CMMC Level 2 · Defense Industrial Base · Leesburg, VA+1 571 410-3066
Capital Cyber Compliance

Supply Chain Risk Management

Your subcontractors' CMMC status is your risk.

CMMC flow-down and subcontractor self-assessments, for primes and the suppliers who answer to them.

Supply chain risk management for defense primes: CMMC and DFARS flow-down, subcontractor self-assessment support, and supplier questions, scoped to NIST SP 800-171 and CMMC.

What it is

In CMMC terms, supply chain risk starts with flow-down: your security obligations do not stop at your own four walls. DFARS 252.204-7012 already requires a prime to put the same CUI safeguarding clause into any subcontract where covered defense information will be shared. CMMC extends that: a subcontractor's own required level is tied to what CUI or FCI it actually handles on that specific contract, not automatically copied from the prime's level. Managing the risk means knowing which subcontractors touch CUI, what each one owes, and whether their self-assessments hold up.

Why it matters

The 7012 flow-down obligation is not new and not paused, it applies today regardless of where CMMC's own phase-in stands. If you are a prime, an unmapped subcontractor base is a real gap right now: you cannot show an assessor the right clauses reached the right suppliers if nobody has worked out which suppliers touch CUI in the first place, and a subcontractor's inflated self-assessment is a problem that lands on your program. If you are a subcontractor, the practical risk is simpler and faster: a prime that cannot get a straight answer from you about your own compliance will look for a supplier who can give one.

Is this the right service?

SCOPED, NOT PRICED

Who it is for

Primes who need to know which subcontractors touch CUI, what each one has to meet, and whether their self-assessments hold up. Also subcontractors who need to answer a prime's questions accurately.

How it starts

With the prime contracts you hold today and a list of the subcontractors and suppliers who touch that work.

How it differs

The gap assessment scores your own environment. Supply chain risk management looks outward, at the contracts above you and the suppliers below you. CMMC In A Container covers your own program, not your supply chain.

What you receive

A read of the DFARS and CMMC clauses in your prime contracts, and what each one requires of you.A map of which subcontractors and suppliers those obligations flow down to, and at what level.Support for your subcontractors through their own NIST SP 800-171 self-assessments, so the answers you receive can be relied on.Flow-down language and supplier questions for your own subcontracts, ready for your counsel to review.

What this is not

Scoped to CMMC and NIST SP 800-171 flow-down. Broader supply chain risk, such as counterfeit parts or foreign ownership, is outside it. Each subcontractor's self-assessment and affirmation remain its own; we support them, we do not sign them. Contract and requirements work, not legal advice, and not a substitute for your own counsel reviewing language before it goes into a signed agreement.

Book a 30-minute call.

BOOK A CALL

Scoped per client, so the first step is a conversation. Pick a time.

What happens in 30 minutes

  1. We read your contract's CMMC and DFARS clauses with you.
  2. We confirm which level applies and how it will be assessed.
  3. We tell you the first step, whether or not it involves us. No slides.

Talk to us about it.

This is scoped per client, not priced on a page. Tell us what you have and we will tell you what it takes.

Book a 30-minute call

Defense supplier under 25 people? Start with the grant.

Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.

Apply for a CGA grant