industry documentation, but this is the least publicly verifiable entry among the active primes. Confirm directly with Parsons. | Industry documented |
| BAE Systems (US) | Aug 12, 2025Supplier communication from BAE's Supply Chain Cybersecurity Risk Manager, hosted on baesystems.com, describing a program integrating CMMC 2.0 readiness data into supplier onboarding and an Exostar based cybersecurity questionnaire. No public thresholds, deadlines, or purchase order conditions stated. | Expectations exist but are not public in detail. US based BAE suppliers should request requirements in writing from the supply chain cybersecurity team. | Prime published |
| Leidos | OngoingSupplier page publishes its flowdown logic: the prime contract identifies the required CMMC level, Leidos flows it down, Level 1 applies to FCI only subcontractors, otherwise the same Level 2 assessment type as the prime applies, or Level 2 C3PAO where the prime carries a Level 3 requirement. | The clearest published mapping of how a prime decides which level applies to which subcontractor. Useful reading even for suppliers of other primes. | Prime published |
| Peraton | OngoingDedicated supplier CMMC page stating that solicitations specify required levels, suppliers upload self assessments to SPRS, C3PAOs upload certification assessments, Peraton requires attestations where CMMC clauses apply, and Peraton buyers distribute cybersecurity questionnaires to verify compliance. | Verification is questionnaire driven and attached to individual procurements rather than a single calendar deadline. | Prime published |
| Textron Systems | OngoingSupplier cybersecurity resource center directing subcontractors to complete the NIST SP 800-171 basic assessment, submit results into SPRS, and respond to its cyber questionnaire, noting that CMMC levels can flow down through every subcontractor tier, whether first or seventh. | Posture is educational rather than deadline driven, so far, but the every tier framing is explicit. | Prime published |
Prime published means the requirement appears on the prime's own public pages or in documents the prime hosts itself. Industry documented means the requirement was communicated in letters or memos sent directly to suppliers and is publicly known through industry sources that reproduce or quote those letters. Both tiers means the entry combines the two. Supplier letters are the more consequential instrument, but they are also the ones a prime can revise without a public trace, so verify directly with your prime before acting.
Several companies carry the requirement in their standard terms rather than in letters. Curtiss-Wright Defense Solutions' purchase order quality clauses state that DFARS 252.204-7021 compliance is required for suppliers to do business with CWDS. Moog's supplemental terms list 252.204-7021 among its lower tier flowdown clauses as of January 2026. Oshkosh embeds CMMC requirements in its supplier standards and in individual technical data packages. V2X's supplier page warns that inability to demonstrate cybersecurity compliance may eliminate suppliers from consideration.
The flowdown is also cascading below the primes. IS4S, a Huntsville based mid-tier contractor, published a signed notice on April 20, 2026 requiring its CUI handling suppliers to be certified at Level 2 and to send a copy of their C3PAO certificate for verification. When companies two tiers down are demanding certificates from companies three tiers down, the mechanism the regulation designed is functioning as written.
A few large government services firms, including CACI, ManTech, and Booz Allen, maintain supplier cybersecurity pages whose CMMC content predates the final rules. Their flowdown obligations are identical under the regulation; their public guidance simply has not caught up.
The following companies were checked and had no public, company issued CMMC supplier notice, deadline, survey, or portal requirement beyond general regulatory references as of the update date: Sikorsky (operates under Lockheed Martin's Exostar verification architecture), Collins Aerospace and Pratt & Whitney (covered under the RTX corporate form), Kratos, Anduril, SAIC, Amentum, Jacobs, Bechtel corporate (apart from BPMI above), Day & Zimmermann, and Hanwha Defense USA. Absence from this list means absence of a public statement. It does not mean the company has no requirement, and under DFARS 252.204-7021 every one of them carries the same flowdown duty.
CMMC Phase 2 begins on November 10, 2026. From that date, the Department of Defense can require Level 2 certification by a third party assessor as a condition of award on contracts involving Controlled Unclassified Information. That is the date on the government's calendar, and it is the one most of the Defense Industrial Base has circled.
It is also, for a growing share of the supply chain, not the date that matters. Prime contractors set the terms under which their subcontractors do business, and the public record shows primes setting CMMC requirements on their own schedules. Some have already made compliance a condition of purchase orders. One has published a certification deadline more than three months ahead of Phase 2. One wrote into its contract terms, back in December 2024, that suppliers must be certified within a year of the rules taking effect. Others have signaled the requirement will arrive through contract language as Phase 2 clauses flow down, and at least one naval prime has pinned it to its fiscal year 2027 terms and conditions.
How fast does the flowdown move once it starts? Elbit Systems of America answered that in a January 2026 letter to its suppliers, reporting it "only took 32 days to receive a solicitation requiring Level 2 certification" after Phase 1 opened. The clauses arrive, and the primes pass them down, because the law gives them no other option.
This page collects every publicly documented prime notice, deadline, and contract term in one place, with dates, so a supplier can see where its customers stand without piecing it together from a dozen sources.
Under DFARS 252.204-7021 and 32 CFR 170.23, a prime contractor must confirm that a subcontractor holds the required CMMC status before awarding a subcontract that involves FCI or CUI, and must obtain annual affirmations of continuous compliance. Northrop Grumman put it plainly in a supplier notice: neither contracting officers nor prime contractors may waive or deviate from CMMC requirements. Honeywell's supplier security terms go further, stating that a lapse in CMMC status constitutes a material breach. Every notice on this page is a prime executing a regulatory duty, not exercising a preference.
This page tracks publicly verifiable statements only. An entry requires either a live page or document on the company's own web properties, or public documentation of a supplier letter, memo, or survey with a date. Nothing on this page comes from private conversations, conference hallway reports, or secondhand accounts that cannot be traced to a document. Supplier communications delivered only through closed portals such as Exostar, or by email, can exist without any public trace, which is one reason a company's absence here proves nothing.
Quoted requirements are reproduced as stated by the company, not characterized. Where a company has published guidance without thresholds or consequences, the entry says so rather than inferring a position. Where a date is known only through industry documentation rather than the company's own materials, the entry says that too.
The page is reviewed and updated monthly, and sooner when a major notice appears. If you are aware of a public prime notice not reflected here, corrections and additions with documentation are welcome at dkoran@davidkoran.com.