CMMC • Contract eligibility • Verify
CMMC is now a contract requirement—when the acquisition record or your prime says it is.
A rule effective date does not answer whether your company needs a particular CMMC status for a particular opportunity. The Government solicitation, prime contract, subcontract, supplier-qualification terms, information, systems, and current implementation phase must be read together.
Direct answer
The Government contract is one trigger. A prime contractor can create another.
DFARS 252.204-7021 turns the specified CMMC level into a contractual performance and eligibility condition when it appears in the acquisition record. The companion solicitation provision at 252.204-7025 tells offerors that a CMMC level applies.
For a subcontractor, the controlling record also includes the prime’s RFQ, subcontract, supplier terms, security addenda, data-flow decision, and onboarding criteria. A prime may require compliance evidence or a current CMMC status or certificate as a condition of bidding, supplier approval, subcontract award, access, or continued performance—even when the Government has not directly required that same gate for the subcontractor through the current phase.
That prime-imposed business requirement must be distinguished from mandatory flowdown. When 252.204-7021 applies and the subcontract will require processing, storing, or transmitting FCI or CUI, the prime must flow the substance of the clause and, before award, ensure the supplier has the current status appropriate to the information under 32 CFR 170.23.
Separately, DFARS 252.204-7012, 7019, and 7020 already require applicable contractors handling covered defense information to provide adequate security, implement NIST SP 800-171, maintain a current methodology-based DoD Assessment score in SPRS, support Government assessment access, and flow requirements to covered suppliers.
Read the clause stack
No single clause tells the whole cybersecurity story.
| Provision or clause | Primary function | Question for the contractor |
|---|---|---|
| FAR 52.204-21 | Basic safeguarding for covered contractor information systems involving FCI. | Will systems process or store Federal Contract Information? |
| DFARS 252.204-7012 | Adequate security, NIST SP 800-171, cyber-incident reporting, preservation, access, and flowdown for covered defense information. | Will covered contractor systems process, store, or transmit covered defense information? |
| DFARS 252.204-7019 | Pre-award notice requiring a current NIST SP 800-171 DoD Assessment for each relevant covered system. | Does SPRS contain a current score for every system relevant to the offer? |
| DFARS 252.204-7020 | Defines Basic, Medium, and High DoD Assessments; requires methodology-based submission, Government access, and supplier handling. | Can the score, SSP, scope, evidence, and supplier representations withstand review? |
| DFARS 252.204-7025 | Solicitation notice that identifies a required CMMC level. | What status must exist before award, option, or other stated gate? |
| DFARS 252.204-7021 | Requires the specified current CMMC status, annual affirmation, covered-system use, reporting, and flowdown. | Which systems and suppliers need which CMMC status, and when? |
Determine applicability
Seven records determine whether the opportunity is ready to bid.
1. Government solicitation
Read every provision, clause, Section L/M instruction, statement of work, security attachment, data requirement, Q&A, and amendment.
2. Prime and subcontract terms
Review the prime’s RFQ, supplier portal, representations, security addendum, subcontract, onboarding gates, and any certification deadline or continuing condition.
3. Information
Identify FCI, CUI categories, covered defense information, markings, export-controlled data, and information created during performance.
4. Required status
Record whether the requirement is regulatory flowdown, prime policy, or both—plus the CMMC level, assessment type, date, and verification evidence.
5. System boundary
Map every system that will process, store, or transmit the information, plus security protection assets, specialized assets, and external providers.
6. Supplier chain
Determine what information and work will flow to each lower-tier supplier and whether its current status satisfies both the applicable clause and contractual terms before award.
7. Business decision
Compare the verified condition, remediation time, bid date, cost, contract value, representations, residual risk, and accountable approval.
Current phase
A DoD phase change does not automatically change a prime’s supplier gate.
DoD’s July 2026 notice says Phase II requirements are suspended while the program is reviewed. It also says Phase I self-assessment requirements remain firmly in place. The current DFARS still contains 7012, 7019, 7020, 7021, and 7025.
Primes remain responsible for managing information, contract flowdown, supplier eligibility, and delivery risk. Many therefore qualify suppliers before the Government’s direct acquisition gate reaches them, or require certification as a contractual risk-control measure. A subcontractor must determine whether the prime is transmitting a required clause, imposing an independent supplier condition, or doing both.
For an active opportunity, use the current Government acquisition record, the prime’s current written terms, the actual information flow, and authoritative program guidance—not a generalized headline about rollout timing.
Do not infer
- That every solicitation requires a C3PAO assessment
- That no prime can require a current status or certificate earlier
- That existing NIST SP 800-171 duties are suspended
- That an old SPRS score proves the present system condition
- That an informal request replaces the subcontract and flowdown record
- That purchasing compliant technology establishes organizational compliance
Manage the lifecycle
Eligibility must remain true from pursuit through performance.
Pipeline
Screen likely clauses, data, level, assessment type, due date, and supplier dependencies before committing capture resources.
Offer and award
Verify current SPRS and CMMC records, system coverage, representations, CMMC UID data, exceptions, and responsible-official approval.
Performance
Keep covered information on authorized systems, operate safeguards, preserve evidence, manage incidents, control changes, and maintain affirmations.
Options and changes
Recheck status before option exercise, extension, new order, changed work, new CUI, boundary changes, acquisitions, or new suppliers.
Substantiate before representing
A registry entry is the output of a supportable assessment—not the assessment itself.
