Cyberuptive

DFARS 252.204-7012 Flow-Down: What Subcontractors Owe Primes

CMMC Phase 2 is suspended. DFARS 252.204-7012 is not. If your subcontract touches covered defense information, you still owe your prime 110 NIST SP 800-171 security controls, a 72-hour incident-reporting clock, and a flow-down obligation that does not wait for CMMC's reform task force to finish its work.

On July 13, 2026, the Department of War suspended implementation of CMMC Phase 2, which had been scheduled to take effect on November 10, 2026, and stood up a reform task force to rework the program under the Acquisition Transformation System directives (Department of War CIO, "About CMMC"). Contracting officers, primes, and subcontractors across the defense industrial base have spent the weeks since asking the same question: what actually still applies? The answer that matters for subcontractors is uncomfortable for anyone hoping for a compliance holiday: DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," was never suspended, was never part of the CMMC rulemaking that paused, and still flows down to every subcontract that touches covered defense information (CDI) or operationally critical support.

What changed, and what did not

CMMC Phase 2 was the rule that would have required contract-specific CMMC Level 1, 2, or 3 certifications, verified through self-assessment or third-party C3PAO review, to be written into new solicitations starting in November 2026. That rule is paused. What is not paused is the underlying source of the CMMC Level 2 control set: DFARS clause 252.204-7012, which has been standard in DoD contracts since 2016 and requires contractors and subcontractors to implement all 110 security requirements in NIST SP 800-171 Revision 2. The Department of War's own CMMC status page confirms this directly: "the suspension does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012," and Phase 1 self-assessment and annual SPRS affirmation obligations remain fully in force (Department of War CIO).

Put plainly: the certification mechanism paused. The underlying legal obligation to protect CDI, and to report incidents, did not. A subcontractor that reads "CMMC is paused" as "cybersecurity flow-down requirements are paused" is reading the wrong rule.

Who is in scope, and when the clause flows down

DFARS 252.204-7012 is required in every DoD contract except those solely for commercial off-the-shelf items, and the prime must include it in subcontracts "for which performance will involve covered defense information or operationally critical support" (DoD Office of Small Business Programs, "Safeguarding Covered Defense Information – The Basics"). The clause flows down without alteration, apart from identifying the parties. The determination of whether information a subcontractor will handle retains its identity as CDI is the prime's call, made in consultation with the contracting officer if needed, but the enforcement obligation runs both ways: the prime must enforce flow-down as a contract term, and if a subcontractor will not agree to comply, CDI should not land on that subcontractor's systems in the first place.

That last point is where a lot of subcontract negotiations go wrong. Primes sometimes treat the 7012 flow-down clause as boilerplate to paste into a subcontract and forget. Subcontractors sometimes treat it as a formality they can sign without building the underlying controls. Neither reading survives a Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) audit or a breach investigation, both of which will ask for evidence the subcontractor actually implemented NIST SP 800-171, not just agreed to a clause.

What you actually owe as a subcontractor

Strip away the acronyms and 7012 flow-down reduces to three concrete obligations, each with its own evidence trail:

  • Implement all 110 NIST SP 800-171 Rev 2 controls on any information system that processes, stores, or transmits CDI, and document how you meet them (or your compensating measures) in a system security plan. Under current Phase 1 CMMC requirements, this is validated through a self-assessment at least every three years, with an annual affirmation entered into the Supplier Performance Risk System (SPRS) (Department of War CIO).
  • Report cyber incidents within 72 hours of discovery to DoD via the DIBNet portal at dibnet.dod.mil, using the Incident Collection Format. The clock starts when you determine an event "may constitute" a cyber incident affecting CDI, not when forensics confirm the scope, and it runs in full 72-hour blocks including weekends (DFARS 252.204-7012(a)). A subcontractor's 72-hour DIBNet reporting duty is independent of, and runs alongside, its obligation to notify the prime "as soon as practicable" so the prime can assess its own reporting exposure up the chain.
  • Preserve evidence and flow the clause further down if you subcontract any part of the CDI-touching work. That means retaining forensic images and monitoring data for at least 90 days after a reported incident, submitting isolated malicious software to the DoD Cyber Crime Center rather than emailing it anywhere, and inserting the substance of 252.204-7012 into your own lower-tier subcontracts when they will touch CDI.

The CMMC clause itself did not disappear either

Separately from 7012, most current DoD contracts also carry DFARS 252.204-7021, the clause that requires a contractor to hold and maintain a current CMMC status at the level specified in the contract for systems handling federal contract information (FCI) or CUI, and explicitly requires flowing "the correct CMMC level" down to subcontracts based on 32 CFR 170.23 (DFARS 252.204-7021). With Phase 2 suspended, the levels actually being enforced today are Level 1 (Self), for systems touching only FCI, and Level 2 (Self), for systems touching CUI, evaluated on the Phase 1 timeline the Department of War has kept in place. Before awarding a subcontract that will involve FCI or CUI, the prime is required to confirm the subcontractor holds a current CMMC status, or an affirmation of compliance in SPRS, at the appropriate level. Subcontractors that assume the CMMC pause means no verification is happening should expect primes to keep asking for that SPRS evidence anyway, because the prime's own compliance depends on it.

Where subcontractors actually fail this

Three patterns account for most of the flow-down gaps that show up in DIBCAC assessments and post-incident reviews:

  1. Treating a signed subcontract clause as the control, not the evidence of a control. Agreeing to 7012 in a subcontract is a contractual commitment, not a system security plan. Auditors and contracting officers will ask for the plan, the SPRS score, and supporting artifacts, not the signature page.
  2. Not registering for DIBNet until an incident happens. DIBNet account registration takes time. Subcontractors that wait until they discover an incident to create an account have already burned a meaningful share of their 72-hour window before they can file anything.
  3. Losing track of which lower-tier systems actually touch CDI. Flow-down determinations get harder the further down the supply chain you go. A fourth-tier supplier providing a subcomponent may not realize a design file it receives qualifies as CDI, and if nobody maps information flows to specific systems, the flow-down obligation quietly stops propagating.

What to do this quarter, regardless of where CMMC reform lands

  1. Confirm your SPRS score and affirmation are current. If your last NIST SP 800-171 self-assessment is more than three years old, or your annual affirmation has lapsed, that gap is visible to any prime checking SPRS before a subcontract award.
  2. Register for DIBNet now, before you need it. Assign named points of contact and confirm access works, so the 72-hour clock does not start with an account-creation problem.
  3. Map your CDI-touching systems explicitly. Build and maintain a current inventory of which information systems process, store, or transmit CDI, tied to specific contract numbers, so a reportable incident can be scoped in hours, not days.
  4. Push the flow-down obligation to your own subcontractors in writing. If you subcontract any CDI-touching work, insert the substance of 252.204-7012 into those agreements now rather than waiting for a prime to ask why you did not.
  5. Treat 7012 and CMMC as parallel tracks, not one program. CMMC Phase 2's suspension changes the certification and verification mechanism. It does not touch the underlying 110-control requirement, the 72-hour reporting clock, or the flow-down duty, all of which sit in 7012 and remain enforceable today.

None of this requires waiting on the CMMC reform task force. If your organization already runs a managed CMMC compliance program or a 24/7 detection and response capability built around NIST SP 800-171, the flow-down obligations above are largely paperwork and verification on top of controls you should already have. If they are not already in place, the suspension of Phase 2 buys time on the certification deadline, not on the underlying legal exposure. Our breakdown of the Phase 2 suspension covers what changed for prime contractors specifically; if you want a second set of eyes on where your subcontract obligations actually stand, reach out to walk through it.

Frequently asked questions about DFARS 252.204-7012 flow-down

Is DFARS 252.204-7012 still required now that CMMC Phase 2 is suspended?

Yes. The July 13, 2026 suspension applies to CMMC Phase 2's certification and verification requirements. DFARS 252.204-7012, which requires implementation of 110 NIST SP 800-171 controls and 72-hour cyber incident reporting, was not part of that suspension and remains fully in force for any contract or subcontract touching covered defense information.

When does DFARS 252.204-7012 flow down to a subcontract?

It flows down whenever subcontract performance will involve covered defense information or operationally critical support, excluding subcontracts solely for commercial off-the-shelf items. The prime determines whether the information a subcontractor will handle retains its identity as covered defense information, in consultation with the contracting officer if necessary.

How fast do subcontractors have to report a cyber incident under 7012?

Within 72 hours of discovery, reported through the DIBNet portal at dibnet.dod.mil using the Incident Collection Format. The clock starts when the organization determines an event may constitute a cyber incident affecting covered defense information, not when an investigation confirms the scope, and it runs continuously including weekends.

Does a subcontractor also have to notify the prime contractor after an incident?

Reporting to DoD via DIBNet is the subcontractor's own independent obligation under 7012. Separately, subcontractors are generally expected to notify their prime, or the next tier up, as soon as practicable so the prime can evaluate its own reporting and risk exposure.

What is the difference between DFARS 252.204-7012 and the CMMC clause, 252.204-7021?

252.204-7012 sets the underlying safeguarding and incident-reporting obligations and is the source of the 110-control NIST SP 800-171 requirement. 252.204-7021 requires the contractor to hold and maintain a current CMMC status at the level specified in the contract, and to flow the correct CMMC level down to subcontracts under 32 CFR 170.23. CMMC Phase 2's suspension affects the second clause's rollout timeline, not the first clause's requirements.

What evidence should a subcontractor keep to prove 7012 compliance?

A current system security plan documenting how each NIST SP 800-171 control is met or compensated for, a current self-assessment score and annual affirmation in SPRS, DIBNet registration with named points of contact, and, after any reported incident, preserved system images and monitoring data for at least 90 days.

Do fourth- and fifth-tier suppliers need to worry about flow-down too?

Yes, if the information they handle qualifies as covered defense information. The flow-down obligation is not limited to first-tier subcontractors; it follows the information through the supply chain, and each tier that receives CDI is responsible for implementing 7012's requirements and flowing the clause down further if it subcontracts CDI-touching work.