Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

Dropped Without CMMC? What a Prime Can Actually Do

Being dropped without CMMC is the threat sitting in your inbox. Somebody at your prime, usually in supply chain and usually by email, has told you that you will be removed from their approved supplier list unless you are CMMC compliant. There is often a date attached. Before you spend a dollar reacting to it, you need to know which of three very different things just happened, because they carry different costs and they are negotiated in completely different ways.

Most owners treat the email as a verdict. Being dropped without CMMC is closer to an opening position than a decision. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.

Three very different reasons a supplier gets dropped without CMMC

What it actually isHow to recognize itHow much room you have
A flowdown obligation The prime’s own contract carries DFARS 252.204-7012 and they are passing it down as required. The email cites a clause number or a contract. Very little on the requirement itself. Real room on timing and on how you demonstrate progress.
Supplier policy The email cites a corporate supplier standard, a vendor code of conduct, or a supply chain risk program. No clause number appears anywhere. Substantial. Policies have exception processes, and exception processes have owners.
A blanket sweep The same message went to hundreds of suppliers, including ones who never touch controlled information. It reads like a form letter because it is one. The most of all. Sweeps routinely catch suppliers who are out of scope, and the prime would rather find that out than lose a source.

Sorting this out costs one phone call and one email. Skipping it can cost six figures in a compliance program you did not need, or a lost customer you could have kept.

Establish whether controlled information is actually in play

The obligation follows the data. If your prime has never sent you anything that qualifies as Controlled Unclassified Information, and your work for them is commercial off the shelf parts, raw stock, calibration services, packaging or freight, then a demand that you carry Level 2 obligations may not survive a five minute conversation with the right person.

Ask yourself, before you ask them:

  • Have you ever received a technical data package, drawing, specification or statement of work from this customer that carried a CUI marking?
  • Does the purchase order or master agreement contain DFARS 252.204-7012 or 252.204-7021?
  • Do you receive information from them through a portal that requires a login and warns about export controlled or controlled unclassified data?
  • Does any employee of yours hold information from them that you would not post publicly?

If all four answers are no, you have a scoping conversation, not a compliance project. If any answer is yes, the requirement is probably real and the question shifts to sequencing. Start with What is Controlled Unclassified Information (CUI)? if you are unsure what qualifies.

The email that gets you a real answer

Write to the person who signs your purchase orders, not to the address the notice came from. Supply chain risk mailboxes are staffed to send, not to decide. Keep it short, businesslike, and cooperative in tone. You are not resisting the requirement. You are asking them to be specific about it so you can meet it.

Ask for four things in one message:

  1. The contract basis. Which clause or which supplier standard is driving this, and does it apply to the specific part numbers you supply.
  2. The scope question, answered by them. Do they consider the information they send you to be CUI. Get that in writing. Their answer determines your entire scope.
  3. The acceptance criteria. Will a current SPRS self assessment score with a Plan of Action and Milestones satisfy them, or are they insisting on a third party certification. There is a large gap between those two positions in both time and money.
  4. The date and what happens on it. Removal from the approved list, a hold on new awards, or a note in a file. These are very different outcomes.

You will be surprised how often the answer to question two is that they do not know, and how often that admission opens the door to a reasonable timeline. If they respond by sending a form instead of an answer, your prime just sent you a cybersecurity questionnaire covers how to fill it in without creating liability.

What a prime can and cannot actually do to you

A prime can decline to give you new business for almost any reason. Approved supplier lists are their property. What a prime generally cannot do is terminate an existing purchase order for a requirement that was never in it. If you have open orders, read the termination provisions before you assume the worst, and note that a supplier who is mid production on a sole source part has considerably more leverage than one bidding on a new commodity.

The commercial reality of being dropped without CMMC usually favors you more than the email suggests. Qualifying a new source for a machined part with a first article inspection is expensive and slow. Buyers know this. Very few primes want to requalify a working supplier over a compliance milestone that the supplier is visibly moving toward.

Show progress, because that is what keeps you from being dropped without CMMC

Since CMMC Phase 2 certification assessments were suspended on July 13, 2026, no supplier can hand a prime a fresh Level 2 certificate. That fact works in your favor. What primes are documenting right now is that their suppliers are on a credible path, and a credible path has three artifacts.

ArtifactWhat it provesRealistic effort
A System Security Plan that describes your actual environmentYou know what you have and where the controlled information livesTwo to six weeks
A current SPRS score with the assessment date inside three yearsYou have scored yourself honestly against all 110 requirementsOne to two weeks after the plan exists
A Plan of Action and Milestones with named owners and datesThe gaps are known, owned and scheduledA few days, and it is the cheapest credibility you will ever buy

Send those three to your buyer with a one page cover note before the deadline they gave you. A supplier who volunteers a documented plan is not the supplier a prime removes from the list. If the deadline is tight, 90 days to get compliant sets out what fits in a quarter and what does not.

When the honest answer is that you should walk

Some of this work is not worth doing. Run the arithmetic before you commit, because nobody at the prime is going to run it for you.

Put the annual revenue from this customer on one side. On the other, put the realistic first year cost of the compliance program: consulting or internal labor, a compliant collaboration environment if controlled information is in play, endpoint tooling, logging and monitoring, and the management attention it will consume. If the revenue is a small share of your book and the margin is thin, the correct business decision may be to tell the prime plainly that you cannot support controlled work, and to keep supplying the parts that do not require it.

That conversation goes better than most owners expect. Primes maintain suppliers in both categories, and a supplier who declares limits early is easier to manage than one who claims capability and cannot back it up when the flowdown language shows up in a subcontract. For what that flowdown language obligates you to pass along to your own vendors, see Flowdown: Which Clauses You Must Pass to Your Subcontractors.

Frequently asked

Questions about this topic

Can a prime legally drop us from their supplier list without CMMC?
Yes, in most cases. Approved supplier lists are managed at the prime’s discretion and a supplier does not have a right to remain on one. What is far less common is terminating an existing purchase order over a requirement that was never part of it. Read your open orders before assuming that current work is at risk.
The prime is demanding certification. Can anyone provide that right now?
CMMC Phase 2 certification assessments were suspended on July 13, 2026, so a new Level 2 certificate is not currently obtainable. Point this out politely and offer the alternative that primes are accepting in practice: a current SPRS self assessment, a System Security Plan and a Plan of Action and Milestones.
Does this requirement apply if we only supply commercial parts?
It depends entirely on whether the prime sends you controlled information. If your work involves no CUI, no covered defense information and no export controlled technical data, the DFARS obligations may not reach you. Ask the prime to state in writing whether they consider what they send you to be CUI, and keep that answer.
How long does the prime usually give suppliers?
Deadlines in these notices are typically 60 to 180 days and are frequently extended when a supplier responds with a documented plan. Silence is what triggers removal far more often than a missed date.
What if we cannot afford the work and get dropped without CMMC?
Compare the annual revenue from this customer against the realistic first year program cost. If the numbers do not work, tell the prime directly that you cannot support controlled information and ask to remain qualified for the work that does not require it. That is a normal supplier position and it is better received than an unmet promise.
Should we tell the prime that our score is low?
Tell them the truth. A low score with a credible improvement plan is a routine supplier profile and rarely costs business on its own. An inflated score is a statement made in connection with a federal contract, and correcting one later is far more damaging than reporting an honest number now.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Tags:
Table of Contents