Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

Cybersecurity Questionnaire From Your Prime? Do This

A prime’s cybersecurity questionnaire usually arrives as a spreadsheet attached to an email from somebody in supply chain, with a due date about nine days out and no explanation. Sometimes it is 30 questions. Sometimes it is 400. Either way, the thing to understand before you type anything into it is that this document is a written representation about your company’s security posture, and it will be read later by people who are not the person who sent it. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.

Why cybersecurity questionnaire volume went up in 2026

Cybersecurity questionnaire volume went up after July 13, 2026, not down. When the Department of War suspended the CMMC Phase 2 assessment requirements, primes lost the thing they were planning to use as a clean pass or fail signal on suppliers, which was a certificate issued by somebody else. The obligation to manage supply chain risk did not go away with it, so they went back to asking suppliers directly.

Underneath that, DFARS 252.204-7020(d) requires a prime to confirm that its subcontractors have a current NIST SP 800-171 assessment posted in SPRS before awarding a subcontract. That is a real, unsuspended obligation on them. Many questionnaires are a prime discharging that duty and gathering commercial risk information in the same document, which is why a single form will ask for your SPRS score on one row and your cyber insurance limits on the next.

Identify which kind of cybersecurity questionnaire you received

The right response depends on what you are actually holding. Five kinds of cybersecurity questionnaire show up in the defense supply base, and they are not answered the same way.

TypeHow to recognize itWhat it really wants
SPRS verificationShort. Asks for CAGE code, score, assessment date, scope.Proof the prime met its 7020(d) obligation. Answer from your SPRS record verbatim.
NIST SP 800-171 requirement by requirement110 rows, one per requirement, with implemented / partial / not implemented columns.Your self assessment. It has to match your System Security Plan and your posted score. A mismatch is the real risk here.
Prime’s own supplier security standardBranded, and it mixes 800-171 with the prime’s own internal policy. Multifactor everywhere, endpoint detection, monitoring around the clock, sometimes ISO 27001.Contract terms, not regulation. Negotiable. Some of it may exceed what your contract requires.
Portal based, such as Exostar, a supplier risk platform, or SIG LiteYou get a login, not a file.Same content, but answers persist, get scored, and are visible to multiple primes. Higher stakes.
Incident drivenArrives out of cycle, asks about specific technologies or a specific date range.Something happened somewhere in the supply chain. Answer narrowly and precisely, and bring counsel in before you send it.

Three lookups before you answer a single question

  1. Pull your actual SPRS record. Not what you remember posting. Log into PIEE, look at the score, the assessment date, the assessment scope description, and the confidence level. Every answer you give has to be consistent with what is already sitting in that record, because the prime can see it too.
  2. Find the clauses in the contract this questionnaire relates to. Is 252.204-7012 in it? 7019? 7020? FAR 52.204-21 only? Your obligations differ enormously depending on the answer, and so does what you owe this prime. If you are not sure what each one triggers, read DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers.
  3. Confirm whether you hold CUI or only FCI. If everything you receive from this prime is FCI, you are at FAR 52.204-21 and fifteen requirements, and half the questionnaire may not apply to you. Say so explicitly rather than answering no down a column of controls you were never obligated to implement.

Budget a day for these. Companies that skip them end up amending their answers a month later, which is worse than being slow.

How to answer a cybersecurity questionnaire without creating liability

A completed cybersecurity questionnaire becomes part of the record. If a prime relies on it, and later there is an incident, a dispute or a False Claims Act inquiry, this document is evidence of what you told them. Four rules hold up well:

  • Answer for the state of the system today, not the state you are working toward. Planned for the fourth quarter is not implemented. A control that is eighty percent deployed is not implemented.
  • Use partial and not implemented freely, with a POA&M date. Primes are used to seeing gaps. What they are not used to seeing is a supplier who claims perfection and then cannot produce a System Security Plan.
  • Never write the word compliant on its own. Compliant with what, assessed by whom, as of when, across which boundary. Write that instead.
  • Have one owner. One person assembles the answers and one senior person reviews before it goes out. Questionnaires filled in by three departments contradict themselves, and contradictions are what get escalated.

The five questions people get wrong

Are you CMMC certified? The accurate answer today is that CMMC Level 2 certification assessments have been suspended since July 13, 2026, so no certificates are currently being issued. State your self assessment score and its date instead. Do not answer yes because a consultant told you that you would pass.

What is your SPRS score? Give the number, the assessment date, and the scope it covers. If your posted score covers a boundary that is narrower than the work this prime is sending you, say that in the same sentence. Discovering it later looks like concealment.

Do you have a System Security Plan? Answer yes only if a document exists that describes your actual environment, its boundary and how each requirement is met. A template with your logo on the cover is a no.

