What does my prime's CMMC questionnaire actually require of my shop?

Four primes, four portals, one set of facts. What each questionnaire asks, what you actually owe under 32 CFR 170.23, and a worksheet that keeps every answer consistent.

Four portals, one set of facts. Exostar CCRA and PIM. RTX and Boeing registration. Answers match SPRS and SSP. Working guide.
In this guide

Updated September 30, 2026

Lockheed wants a form filled out in Exostar. Raytheon wants your annual supplier registration "current on CMMC status." A Boeing buyer sent a portal link, and a contracts admin at a fourth customer sent a one-line email that says "please confirm you comply with 7021." Nobody explains what any of it means, and the person holding all four is usually the quality manager, because the AS9100 binder was already on her desk.

By regulation, you owe each prime one thing: a current CMMC status at the level that fits the information they send you, backed by a yearly signed statement. Everything else on those forms is the prime's own checklist. Fill it in from one set of facts, the same facts you posted with the government, and it stops being four projects.

A few words before the portals. The prime is the company that holds the Defense Department contract and buys parts from you. CMMC is the DoD's program for checking that suppliers protect the information they're given. FCI (federal contract information) is non-public contract detail such as order quantities and delivery dates. CUI (controlled unclassified information) is the drawings, models, and specs the government marks as sensitive. SPRS (the Supplier Performance Risk System) is the DoD database where you post your CMMC status and score. Your SSP (system security plan) is the document that says which computers handle CUI and how each security requirement is met.

Why they keep asking

Your prime can't look you up. The contract clause that governs SPRS scores says they're available to "DoD personnel," plus the company itself, and nobody else (DFARS 252.204-7020(d)). The replacement clause DoD has used on new contracts since February 1, 2026, under its class deviation, keeps the same limit (deviation 2026-O0025, Rev. 3, clause 252.240-7997(f)). Lockheed says it plainly on its supplier page: "Lockheed Martin does not have access to review suppliers SPRS submissions in the DoD's system" (Lockheed Martin, April 2026).

Meanwhile the prime is on the hook. Before it awards you a subcontract, it has to make sure you have a current CMMC status at the right level (DFARS 252.204-7021(f)(2)). So it asks you, in writing, through whatever portal its supply chain team bought. That's why the same questions show up four times, and why one small supplier on a CMMC forum wrote that their prime "emails us every so often to see if we have met this score." The questionnaire is the prime's only window into SPRS. Treat each answer as a copy of what's in SPRS, because that's what the prime thinks it is.

What each prime is asking for

Check your own prime's supplier page before you answer; they update these pages often. As of this week:

Prime Where you answer What they ask
Lockheed Martin Exostar Supplier Management: the CCRA (Cybersecurity Compliance and Risk Assessment) Every supplier completes the CCRA Compliance survey. Suppliers that report CMMC Level 2 or higher skip the Risk survey and get a Green rating (Lockheed CCRA page)
RTX (Raytheon, Pratt, Collins) Annual Supplier Registration: data, representations and certifications Keep the registration "current on CMMC status." CMMC certification, "where required," is a condition of award, at the level the prime contract or solicitation defines (RTX Supplier Cybersecurity)
Boeing ESLC (Enterprise Supplier Lifecycle) portal Progress and evidence of your CMMC level; the level comes from each solicitation (Boeing supplier cybersecurity)
L3Harris Exostar PIM (Partner Information Manager) Attest to each NIST SP 800-171 requirement, one by one. Complete it once and share it with "any other participating prime contractors who request it" (L3Harris supplier cybersecurity)

L3Harris deserves a note. Its Missile Solutions division sent suppliers a letter dated April 6, 2026, asking CUI suppliers for a C3PAO certificate and the assessment report by July 30, 2026, roughly 80 business days later (Summit 7's summary of the letter). A C3PAO is an independent firm licensed to issue CMMC certificates. We have seen no public withdrawal of that letter since the pause. If you supply Missile Solutions, ask your buyer in writing where it stands.

What the rule says you owe

The regulation that sets subcontractor levels is short (32 CFR 170.23). If you handle only FCI, you need Level 1 (Self): 15 basic safeguards, scored by you, posted in SPRS. If you handle CUI, Level 2 (Self) is the minimum: all 110 requirements, scored by you. You need Level 2 (C3PAO), a certificate from an outside assessor, only when the prime's own contract requires C3PAO.

That last condition has mostly gone away for now. On July 13, 2026, DoD suspended the second phase of CMMC and told program offices they "may not designate CMMC Level 2 (C3PAO)" while it lasts (DoW memo). The class deviation tells contracting officers to remove or revise certificate requirements, and in contracts already signed that happens by modification, at the next option period or routine paperwork change (deviation 2026-O0025, Rev. 3). Until then, a prime whose own contract still says Level 2 (C3PAO) can pass that down to you. Your baseline duty to protect CUI under DFARS 7012 didn't pause at all. RTX's page says the same: Level 1 (Self) and Level 2 (Self) "remain in place."

Two things the pause did not change. A clause in a purchase order you accepted is a contract term: if your PO terms say "maintain a CMMC Level 2 certificate," you owe it until the prime amends them, pause or no pause. And before you accept, a prime can ask for more than the regulation does and give the work to someone else if you say no. Several have kept their deadlines, and RTX still lists certification as a condition of award "where required." That's leverage, not law, so price it before you agree. What a prime can require during the pause →

The "comply with 7021" letter

Some letters name no level, no PO, and no date. They say "comply with DFARS 252.204-7021," usually from a junior contracts admin working down a list. The clause itself asks for status "at the CMMC level that is appropriate," so the letter hasn't told you what it wants yet. Reply with one question: which purchase orders does this cover, will you send us CUI on them, and which level do you need? Once you have the answer, send your status in the format from our reply template for prime letters. Don't answer "yes, we comply" to a question nobody has defined. That sentence ends up in someone's file.

Your answers have to match

A questionnaire answer is a statement about your security, and the prime relies on it when it certifies its own compliance to the government. That is how a subcontractor ends up in a False Claims Act case. Swiss Automation, a precision machining company in Illinois, paid $421,234 in December 2025. The case was started by its former quality-control manager, and DOJ said the company knew the cybersecurity requirements applied "not only to DoD prime contractors, but also to subcontractors and suppliers" (DOJ). MORSECORP posted an SPRS score of 104, learned from a consultant that the real number was −142, didn't update it, and paid $4.6 million (DOJ).

So the rule for every portal: the answer comes from SPRS or the SSP, never from memory and never from what the form seems to want. If your SSP says multi-factor login is on your plan of action with a close date in March, the PIM answer for that requirement is "not yet, March," not "yes." A prime can forgive "not yet." Nobody forgives a Yes that the SSP contradicts.

The response worksheet

Build this once, in a spreadsheet, and keep it with your SSP. When a new portal or letter arrives, map each of its questions to a row. If a question doesn't fit a row, it's either a new fact you need to record or something the prime has no right to, and you'll know which.

The prime asks Where the true answer lives What you write
"What is your CMMC level / status?" SPRS, CMMC status page The exact status (for example, "Final Level 2 (Self)"), CMMC UID, and status date
"What is your SPRS score?" SPRS, NIST 800-171 assessment Score out of 110, assessment date, and the date your open items close
"Do you receive CUI from us?" The drawings and POs you've received from this prime "CUI on POs [x, y]" or "FCI only"
"Do you meet requirement 3.x.x?" That requirement's section in your SSP, and your plan of action Yes only if the SSP shows it met today; otherwise "planned" with the date
"Is your email or file storage FedRAMP Moderate?" The SSP's list of cloud services Service name and its FedRAMP Marketplace listing
"When was your annual affirmation, and who signed?" SPRS Date and the signer's title
"Can you report incidents to DoD within 72 hours?" Your incident response plan Yes, with the name of whoever holds the DoD medium-assurance certificate needed to file the report (DFARS 7012(c))
"Do you flow requirements to your suppliers?" Your list of outside processors that receive CUI Names and their status; see outside processors and CUI
"Upload your SSP" The PO or subcontract terms A one-page scope summary now; the full SSP only under an NDA (below)
"Provide a C3PAO certificate by [date]" The clause the request cites Your current status, whether the contract requires C3PAO, and the date you could have one if the prime insists

Have one person own the worksheet and every submission. Two people answering two portals from memory is how a shop ends up telling Lockheed one score and RTX another.

Share the SSP only under an NDA

Your SSP is a map of your network with the weak spots labeled. A prime rarely needs the whole thing to check you off; a one-page summary of scope, status, and dates answers most requests. If the prime insists, sign a mutual NDA first that names the document, limits it to the people doing supplier review, forbids passing it to other suppliers, sets a return-or-destroy date, and requires notice if it leaks. Send it through an encrypted channel you both agree on, and log what went to whom and when.

Recovering the cost

The DoD's own estimate for a small business, counting the assessment only and assuming the security work is already done, is $37,196 over three years for Level 2 (Self) and $104,670 for Level 2 (C3PAO) (CMMC final rule, 89 FR 83092). The remediation is extra, and for most shops it's the bigger number. Costs like these are allowable on government work when they're reasonable and allocable (FAR 31.201-2), but your POs are almost all firm fixed price, so nobody reimburses you line by line. You recover it through your overhead rate and your quotes. Build it into the burden rate on every defense quote starting now. When a prime demands a C3PAO certificate that its own contract doesn't require, quote the certificate as its own line or ask the prime to share the cost, in writing, before you book the assessor.

Garde1 keeps the scope, the SSP, and the score in one place, and compares the score you posted in SPRS with the score from its mock assessment. That comparison is the one to run before you type a number into any portal.

Mock assessment

One set of facts for every portal.

Garde1 writes your SSP from your scope, scores all 110 Level 2 requirements in a mock assessment, and compares that score with the one you posted in SPRS.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE