Subcontractor CMMC Tracker
Findings · finding 6 of 12

Subcontractor handles CUI at CMMC Level 1: what 32 CFR 170.23 says

Level 1 covers Federal contract information only. Where a subcontractor will process, store or transmit CUI, 32 CFR 170.23(a)(2) makes Level 2 (Self) the minimum, subject to the level the subcontract itself requires.

What the register reads

a question

A question for the subcontracts lead: does this subcontract flow down CUI, and if it does, which Level 2 assessment is planned?

The rule sentences behind it

2 cited
32 CFR 170.23(a)(1)codified text, eCFR current to 24 Sep 2026

If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required for the subcontractor.

Threshold read: FCI only: Level 1 (Self). Source
32 CFR 170.23(a)(2)codified text, eCFR current to 24 Sep 2026

If a subcontractor will process, store, or transmit CUI in performance of the subcontract, then a CMMC Status of Level 2 (Self) is the minimum requirement for the subcontractor.

Threshold read: CUI: Level 2 (Self) at least. Source

The clauses behind it

CMMC L1 AC.L1-3.1.1Authorized Access Control

CMMC 2.0 Level 1 (Foundational) practice AC.L1-3.1.1: Authorized Access Control - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(i) (3.1.1).

What an assessor asks to see: Account inventory limiting system access to authorized users, processes and devices; Access authorization records
Where subcontractors usually fall short: Shared/unauthorized accounts with FCI access
Source: CMMC 2.0 Level 1 (FAR 52.204-21 safeguarding)
CMMC L2 AC.L2-3.1.3Control CUI Flow 1 point in the score

Enforce approved authorization rules on the movement of CUI between systems, components and destinations, so CUI flows only where policy permits.

What an assessor asks to see: Documented CUI flow authorizations and approved flow paths; Firewall, proxy, DLP or gateway rules enforcing those flows; Data flow diagrams identifying CUI sources, stores and destinations; Records of blocked or exception-approved transfers
Where subcontractors usually fall short: CUI flows documented but not technically enforced; Egress to cloud and email paths unmonitored for CUI; No defined authorization for flows to external partners
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)

A line that raises it

invented

Granite Loop Plating | 5GL62 | 101 | 2025-07-07 | Level 1 (Self) | 2026-07-07 | yes | no | yes

See it in the specimen