Updated August 26, 2026

CMMC • Contract eligibility • Verify

CMMC is now a contract requirement—when the acquisition record or your prime says it is.

A rule effective date does not answer whether your company needs a particular CMMC status for a particular opportunity. The Government solicitation, prime contract, subcontract, supplier-qualification terms, information, systems, and current implementation phase must be read together.

Direct answer

The Government contract is one trigger. A prime contractor can create another.

DFARS 252.204-7021 turns the specified CMMC level into a contractual performance and eligibility condition when it appears in the acquisition record. The companion solicitation provision at 252.204-7025 tells offerors that a CMMC level applies.

For a subcontractor, the controlling record also includes the prime’s RFQ, subcontract, supplier terms, security addenda, data-flow decision, and onboarding criteria. A prime may require compliance evidence or a current CMMC status or certificate as a condition of bidding, supplier approval, subcontract award, access, or continued performance—even when the Government has not directly required that same gate for the subcontractor through the current phase.

That prime-imposed business requirement must be distinguished from mandatory flowdown. When 252.204-7021 applies and the subcontract will require processing, storing, or transmitting FCI or CUI, the prime must flow the substance of the clause and, before award, ensure the supplier has the current status appropriate to the information under 32 CFR 170.23.

Separately, DFARS 252.204-7012, 7019, and 7020 already require applicable contractors handling covered defense information to provide adequate security, implement NIST SP 800-171, maintain a current methodology-based DoD Assessment score in SPRS, support Government assessment access, and flow requirements to covered suppliers.

Read the clause stack

No single clause tells the whole cybersecurity story.

Provision or clause Primary function Question for the contractor
FAR 52.204-21 Basic safeguarding for covered contractor information systems involving FCI. Will systems process or store Federal Contract Information?
DFARS 252.204-7012 Adequate security, NIST SP 800-171, cyber-incident reporting, preservation, access, and flowdown for covered defense information. Will covered contractor systems process, store, or transmit covered defense information?
DFARS 252.204-7019 Pre-award notice requiring a current NIST SP 800-171 DoD Assessment for each relevant covered system. Does SPRS contain a current score for every system relevant to the offer?
DFARS 252.204-7020 Defines Basic, Medium, and High DoD Assessments; requires methodology-based submission, Government access, and supplier handling. Can the score, SSP, scope, evidence, and supplier representations withstand review?
DFARS 252.204-7025 Solicitation notice that identifies a required CMMC level. What status must exist before award, option, or other stated gate?
DFARS 252.204-7021 Requires the specified current CMMC status, annual affirmation, covered-system use, reporting, and flowdown. Which systems and suppliers need which CMMC status, and when?

Applicability, exceptions, dates, level, assessment type, and flowdown depend on the current text and the specific acquisition record.

Determine applicability

Seven records determine whether the opportunity is ready to bid.

1. Government solicitation

Read every provision, clause, Section L/M instruction, statement of work, security attachment, data requirement, Q&A, and amendment.

2. Prime and subcontract terms

Review the prime’s RFQ, supplier portal, representations, security addendum, subcontract, onboarding gates, and any certification deadline or continuing condition.

3. Information

Identify FCI, CUI categories, covered defense information, markings, export-controlled data, and information created during performance.

4. Required status

Record whether the requirement is regulatory flowdown, prime policy, or both—plus the CMMC level, assessment type, date, and verification evidence.

5. System boundary

Map every system that will process, store, or transmit the information, plus security protection assets, specialized assets, and external providers.

6. Supplier chain

Determine what information and work will flow to each lower-tier supplier and whether its current status satisfies both the applicable clause and contractual terms before award.

7. Business decision

Compare the verified condition, remediation time, bid date, cost, contract value, representations, residual risk, and accountable approval.

Current phase

A DoD phase change does not automatically change a prime’s supplier gate.

DoD’s July 2026 notice says Phase II requirements are suspended while the program is reviewed. It also says Phase I self-assessment requirements remain firmly in place. The current DFARS still contains 7012, 7019, 7020, 7021, and 7025.

Primes remain responsible for managing information, contract flowdown, supplier eligibility, and delivery risk. Many therefore qualify suppliers before the Government’s direct acquisition gate reaches them, or require certification as a contractual risk-control measure. A subcontractor must determine whether the prime is transmitting a required clause, imposing an independent supplier condition, or doing both.

For an active opportunity, use the current Government acquisition record, the prime’s current written terms, the actual information flow, and authoritative program guidance—not a generalized headline about rollout timing.

Do not infer

  • That every solicitation requires a C3PAO assessment
  • That no prime can require a current status or certificate earlier
  • That existing NIST SP 800-171 duties are suspended
  • That an old SPRS score proves the present system condition
  • That an informal request replaces the subcontract and flowdown record
  • That purchasing compliant technology establishes organizational compliance

Manage the lifecycle

Eligibility must remain true from pursuit through performance.

Pipeline

Screen likely clauses, data, level, assessment type, due date, and supplier dependencies before committing capture resources.

Offer and award

Verify current SPRS and CMMC records, system coverage, representations, CMMC UID data, exceptions, and responsible-official approval.

