Updated September 30, 2026
The prime sent a subcontract with a security exhibit (the attachment that spells out your cybersecurity obligations) that says "Supplier shall comply with all applicable cybersecurity requirements and maintain CMMC certification across all systems." You have one locked-down area for the prime's work, used by three engineers. Sign that as written and you've promised something about every computer you own, including the ones nobody has assessed.
That promise isn't just between you and the prime. The prime passes your answer up to the government, so an inflated claim can become a False Claims Act matter, where the government can recover three times its damages plus a penalty per claim (31 U.S.C. 3729). And when the promise is too vague to act on, the first incident turns into an argument about who should have called whom.
A good exhibit is one page of facts: the work, the systems allowed to touch it, your CMMC status as the government's records show it, and who calls whom when something goes wrong. CMMC is the Defense Department's cybersecurity certification for contractors. The exhibit sits alongside the standard defense contract clauses the prime is required to pass down to you (called flowdowns) and doesn't replace them.
The exhibit
Adapt this with whoever handles your contracts, and have a lawyer read the final version. The words in brackets are yours to fill in.
Covered work. PO [number], [part or work package].
Information. CUI categories [as marked by the prime], with handling instructions [attached or referenced].
Authorized environment. Supplier will receive, store, and process covered information only in [named enclave or tenant], used by [number] named personnel. No other supplier systems are authorized.
Assessment status. [Final Level 2 (Self) or Final Level 2 (C3PAO)] for the environment above, posted in SPRS under CAGE [code], dated [date]. Supplier will notify Prime within [10] business days of any change in status or scope.
Access. Supplier grants and removes access for its own personnel. Prime-provided accounts are removed within [1] business day of a Supplier notice.
Incidents. Supplier reports to DoD under DFARS 252.204-7012 within 72 hours of discovery and gives Prime the DoD incident report number. Supplier's contact: [name, phone]. Prime's contact: [name, phone]. These contacts are tested every [6] months.
End of work. Within [30] days of completion, Supplier returns or destroys covered information, except backups retained under [policy], which remain protected until they expire.
A few terms in there. CUI is controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive. An enclave or tenant is the separate, locked-down set of accounts and computers where that work happens. If an MSP administers it, the MSP belongs in that description too. SPRS is the DoD's Supplier Performance Risk System, the website where your assessment result is posted, and a CAGE code is the five-character ID your business location is registered under. "Level 2 (Self)" means you assessed yourself; "Level 2 (C3PAO)" means an accredited outside firm did.
Look closely at the Incidents paragraph. If the prime wants notice within 24 hours, agreeing is fine, as long as it's labeled a business term between the two of you. It sits on top of the 72-hour report to DoD and doesn't replace it.
Test it before you sign
Walk three events through it with the people named in it. A new engineer needs access to the prime's portal. A suspected phishing compromise at 9 pm on a Friday. The job ends and the backups still hold drawings. If the exhibit doesn't tell someone what to do in each case, fix the words before you sign.
If the prime's template insists on "all systems," answer with the facts: the environment, the status, the date. Then ask, in writing, for the exhibit to match them. A careful prime is checking whether your status covers the systems doing its work, and those facts answer exactly that.
Read a certificate clause the same way. During the pause, DoD's own rules ask a subcontractor with CUI for Level 2 (Self), and a certificate only when the prime's DoD contract still requires one. Once a certificate is in an exhibit you signed, you owe it whatever DoD does, until the prime amends it. So price it or strike it before you sign. What a prime can require during the pause → Answering a prime's CMMC letter · Flowdowns during the pause
The clauses underneath, for whoever reads contracts
Point to these by number rather than paraphrasing them in the exhibit.
DFARS 252.204-7012 (m) passes the safeguarding and incident-reporting clause down to any subcontractor handling covered defense information. When you report an incident to DoD, you also give the prime the incident report number DoD assigns, as soon as practicable. DFARS 7012
DFARS 252.204-7020 (g), where the prime contract still contains it, requires the prime to confirm before awarding the subcontract that you've posted at least a Basic NIST SP 800-171 assessment in SPRS within the last three years. DFARS 7020 Contracts written since February 1, 2026, under DoD's class deviation 2026-O0025, replace 7020 with 252.240-7997, which lets DoD run Medium and High assessments, flows down to you, and has no pre-award score check. On those, 7021 carries the check. Deviation 2026-O0025, Revision 3
DFARS 252.204-7021 passes the CMMC requirement to you when you'll handle FCI (federal contract information, the basic non-public contract data) or CUI. The prime must make sure you hold a current CMMC status at the required level before award, and your affirming official, the senior person who signs for the company, renews your affirmation in SPRS every year. DFARS 7021
The exhibit fills in what those clauses leave to the two companies: which systems, which people, which phone numbers.
