Skip to main content
Compliance & ATO

CMMC for a company with a single DoD subcontract

One subcontract does not automatically put your whole company inside a certification boundary. What decides the answer is the information that will actually reach you and the clauses in the document you signed. Work those two out first, because for a meaningful share of suppliers they change the size of the problem by an order of magnitude.

Engineering perspective, and the program is still moving Written by engineers who build these environments, not by lawyers or certified assessors. The sources are public: 32 CFR part 170, the DFARS clause text on acquisition.gov, the FAR basic safeguarding clause, and the published assessment guides. The phase-in timeline for the certification requirement has been adjusted before, so confirm the current program status and the clause text in your own subcontract rather than relying on a summary. Where a detail is uncertain we say so and name what to check.

The first question is not which level

A supplier with one defense subcontract usually opens this subject by asking which certification level applies to the company. That framing has the problem backwards. The level does not attach to your company, your headcount or your revenue. It attaches to the kind of government information that will sit on systems you own. A four-person shop handling controlled unclassified information faces the same one hundred and ten security requirements a large prime does. A two-hundred-person firm that only ever sees a purchase order and a delivery date faces fifteen. The difference between those two outcomes is not negotiable, but it is frequently misdiagnosed, and misdiagnosing it upward is expensive.

So the useful sequence is: find out what will actually be sent to you, find out what your subcontract says about it, and only then ask what it costs. In our experience the first step alone resolves a surprising number of cases, because the supplier had assumed the worst on the basis of a prime's boilerplate email rather than on the basis of the data.

You are probably here because

  • A prime sent a questionnaire and a deadline and you are not sure what half of it means
  • You have one defense contract, good margin on it, and no idea whether it is still worth having
  • Somebody quoted you a program price that is a large fraction of the contract's value
  • You want to know whether you can do this without hiring anybody

Start with the clause table. If the only clause in your subcontract is the basic safeguarding one, the rest of this article is much shorter than you feared.

Read the subcontract before you read anything else

Open the document you signed and find the clause list. Four clause numbers decide most of what follows, and their presence or absence is a matter of fact rather than opinion.

What to look forWhat it signalsWhat to do about it
FAR 52.204-21
Basic safeguarding of covered contractor information systems
Federal contract information is in play. Fifteen requirements.This is the Level 1 world. Self-assessment, annual affirmation, genuinely achievable in-house.
DFARS 252.204-7012
Safeguarding covered defense information
Controlled unclassified information is expected. The 110 requirements of NIST SP 800-171 apply.This is the Level 2 world. Also brings incident reporting, media preservation and flowdown duties.
DFARS 252.204-7019 and -7020
Assessment requirements
A current self-assessment score has to be posted, and the government may assess you directly.Post an honest score. Primes are obliged to check that their subcontractors have one.
DFARS 252.204-7021
CMMC requirement
A specified certification status is a condition of the work, at a stated level.Find out which level and which assessment path the subcontract actually requires.
None of the abovePossible, and worth confirming rather than celebrating.Ask the prime in writing what information you will receive and why no clause flowed down.

Two traps live in that table. The first is that a clause can be present in a template without the underlying information ever arriving — primes flow down broadly because it is cheaper than deciding case by case. The second is the reverse and worse: information can arrive that qualifies as controlled without a marking on it, because the marking obligation sits with the government agency and markings get missed. A supplier who decides its posture purely from what has a banner on it has decided from the wrong evidence.

The fix for both is the same, it takes one email, and almost nobody sends it: ask the prime, in writing, to state what categories of information they will transmit to you during performance, and whether any of it is controlled or export-controlled. Keep the answer. It is the foundation of every decision below and it is also the document you will want if the answer later turns out to be wrong.

Three honest strategies

Assuming controlled information really is coming, a single-contract supplier has three routes. They are genuinely different in cost, in timeline and in what they do to the rest of the business.

The cheapest way to protect controlled information is to not have any. That is a real strategy, primes use it constantly, and most small suppliers never think to ask for it.

Strategy one: arrange not to receive it

The most underused option is to keep the information out of your systems entirely. In practice this takes a few forms. The prime issues equipment they own and manage, and your people work inside it. The prime hosts a remote desktop environment that your named staff log into, with nothing permitted to leave it. Or the work is restructured so that what you receive is stripped of the controlled elements — a dimensioned drawing without the export-controlled annotations, a specification without the performance data, a task description without the platform identified.

None of that is exotic. Large primes run these arrangements routinely because they would rather manage one environment than audit forty suppliers. What stops it happening is that nobody asks, and the supplier's procurement contact does not have the authority to offer it. Ask the prime's supply chain security or industrial security function directly, and ask early, because retrofitting this after you have already been sent a package of drawings is much harder.

Be honest with yourself about the residual. If your engineers can screenshot the hosted environment, if the drawings get printed on the shop floor, if a copy lands in your quality system, then you have received the information whatever the architecture says. This strategy works when it is designed and enforced, and it fails quietly when it is only asserted.

Strategy two: a small enclave

If the information has to come to you, the next question is how little of your company it needs to touch. A defined enclave — a separate environment, a named set of people, a documented boundary — is the standard answer, and for a single-contract supplier it is usually the right one.

The appeal is that the requirements apply to what is inside the boundary. The catch is that several things come along with the boundary whether you want them to or not: whoever administers it, your identity system, your backups, your logging, and the physical security of the place where the work happens. A boundary drawn on a diagram but not enforced in the systems is worse than no boundary, because it produces a documented claim that an assessor can disprove.

The other thing to be clear-eyed about is that an enclave is a permanent operating cost, not a project. Somebody administers it every week, reviews access, patches it, watches the logs, and re-affirms annually. For a business with one contract, the recurring burden is often what decides the answer, not the one-time build.

Strategy three: the whole company

Bringing the entire company into scope is the right answer less often than it is chosen, but it is not always wrong. It makes sense when defense work is most of your revenue, when the work is inseparable from your main production systems, or when the company is small enough that maintaining two environments costs more attention than maintaining one good one. A ten-person engineering shop where every engineer touches every job is frequently better served by one well-run environment than by an enclave nobody respects.

It is the wrong answer when defense is a small share of revenue and the controls would degrade how the rest of the business works. Requirements written for controlled information have real friction, and imposing that friction on a commercial line that never needed it is a cost you pay every day forever, in exchange for a contract you have once.

Realistic for a one-contract supplier? — our read

Level 1 self-assessment, done in-house
93
Asking the prime to hold the data
70
A small enclave for a named team
66
Whole company, under fifteen people
48
Whole company, mixed commercial and defense lines
24
Doing nothing and hoping the clause is not enforced
6

Our judgment from building these environments, not a survey. The bottom row is included because it is a strategy people actually choose.

The arithmetic nobody wants to do

At some point somebody has to put the contract's margin next to the cost of keeping it, and this is where a single-contract supplier differs from everybody else. A firm with twenty defense contracts amortises the environment across all of them. You do not. Every hour, every licence and every assessment is carried by one job.

We will not invent numbers for you, and you should distrust anyone who quotes an industry-average figure without knowing your environment. What we will say is what to put in the model, because most estimates we see are missing the second half of it. The one-time side is the design, the build, the documentation and the assessment itself. The recurring side is licensing, the administrator's time every week, training, access reviews, annual affirmation, and the periodic reassessment. The recurring side is the one that usually decides it, and it is the one people leave out.

Then set that total against the whole relationship rather than the single purchase order. If this contract is the first of several, or the reference that gets you onto a qualified supplier list, the arithmetic looks entirely different than if it is a one-off with thin margin. Both answers are legitimate. Walking away from work you cannot profitably support is a strategic decision, not a failure, and a supplier who does that with a clear explanation keeps the relationship in better shape than one who accepts and then cannot deliver.

What the prime can and cannot do for you

Primes have more room to help than they usually volunteer. They can restructure what is sent so less of it is controlled. They can host you in their environment. They can tell you plainly which level the subcontract actually requires rather than the highest level in their template. Some run supplier readiness programs with real substance in them. All of that is worth asking about, and the worst outcome of asking is a no.

What they will generally not do is pay for your compliance as a line item. The customary treatment is that cybersecurity compliance is an ordinary cost of doing business, recovered through your indirect rates like insurance or quality certification, rather than billed directly. Whether a particular prime will negotiate something different is a commercial conversation and depends entirely on how much they need you. If you are hard to replace, ask. If you are one of thirty, expect the customary answer.

The one move that turns this into a legal problem

There is a shortcut available and it should be named so it can be rejected. A firm under time pressure can post a score it has not earned, or affirm a status it has not achieved, and nothing visible happens that week.