A defensible condition starts with the contract and CUI analysis, an adequate SSP, a defined system boundary and asset inventory, implemented requirements, objective-level evidence, accurate methodology scoring, documented limitations, and accountable review.
SPRS, a CMMC UID, an affirmation, or a certificate records a result. Each must correspond to the systems and condition actually used for the work.
Minimum decision record
- Acquisition documents and clause matrix
- Information and flow determination
- System and supplier scope
- SSP, diagrams, inventories, and responsibilities
- Assessment method, evidence, findings, and score
- POA&M eligibility and closure status
- SPRS/CMMC identifiers and currency
- Named business, contracts, security, and affirming officials
Respond by condition
Choose the bid response that the evidence supports.
Ready
The required status is current, covers the correct systems, matches the information and work, and is supported by maintained evidence and supplier status.
Conditionally viable
A permitted path exists, but documented remediation, architecture, supplier, scheduling, or contractual assumptions must be resolved before the stated gate.
Not supportable
The organization cannot currently substantiate the required status or meet the timing. Escalate, seek clarification, redesign scope, partner differently, or decline.
Practical sequence
Build a repeatable cyber-eligibility gate.
- Intake the full solicitation, contract, or subcontract package.
- Build the clause, data, deliverable, and flowdown matrix.
- Confirm FCI/CUI and the systems and suppliers that will handle it.
- Identify the required SPRS and CMMC status and deadline.
- Map the acquisition scope to the actual assessed environment.
- Validate currency, affirmations, evidence, POA&M, and material changes.
- Document gaps, cost, schedule, dependencies, and permitted response paths.
- Obtain accountable approval before the offer or supplier award.
- Monitor the condition throughout performance and before every change gate.
One owner is not enough
Contracts interprets the acquisition record; security substantiates the environment; delivery confirms how work will occur; procurement manages supplier flowdown; finance evaluates the business case; and an authorized official accepts the representation. Assign responsibilities before an opportunity becomes urgent.
Source and review record
Primary sources used for this draft.
- DoD CIO — current CMMC status and Phase II suspension notice
- DFARS 204.7504 — CMMC provision and clause prescription
- DFARS 252.204-7021 — Contractor CMMC requirements
- DFARS 252.204-7025 — Solicitation notice
- DFARS 252.204-7012 — Safeguarding and reporting
- DFARS 204.7302 — current NIST SP 800-171 assessment policy
- DFARS 204.7303 — SPRS verification procedures
- 32 CFR Part 170 — CMMC program requirements
Assess the score correctly
Read Low Confidence Does Not Mean Low Effort for the SSP, scope, objective-level review, scoring, and evidence behind a Basic Assessment.
Prepare the environment
Read Preparing for a CMMC Level 2 Assessment for the end-to-end readiness sequence.
Diagnose false readiness
Read Why CMMC Readiness Efforts Fail before relying on tools, policy, or a stale score.
Contextual next step
Qualify the opportunity before making the representation.
eTrepid can help reconcile acquisition documents, CUI and system scope, SPRS and CMMC status, suppliers, architecture, objective-level evidence, remediation, and the operating responsibilities required to support a defensible bid decision.
Contract-requirement questions
Questions DIB leaders should answer early.
Does every DoD solicitation require CMMC right now?
No. Applicability depends on the current phase, acquisition documents, information, systems, exceptions, and contracting activity decisions. Read the specific solicitation and amendments; do not infer the answer from a general rollout date.
Can a prime require CMMC before DoD directly requires it for that subcontractor?
Yes. A prime may make compliance evidence, a current CMMC status, or certification a condition of supplier qualification, bidding, award, access, or performance. Determine whether the requirement is mandatory regulatory flowdown, an independent prime contractual condition, or both—and obtain it in the written subcontract record.
Did the Phase II suspension remove CMMC?
No. DoD announced the suspension of Phase II while retaining Phase I self-assessment requirements. Existing DFARS safeguarding and NIST SP 800-171 assessment duties also remain. The suspension also does not automatically cancel a prime’s valid supplier requirements.
What makes CMMC a contract requirement?
DFARS 252.204-7025 provides solicitation notice, and 252.204-7021 establishes the specified CMMC status, system-use, annual-affirmation, reporting, and flowdown obligations when included in the applicable acquisition. A prime can also establish a supplier requirement through its RFQ, subcontract, security addendum, or onboarding terms.
Do 7012, 7019, and 7020 still matter when 7021 appears?
Yes. They address related but distinct safeguarding, pre-award assessment, SPRS, Government-assessment, access, and supplier obligations. Build a clause matrix rather than treating CMMC as a replacement for the existing DFARS stack.
Can a contractor bid before it has the required status?
The answer depends on the Government solicitation, prime RFQ, required status, timing, evaluation criteria, and contractual terms. Do not assume that status can be obtained after award. Request clarification through the authorized acquisition channel when the record is unclear.
Does our SPRS score cover every opportunity?
Not automatically. It must be current and correspond to each covered contractor information system relevant to the offer. Changed scope, systems, CUI, implementation, suppliers, or evidence may require reassessment and updated records.
What must be flowed to subcontractors?
The applicable clauses and level depend on the information and work being flowed down. Under 7021, covered suppliers must hold the appropriate current status before subcontract award and maintain the required affirmation. Prime-imposed conditions should be separately identified in the written supplier terms.
Who should approve the final representation?
An authorized, informed official should approve it using reconciled input from contracts, security, delivery, procurement, and qualified advisers. The approval record should identify the systems, evidence, assumptions, limitations, and Government and prime acquisition documents relied upon.