Subcontractor CMMC Tracker
Findings · finding 1 of 12

Subcontractor has no SPRS score: what DFARS 252.204-7012 and 252.204-7021 say

Where a subcontract carries DFARS 252.204-7012 and the work involves CUI or covered defense information, whether a current NIST SP 800-171 assessment in SPRS is needed before award depends on the clauses in that subcontract, the information flowed down and the CMMC level it requires (codified 252.204-7020(g)(2); 252.204-7021(f)(2)). A prime cannot see a subcontractor's score in SPRS; it can only ask for it. The SPRS score is a number from an assessment; it is not a CMMC status.

What the register reads

a date to chase

Ask for the SPRS score and the date of the assessment behind it, or confirm the subcontract involves no CUI.

The rule sentences behind it

5 cited
DFARS 252.204-7020(g)(2)codified text, eCFR current to 24 Sep 2026; replaced in Department of War (DoD) contracts by 252.240-7997 under Class Deviation 2026-O0025, effective 1 Feb 2026

The Contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment

Threshold read: no subcontract award without an assessment completed within the last 3 years. Source
DFARS 252.240-7997(g) (DEVIATION 2026-O0025)Class Deviation 2026-O0025, effective 1 Feb 2026

The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf items).

Threshold read: the deviation clause flows down; it carries no award sentence or age of its own. Source
DFARS 252.204-7021(f)(2)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.

Threshold read: before a subcontract award: a current CMMC status at the level the information flowed down calls for. Source
32 CFR 170.23(a)(2)codified text, eCFR current to 24 Sep 2026

If a subcontractor will process, store, or transmit CUI in performance of the subcontract, then a CMMC Status of Level 2 (Self) is the minimum requirement for the subcontractor.

Threshold read: CUI: Level 2 (Self) at least. Source
DFARS 252.204-7012(m)(1)codified text, eCFR current to 24 Sep 2026

Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties.

Threshold read: flows down where subcontract performance involves covered defense information. Source

The clauses behind it

DFARS 252.204-7012 (b)Security on covered systems: implement NIST SP 800-171

The Contractor shall provide adequate security on all covered contractor information systems; for systems that are not part of an IT service or system operated on behalf of the Government, this means implementing the security requirements in NIST SP 800-171 in effect at the time the solicitation is issued (or as authorised by the Contracting Officer).

What an assessor asks to see: A System Security Plan (SSP) describing how each NIST SP 800-171 requirement is met; An SPRS self-assessment score; Implementation evidence for the 110 NIST SP 800-171 security requirements
Where subcontractors usually fall short: Missing or stale SSP; No SPRS score submitted; Claiming full implementation without supporting artefacts
Source: DFARS 252.204-7012
DFARS 252.204-7012 (m)Subcontract flowdown

The Contractor shall include this clause, without alteration except to identify the parties, in subcontracts (including for commercial products or services) for operationally critical support or whose performance will involve covered defense information, determine whether information retains its identity as covered defense information, and require subcontractors to report cyber incidents to the prime (or next higher-tier subcontractor) and to DoD via dibnet.

What an assessor asks to see: Subcontracts containing clause 252.204-7012 unaltered; Determination of which subcontracts involve covered defense information; Subcontractor incident-reporting obligations to the prime and DoD
Where subcontractors usually fall short: Omitting the clause from in-scope subcontracts; No mechanism for subcontractor incident reporting to the prime
Source: DFARS 252.204-7012

A line that raises it

invented

Cobalt Ridge Cable Harness | 7RT22 | | | Level 2 (Self) | | yes | no | yes

See it in the specimen