Your Prime Just Added a CMMC Clause. Do You Know What You Agreed To?
Sep 24, 2026, 2:15:27 PM Wesley Reinhart 11 min read
This isn't a hypothetical for construction. The Associated General Contractors of America has told its members that most will fall under CMMC Level 1 or Level 2 and should expect the clause in their contracts. It's already showing up on real jobs. One recent Army Corps of Engineers solicitation, to replace transformer stations and a pump station at a fuel depot in Japan, designated a CMMC Level 2 self-assessment and stated that the government would check each offeror's status in SPRS before award.
Not long ago, a construction firm reached out to us for exactly this reason. Their prime contractor had started pushing them on CMMC, and they wanted to understand what they were being asked to commit to before it became a problem. That's the right instinct. Most firms don't ask until after the ink is dry.
In this article:
- "Wait, didn't CMMC get paused?"
- What the flowdown clause really requires
- Read your subcontract for these
- If you already signed
- The bottom line
- Frequently Asked Questions
Partly, yes, and that's where a lot of the confusion comes from.
On July 13, 2026, the Department of War (formerly the Department of Defense) suspended Phase 2 of CMMC. Phase 2 was the stage, scheduled for November 10, 2026, when third-party certification assessments would have become a condition of award for contracts involving Controlled Unclassified Information. Phases 3 and 4 were put on hold too, and a CMMC Reform Task Force was created to review the program. The Department then reissued a class deviation on September 3. It tells contracting officers to remove third-party CMMC requirements from solicitations, allows Level 1 and Level 2 self-assessments, and keeps NIST SP 800-171 as the baseline. The Task Force's recommendations went to the Department's CIO in September but haven't been made public as of this writing.
My colleague Jim Ambrosini covered the suspension in detail in CMMC Update: The Certification Is Suspended. The Standard Is Not. His title says it well.
What was paused is the independent audit. What wasn't paused is the following:
- The Phase 1 self-assessment requirements
- DFARS 252.204-7012 and its NIST SP 800-171 controls
- SPRS score submission
- Annual affirmations
- Your subcontract with your prime
- DFARS 252.204-7021. This is the CMMC clause itself. Note which level it specifies and whether it calls for a self-assessment or a third-party certification. If it still says third-party, ask your prime whether they plan to update it in light of the deviation.
- DFARS 252.204-7012. Safeguarding covered defense information. If this is present, you're expected to implement NIST SP 800-171 and report cyber incidents to DoD within 72 hours.
- DFARS 252.204-7019 and 7020. These cover NIST SP 800-171 assessments and your score in SPRS, the Supplier Performance Risk System.
- FAR 52.204-21. Basic safeguarding of contractor information systems, the foundation of Level 1.
- Prime-specific language. Look for deadlines, certification dates, indemnification, audit rights, or requirements to notify the prime if your status changes. These are private contract terms, and the pause doesn't touch them.
- CUI markings and handling instructions. Does the contract say whether you'll receive CUI, and how it will be marked and transmitted?
A government memo can suspend a government program. It can't rewrite the agreement you signed with a private company. Primes still have to manage risk in their supply chains, and most of them aren't loosening their flowdown language while a review plays out.
A government memo can suspend a government program. It can't rewrite the agreement you signed with a private company.
So the question isn't whether CMMC still matters. The question is what your clause actually requires today.
It's about the data you touch, not the work you do. CMMC levels follow the information you receive, store, or send.
Federal Contract Information (FCI) is non-public information generated or provided under a government contract. For a construction firm, that could be project schedules, pricing, or correspondence about a federal job. FCI generally maps to Level 1, which is a set of basic safeguarding requirements from FAR 52.204-21. It requires an annual self-assessment and an affirmation by a senior official.
Controlled Unclassified Information (CUI) is more sensitive. In construction, it's often the drawings and specifications for DoD facilities, security plans, and site access details for military installations. If your team is pulling marked drawings into a plan room, emailing them to a detailer, or opening them on a tablet in the field, that data is living on your systems. CUI generally maps to Level 2 and all 110 controls in NIST SP 800-171.
If you're unsure which applies to you, our article on CMMC Level 1 vs. Level 2 walks through the decision.

Your level isn't automatically your prime's level. A prime might need Level 2 overall while your scope only involves FCI, or the reverse. The clause should say which level applies to you, and it should match the data you'll actually handle.
Timing matters. CMMC status is generally required before award and must be maintained for the life of the contract. It's not something to finish "sometime during the project."
Pull the agreement out and look for the following:
- DFARS 252.204-7021. This is the CMMC clause itself. Note which level it specifies and whether it calls for a self-assessment or a third-party certification. If it still says third-party, ask your prime whether they plan to update it in light of the deviation.
