DFARS Flow-Down Clauses A Subcontractor's Guide

A DFARS flow-down clause is a contract requirement that a prime contractor must insert into its subcontracts, so the cybersecurity duties the government placed on the prime bind every supplier beneath it. If you sell parts, software, or services into the defense supply chain, clauses like DFARS 252.204-7012 arrive inside your purchase orders whether or not you have ever signed a contract with the Department of Defense. Accepting them commits your company to NIST 800-171 safeguards, an SPRS score, and 72-hour cyber incident reporting, and those commitments are enforceable.

Compliance Since 2002/ BBB A+ Since 2003/ CyberAB RPO #1449/ Raleigh, NC
Key Takeaways
  • Flow-down is contractual, not advisory. The moment you accept a purchase order carrying the clause, the obligations are yours. It does not matter that you never contracted with the government directly.
  • Five clauses do most of the work. FAR 52.204-21, DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021 are the cybersecurity flow-downs that determine what your company must implement, score, and report.
  • DFARS 252.204-7012 flows down without alteration. Paragraph (m) requires primes to include the entire clause in subcontracts involving covered defense information or operationally critical support. Only contracts solely for COTS items are excluded.
  • Your SPRS score is now a bid gate. Under 252.204-7020, a prime may not award a covered subcontract to a supplier without a current NIST 800-171 assessment posted in SPRS. No score means no purchase order.
  • Signing without complying is legal exposure. The Department of Justice's Civil Cyber-Fraud Initiative pursues False Claims Act cases against contractors that accept cybersecurity clauses and misrepresent their compliance.

Definition

What a Flow-Down Clause Actually Is

The mechanism is simple, and understanding it explains why a company with no government contracts can still carry government obligations.

Federal contracts are built from standardized clauses in the Federal Acquisition Regulation (FAR) and, for defense work, the Defense Federal Acquisition Regulation Supplement (DFARS). Some of those clauses regulate only the prime contractor. Others are written to protect something that travels down the supply chain, such as controlled unclassified information, and those clauses instruct the prime to include the same terms in its subcontracts. That act of passing a clause into a lower-tier contract is the flow-down.

The legal logic matters. A subcontractor has no privity of contract with the government: the Department of Defense cannot enforce a contract it never signed with you. Flow-down solves that by making the requirement a term of the contract you did sign, the one with your prime or the next tier up. When you accept a purchase order or sign a subcontract that incorporates DFARS 252.204-7012, your compliance obligation runs to your customer, and your customer's obligation runs to the government. Each tier is contractually responsible for the tier below it, which is why primes have become aggressive about questionnaires, SPRS score checks, and evidence requests before they award work.

Flow-down clauses also self-propagate. Most of the cybersecurity clauses require each recipient to flow the same terms into its own subcontracts. A machine shop that subcontracts anodizing must pass the clause to the anodizer if covered defense information travels with the work. The chain only stops where the information stops, or at a supplier furnishing only commercial off-the-shelf items.

The practical consequence: reading your contracts is now a security activity. As our team puts it in CMMC scoping engagements, the clauses in your prime contracts and flow-downs establish whether you should be receiving controlled information at all, and what you owe anyone you share it with.


The Clauses

The Five Cybersecurity Flow-Downs That Matter

Dozens of clauses can flow down in a defense subcontract, covering everything from specialty metals to counterfeit parts. These five carry the cybersecurity obligations.

Clause What It Requires of You When It Flows Down
FAR 52.204-21 15 basic safeguarding requirements for any system that processes federal contract information (FCI): access control, authentication, media disposal, patching, and similar hygiene controls. Subcontracts where FCI is present, except those solely for COTS items.
DFARS 252.204-7012 Implement all 110 controls of NIST SP 800-171 on any system holding covered defense information, report cyber incidents to the DoD within 72 hours, preserve forensic images, and use FedRAMP Moderate (or equivalent) cloud services for covered data. Subcontracts involving covered defense information or operationally critical support. Flows down without alteration; COTS-only suppliers excluded.
DFARS 252.204-7019 Hold a current NIST 800-171 self-assessment score (not more than three years old) posted in the Supplier Performance Risk System before you can be considered for award. Solicitations and awards involving covered defense information; works in tandem with 7020.
DFARS 252.204-7020 Give the DoD access to conduct Medium or High assessments of your implementation, and refuse to award lower-tier subcontracts to suppliers without a current SPRS assessment of their own. Subcontracts involving covered defense information, except COTS-only.
DFARS 252.204-7021 Hold a current CMMC certificate or self-assessment at the level the contract specifies, and maintain it for the life of the contract. This is the clause that makes CMMC Level 2 a condition of doing business. Phasing into contracts now that the CMMC acquisition rule is final; flows down to subcontractors at the level appropriate to the information they handle.

Two details in that table decide most real-world disputes. First, "without alteration" in 7012 means a prime cannot soften the clause for a small supplier, and a supplier cannot negotiate the 72-hour reporting window down to something more comfortable. Second, the COTS exclusion is narrow: it protects a supplier furnishing catalog products sold in the commercial market without modification. The moment your part is built to a drawing, machined to a spec, or modified for the program, you are not a COTS supplier for that work.


What You Signed

What Accepting DFARS 252.204-7012 Commits You To

Most subcontractors meet the flow-down clauses as boilerplate on page nine of a purchase order. Here is what acceptance actually obligates your company to do.

Security Obligations

  • Implement NIST SP 800-171. All 110 security requirements apply to every system that stores, processes, or transmits covered defense information, documented in a system security plan with plans of action for any gaps.
  • Control where the data lives. If covered defense information touches a cloud service you use, that service must meet the FedRAMP Moderate baseline or an equivalent standard. Consumer file-sharing and free email tiers do not qualify.
  • Flow the clause down again. Your own suppliers receive the same terms when covered defense information or operationally critical support moves to them. Their weakness is contractually your problem.

Reporting Obligations

  • Report incidents within 72 hours. Cyber incidents affecting covered defense information or your ability to perform critical support are reported directly to the DoD through DIBNet, which requires a DoD-approved medium assurance certificate you should obtain before you ever need it.
  • Tell your prime. A subcontractor that reports an incident must also provide the incident report number to the next tier up, so notification climbs the chain to the contracting officer.
  • Preserve the evidence. Affected systems and forensic images must be preserved for at least 90 days so the DoD can request them. Wiping and reimaging a compromised machine the same afternoon violates the clause even if it feels like good incident response.

Craig Petronella, CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, has walked hundreds of pages of prime flow-down packages with North Carolina manufacturers, and the pattern repeats: the clause was accepted by someone in sales or operations who reasonably assumed the legal language was routine, and the security team, if there is one, hears about it at questionnaire time. The book dedicates a full section to SPRS scoring precisely because the score is where paper obligations become a number a prime can see.


The Stakes

Myths That Cost Subcontractors Their Contracts

The defense industrial base runs on small suppliers, and small suppliers repeat the same four misunderstandings about flow-down clauses.

The Myth

"We are too small for this to apply."

The clause applies by contract, not by company size. A five-person machine shop that accepts a purchase order carrying 252.204-7012 has the same 110-control obligation as a mid-tier integrator.

"We only see drawings, not classified material."

Covered defense information is unclassified by definition. Controlled technical information, export-controlled drawings, and specifications marked for limited distribution are exactly what the clause protects.

"We will deal with it if we win the work."

Under 7019 and 7020, the SPRS score comes before award. Primes screen suppliers during sourcing, and a missing or low score removes you from the bid list before anyone calls to explain why.

"Nobody checks any of this."

Primes audit because their own flow-down obligation makes a weak subcontractor their problem. And the Department of Justice's Civil Cyber-Fraud Initiative has recovered multimillion-dollar False Claims Act settlements from contractors that attested to controls they had not implemented.

The Reality

Scope decides the cost, and scope is controllable.

The clause applies to systems that hold covered defense information, not to your whole company by default. An enclave that concentrates CUI into a small, well-controlled environment keeps the 110 controls affordable for a small team.

Marking questions are answerable.

Your contracts, CDRLs, and distribution statements tell you what you receive. When markings are ambiguous, the clause gives you the right to ask the contracting officer through your prime, and asking is far cheaper than guessing wrong in either direction.

A defensible score is achievable before the next bid.

A gap assessment, a realistic system security plan, and plans of action move most suppliers from no score to a defensible posted score quickly, and every remediated gap raises it from there.

Honest documentation is the legal shield.

The False Claims Act cases are about misrepresentation, not imperfection. A truthful SPRS score backed by a real system security plan and dated plans of action is a position you can defend to a prime, an assessor, or a lawyer.


Free Tool

Know Your Number Before Your Prime Asks

The NIST 800-171 assessment behind clauses 7019 and 7020 produces a score from -203 to 110, and primes can see it in SPRS. Our free calculator walks the same methodology so you know where you stand before it becomes a sourcing decision.


For Primes

If You Are the One Flowing the Clauses Down

Prime and mid-tier contractors carry the other half of the obligation, and it is more than pasting clauses into purchase orders.

The flow-down clauses make you responsible for including the right terms in the right subcontracts, and 252.204-7020 goes further: you may not award a covered subcontract to a supplier that lacks a current assessment in SPRS. That turns supplier cybersecurity into a sourcing gate you have to operate, which means someone in your purchasing process needs to know which subcontracts involve covered defense information, check scores before award, and keep evidence that the check happened.

The failure mode we see most often in CMMC compliance engagements is blanket flow-down: pushing every DFARS clause into every purchase order to be safe. It feels conservative, but it imposes NIST 800-171 obligations on suppliers who never touch covered defense information, inflates their costs, and produces pushback that delays real orders. The disciplined approach is information-driven: know where CUI actually travels in your supply chain, flow the full clause set there, and flow FAR 52.204-21 where only federal contract information moves. That distinction is also the heart of honest CUI identification, and it is a scoping exercise, not a legal formality.

Primes also inherit the incident chain. When a subcontractor reports a compromise to the DoD, the incident report number comes to you, and your contracting officer will expect you to know what information was at that supplier and why. A supplier map that answers those questions in an afternoon is worth building before the afternoon you need it.


Comparison

Handling Flow-Down Compliance: Three Approaches

What changes when the clauses are handled internally, by a general IT provider, or by a compliance-focused registered provider organization.

Question Do It Yourself General IT Provider Petronella Technology Group
Who reads the clauses? Whoever signs the PO, usually without a clause-by-clause review. Rarely part of the engagement; contracts stay in the front office. Contract and flow-down review is the first step of scoping, performed by a CMMC-RP certified team.
How is scope decided? Usually not decided at all: the whole network becomes the compliance boundary by default. Controls get applied wherever the tools happen to reach. Enclave design concentrates CUI into a small boundary so 110 controls cover dozens of machines, not hundreds.
Where does the documentation come from? A template SSP that drifts from reality within months. Often out of scope; documentation is billed as extra consulting. The ComplianceArmor® platform generates and maintains the SSP, plans of action, and evidence against each control.
What happens at incident time? 72-hour DIBNet reporting is researched for the first time during the incident. Restoration first; evidence preservation and DoD reporting duties are frequently missed. Incident response runs with the clause in hand: DIBNet report, prime notification, and 90-day image preservation, led by a NC Licensed Digital Forensics Examiner.

One client review captures the difference in approach: "Petronella Cybersecurity provides outstanding service! Their team is extremely knowledgeable, responsive, and truly cares about protecting their clients. They take the time to explain complex issues in simple terms and deliver real solutions, not just promises." (GB Entraînement, TrustIndex verified review; Petronella Technology Group is rated 4.7 across 92 verified TrustIndex reviews.)


Playbook

A Flow-Down Just Landed in Your Inbox. Now What?

The sequence we run with new defense suppliers, in the order that avoids rework.

1

Inventory the clauses in every active contract and PO, not just the newest one

2

Determine what information you actually receive: FCI, CUI, or neither

3

Scope the boundary: which systems and people touch that information

4

Assess against NIST 800-171 and calculate your SPRS score honestly

5

Write the SSP and plans of action, then post the score to SPRS

6

Remediate gaps, prepare DIBNet access, and flow the clauses to your own suppliers


FAQ

DFARS Flow-Down Questions, Answered

What is a DFARS flow-down clause?
A DFARS flow-down clause is a term from a Department of Defense prime contract that the prime contractor is required to include in its subcontracts, binding lower-tier suppliers to the same obligations. For cybersecurity, the key flow-downs are FAR 52.204-21, DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021, which together require NIST 800-171 implementation, SPRS score submission, 72-hour cyber incident reporting, and CMMC certification as it phases into contracts.
Do DFARS flow-down clauses apply to small businesses?
Yes. The clauses apply based on the contract and the information involved, not company size. There is no small business exemption from DFARS 252.204-7012 or the SPRS assessment requirements. Small suppliers control their cost through scoping: concentrating covered information into a small, well-controlled enclave rather than treating the entire company network as the compliance boundary.
Which subcontractors are exempt from DFARS flow-down?
The main exclusion is for subcontracts solely for commercial off-the-shelf (COTS) items: catalog products sold in the commercial marketplace without modification. A supplier machining parts to a customer drawing, modifying a commercial product, or providing services is not COTS for that work. If no covered defense information is involved and the work is not operationally critical support, 252.204-7012 also does not apply, though FAR 52.204-21 may still flow down where federal contract information is present.
What SPRS score do subcontractors need?
The clauses require a current posted score, not a specific number: the scale runs from -203 to a perfect 110. In practice, primes set their own thresholds when screening suppliers, and a low or missing score increasingly means lost bids. Under DFARS 252.204-7020, a prime may not award a covered subcontract to a supplier without a current assessment in SPRS at all. You can estimate your score with our free SPRS calculator before posting it.
Does CMMC flow down to subcontractors?
Yes. DFARS 252.204-7021 flows CMMC requirements down the supply chain, with the required level determined by the information the subcontractor handles: Level 1 self-assessment where only federal contract information is involved, and Level 2 where CUI is present. With the CMMC acquisition rule final and phasing into contracts, primes have begun requiring evidence of CMMC readiness from suppliers ahead of formal contract requirements, because their own award eligibility depends on their supply chain.
What happens if we accept the clause and do not comply?
Three escalating consequences. Commercially, primes screen SPRS and questionnaires, and non-compliant suppliers get quietly dropped from bid lists. Contractually, non-compliance is breach, and a prime facing its own liability can terminate and seek damages. Legally, the Department of Justice's Civil Cyber-Fraud Initiative pursues False Claims Act cases against contractors that misrepresent their cybersecurity compliance, and settlements have run into the millions. An honest score with documented plans of action is defensible; a false attestation is not.
We received a cyber incident report from our subcontractor. What do we do?
Under DFARS 252.204-7012, the subcontractor reports to the DoD through DIBNet within 72 hours and provides the incident report number up the chain. As the higher-tier contractor, you pass notification up to your prime or contracting officer, determine what covered defense information the affected supplier held, and cooperate with any DoD damage assessment. This is also the moment your supplier map earns its keep: knowing what information sat at that supplier should take minutes, not weeks.
Do flow-down clauses require expensive cloud changes?
Sometimes, and it is better to learn early. If covered defense information is stored or processed in a cloud service, 252.204-7012 requires that service to meet the FedRAMP Moderate baseline or equivalent. Standard commercial tenants of common productivity suites frequently do not qualify, which is why defense suppliers migrate covered work into government community cloud offerings or keep CUI inside an on-premises enclave. Scoping first prevents paying for compliant cloud seats nobody needs.

Get Ahead of Your Next Flow-Down

Petronella Technology Group has supported regulated businesses and defense suppliers in Raleigh, Durham, and across North Carolina since 2002, as a CyberAB Registered Provider Organization (RPO #1449) with an entirely CMMC-RP certified team. Send us your prime's flow-down package and we will tell you what it obligates you to do, what it should cost, and where an enclave can shrink both. Call 919-348-4912 or schedule a free consultation.

Last Updated: August 24, 2026. Reviewed by Craig Petronella, CMMC Registered Practitioner, MIT-certified, NC Licensed Digital Forensics Examiner (License# 604180-DFE).