If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Dropped Without CMMC? What a Prime Can Actually Do
Being dropped without CMMC is the threat sitting in your inbox. Somebody at your prime, usually in supply chain and usually by email, has told you that you will be removed from their approved supplier list unless you are CMMC compliant. There is often a date attached. Before you spend a dollar reacting to it, you need to know which of three very different things just happened, because they carry different costs and they are negotiated in completely different ways.
Most owners treat the email as a verdict. Being dropped without CMMC is closer to an opening position than a decision. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.
Three very different reasons a supplier gets dropped without CMMC
| What it actually is | How to recognize it | How much room you have |
|---|---|---|
| A flowdown obligation | The prime’s own contract carries DFARS 252.204-7012 and they are passing it down as required. The email cites a clause number or a contract. | Very little on the requirement itself. Real room on timing and on how you demonstrate progress. |
| Supplier policy | The email cites a corporate supplier standard, a vendor code of conduct, or a supply chain risk program. No clause number appears anywhere. | Substantial. Policies have exception processes, and exception processes have owners. |
| A blanket sweep | The same message went to hundreds of suppliers, including ones who never touch controlled information. It reads like a form letter because it is one. | The most of all. Sweeps routinely catch suppliers who are out of scope, and the prime would rather find that out than lose a source. |
Sorting this out costs one phone call and one email. Skipping it can cost six figures in a compliance program you did not need, or a lost customer you could have kept.
Establish whether controlled information is actually in play
The obligation follows the data. If your prime has never sent you anything that qualifies as Controlled Unclassified Information, and your work for them is commercial off the shelf parts, raw stock, calibration services, packaging or freight, then a demand that you carry Level 2 obligations may not survive a five minute conversation with the right person.
Ask yourself, before you ask them:
- Have you ever received a technical data package, drawing, specification or statement of work from this customer that carried a CUI marking?
- Does the purchase order or master agreement contain DFARS 252.204-7012 or 252.204-7021?
- Do you receive information from them through a portal that requires a login and warns about export controlled or controlled unclassified data?
- Does any employee of yours hold information from them that you would not post publicly?
If all four answers are no, you have a scoping conversation, not a compliance project. If any answer is yes, the requirement is probably real and the question shifts to sequencing. Start with What is Controlled Unclassified Information (CUI)? if you are unsure what qualifies.
The email that gets you a real answer
Write to the person who signs your purchase orders, not to the address the notice came from. Supply chain risk mailboxes are staffed to send, not to decide. Keep it short, businesslike, and cooperative in tone. You are not resisting the requirement. You are asking them to be specific about it so you can meet it.
Ask for four things in one message:
- The contract basis. Which clause or which supplier standard is driving this, and does it apply to the specific part numbers you supply.
- The scope question, answered by them. Do they consider the information they send you to be CUI. Get that in writing. Their answer determines your entire scope.
- The acceptance criteria. Will a current SPRS self assessment score with a Plan of Action and Milestones satisfy them, or are they insisting on a third party certification. There is a large gap between those two positions in both time and money.
- The date and what happens on it. Removal from the approved list, a hold on new awards, or a note in a file. These are very different outcomes.
You will be surprised how often the answer to question two is that they do not know, and how often that admission opens the door to a reasonable timeline. If they respond by sending a form instead of an answer, your prime just sent you a cybersecurity questionnaire covers how to fill it in without creating liability.
What a prime can and cannot actually do to you
A prime can decline to give you new business for almost any reason. Approved supplier lists are their property. What a prime generally cannot do is terminate an existing purchase order for a requirement that was never in it. If you have open orders, read the termination provisions before you assume the worst, and note that a supplier who is mid production on a sole source part has considerably more leverage than one bidding on a new commodity.
The commercial reality of being dropped without CMMC usually favors you more than the email suggests. Qualifying a new source for a machined part with a first article inspection is expensive and slow. Buyers know this. Very few primes want to requalify a working supplier over a compliance milestone that the supplier is visibly moving toward.
Show progress, because that is what keeps you from being dropped without CMMC
Since CMMC Phase 2 certification assessments were suspended on July 13, 2026, no supplier can hand a prime a fresh Level 2 certificate. That fact works in your favor. What primes are documenting right now is that their suppliers are on a credible path, and a credible path has three artifacts.
| Artifact | What it proves | Realistic effort |
|---|---|---|
| A System Security Plan that describes your actual environment | You know what you have and where the controlled information lives | Two to six weeks |
| A current SPRS score with the assessment date inside three years | You have scored yourself honestly against all 110 requirements | One to two weeks after the plan exists |
| A Plan of Action and Milestones with named owners and dates | The gaps are known, owned and scheduled | A few days, and it is the cheapest credibility you will ever buy |
Send those three to your buyer with a one page cover note before the deadline they gave you. A supplier who volunteers a documented plan is not the supplier a prime removes from the list. If the deadline is tight, 90 days to get compliant sets out what fits in a quarter and what does not.
When the honest answer is that you should walk
Some of this work is not worth doing. Run the arithmetic before you commit, because nobody at the prime is going to run it for you.
Put the annual revenue from this customer on one side. On the other, put the realistic first year cost of the compliance program: consulting or internal labor, a compliant collaboration environment if controlled information is in play, endpoint tooling, logging and monitoring, and the management attention it will consume. If the revenue is a small share of your book and the margin is thin, the correct business decision may be to tell the prime plainly that you cannot support controlled work, and to keep supplying the parts that do not require it.
That conversation goes better than most owners expect. Primes maintain suppliers in both categories, and a supplier who declares limits early is easier to manage than one who claims capability and cannot back it up when the flowdown language shows up in a subcontract. For what that flowdown language obligates you to pass along to your own vendors, see Flowdown: Which Clauses You Must Pass to Your Subcontractors.
Frequently asked
Questions about this topic
Can a prime legally drop us from their supplier list without CMMC?
The prime is demanding certification. Can anyone provide that right now?
Does this requirement apply if we only supply commercial parts?
How long does the prime usually give suppliers?
What if we cannot afford the work and get dropped without CMMC?
Should we tell the prime that our score is low?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI in Commercial Microsoft 365: What to Do Now →
- CUI Marked Drawings You Were Not Expecting? Do This →
- Cybersecurity Questionnaire From Your Prime? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5