If a prime flowed a DFARS clause down to you, its security obligations became yours. Subcontractors deep in the defense supply chain inherit NIST 800-171 and DFARS 252.204-7012 requirements through their purchase orders - and those remain in force in 2026 even though third-party certification is paused.
Book a 15-minute review →How flow-down works: when a prime wins DoD work involving covered defense information, DFARS 252.204-7012 requires it to flow the safeguarding obligation down to subcontractors whose work touches that information. You don't have to hold the prime contract to be bound - your PO carries the clause.
What the suspension changed for you: the third-party C3PAO certification that was coming in Phase 2 is paused. What didn't change: your obligation to implement NIST 800-171, self-assess, and safeguard covered defense information if it flows to you. Ask your prime directly whether they're amending flow-down terms in light of the suspension - some are, many aren't.
The small-supplier reality is that you inherit the same requirements as a large prime, usually without the same staff or budget. That mismatch is exactly what the DoD cited when it paused Phase 2 - and it's why an affordable path to readiness matters most for firms your size.
MDRwatchdog is built for small suppliers: continuous monitoring that generates your self-assessment evidence, SSP, POA&M, and SPRS score at a fraction of consultant pricing. You stay ready for whatever your prime - or a future assessment - asks. Readiness and evidence, not certification, and not legal advice.
Subcontractors handling covered defense information inherit DFARS 252.204-7012 and NIST 800-171 obligations through flow-down. Third-party certification is paused as of July 2026, but the safeguarding and self-assessment obligations remain.
Check your purchase order and subcontract for the DFARS clauses, and ask your prime directly. If covered defense information reaches your systems, the safeguarding obligation generally applies.
Yes - generating evidence from monitoring you already run is far cheaper than consultant-led readiness. MDRwatchdog's setup runs $5,000-$15,000 with monitoring at $2,000-$5,000/month.
MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).