What can a prime contractor require of me during the CMMC pause?

Three layers: what DoD requires through your contract clauses, what you already signed, and what the prime simply prefers. Only the first two bind you.

Three different authorities. Government clause. Executed subcontract. New supplier condition. Working guide.
In this guide

Updated September 30, 2026

Your biggest customer's supplier portal says every vendor needs a CMMC Level 2 certificate by November. You've also read that the government paused those certificates. Both can be true, and the difference decides whether you're negotiating or already obligated.

During the pause, the government asks a subcontractor for a self-assessment, not a certificate. Anything more your customer wants is binding only if it's already in a subcontract you signed. Before you sign, it's a request, and you can negotiate it.

A few words first, because the letters you're getting assume you know them. The prime is the company that holds the contract with the Defense Department and buys from you. CMMC (Cybersecurity Maturity Model Certification) is the DoD program that checks whether suppliers protect the information they're given. FCI (federal contract information) is non-public order data like quantities and delivery dates. CUI (controlled unclassified information) is the drawings, specs, and technical data the government marks as sensitive. Level 1 covers FCI and Level 2 covers CUI. Either can be a self-assessment, where you score yourself and post the result in SPRS (the Supplier Performance Risk System, DoD's supplier database). A Level 2 certificate comes from a C3PAO, an outside assessment firm the program licenses.

Three layers, and only two of them bind you

Layer What the prime can require What it can't What you do Where it comes from
The law: DoD rules in your contract clauses Protect CUI with the 110 security requirements. Report cyber incidents to DoD within 72 hours. Before award, have a self-assessment in SPRS that fits what they send you (Level 1 for order data, Level 2 for drawings), renewed with a signed statement every year Require a C3PAO certificate as a DoD rule on contracts DoD has written since July 13, 2026. See your SPRS score: only DoD and you can Keep your SPRS entry current. When asked, send your status, date, and CMMC UID (the ID SPRS gives each assessment) DFARS 252.204-7012; 252.204-7021; 32 CFR 170.23; 252.204-7019/7020 on older contracts, 252.240-7997 on newer ones; 7020(d)
Your signed subcontract Everything written in it: a certificate by a date, your security plan, 24-hour incident notice, an on-site visit Add new terms without a written change you both sign Meet it, or ask in writing for an amendment. The pause doesn't erase it Your subcontract, its purchase order terms, and its exhibits
The prime's business choices Ask for anything before you sign. Rank suppliers, and choose who gets the work Present its own preference as a DoD requirement Negotiate: who pays, by when, and how your documents are protected Its supplier policy or portal; no clause

What this means for you. Only the first row comes from the government, and during the pause it asks for a self-assessment, not a certificate. The second row is whatever you signed, and it holds until a written amendment changes it. The third row is a sales conversation, so answer it with a price and a date, never with a promise you haven't priced.

The law, in plain terms

The rules the prime has to pass down to you are numbered clauses in the DFARS, the Pentagon's contracting rulebook. They reach you only when your work triggers them.

If you'll receive CUI, the safeguarding clause comes with it (DFARS 252.204-7012, paragraph (m)). It means the 110 requirements of NIST SP 800-171 on every system that touches CUI, a report to DoD within 72 hours of finding a cyber incident with the DoD incident number passed to the prime, and cloud services for CUI that meet FedRAMP Moderate, the government's cloud security baseline. The pause didn't touch any of that.

If you'll receive FCI or CUI and the prime's contract names a CMMC level, the CMMC clause comes too (DFARS 252.204-7021). Before award, the prime must "ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down," and your senior official renews an affirmation in SPRS every year. The level follows the information you get, not the prime's own level. A subcontractor with only FCI needs Level 1 (Self). A subcontractor with CUI needs Level 2 (Self) at minimum, and Level 2 (C3PAO) only "if the prime contract requires" it (32 CFR 170.23). A prime on a Level 2 contract that sends you only purchase orders should be asking for Level 1. A careful prime also checks that your status covers the site doing its work, not just your company name.

The pause changed what DoD writes into its own contracts. The July 13 memo says program offices "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)" (DoW CIO memo, July 13, 2026). The current contracting instruction, class deviation 2026-O0025 Revision 3 signed September 3, tells contracting officers to "remove or revise the CMMC requirements in new and existing solicitations and contracts" under that memo (deviation, page 2). So on a prime contract written since July 13, the prime has no government rule to point to for a certificate from you.

Contracts signed earlier are the exception. Between November 10, 2025 and July 13, 2026, DoD could put Level 2 (C3PAO) into a contract "in place of the Level 2 (Self)" (32 CFR 170.3(e)(1)). Where it did, that language stays until the contracting officer removes it by modification, which the memo directs "prior to the exercise of the next option period or during the next scheduled administrative modification." Until that modification is signed, 170.23 makes a certificate a real flow-down on that prime contract. Ask the prime which level its own contract names and whether it has been modified. It's a fair question and the answer is a fact.

The prime also can't look up your score. SPRS scores are "available to DoD personnel," and your own company can view yours; the prime is not on that list (DFARS 252.204-7020(d)). That's why the questionnaires keep coming. Filling in prime questionnaires from one set of facts →

If you read contracts: older contracts carry 252.204-7019 and 7020, and 7020(g) bars the prime from awarding you a subcontract unless you've posted at least a Basic NIST SP 800-171 assessment within the last three years. Contracts written since February 1, 2026, under DoD's class deviation 2026-O0025, use 252.240-7997 instead. It lets DCMA run Medium and High assessments, flows to every subcontract except commercial off-the-shelf purchases, and has no pre-award score check; 7021 carries that check. Older contracts keep 7019/7020 until they're modified.

Your signed subcontract

Pay attention to what you've already signed. If a security exhibit or your PO terms say "maintain a CMMC Level 2 certificate," the pause doesn't cancel that sentence. It's a contract term between two companies, not a DoD instruction, so a DoD memo can't reach it. You owe it until the prime amends it, and missing it is a breach they can use to move the work elsewhere. The fix is a written amendment, not an argument about the news.

The prime's business choices

Before you sign, a prime can ask for plenty, and it's legitimate: a C3PAO certificate anyway, a security questionnaire, your SSP (system security plan: the document that describes how you protect CUI), a right to audit you, a shorter window to tell them about an incident. Some primes want certified suppliers because it lowers the risk on their own bids, and they can give the work to someone else if you say no. That's leverage, not law, and you answer it like a business. Ask who pays for the assessment (DoD's own estimate for a small business is $104,670 over three years for Level 2 (C3PAO), against $37,196 for Level 2 (Self), per the CMMC final rule), what deadline is realistic, and how they'll protect your SSP once they have it.

Sorting a demand in five minutes

When a prime sends a CMMC requirement, open your subcontract next to it and answer three questions. Will the prime actually send you CUI, or only order data? Which clause or exhibit does the demand cite: 7012, 7021, a signed exhibit, or nothing? And does the prime's own DoD contract still name Level 2 (C3PAO), or has it been modified since July 13? If the demand cites nothing and you haven't signed it, it's a request. Reply with what you'll offer instead: your current Level 2 (Self) status, a description of which systems handle their information, and the dates you'll close your open items.

Keep the prime's answer in writing, filed with the subcontract. When the next request comes, you'll start from facts instead of a fresh email thread. A reply template for the prime's letter →

Mock assessment

Answer the prime with a record, not a promise.

Garde1 ties your scope, SSP, and Level 2 (Self) score to the work each subcontract actually covers.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE