CMMC for Defense Subcontractors and Tier-2 Suppliers
Your prime isn't waiting for November 2026. Neither should you.
Schedule a Subcontractor CMMC Scoping CallCMMC for defense subcontractors covers the requirements, flow-down obligations, and compliance path for tier-2 and lower-tier suppliers who receive Controlled Unclassified Information from a prime contractor on a DoD program. Consilien helps Southern California defense subcontractors, machining shops, engineering services firms, and specialized manufacturers understand their CMMC level, map their CUI scope, and build a compliant program before their prime or a contract deadline forces the issue.
In December 2025, Northrop Grumman told its suppliers directly: CMMC requirements can't be waived, regardless of relationship history. Neither contracting officers nor prime contractors may deviate from the requirements.
That notice wasn't unusual. It was the pattern. By late 2025, Lockheed Martin, Boeing, Raytheon, Elbit Systems of America, Parsons Corporation, and L3Harris had all issued formal supplier notices. Elbit's was among the most direct: their buyers will not issue purchase orders to suppliers who fail to meet contractual CMMC flow-down requirements.
The phase 2 government deadline - November 2026, when mandatory C3PAO assessments begin appearing in most DoD contracts involving CUI - is one clock. Your prime's internal enforcement schedule is a different, often earlier clock. And that second clock doesn't move when the government schedule does.
If you supply to any major defense prime and your work involves Controlled Unclassified Information at any tier, your compliance window is narrower than the official rollout suggests.
See the full CMMC compliance program for Southern California defense contractors
How Flow-Down Actually Works
The most common misconception in the defense supply chain: subcontractors assuming the prime's CMMC certification covers them.
It doesn't. Never has.
CMMC for defense subcontractors means that when a prime contractor receives CUI under a DoD contract and passes any of that information to a subcontractor - drawings, technical specifications, program data, test results, engineering analysis - that subcontractor must meet the same CMMC level the prime's contract requires. This obligation is codified in 32 CFR § 170.23 and enforced through DFARS 252.204-7021, which took effect November 10, 2025. The prime is legally required to flow these requirements down to every subcontract where the sub handles FCI or CUI. The prime is also responsible for verifying that its subs are compliant.
That last point matters. Prime contractors aren't just passing requirements down the chain. They're being held accountable for what's in their supply chain. Primes face False Claims Act liability if their supply chain is non-compliant and risk their own contract eligibility if they knowingly work with non-certified subs when certification is required. That pressure - not just regulatory pressure but commercial survival pressure - is why enforcement started ahead of the official government schedule.
The tier structure doesn't limit exposure. A tier-3 machining shop that receives a CUI-marked customer drawing from a tier-2 supplier that received it from a tier-1 supplier serving Lockheed Martin falls under CMMC obligations. The chain runs to every tier where CUI flows. Not just the first tier.
What Primes Are Actually Doing Right Now
This isn't speculation about what primes might do. It's what they've already done.
Lockheed Martin uses the Cyber Compliance Risk Assessment questionnaire, a standardized 60-question tool drawn from NIST SP 800-171 delivered through Exostar. A green CCRA rating requires attestation of all 31 identified NIST requirements. Their message to suppliers is explicit: "Suppliers without a green CCRA rating create significant risk for programs anticipating CMMC requirements, and may evoke program mitigation actions to reduce or eliminate dependencies on suppliers who are under-prepared."
Northrop Grumman issued notice in December 2025 that CMMC requirements cannot be waived regardless of supplier relationship history. Their position: neither contracting officers nor prime contractors may deviate from the requirements.
Boeing has been sending supplier newsletters since 2025 stating that compliance is a condition of contract award. Boeing's position: they are currently assessing supplier cybersecurity practices and identifying gaps. Suppliers handling FCI or CUI will be required to have the appropriate CMMC certification as a condition of winning work.
Elbit Systems of America stated outright that buyers will not issue purchase orders to suppliers who fail to meet contractual CMMC flow-down requirements.
L3Harris Missile Solutions issued a notice on April 6, 2026 stating that all suppliers on DoD programs who receive CUI at all tiers must be certified if required by the prime contract, including small businesses. Suppliers who don't qualify for Level 2 certification will be precluded from programs.
The enforcement language isn't vague. It isn't conditional. It's in writing.
What Level Do You Actually Need
Not every defense subcontractor needs Level 2. The level depends on what information you handle.
The question that determines your level isn't what your contract says. It's what information actually flows to you. A subcontractor who receives customer-supplied drawings with CUI distribution statement markings, ITAR-controlled technical data, or contract line item numbers from a DoD program is handling CUI whether or not the word "CMMC" appears anywhere in their purchase order.
This is where a lot of tier-2 and tier-3 suppliers get caught. They assume their work is too small or too indirect to trigger CMMC obligations. Then their prime sends a compliance questionnaire, and the answer becomes obvious.
The Five Situations Subcontractors Get Caught In
Experience across California's defense supply chain surfaces the same five patterns.
1. "Our prime hasn't asked yet." The prime hasn't asked yet. They will. Several large California primes added contractual rights to audit subcontractor compliance in 2025, with stop-work clauses for non-compliant evidence. The gap between when your prime asks and when you can produce a defensible SPRS score and compliance documentation is measured in months, not days.
2. "We're too small to matter." Size doesn't determine CMMC obligation. CUI exposure does. A 12-person precision machining shop that receives controlled drawings from a tier-1 aerospace supplier falls under CMMC Level 2 the same as a 300-person defense electronics manufacturer. L3Harris's April 2026 notice was explicit on this: the requirement applies to small businesses.
3. "We assumed the prime's certification covers our work." It covers the prime's environment. Not yours. Your systems, your handling of CUI, your controls, your documentation are evaluated separately. There's no umbrella certification in the CMMC framework.