Performance

Keep covered information on authorized systems, operate safeguards, preserve evidence, manage incidents, control changes, and maintain affirmations.

Options and changes

Recheck status before option exercise, extension, new order, changed work, new CUI, boundary changes, acquisitions, or new suppliers.

Substantiate before representing

A registry entry is the output of a supportable assessment—not the assessment itself.

A defensible condition starts with the contract and CUI analysis, an adequate SSP, a defined system boundary and asset inventory, implemented requirements, objective-level evidence, accurate methodology scoring, documented limitations, and accountable review.

SPRS, a CMMC UID, an affirmation, or a certificate records a result. Each must correspond to the systems and condition actually used for the work.

Minimum decision record

  • Acquisition documents and clause matrix
  • Information and flow determination
  • System and supplier scope
  • SSP, diagrams, inventories, and responsibilities
  • Assessment method, evidence, findings, and score
  • POA&M eligibility and closure status
  • SPRS/CMMC identifiers and currency
  • Named business, contracts, security, and affirming officials

Respond by condition

Choose the bid response that the evidence supports.

Ready

The required status is current, covers the correct systems, matches the information and work, and is supported by maintained evidence and supplier status.

Conditionally viable

A permitted path exists, but documented remediation, architecture, supplier, scheduling, or contractual assumptions must be resolved before the stated gate.

Not supportable

The organization cannot currently substantiate the required status or meet the timing. Escalate, seek clarification, redesign scope, partner differently, or decline.

Practical sequence

Build a repeatable cyber-eligibility gate.

  1. Intake the full solicitation, contract, or subcontract package.
  2. Build the clause, data, deliverable, and flowdown matrix.
  3. Confirm FCI/CUI and the systems and suppliers that will handle it.
  4. Identify the required SPRS and CMMC status and deadline.
  5. Map the acquisition scope to the actual assessed environment.
  6. Validate currency, affirmations, evidence, POA&M, and material changes.
  7. Document gaps, cost, schedule, dependencies, and permitted response paths.
  8. Obtain accountable approval before the offer or supplier award.
  9. Monitor the condition throughout performance and before every change gate.

One owner is not enough

Contracts interprets the acquisition record; security substantiates the environment; delivery confirms how work will occur; procurement manages supplier flowdown; finance evaluates the business case; and an authorized official accepts the representation. Assign responsibilities before an opportunity becomes urgent.

Contextual next step

Qualify the opportunity before making the representation.

eTrepid can help reconcile acquisition documents, CUI and system scope, SPRS and CMMC status, suppliers, architecture, objective-level evidence, remediation, and the operating responsibilities required to support a defensible bid decision.

Do not submit CUI, export-controlled data, credentials, contracts, vulnerability information, system diagrams, assessment evidence, or nonpublic solicitation material through a public website form or chat.

Contract-requirement questions

Questions DIB leaders should answer early.

Does every DoD solicitation require CMMC right now?

No. Applicability depends on the current phase, acquisition documents, information, systems, exceptions, and contracting activity decisions. Read the specific solicitation and amendments; do not infer the answer from a general rollout date.

Can a prime require CMMC before DoD directly requires it for that subcontractor?

Yes. A prime may make compliance evidence, a current CMMC status, or certification a condition of supplier qualification, bidding, award, access, or performance. Determine whether the requirement is mandatory regulatory flowdown, an independent prime contractual condition, or both—and obtain it in the written subcontract record.

Did the Phase II suspension remove CMMC?

No. DoD announced the suspension of Phase II while retaining Phase I self-assessment requirements. Existing DFARS safeguarding and NIST SP 800-171 assessment duties also remain. The suspension also does not automatically cancel a prime’s valid supplier requirements.

What makes CMMC a contract requirement?

DFARS 252.204-7025 provides solicitation notice, and 252.204-7021 establishes the specified CMMC status, system-use, annual-affirmation, reporting, and flowdown obligations when included in the applicable acquisition. A prime can also establish a supplier requirement through its RFQ, subcontract, security addendum, or onboarding terms.

Do 7012, 7019, and 7020 still matter when 7021 appears?

Yes. They address related but distinct safeguarding, pre-award assessment, SPRS, Government-assessment, access, and supplier obligations. Build a clause matrix rather than treating CMMC as a replacement for the existing DFARS stack.

Can a contractor bid before it has the required status?

The answer depends on the Government solicitation, prime RFQ, required status, timing, evaluation criteria, and contractual terms. Do not assume that status can be obtained after award. Request clarification through the authorized acquisition channel when the record is unclear.

Does our SPRS score cover every opportunity?

Not automatically. It must be current and correspond to each covered contractor information system relevant to the offer. Changed scope, systems, CUI, implementation, suppliers, or evidence may require reassessment and updated records.

What must be flowed to subcontractors?

The applicable clauses and level depend on the information and work being flowed down. Under 7021, covered suppliers must hold the appropriate current status before subcontract award and maintain the required affirmation. Prime-imposed conditions should be separately identified in the written supplier terms.

Who should approve the final representation?

An authorized, informed official should approve it using reconciled input from contracts, security, delivery, procurement, and qualified advisers. The approval record should identify the systems, evidence, assumptions, limitations, and Government and prime acquisition documents relied upon.