The reason not to do it is not squeamishness. The affirmation is a formal statement made by a named senior official, it is recorded, and the Justice Department has publicly pursued misrepresentation of cybersecurity compliance by government contractors under the False Claims Act — the Civil Cyber-Fraud Initiative is public and easy to look up. An honest low score is a commercial problem you can work on. A false high one is a different category of problem entirely, and it attaches to a person's name.

The practical version of this is less dramatic and comes up more often: do not let a sales conversation get ahead of the environment. If a prime's questionnaire asks whether you meet a requirement and the truthful answer is partially, write partially and say what is missing and when it closes. Buyers deal with that answer constantly. What they cannot deal with is discovering later that they were told something untrue.

A realistic order of operations

  • Get in writing what information the prime will send you, and whether any of it is controlled or export-controlled
  • List the clauses actually in your subcontract, and ask about any that seem to be there by template
  • Decide the boundary before buying anything — it sets the size of every later bill
  • Ask whether the prime will hold the data or host your people
  • Score yourself honestly against the requirements using the free published assessment procedures
  • Fund identity, encryption and boundary work first — those are the ones that cannot be deferred
  • Post an honest score, with a real date for full implementation
  • Model the recurring cost, not just the build, then compare it to the whole relationship
  • Confirm the current program timeline against the primary sources before committing money

Where this goes wrong

  • Assuming the highest level applies because a prime's template said so, without checking the data
  • Deciding from markings, when unmarked controlled information is still controlled
  • Buying tools before drawing the boundary, and then discovering the boundary makes them unnecessary
  • Modelling the build and forgetting the weekly operating cost that follows it forever
  • Never asking the prime to hold the data, which is the cheapest option and free to request
  • Extending controls across a commercial line that never needed them, permanently
  • Posting a score nobody could defend, in a system the government and your prime both read
  • Treating a hosted environment as a boundary while printing the drawings on the shop floor

Bottom line

For a supplier with one defense subcontract, the answer is decided by two documents you already have access to: the list of clauses you signed, and a written statement from your prime about what they will actually send you. Get both, and the problem usually shrinks. If the information really is controlled, the cheapest strategies are the ones that keep it out of your systems or confine it to a small enclave, and the honest arithmetic includes the operating cost forever rather than the build once. If that arithmetic says no, saying so early and plainly is a better outcome for everyone than saying yes and discovering it later.

Frequently asked questions

We only get purchase orders and drawings. Which level is that?

It depends entirely on what the drawings contain. Purchase orders, delivery dates and similar transactional material generally sit in the federal contract information world, which is the fifteen basic safeguarding requirements. Technical drawings frequently carry controlled or export-controlled content, which is a different world. Do not guess from the file type — ask the prime in writing to characterise what they are sending.

Can we get certified for just one part of the company?

Yes, and for a single-contract supplier that is usually the right design. The requirements attach to a defined boundary, so a documented enclave with named people and enforced separation is a legitimate and common structure. What comes along with it are the systems that administer or secure it — identity, backups, logging, and whoever holds administrative credentials — so draw the boundary around what those actually reach rather than around a diagram.

Will the prime pay for it?

Usually not as a line item. The customary treatment is that compliance is an ordinary cost of doing business recovered through indirect rates. What primes will often do instead is more valuable: restructure what they send so less of it is controlled, host your people in their own environment, or confirm that a lower level is what the subcontract actually requires. Those are worth asking for directly.

Is it ever right to walk away from the contract?

Yes. If a single job has to carry the whole one-time and recurring cost of an environment, and the margin does not support it, declining is a rational business decision rather than a failure. Say so early and explain the arithmetic. Primes deal with capable suppliers who cannot support a particular requirement all the time, and that conversation damages a relationship far less than accepting and then falling short.

Do we need to hire a consultant?

If you are in the fifteen-requirement world, almost certainly not. The requirements are published, the assessment procedures are free, and a capable operations person can work through them. Outside help earns its keep when there is a real boundary to design, a production network in the middle of it, several tenants, or an assessment date you have already missed once. Anyone selling a program before asking what information you receive is selling the wrong thing.

1 business day response

Want a plain read on what your subcontract actually requires?

Send the clause list and a description of what the prime sends you, and we will tell you which world you are in and roughly what it takes to get there. Email bo@precisionfederal.com.

Email an engineerCapabilitiesMore insights →
CMMCSubcontractsFCI & CUISmall Suppliers