4. "We'll handle it when we have to." The C3PAO scheduling backlog currently runs 6 to 9 months. Preparation time runs 6 to 18 months. Adding those up means a subcontractor who decides to "handle it when they have to" in mid-2026 is looking at a 2027 or 2028 certification date - well past Phase 2, well past when primes start excluding non-certified suppliers from bids.
5. "Our existing IT security is probably good enough." Probably isn't assessed. Only documented, tested, and evidenced controls satisfy CMMC. An IT environment with MFA deployed, patched endpoints, and good basic hygiene but no SSP, no CUI scope documentation, and no evidence collection cadence has zero assessed controls in the CMMC framework. Zero.
How We Work With Defense Subcontractors
The engagement starts with a conversation about what you actually handle and where you actually stand. Not a sales pitch. A scoping call that tells us both whether CMMC Level 1 or Level 2 applies, what your CUI footprint looks like, and what a realistic preparation timeline requires given your assessment window.
From there the program follows the same architecture we build for every defense contractor in California, sized to the subcontractor's actual environment:
Gap assessment and SPRS score:
Walk all 110 NIST SP 800-171 controls against the real environment. Produce an accurate SPRS score with documented methodology behind it. Map the CUI footprint so scope is set correctly before any documentation or remediation work begins.
SSP and documentation architecture:
Build the System Security Plan custom to the environment, not from a template. For subcontractors with simpler CUI footprints, this is materially less complex than a prime's SSP - but it still needs to be accurate. Include the incident response playbooks, operations security procedures, and shared responsibility matrices for any cloud or managed service providers handling CUI.
Evidence program:
Establish the weekly and monthly evidence collection cadence that produces dated, verifiable artifacts for every assessment objective. For smaller subcontractors, we right-size the evidence program to the actual scope rather than over-engineering it.
C3PAO readiness and mock assessment:
Run a mock assessment before the C3PAO arrives. Verify SSP accuracy against the real environment. Prepare the personnel named as control owners for the Interview phase. Book the C3PAO assessment slot as early as the timeline allows.
By the Numbers
defense contractors estimated to need CMMC Level 2 certification across the DIB (DoD CMMC Program Office, 2026)
the regulatory authority requiring primes to flow CMMC requirements to all subcontractors at every tier handling FCI or CUI
current C3PAO assessment scheduling lead time; contractors who wait for their prime to ask before starting preparation will not be ready in time (Elevateconsult, March 2026)
Who This Is Right For
This engagement fits:
- Tier-2 and tier-3 defense subcontractors across Los Angeles, Orange County, the Inland Empire, San Diego, and California who supply to Lockheed Martin, Northrop Grumman, Boeing, Raytheon, L3Harris, or other major primes on DoD programs involving CUI
- Precision machining shops, electronics manufacturers, engineering services firms, logistics and distribution companies, and specialized manufacturers who receive controlled drawings, technical specifications, or program data from a prime
- Subcontractors who have received a CMMC compliance questionnaire, CCRA request, or supplier notice from a prime and don't know where to start
- Companies that believed their work was too small or indirect to trigger CMMC obligations and recently discovered otherwise
Not the right fit:
Your DoD subcontract work involves only Federal Contract Information and no Controlled Unclassified Information. In that case CMMC Level 1 applies, which requires a self-assessment and annual affirmation but not a C3PAO engagement. We can confirm which level applies during the scoping call. If it's Level 1, we'll tell you that directly.
What Consilien Brings to Subcontractor CMMC Work
Founded in 2001 and headquartered in Torrance, Consilien has worked across the Southern California defense supply chain for over two decades. We've built CMMC programs for NADCAP-accredited aerospace metal finishing suppliers, tier-2 machining shops, multi-process manufacturers, and specialized defense suppliers in Los Angeles, Orange County, the Inland Empire, San Diego, and California.
The subcontractor engagement looks different from the prime engagement in scope and complexity, but the fundamentals are the same. CUI scope has to be mapped correctly. The SSP has to reflect the real environment. The evidence has to be there when the assessor looks for it. And the prime - Lockheed Martin, Northrop Grumman, Boeing, or whoever it is - needs to see a defensible compliance posture, not a self-attestation with nothing behind it.
We know the California defense supply chain. We know what the primes are asking for. And we work at the size and complexity level where most of this region's subcontractors actually live.
Common Questions From Defense Subcontractors About CMMC
How do I know if I handle CUI?
My prime hasn't mentioned CMMC in my purchase order. Do I still need it?
Can I just wait until my prime formally requires it?
Does our MSP or IT provider handle CMMC for us?
How is CMMC different from the DFARS 7012 requirement we already comply with?
What happens to our business if we don't achieve CMMC certification?
Your Prime Is Already Watching
The warning phase is over. Lockheed Martin, Boeing, Northrop Grumman, Raytheon, Elbit, L3Harris, and Parsons have all formally notified their supply chains. The SPRS scores your prime can see, the CCRA questionnaires they're sending, and the supplier notices already in circulation are the leading indicators of what happens when Phase 2 enforcement hits.
The subcontractors who survive that transition are the ones who get ahead of it. The ones who wait are competing for a shrinking pool of program slots against certified suppliers who moved earlier.
California has one of the densest concentrations of defense primes and their supply chains in the country. Northrop Grumman, Boeing, Raytheon, Lockheed Martin, and Anduril all anchor major programs in El Segundo, Long Beach, Palmdale, San Bernardino, and Hawthorne. The tier-2 and tier-3 suppliers serving those programs are concentrated across Torrance, the Inland Empire, Orange County, and San Diego. If that's where you operate, this is your window.
Not sure which CMMC level applies or where your CUI actually flows? Start with our CMMC gap assessment to get an accurate read on your starting posture and your realistic path to certification.