The Notice That Changed Nothing
If you own the CMMC program inside a prime contractor, the work has likely started the same way it has across the rest of the Defense Industrial Base. Notices go out to suppliers. A letter states that CMMC requirements now apply, a questionnaire asks the supplier to attest to its progress, the form comes back, and the file is marked complete. The trouble is that none of this confirms anything. A notice moves a requirement onto the supplier, but it does not establish that the supplier can meet that requirement, is meeting it, or will keep meeting it as certifications expire and assessment scopes change.
The controlled drawing still travels to the same small finishing shop three tiers down, and whether that shop protects the information remains unanswered. The burden has moved down the chain. The consequence has not. A signature on a flowdown clause and a returned questionnaire are records of communication, not records of compliance management, and the difference is where the exposure lives.
The Regulation Reaches Every Tier
The scope question is settled. Section 170.23 of the CMMC program rule states that CMMC requirements apply to prime contractors and subcontractors throughout the supply chain at all tiers that process, store, or transmit FCI or CUI. The obligation cascades. The prime flows the requirement to its subcontractor, that subcontractor flows it to the next tier, and onward, for as long as controlled information keeps moving down the chain. There is no tier at which the obligation stops on its own. It stops only when the information stops.
The required level follows the data rather than the position in the chain. A supplier that handles only Federal Contract Information needs Level 1. A supplier that handles Controlled Unclassified Information needs at least Level 2. A small finishing shop that never sees the contract and never reads the statement of work, yet receives a production drawing marked CUI//SP-CTI because it holds controlled technical information, is handling CUI, and its size and its distance from the government customer do not lower that requirement.
Compliance is required at every tier. Under 32 CFR 170.23, CMMC applies throughout the supply chain at all tiers that process, store, or transmit FCI or CUI, and the obligation cascades from the prime to the last specialty processor that touches the controlled drawing.
The level follows the data. A supplier handling only FCI needs Level 1. A supplier handling CUI needs at least Level 2. The determination is made by what the supplier receives, not by how far it sits from the government customer.
A notice is not evidence. A returned questionnaire records what a supplier said about itself on the day it answered. It is not the current, verified status the regulation requires before controlled information moves.
Where Controlled Information Actually Goes
A map of how controlled information moves through a supply chain does not resemble an organization chart. It follows the part. An assembly requires a machined component, which requires raw material cut to a specification, machining to a controlled drawing, a heat treatment to a process specification, a surface finish such as anodize or chemical conversion coating, a protective plating, a qualified primer or paint, and a nondestructive test. Each operation is performed by a different company, and several are small shops that specialize in a single process.
The controlled information moves with the part, including the tool path or G-code generated from a model based on government technical data. Where that derivative still carries the geometry, tolerances, and process detail needed to produce the controlled part, it remains controlled. By the time the part is complete, the controlled drawing and its derivatives have passed through five or six companies, most of which the prime has never directly qualified and may not be able to name. Many of these lower-tier processors run lean, were selected decades ago for the quality of their process, and have no in-house person who can read NIST SP 800-171 and translate it into the single office network they actually run.
The Consequence Stays With the Prime
Sending a notice does not move the consequence of a gap onto the supplier. Where DFARS 252.204-7021 applies, a prime may not let CUI be processed, stored, or transmitted on a supplier system that lacks the required status, and before awarding a covered subcontract it must confirm the supplier holds the current status appropriate to the information being flowed down. The prime also affirms its own continued compliance and carries the obligation to ensure that covered subcontractors hold current status and complete their own affirmations.
And the prime carries liability under the False Claims Act. A representation about cybersecurity compliance that is materially false, made knowingly or with reckless disregard and connected to payment, award eligibility, or contract performance, creates exposure that does not require an actual breach. The Department of Justice has pursued these cases through its Civil Cyber-Fraud Initiative. In 2025, Raytheon, RTX, and Nightwing agreed to pay $8.4 million to resolve such allegations across 29 DoD contracts and subcontracts, in a matter brought by a former engineer under the qui tam provisions.
The consequence runs to the prime. Award eligibility, the annual affirmation, and False Claims Act exposure all return to the party that holds the government contract. The regulation distributes the obligation downward, but the consequence of a failure anywhere in the chain comes back up.
Enforcement is already here. In 2025, Raytheon, RTX, and Nightwing agreed to pay $8.4 million to resolve False Claims Act allegations of cybersecurity noncompliance across 29 DoD contracts and subcontracts, a matter brought by a whistleblower under the qui tam provisions.
Monitoring alone is not enough. A requirement a small supplier cannot meet on its own stays open until someone helps it get there. Assistance is what keeps a qualified supplier in the chain rather than losing it as deadlines arrive.
From Notices to a Managed Function
The answer is to treat CMMC across the subcontractor base the way a defense manufacturer already treats supplier quality and trade compliance: as a defined function with trained staff, a documented process, and the authority to stop a transaction that does not meet the standard. That function does two jobs. It monitors compliance status across every tier that handles controlled information, through a living map of which suppliers receive FCI or CUI, level determination for each, verification of status before any award that moves controlled information, management of the flowdown clauses that carry the obligation onward, and a recurring cadence that catches affirmations coming due and assessments about to expire.
It also assists the suppliers that cannot reach the standard alone, through triage by criticality and distance from status, practical help translating NIST SP 800-171 into a small shop's actual environment, and readiness expertise sourced where the prime has none. The most effective control is often to reduce the flow itself, sending a supplier only what it needs to perform its operation rather than a full drawing package released into systems that then have to be protected. A prime that builds this has replaced a stack of notices with a managed capability, and it holds the evidence behind its own contract compliance when the question is asked.
Download the Full White Paper
The full paper covers the regulatory basis for whole-chain responsibility under 32 CFR 170.23 and DFARS 252.204-7021, how controlled information actually travels through a manufacturing supply chain, the three mechanisms that keep the consequence with the prime including False Claims Act exposure, the monitoring and assistance function and its responsibilities, the discipline of reducing unnecessary controlled-information flow, and a five-step sequence for standing the function up without a fully staffed department on day one.
The CMMC Decision, Second Edition
Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.
Read More →