Your Raytheon Contract Says You Need CMMC: Here’s What That Actually Means

The Flow-Down Clause You Cannot Ignore

You run a 25-person machine shop in Tucson. Or a small engineering consultancy in Mesa. Or a staffing firm in Chandler that places cleared workers. You have been doing work for a defense prime contractor for years—maybe decades—and business has been good. Then a new contract comes through, and buried in the terms is a clause you have never seen before: a requirement to comply with CMMC.

That clause is not going away. It is appearing in more contracts, from more primes, across Arizona’s defense corridor. And it means your business needs to meet cybersecurity standards that were previously only expected of large defense companies.

This post explains what CMMC actually means for subcontractors, how to read the flow-down requirements in your contracts, what Controlled Unclassified Information (CUI) looks like in practice, and how small Arizona defense shops can start getting compliant without losing their minds or their margins.

Arizona’s Defense Supply Chain

Arizona is one of the most defense-dense states in the country. The major primes are here in force: Raytheon maintains a massive missile systems campus in Tucson, Boeing operates helicopter and satellite facilities in Mesa, and Northrop Grumman has significant operations in Chandler and the greater Phoenix area. General Dynamics, L3Harris, and dozens of other defense firms have Arizona footprints.

These primes do not build everything in-house. They depend on a network of subcontractors—small and mid-size businesses that provide components, engineering services, logistics, IT support, staffing, and specialized manufacturing. If your company is part of this supply chain, CMMC is headed your way.

The Department of Defense is phasing CMMC requirements into contracts through its rulemaking process. While the implementation timeline has seen adjustments, the direction is clear: subcontractors who handle CUI will need to demonstrate compliance to continue winning work.

What Is CMMC and Why Does It Exist?

The Cybersecurity Maturity Model Certification (CMMC) is the DoD’s framework for ensuring that defense contractors protect sensitive information. It was created because the existing system—where contractors self-attested to their compliance with NIST SP 800-171—was not working. Audits found that many contractors who claimed compliance had significant security gaps.

CMMC changes the game by requiring third-party assessments for contractors handling CUI. Instead of self-certification, an accredited assessor evaluates your cybersecurity controls and issues a certification at the appropriate level.

There are two primary levels that matter for most subcontractors:

CMMC Level 1: Covers basic cyber hygiene—17 practices drawn from FAR 52.204-21. This applies to contractors who handle Federal Contract Information (FCI) but not CUI. Self-assessment is allowed at Level 1.

CMMC Level 2: Covers the full 110 controls of NIST SP 800-171. This applies to contractors who handle CUI. Most Level 2 contractors will need a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO).

For a comprehensive overview, see our CMMC compliance basics guide for Arizona businesses.

Reading the Flow-Down Clause in Your Contract

Flow-down clauses are the mechanism by which prime contractors pass federal requirements to their subcontractors. When a prime like Raytheon holds a DoD contract that requires CMMC Level 2, they are obligated to flow that requirement down to subcontractors who will handle CUI as part of the work.

Here is what to look for in your contract or subcontract agreement:

DFARS 252.204-7012: This clause requires contractors to provide adequate security for covered defense information and report cyber incidents to the DoD within 72 hours. If your subcontract includes this clause, you are handling covered defense information and will need CMMC certification.

DFARS 252.204-7021: This is the CMMC-specific clause. It specifies the CMMC level required for the contract and requires contractors (and their subcontractors) to achieve that certification level before contract award.

DFARS 252.204-7020: This clause covers NIST SP 800-171 assessment requirements and ties into your SPRS score. Understanding how SPRS scores work is critical for contractors navigating the transition to CMMC.

If you see any of these clauses in your subcontract, CMMC compliance is not optional—it is a contractual requirement. Do not assume these clauses will not be enforced. Primes are under increasing pressure to verify subcontractor compliance, and they are starting to audit their supply chains.

What CUI Actually Looks Like in a Small Shop

One of the biggest sources of confusion for small subcontractors is understanding what CUI is and whether they handle it. The formal definition—information the government creates or possesses that requires safeguarding under law, regulation, or government-wide policy—is broad and somewhat abstract.

Here is what CUI looks like in practice for a typical Arizona defense subcontractor:

Technical Drawings and Specifications: If a prime sends you engineering drawings, CAD files, or technical specifications marked with CUI designations (or that contain technical data subject to export controls), that is CUI. You need to protect those files throughout their lifecycle—in your email, on your file servers, on the shop floor, and in your backups.

Manufacturing Process Information: Detailed manufacturing instructions, quality control procedures, and test results for defense components may be CUI, especially if they reveal capabilities or vulnerabilities of defense systems.