Is CUI encrypted using FIPS validated cryptography? This question is about validated modules, not about whether you use encryption. Note also that FIPS 140-2 certificates move to historical status on September 21, 2026, so anything you are relying on should be checked against the CMVP list before you answer.

Do you use a cloud service that meets DFARS 252.204-7012(b)(2)(ii)(D)? This is the one that catches manufacturers. Commercial Microsoft 365 was not built to meet the 7012 cloud conditions. If your CUI sits in a commercial tenant, the honest answer is no, with a remediation plan attached. The options are laid out in your CUI is sitting in commercial Microsoft 365.

What to send back with the cybersecurity questionnaire, and what to keep

SendDo not send
The completed questionnaireYour full System Security Plan
A one page cover summary with score, assessment date, boundary and POA&M statusNetwork diagrams and IP addressing
A POA&M extract showing gaps with owners and datesVulnerability scan output or pen test reports
Named point of contact for security questionsConfiguration exports or screenshots showing credentials

Your SSP is a roadmap to your weaknesses. Primes almost never need it, and the ones who ask usually accept a summary plus an offer to walk it in a call. If a prime insists on the full document, get a written commitment on how it will be stored and who sees it.

The cover summary that changes the conversation

Four short paragraphs, attached to the cybersecurity questionnaire:

  1. Scope. Which part of your business handles their data, and what the boundary is.
  2. Current posture. Posted SPRS score, assessment date, and what methodology produced it.
  3. Gaps and plan. The three or four largest open items, each with an owner and a target date.
  4. Status of CMMC. One sentence acknowledging the Phase 2 suspension and stating that you are maintaining 800-171 implementation and your annual affirmation regardless.

A supplier who writes that page is treated differently from one who returns a spreadsheet with every box ticked green. The first looks like a company that knows its own environment. The second looks like a company that has not looked.

After you send it

Expect one of three outcomes. Most common is silence, which means you cleared the bar. Second is a follow up call about one or two specific answers, and the person who assembled the responses should be on that call rather than a salesperson. Third, and rarest, is a corrective action request with a deadline. That one is negotiable more often than not, because a prime would rather have a dated remediation plan than lose a supplier who can deliver parts.

Whatever comes back, keep the submitted version, the date, and who approved it. When the same prime sends the next questionnaire in eleven months, your answers need to be consistent with these or explain what changed. Related: a prime told you you’ll be dropped without CMMC covers what to do when the follow-up is an ultimatum, and your MSP says you’re already compliant covers verifying the answers your provider gives you before you sign them.

Next step

Before you answer a requirement by requirement questionnaire, produce the number and the worksheet behind it. The SPRS Score Calculator walks all 110 NIST SP 800-171 requirements using the DoD scoring methodology, and gives you an answer set you can copy into any prime’s form without contradicting yourself. It is free, and nothing you enter leaves your browser.

Frequently asked

Questions about this topic

Do I have to complete a prime’s cybersecurity questionnaire?
There is rarely a regulation compelling you to fill out a specific prime’s form. There is usually a business consequence for declining, and if your subcontract flows down DFARS 252.204-7020 the prime has an obligation to verify your SPRS posting. In practice you complete it, but you complete it on your terms as to what supporting material leaves your building.
What if my SPRS score is low?
Report it accurately. DFARS 252.204-7019 conditions award eligibility on having a current assessment posted, not on the score being high. A low score with a credible POA&M is a normal supplier position in 2026. An inflated score you cannot evidence is the version that creates False Claims Act exposure.
Can I say we are CMMC certified if we passed a readiness assessment?
No. A readiness or gap assessment performed by a consultant is not a certification, and no CMMC Level 2 certificates are being issued while Phase 2 assessments are suspended. Describe what was actually done: who assessed you, against what, when, and what the result was.
How long should we take to respond?
Ask for the deadline you need. Two to three weeks for a requirement by requirement questionnaire is reasonable and is granted more often than people expect. Requesting time reads as diligence. Returning a fast questionnaire full of unsupportable green checkmarks reads as risk.
Should our MSP fill this out?
Your MSP should supply the technical facts. Your company answers the questionnaire, and someone with authority signs it. The obligation sits with the contract holder, and an MSP’s assurance is not a defense if an answer turns out to be wrong.
The questionnaire asks for things our contract does not require. Do we have to comply?
Not automatically. Distinguish regulatory requirements from the prime’s own supplier standard. Answer the regulatory portion straight. For the items specific to that prime that exceed your contract, answer accurately and, where the requirement is expensive and not contractually flowed down, ask which contract clause it derives from. Sometimes the answer is that it does not, and it becomes negotiable. See Flowdown: Which Clauses You Must Pass to Your Subcontractors.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents