Most small suppliers do not get breached through some exotic zero day. They get breached through a connection someone else designed: a portal login, a shared mailbox, a file transfer tool, a standing remote session that a larger partner set up years ago and nobody has reviewed since.
That is the uncomfortable part. The access path was often created by the prime or the customer, for the prime's convenience, and the consequences land on the smaller party. The contract flows obligations downhill. The connection flows risk in both directions.
What does the door the prime left open actually mean?
Think about how work really moves between a prime and a small supplier. There is usually a supplier portal with a login. There is often a virtual private network tunnel or a remote access tool so engineers can reach a shared environment. There is almost always an email thread carrying drawings, specifications and scope, some of which may be controlled unclassified information. Sometimes there is a shared drive or a managed file transfer link that never expires.
Every one of those is a door. The prime built most of them. But the credentials sit on your laptops, in your browsers, in your password manager, or worse, in a spreadsheet. If an attacker phishes one of your people, they inherit the prime's trust in you.
Ask yourself honestly: if you had to list every external system your team can log into on behalf of a customer today, could you produce that list this afternoon? Who would you have to call to finish it?
Why does the contract push the obligation down to you?
Because it is written to. Under DFARS 252.204-7012, contractors handling covered defense information are required to implement the security requirements in NIST SP 800-171, and the clause is designed to flow down to subcontractors when covered defense information is involved in the subcontracted work. The Cybersecurity Maturity Model Certification program rule at 32 CFR part 170 similarly contemplates requirements reaching subcontractors depending on the information they handle.
The practical effect is that a prime can hand you a connection and a clause in the same week. The connection makes their life easier. The clause makes the security posture your legal problem.
That is not a reason to be bitter about it. It is a reason to be specific. If you are being asked to accept access, you are entitled to ask how that access is configured, who else uses it, and what happens to it when your project ends.
Does the pause in CMMC implementation mean you can wait?
This is where a lot of small suppliers are getting bad advice right now. Federal News Network reported in August 2026 that CMMC implementation has been paused, and that contractors who certified early are now asking what that first mover decision bought them. The details of what the pause covers and how long it lasts are not settled, and anyone telling you they know the final shape of it is guessing.
Here is what has not paused. DFARS 252.204-7012 has been in contracts for years. NIST SP 800-171 did not stop being the underlying control set. And an attacker with your portal credentials does not check the Federal Register first.
So the honest framing is this: certification timing is uncertain, and the underlying obligation is not. If you were planning to start work only when a certification deadline forced you, what is your plan for the twelve months in between?
What do water systems and rural utilities have to do with a defense sub?
More than it looks. In early August 2026, New York State awarded cybersecurity grants through its SECURE program to well over a hundred local water systems. The Department of Energy runs a Rural and Municipal Utility Advances Cybersecurity program that pairs grants with technical assistance for small and rural utilities.
The pattern is the same as yours. Small organizations, embedded in a larger critical system, connected to bigger partners, with no full time security leader. Public programs increasingly recognize that the smallest node in a chain cannot solve this alone, so they pair help with hands on assistance rather than handing over a checklist and walking away.
If states and federal energy programs have accepted that small operators need in-kind help rather than another list of requirements, why would a small defense supplier be expected to figure it out unaided?
Get a Funded Read on the Access Your Partners Hold
If you are a small business, nonprofit or defense supplier, our in-kind gap assessment grants give you a clear, funded picture of where you stand -- we perform the assessment for you rather than handing over cash.
Apply for the Gap Assessment Grant →What should you close on your own side first?
Start with the things that are entirely within your control and do not require the prime to answer an email.
- Inventory external access. Every portal, tunnel, shared drive and third party tool your staff touch on behalf of a customer, and the name of the human responsible for each.
- Kill orphaned accounts. Former employees, former contractors, the intern from two summers ago. Offboarding is the single most common gap we see in small teams, and it is not a technical problem, it is a checklist problem.
- Turn on multi factor authentication everywhere it is offered, especially on email. Phishing against a small supplier is usually the first move, not the last.
- Write down what happens when something goes wrong. Not a binder. A page. Who calls the prime, who calls the insurer, who preserves the laptop instead of wiping it.
Which of those four could your team finish before the end of next week?
What can you ask your prime without straining the relationship?
Frame it as protecting their program, because that is exactly what it is. Reasonable questions include: which of your systems does my team have standing access to, and can that access be time limited to the period of performance? Is our access reviewed on a schedule, and who reviews it? If we detect a compromise on our side, who is the named contact on yours, and how fast do you expect to hear from us? Does the data you are sending us actually require the handling you are asking for, or has it been over marked out of caution?
Good primes answer these. Some will be relieved you asked, because they are being audited on supply chain assurance too. The ones who cannot answer have told you something useful about the door they left open.
Frequently Asked Questions
If a breach starts through my prime's portal, whose responsibility is it?
It depends on where the compromise actually occurred and what the contract says, so there is no universal answer. In practice, if attackers used credentials held by your organization, you will be expected to demonstrate that you protected those credentials appropriately. This is why written access inventories and offboarding records matter well before an incident, not after.
Does DFARS 252.204-7012 apply to me if I am a second tier subcontractor?
The clause is written to flow down to subcontractors when the subcontracted work involves covered defense information. Tier alone does not determine it. What determines it is whether the information you handle falls within scope, which is why reading your actual purchase order language matters more than assuming your size exempts you.
CMMC implementation is reportedly paused. Should I stop preparing?
No. Reporting in August 2026 indicates a pause in implementation, but the scope and duration are not settled. The NIST SP 800-171 requirements underlying the program have been referenced in defense contracts for years and did not disappear with the pause. Preparation work such as access inventories, multi factor authentication and offboarding retains its value regardless of what happens to certification timing.
What is the most common way small suppliers actually get compromised?
Credential based attacks against email and remote access remain the dominant entry path reported by federal cybersecurity agencies. For small suppliers specifically, the aggravating factor is shared access to partner systems, which turns one phished mailbox into a path toward a much larger organization. That is what makes small suppliers attractive targets rather than incidental ones.
We have no security staff at all. Where does a team like ours begin?
Begin with inventory and identity. Know every external system your people can reach, remove access for anyone who has left, and turn on multi factor authentication on email first. These steps require organization and follow through more than technical depth, and they close the paths attackers use most often.
Do grant style programs exist for small organizations that cannot hire a security lead?
Yes, in several forms and at several levels of government. New York's SECURE awards to local water systems and the Department of Energy's rural and municipal utility program both pair assistance with hands on technical help for small operators. Cyber Grants Alliance follows the same logic for small businesses, nonprofits and small defense suppliers, providing gap assessment help in kind rather than as funding.
Sources: Federal News Network, CMMC implementation on hold, August 2026; Govly, New York cybersecurity grants for water systems, August 2026; U.S. Department of Energy, Rural and Municipal Utility Advances Cybersecurity program; DFARS 252.204-7012; NIST SP 800-171; 32 CFR part 170, CMMC Program.