- DFARS 252.204-7012. Safeguarding covered defense information. If this is present, you're expected to implement NIST SP 800-171 and report cyber incidents to DoD within 72 hours.
- DFARS 252.204-7019 and 7020. These cover NIST SP 800-171 assessments and your score in SPRS, the Supplier Performance Risk System.
- FAR 52.204-21. Basic safeguarding of contractor information systems, the foundation of Level 1.
- Prime-specific language. Look for deadlines, certification dates, indemnification, audit rights, or requirements to notify the prime if your status changes. These are private contract terms, and the pause doesn't touch them.
- CUI markings and handling instructions. Does the contract say whether you'll receive CUI, and how it will be marked and transmitted?
Related article: Where you store your CUI data matters more than you think
Take a breath. Signing the clause doesn't mean you're out of compliance today. It means you've committed to getting there, and you should know where you stand. Here's where I'd start.
- Find out what data you're actually receiving. Ask your prime directly whether you'll get CUI, and in what form. Many subs discover their scope is narrower than they feared, and a few discover it's broader.
- Check your SPRS status. If a score is required and you don't have one, that's your first gap.
- Do an honest self-assessment. Walk through the controls that apply to you and document what's truly in place, not what you intend to have in place.
- Talk to your prime. They'd rather have a sub who's upfront about a remediation plan than one who goes quiet. Primes need capable subcontractors, so the conversation is usually more collaborative than people expect.
- Don't round up. A self-assessment is a statement to the government. In December 2025, an Illinois machining company became the first supply-chain subcontractor to settle a False Claims Act cybersecurity case, over how it protected technical drawings for parts it made for DoD primes. Drawings are exactly what many construction subs handle.
- Keep your paperwork. Your System Security Plan, your policies, and your evidence are what hold your score up if anyone ever asks.
The pause bought everyone some breathing room on third-party audits. It didn't change the clause in your subcontract or the security expectations behind it. Firms that use this window to understand their data and close real gaps will be in a strong position whatever the Task Force recommends. Firms that treat the pause as a reason to wait will be starting from scratch when the timeline returns.
If your prime is asking about CMMC and you're not sure what you've committed to, we're happy to help you sort it out. We work with construction and engineering firms on exactly these questions. Our CMMC Readiness services can help you read your flowdown language, figure out which level applies, and build a plan you can stand behind.
YOU MAY NEED TO KNOW
Frequently Asked Questions
Is CMMC cancelled?
No. Phase 2 third-party certification is suspended while the program is reviewed. Phase 1 self-assessments, DFARS 7012, SPRS scores, and annual affirmations all remain in effect.
My prime says we need to be "CMMC certified." Is that accurate right now?
With the third-party requirement paused, most current contracts call for a self-assessment rather than a certification. Your prime may still set its own expectations in the subcontract, so ask them what they need from you specifically and get it in writing.
How do we know if we handle CUI?
Start with your contract and the documents you receive. CUI is usually marked, and on construction jobs it often shows up in facility drawings, specs, security plans, and site access information. If you're unsure, ask your prime to confirm what will be shared.
We mostly do field work. Does this still apply?
If your team emails, stores, prints, or opens project documents on phones, tablets, or laptops, those devices and systems are in scope. Field work doesn't take you out of scope. Where the data lives is what matters.
What is SPRS, and who submits our score?
SPRS is the Supplier Performance Risk System, the DoD database where contractors post assessment results. Your company submits its own score, and primes and contracting officers can check it before award.
Who signs the affirmation?
A senior official at your company affirms that you meet the requirements and will continue to. That's a personal attestation, so the person signing should understand what's behind it.
What if our Level 2 self-assessment score isn't a perfect 110?
Level 2 allows a conditional status if you meet a minimum score and close the remaining items on a Plan of Action and Milestones within 180 days, though some controls can't be deferred. Level 1 doesn't allow deferrals, so every requirement has to be met.
Can our prime share CUI with us before we meet the requirements?
Generally, primes are expected to flow CUI only to subcontractors whose systems meet the required level. That's a big reason primes are asking now: they need to know they can share project information with you.
Does this apply to non-DoD federal work?
CMMC itself is a DoD program, but FAR 52.204-21 applies to FCI on federal contracts across agencies. A broader government-wide CUI rule is also moving through the FAR process, so expect similar expectations to spread.
Should we wait for the Task Force before doing anything?
You can reasonably hold off on spending money on audit preparation. You shouldn't wait on the controls themselves, because those obligations are already in your contract, and whatever comes next will almost certainly be built on NIST SP 800-171.
Wesley Reinhart
Wesley is an experienced cybersecurity executive with a focus on Information Technology / Cybersecurity Lifecycle Management, Compliance, and Governance. Wesley is the Director of our CMMC Program at CompassMSP.