Contract and Pricing Information: Not all contract information is CUI, but certain procurement-sensitive details—particularly those related to cost and pricing data for defense acquisitions—may carry CUI markings.

Personnel Information: If you handle security clearance information, personnel records for cleared employees, or organizational charts for defense projects, these may be CUI.

Emails and Communications: CUI is not just in files. If a prime contractor emails you technical details about a defense project, that email contains CUI. If you discuss CUI over a video call, that communication needs to be protected. This is where many small shops have gaps—they protect their formal document storage but not their email or communication channels.

The key question is not whether information seems sensitive to you, but whether the prime contractor or the government has designated it as CUI. Look for CUI markings on documents, ask your prime about what information qualifies, and when in doubt, treat it as CUI.

The 25-Person Shop Reality

CMMC was designed with large defense contractors in mind, but most of Arizona’s defense subcontractors are small businesses. A 25-person manufacturing shop does not have a Chief Information Security Officer, a dedicated IT staff, or a six-figure cybersecurity budget. Yet the compliance requirements are the same.

Here is a realistic look at what CMMC compliance involves for a small subcontractor:

Scoping Your CUI Environment

The first step is identifying where CUI lives in your organization. This is called scoping, and it directly affects the cost and complexity of compliance. Every system, device, and person that touches CUI falls within your CMMC assessment boundary.

Smart scoping can dramatically reduce your compliance burden. If you can isolate CUI processing to a small number of systems—a dedicated workstation, a separate network segment, a specific file share—you shrink the boundary of what needs to meet CMMC controls. This is the single most impactful thing a small shop can do to manage compliance costs.

The 110 Controls

CMMC Level 2 maps to the 110 security requirements in NIST SP 800-171. These cover 14 families of controls, including access control, audit and accountability, configuration management, incident response, and system and communications protection.

Some of these controls are straightforward—require passwords, install updates, run antivirus. Others are more complex—implement multi-factor authentication, maintain audit logs, establish an incident response plan, encrypt CUI at rest and in transit. A small shop will likely need outside help to implement and document all 110 controls.

Documentation Requirements

CMMC is not just about having controls in place—it is about proving you have them. This means written policies, procedures, and system security plans. You need to document how each control is implemented, who is responsible for it, and how you monitor its effectiveness.

For a 25-person shop, this documentation burden can feel overwhelming. But it does not have to be custom-written from scratch. Working with an IT provider experienced in compliance for small businesses can accelerate the documentation process significantly.

Cost Expectations

Total cost for a small subcontractor to achieve CMMC Level 2 readiness typically ranges from $50,000 to $150,000, depending on your starting point and the scope of CUI in your environment. This includes technology investments (hardware, software, cloud services), consulting and implementation, documentation development, and the assessment itself.

Some costs are ongoing—managed security services, continuous monitoring, annual assessments, and employee training are not one-time expenses. Budget for recurring costs of $1,500 to $5,000 per month depending on your environment’s size and complexity.

This is a significant investment for a small business. But consider the alternative: losing your defense contracts. If your prime requires CMMC and you cannot comply, they will find a subcontractor who can.

Getting Started: A Practical Path Forward

If your contract says you need CMMC, here is a practical sequence for a small Arizona subcontractor:

1. Identify your CUI. Work with your prime contractor to understand exactly what information you handle that qualifies as CUI. Get this in writing.

2. Scope your environment. Map every system, device, network, and person that touches CUI. Look for opportunities to reduce this scope.

3. Assess your gaps. Compare your current security posture against the NIST SP 800-171 controls. This gap assessment tells you what you need to implement.

4. Build your Plan of Action and Milestones (POA&M). Document the gaps and your timeline for closing them. This becomes your roadmap to compliance.

5. Implement controls. Deploy the technical controls, write the policies, configure the systems. This is the heavy lifting, and it is where an experienced IT partner adds the most value.

6. Document everything. Write your System Security Plan (SSP), maintain your POA&M, and create policies for each control family.

7. Prepare for assessment. Once your controls are in place and documented, engage a C3PAO for your official CMMC assessment.

Do Not Wait for the Deadline

The biggest mistake Arizona subcontractors make is waiting until CMMC is explicitly required in their next contract. By then, you are in a race against a deadline with limited availability of assessors and consultants. The shops that start now will be ready when the requirement hits—and they will have a competitive advantage over those who are scrambling.

Asteroid IT provides CMMC compliance support for Arizona defense subcontractors. We work with small and mid-size businesses across the Valley and Southern Arizona to scope CUI environments, implement NIST SP 800-171 controls, and prepare for third-party assessments. We understand the reality of small-shop budgets and build compliance programs that are thorough without being bloated.

Contact us for a free CMMC readiness consultation to find out where you stand and what it will take to get compliant.

Scroll to Top