What to Ask a Subcontractor About CMMC (and What Not To)
A request comes in from a prime. They need our CMMC documentation for their supply chain file. Not the score. The System Security Plan, the network diagram, the enclave boundary, the remediation plan. Everything we've put our heart and soul into for five years.
The person asking is almost never a security person. They are a contracts or supply chain professional working from an internal checklist that says obtain evidence of compliance, and nobody handed them a definition of what evidence looks like under this framework. The framework has been moving for four years and the guidance aimed at buyers has lagged badly behind the guidance aimed at contractors.
So this is written for the person sending the request. Here is what you actually need, why the rest stays where it is, and what to ask for instead.
Start by knowing which level applies
Most of the confusion traces back to a single mix-up, and it is worth being precise about it.
Level 1 covers Federal Contract Information. Fifteen basic safeguarding requirements out of FAR 52.204-21. Self-assessed annually, with an annual affirmation. No partial credit; all fifteen have to be met.
Level 2 covers Controlled Unclassified Information. One hundred and ten requirements out of NIST SP 800-171. Assessed every three years, affirmed annually, with a limited allowance for open remediation items on a plan of action.
Those are different obligations with different evidence, and they are frequently requested interchangeably. If you send a subcontractor a document request built for Level 2 when the contract only involves FCI, you are asking them to spend money proving something the contract does not require. If you send a Level 1 request when CUI is actually in scope, you have accepted far less assurance than you needed. Know which one is on the contract before the request goes out.
"Self-assessment" is not "unverified"
People hear self-assessment, read it as ungraded homework, and conclude the only way to get real assurance is to see the underlying documents. The word itself is the problem.
A Level 2 self-assessment produces a numeric score submitted to the Supplier Performance Risk System. The scoring is not subjective. You begin at 110 and deduct a fixed value for each requirement not met, weighted by how much that requirement matters. The result is a defined number, tied to a CAGE code, with a date.
Behind that score sits an affirmation. A named senior official at the company attests in SPRS that the assessment is accurate. That attestation is a statement to the Government, which means it carries False Claims Act exposure, and the Department of Justice has spent the last several years demonstrating that this is not theoretical. There is a real docket of settlements involving contractors who misrepresented their cybersecurity posture.
So when a subcontractor gives you a score and a CAGE code, they have not given you an unverified claim. They have given you a number that an executive at their company signed their name to under penalty of the civil fraud statutes. That is a stronger form of accountability than most documents you could ask for, because a document can be aspirational and an affirmation cannot.
Why the security plan stays where it is
A System Security Plan describes where controlled information lives in an environment, how that environment is bounded, which controls are in place, and which are not yet. The plan of action is a list, in writing, of the places the defenses are still thin and when they will be fixed.
If you had access to the SSP, you would be holding a map of a supplier's weak points, sitting in a shared contracts mailbox, forwarded through however many hands your internal process requires. The document set is routinely treated as sensitive and is often marked as controlled information in its own right. Requesting it in bulk, over email, from every supplier in a program creates precisely the concentration of risk the standard exists to prevent.
The regulation does give someone the right to look inside. It gives it to the Government. DFARS 252.204-7020 provides for Government assessment access. It does not create a prime contractor right of audit over a subcontractor's security documentation. What flows down to a subcontractor under DFARS 252.204-7012 is the obligation to meet the requirement, not an obligation to open their file cabinet to every company above them in the chain.
If you want that right, it is a negotiated term. It belongs in the subcontract, agreed before award, with defined scope and handling requirements. It is not something a mid-performance email can conjure into existence.
What to ask for instead
This is the part that usually goes missing, so here is a workable set.
The SPRS score and CAGE code, with the assessment date. This is the artifact the system was built to produce. If you have portal access as a prime, you can verify it yourself rather than taking anyone's word for it.
A signed attestation letter. One page, from someone authorized to sign, confirming the assessment status, the standard assessed against, and the date. Most contractors will turn this around quickly because it costs them nothing but a signature.
A scoped questionnaire, if you need more. Not the full document set. Specific questions tied to the actual data flow between your company and theirs. What CUI moves, where it lands, how it is protected in transit, who has access. A supplier who will not answer targeted questions about your own data is telling you something. A supplier who will not mail you their complete security architecture is behaving correctly.
A shared responsibility conversation. The most useful thirty minutes in this whole process is usually a call between the two security leads about what is actually being exchanged. It surfaces more real risk than any document request, and it costs nothing.
Flow-down terms negotiated up front. If your program genuinely requires deeper visibility, put it in the subcontract with handling obligations attached. Everyone can plan for that. Nobody can plan for a document demand that arrives in month seven.
The July suspension made this harder, not easier
On July 13, 2026, the Department of War (formerly Defense) suspended the Phase II rollout of CMMC and stood up a reform task force. The practical effect is that contracting officers may now designate Level 1 self-assessment or Level 2 self-assessment, and may not designate third-party certification at Level 2 or Government-led assessment at Level 3, with no waivers issued while the review is underway. Recommendations are expected around mid-September.
Read that from a prime's chair and the problem is obvious. The verification mechanism you were planning on for November is gone. You still owe your contracting officer a defensible basis for confidence in your supply chain. So the pressure that would have been absorbed by a third-party certificate has nowhere to go, and it is landing as document requests on subcontractors.
Two things did not change. The self-assessment obligation is fully in force. And the clause on your contract is still the clause on your contract until a modification says otherwise, so nobody should be reading requirements out of existing agreements on the strength of a press release.
The one thing that genuinely did get heavier is the weight on the signature. With no assessor in the middle, the affirmation is the whole verification story. Which is a reason to take the score seriously as evidence, not a reason to go looking for something to replace it with.
The short version
Ask for the score, the CAGE code, the date, and a signed letter. Ask specific questions about your own data if you need more. Negotiate deeper access as a term, not as a favor. And leave the security plan where it belongs, which is inside the environment it describes.
#CMMC #SPRS #Level 1 #Level 2

