Supply Chain Risk Management
Your subcontractors' CMMC status is your risk.
CMMC flow-down and subcontractor self-assessments, for primes and the suppliers who answer to them.
Supply chain risk management for defense primes: CMMC and DFARS flow-down, subcontractor self-assessment support, and supplier questions, scoped to NIST SP 800-171 and CMMC.
What it is
In CMMC terms, supply chain risk starts with flow-down: your security obligations do not stop at your own four walls. DFARS 252.204-7012 already requires a prime to put the same CUI safeguarding clause into any subcontract where covered defense information will be shared. CMMC extends that: a subcontractor's own required level is tied to what CUI or FCI it actually handles on that specific contract, not automatically copied from the prime's level. Managing the risk means knowing which subcontractors touch CUI, what each one owes, and whether their self-assessments hold up.
Why it matters
The 7012 flow-down obligation is not new and not paused, it applies today regardless of where CMMC's own phase-in stands. If you are a prime, an unmapped subcontractor base is a real gap right now: you cannot show an assessor the right clauses reached the right suppliers if nobody has worked out which suppliers touch CUI in the first place, and a subcontractor's inflated self-assessment is a problem that lands on your program. If you are a subcontractor, the practical risk is simpler and faster: a prime that cannot get a straight answer from you about your own compliance will look for a supplier who can give one.
Is this the right service?
SCOPED, NOT PRICEDWho it is for
Primes who need to know which subcontractors touch CUI, what each one has to meet, and whether their self-assessments hold up. Also subcontractors who need to answer a prime's questions accurately.
How it starts
With the prime contracts you hold today and a list of the subcontractors and suppliers who touch that work.
How it differs
The gap assessment scores your own environment. Supply chain risk management looks outward, at the contracts above you and the suppliers below you. CMMC In A Container covers your own program, not your supply chain.
The $5,000 gap assessment, CMMC In A Container™, or all three side by side.
What you receive
What this is not
Scoped to CMMC and NIST SP 800-171 flow-down. Broader supply chain risk, such as counterfeit parts or foreign ownership, is outside it. Each subcontractor's self-assessment and affirmation remain its own; we support them, we do not sign them. Contract and requirements work, not legal advice, and not a substitute for your own counsel reviewing language before it goes into a signed agreement.
Book a 30-minute call.
BOOK A CALLScoped per client, so the first step is a conversation. Pick a time.
What happens in 30 minutes
- We read your contract's CMMC and DFARS clauses with you.
- We confirm which level applies and how it will be assessed.
- We tell you the first step, whether or not it involves us. No slides.
Talk to us about it.
This is scoped per client, not priced on a page. Tell us what you have and we will tell you what it takes.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.