DFARS Flow-Down Clauses A Subcontractor's Guide
A DFARS flow-down clause is a contract requirement that a prime contractor must insert into its subcontracts, so the cybersecurity duties the government placed on the prime bind every supplier beneath it. If you sell parts, software, or services into the defense supply chain, clauses like DFARS 252.204-7012 arrive inside your purchase orders whether or not you have ever signed a contract with the Department of Defense. Accepting them commits your company to NIST 800-171 safeguards, an SPRS score, and 72-hour cyber incident reporting, and those commitments are enforceable.
- Flow-down is contractual, not advisory. The moment you accept a purchase order carrying the clause, the obligations are yours. It does not matter that you never contracted with the government directly.
- Five clauses do most of the work. FAR 52.204-21, DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021 are the cybersecurity flow-downs that determine what your company must implement, score, and report.
- DFARS 252.204-7012 flows down without alteration. Paragraph (m) requires primes to include the entire clause in subcontracts involving covered defense information or operationally critical support. Only contracts solely for COTS items are excluded.
- Your SPRS score is now a bid gate. Under 252.204-7020, a prime may not award a covered subcontract to a supplier without a current NIST 800-171 assessment posted in SPRS. No score means no purchase order.
- Signing without complying is legal exposure. The Department of Justice's Civil Cyber-Fraud Initiative pursues False Claims Act cases against contractors that accept cybersecurity clauses and misrepresent their compliance.
What a Flow-Down Clause Actually Is
The mechanism is simple, and understanding it explains why a company with no government contracts can still carry government obligations.
Federal contracts are built from standardized clauses in the Federal Acquisition Regulation (FAR) and, for defense work, the Defense Federal Acquisition Regulation Supplement (DFARS). Some of those clauses regulate only the prime contractor. Others are written to protect something that travels down the supply chain, such as controlled unclassified information, and those clauses instruct the prime to include the same terms in its subcontracts. That act of passing a clause into a lower-tier contract is the flow-down.
The legal logic matters. A subcontractor has no privity of contract with the government: the Department of Defense cannot enforce a contract it never signed with you. Flow-down solves that by making the requirement a term of the contract you did sign, the one with your prime or the next tier up. When you accept a purchase order or sign a subcontract that incorporates DFARS 252.204-7012, your compliance obligation runs to your customer, and your customer's obligation runs to the government. Each tier is contractually responsible for the tier below it, which is why primes have become aggressive about questionnaires, SPRS score checks, and evidence requests before they award work.
Flow-down clauses also self-propagate. Most of the cybersecurity clauses require each recipient to flow the same terms into its own subcontracts. A machine shop that subcontracts anodizing must pass the clause to the anodizer if covered defense information travels with the work. The chain only stops where the information stops, or at a supplier furnishing only commercial off-the-shelf items.
The practical consequence: reading your contracts is now a security activity. As our team puts it in CMMC scoping engagements, the clauses in your prime contracts and flow-downs establish whether you should be receiving controlled information at all, and what you owe anyone you share it with.
The Five Cybersecurity Flow-Downs That Matter
Dozens of clauses can flow down in a defense subcontract, covering everything from specialty metals to counterfeit parts. These five carry the cybersecurity obligations.
Two details in that table decide most real-world disputes. First, "without alteration" in 7012 means a prime cannot soften the clause for a small supplier, and a supplier cannot negotiate the 72-hour reporting window down to something more comfortable. Second, the COTS exclusion is narrow: it protects a supplier furnishing catalog products sold in the commercial market without modification. The moment your part is built to a drawing, machined to a spec, or modified for the program, you are not a COTS supplier for that work.
What Accepting DFARS 252.204-7012 Commits You To
Most subcontractors meet the flow-down clauses as boilerplate on page nine of a purchase order. Here is what acceptance actually obligates your company to do.
Security Obligations
- Implement NIST SP 800-171. All 110 security requirements apply to every system that stores, processes, or transmits covered defense information, documented in a system security plan with plans of action for any gaps.
- Control where the data lives. If covered defense information touches a cloud service you use, that service must meet the FedRAMP Moderate baseline or an equivalent standard. Consumer file-sharing and free email tiers do not qualify.
- Flow the clause down again. Your own suppliers receive the same terms when covered defense information or operationally critical support moves to them. Their weakness is contractually your problem.
Reporting Obligations
- Report incidents within 72 hours. Cyber incidents affecting covered defense information or your ability to perform critical support are reported directly to the DoD through DIBNet, which requires a DoD-approved medium assurance certificate you should obtain before you ever need it.
- Tell your prime. A subcontractor that reports an incident must also provide the incident report number to the next tier up, so notification climbs the chain to the contracting officer.
- Preserve the evidence. Affected systems and forensic images must be preserved for at least 90 days so the DoD can request them. Wiping and reimaging a compromised machine the same afternoon violates the clause even if it feels like good incident response.
Craig Petronella, CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, has walked hundreds of pages of prime flow-down packages with North Carolina manufacturers, and the pattern repeats: the clause was accepted by someone in sales or operations who reasonably assumed the legal language was routine, and the security team, if there is one, hears about it at questionnaire time. The book dedicates a full section to SPRS scoring precisely because the score is where paper obligations become a number a prime can see.
Myths That Cost Subcontractors Their Contracts
The defense industrial base runs on small suppliers, and small suppliers repeat the same four misunderstandings about flow-down clauses.
"We are too small for this to apply."
The clause applies by contract, not by company size. A five-person machine shop that accepts a purchase order carrying 252.204-7012 has the same 110-control obligation as a mid-tier integrator.
"We only see drawings, not classified material."
Covered defense information is unclassified by definition. Controlled technical information, export-controlled drawings, and specifications marked for limited distribution are exactly what the clause protects.
"We will deal with it if we win the work."
Under 7019 and 7020, the SPRS score comes before award. Primes screen suppliers during sourcing, and a missing or low score removes you from the bid list before anyone calls to explain why.
"Nobody checks any of this."
Primes audit because their own flow-down obligation makes a weak subcontractor their problem. And the Department of Justice's Civil Cyber-Fraud Initiative has recovered multimillion-dollar False Claims Act settlements from contractors that attested to controls they had not implemented.
Scope decides the cost, and scope is controllable.
The clause applies to systems that hold covered defense information, not to your whole company by default. An enclave that concentrates CUI into a small, well-controlled environment keeps the 110 controls affordable for a small team.
Marking questions are answerable.
Your contracts, CDRLs, and distribution statements tell you what you receive. When markings are ambiguous, the clause gives you the right to ask the contracting officer through your prime, and asking is far cheaper than guessing wrong in either direction.
A defensible score is achievable before the next bid.
A gap assessment, a realistic system security plan, and plans of action move most suppliers from no score to a defensible posted score quickly, and every remediated gap raises it from there.
Honest documentation is the legal shield.
The False Claims Act cases are about misrepresentation, not imperfection. A truthful SPRS score backed by a real system security plan and dated plans of action is a position you can defend to a prime, an assessor, or a lawyer.
Know Your Number Before Your Prime Asks
The NIST 800-171 assessment behind clauses 7019 and 7020 produces a score from -203 to 110, and primes can see it in SPRS. Our free calculator walks the same methodology so you know where you stand before it becomes a sourcing decision.
If You Are the One Flowing the Clauses Down
Prime and mid-tier contractors carry the other half of the obligation, and it is more than pasting clauses into purchase orders.
The flow-down clauses make you responsible for including the right terms in the right subcontracts, and 252.204-7020 goes further: you may not award a covered subcontract to a supplier that lacks a current assessment in SPRS. That turns supplier cybersecurity into a sourcing gate you have to operate, which means someone in your purchasing process needs to know which subcontracts involve covered defense information, check scores before award, and keep evidence that the check happened.
The failure mode we see most often in CMMC compliance engagements is blanket flow-down: pushing every DFARS clause into every purchase order to be safe. It feels conservative, but it imposes NIST 800-171 obligations on suppliers who never touch covered defense information, inflates their costs, and produces pushback that delays real orders. The disciplined approach is information-driven: know where CUI actually travels in your supply chain, flow the full clause set there, and flow FAR 52.204-21 where only federal contract information moves. That distinction is also the heart of honest CUI identification, and it is a scoping exercise, not a legal formality.
Primes also inherit the incident chain. When a subcontractor reports a compromise to the DoD, the incident report number comes to you, and your contracting officer will expect you to know what information was at that supplier and why. A supplier map that answers those questions in an afternoon is worth building before the afternoon you need it.
Handling Flow-Down Compliance: Three Approaches
What changes when the clauses are handled internally, by a general IT provider, or by a compliance-focused registered provider organization.
One client review captures the difference in approach: "Petronella Cybersecurity provides outstanding service! Their team is extremely knowledgeable, responsive, and truly cares about protecting their clients. They take the time to explain complex issues in simple terms and deliver real solutions, not just promises." (GB Entraînement, TrustIndex verified review; Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews.)
A Flow-Down Just Landed in Your Inbox. Now What?
The sequence we run with new defense suppliers, in the order that avoids rework.
Inventory the clauses in every active contract and PO, not just the newest one
Determine what information you actually receive: FCI, CUI, or neither
Scope the boundary: which systems and people touch that information
Assess against NIST 800-171 and calculate your SPRS score honestly
Write the SSP and plans of action, then post the score to SPRS
Remediate gaps, prepare DIBNet access, and flow the clauses to your own suppliers
DFARS Flow-Down Questions, Answered
What is a DFARS flow-down clause?
Do DFARS flow-down clauses apply to small businesses?
Which subcontractors are exempt from DFARS flow-down?
What SPRS score do subcontractors need?
Does CMMC flow down to subcontractors?
What happens if we accept the clause and do not comply?
We received a cyber incident report from our subcontractor. What do we do?
Do flow-down clauses require expensive cloud changes?
Build Your Defense Compliance Program
Get Ahead of Your Next Flow-Down
Petronella Technology Group has supported regulated businesses and defense suppliers in Raleigh, Durham, and across North Carolina since 2002, as a CyberAB Registered Provider Organization (RPO #1449) with an entirely CMMC-RP certified team. Send us your prime's flow-down package and we will tell you what it obligates you to do, what it should cost, and where an enclave can shrink both. Call 919-348-4912 or schedule a free consultation.
Last Updated: August 24, 2026. Reviewed by Craig Petronella, CMMC Registered Practitioner, MIT-certified, NC Licensed Digital Forensics Examiner (License# 604180-DFE).