If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Cybersecurity Questionnaire From Your Prime? Do This
A prime’s cybersecurity questionnaire usually arrives as a spreadsheet attached to an email from somebody in supply chain, with a due date about nine days out and no explanation. Sometimes it is 30 questions. Sometimes it is 400. Either way, the thing to understand before you type anything into it is that this document is a written representation about your company’s security posture, and it will be read later by people who are not the person who sent it. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.
Why cybersecurity questionnaire volume went up in 2026
Cybersecurity questionnaire volume went up after July 13, 2026, not down. When the Department of War suspended the CMMC Phase 2 assessment requirements, primes lost the thing they were planning to use as a clean pass or fail signal on suppliers, which was a certificate issued by somebody else. The obligation to manage supply chain risk did not go away with it, so they went back to asking suppliers directly.
Underneath that, DFARS 252.204-7020(d) requires a prime to confirm that its subcontractors have a current NIST SP 800-171 assessment posted in SPRS before awarding a subcontract. That is a real, unsuspended obligation on them. Many questionnaires are a prime discharging that duty and gathering commercial risk information in the same document, which is why a single form will ask for your SPRS score on one row and your cyber insurance limits on the next.
Identify which kind of cybersecurity questionnaire you received
The right response depends on what you are actually holding. Five kinds of cybersecurity questionnaire show up in the defense supply base, and they are not answered the same way.
| Type | How to recognize it | What it really wants |
|---|---|---|
| SPRS verification | Short. Asks for CAGE code, score, assessment date, scope. | Proof the prime met its 7020(d) obligation. Answer from your SPRS record verbatim. |
| NIST SP 800-171 requirement by requirement | 110 rows, one per requirement, with implemented / partial / not implemented columns. | Your self assessment. It has to match your System Security Plan and your posted score. A mismatch is the real risk here. |
| Prime’s own supplier security standard | Branded, and it mixes 800-171 with the prime’s own internal policy. Multifactor everywhere, endpoint detection, monitoring around the clock, sometimes ISO 27001. | Contract terms, not regulation. Negotiable. Some of it may exceed what your contract requires. |
| Portal based, such as Exostar, a supplier risk platform, or SIG Lite | You get a login, not a file. | Same content, but answers persist, get scored, and are visible to multiple primes. Higher stakes. |
| Incident driven | Arrives out of cycle, asks about specific technologies or a specific date range. | Something happened somewhere in the supply chain. Answer narrowly and precisely, and bring counsel in before you send it. |
Three lookups before you answer a single question
- Pull your actual SPRS record. Not what you remember posting. Log into PIEE, look at the score, the assessment date, the assessment scope description, and the confidence level. Every answer you give has to be consistent with what is already sitting in that record, because the prime can see it too.
- Find the clauses in the contract this questionnaire relates to. Is 252.204-7012 in it? 7019? 7020? FAR 52.204-21 only? Your obligations differ enormously depending on the answer, and so does what you owe this prime. If you are not sure what each one triggers, read DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers.
- Confirm whether you hold CUI or only FCI. If everything you receive from this prime is FCI, you are at FAR 52.204-21 and fifteen requirements, and half the questionnaire may not apply to you. Say so explicitly rather than answering no down a column of controls you were never obligated to implement.
Budget a day for these. Companies that skip them end up amending their answers a month later, which is worse than being slow.
How to answer a cybersecurity questionnaire without creating liability
A completed cybersecurity questionnaire becomes part of the record. If a prime relies on it, and later there is an incident, a dispute or a False Claims Act inquiry, this document is evidence of what you told them. Four rules hold up well:
- Answer for the state of the system today, not the state you are working toward. Planned for the fourth quarter is not implemented. A control that is eighty percent deployed is not implemented.
- Use partial and not implemented freely, with a POA&M date. Primes are used to seeing gaps. What they are not used to seeing is a supplier who claims perfection and then cannot produce a System Security Plan.
- Never write the word compliant on its own. Compliant with what, assessed by whom, as of when, across which boundary. Write that instead.
- Have one owner. One person assembles the answers and one senior person reviews before it goes out. Questionnaires filled in by three departments contradict themselves, and contradictions are what get escalated.
The five questions people get wrong
Are you CMMC certified? The accurate answer today is that CMMC Level 2 certification assessments have been suspended since July 13, 2026, so no certificates are currently being issued. State your self assessment score and its date instead. Do not answer yes because a consultant told you that you would pass.
What is your SPRS score? Give the number, the assessment date, and the scope it covers. If your posted score covers a boundary that is narrower than the work this prime is sending you, say that in the same sentence. Discovering it later looks like concealment.
Do you have a System Security Plan? Answer yes only if a document exists that describes your actual environment, its boundary and how each requirement is met. A template with your logo on the cover is a no.
Is CUI encrypted using FIPS validated cryptography? This question is about validated modules, not about whether you use encryption. Note also that FIPS 140-2 certificates move to historical status on September 21, 2026, so anything you are relying on should be checked against the CMVP list before you answer.
Do you use a cloud service that meets DFARS 252.204-7012(b)(2)(ii)(D)? This is the one that catches manufacturers. Commercial Microsoft 365 was not built to meet the 7012 cloud conditions. If your CUI sits in a commercial tenant, the honest answer is no, with a remediation plan attached. The options are laid out in your CUI is sitting in commercial Microsoft 365.
What to send back with the cybersecurity questionnaire, and what to keep
| Send | Do not send |
|---|---|
| The completed questionnaire | Your full System Security Plan |
| A one page cover summary with score, assessment date, boundary and POA&M status | Network diagrams and IP addressing |
| A POA&M extract showing gaps with owners and dates | Vulnerability scan output or pen test reports |
| Named point of contact for security questions | Configuration exports or screenshots showing credentials |
Your SSP is a roadmap to your weaknesses. Primes almost never need it, and the ones who ask usually accept a summary plus an offer to walk it in a call. If a prime insists on the full document, get a written commitment on how it will be stored and who sees it.
The cover summary that changes the conversation
Four short paragraphs, attached to the cybersecurity questionnaire:
- Scope. Which part of your business handles their data, and what the boundary is.
- Current posture. Posted SPRS score, assessment date, and what methodology produced it.
- Gaps and plan. The three or four largest open items, each with an owner and a target date.
- Status of CMMC. One sentence acknowledging the Phase 2 suspension and stating that you are maintaining 800-171 implementation and your annual affirmation regardless.
A supplier who writes that page is treated differently from one who returns a spreadsheet with every box ticked green. The first looks like a company that knows its own environment. The second looks like a company that has not looked.
After you send it
Expect one of three outcomes. Most common is silence, which means you cleared the bar. Second is a follow up call about one or two specific answers, and the person who assembled the responses should be on that call rather than a salesperson. Third, and rarest, is a corrective action request with a deadline. That one is negotiable more often than not, because a prime would rather have a dated remediation plan than lose a supplier who can deliver parts.
Whatever comes back, keep the submitted version, the date, and who approved it. When the same prime sends the next questionnaire in eleven months, your answers need to be consistent with these or explain what changed. Related: a prime told you you’ll be dropped without CMMC covers what to do when the follow-up is an ultimatum, and your MSP says you’re already compliant covers verifying the answers your provider gives you before you sign them.
Next step
Before you answer a requirement by requirement questionnaire, produce the number and the worksheet behind it. The SPRS Score Calculator walks all 110 NIST SP 800-171 requirements using the DoD scoring methodology, and gives you an answer set you can copy into any prime’s form without contradicting yourself. It is free, and nothing you enter leaves your browser.
Frequently asked
Questions about this topic
Do I have to complete a prime’s cybersecurity questionnaire?
What if my SPRS score is low?
Can I say we are CMMC certified if we passed a readiness assessment?
How long should we take to respond?
Should our MSP fill this out?
The questionnaire asks for things our contract does not require. Do we have to comply?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI in Commercial Microsoft 365: What to Do Now →
- CUI Marked Drawings You Were Not Expecting? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Dropped Without CMMC? What a Prime Can Actually Do →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5