CMMC20X
Your part in the security system

Give suppliers enough contract and mission context to scope the work.

A supplier cannot scope the work correctly when a flowdown omits the CUI, system boundary, mission consequence, or shared service behind it.

The position

Tell the supplier what the contract actually protects.

A prime can enforce its contract. It should not demand a broad security claim after giving the supplier vague scope or data context.

Security responsibility

What you own. What others need from you.

The six roles perform different work and hold different authority. These are the facts this role has to supply, receive, and keep current.

Owns
The prime is responsible for clearly passing down the contract’s data, security, mission, and shared-service context.
Produces
Clear data-handling instructions, responsibility boundaries, evidence for shared services, escalation contacts, and feedback on supplier changes.
Receives
Supplier scope and evidence records, provider dependencies, authorized assessment findings, and notices of changes that affect the contract or mission.
Rechecks when
Update the context when program criticality, information sensitivity, contract requirements, shared systems, supplier roles, or known threats change.
See how all six roles work together
In practice

Three ways to apply it.

  1. 01

    Tell the supplier what information and mission the requirement protects so it can scope the work correctly.

  2. 02

    Reuse evidence for shared services when justified, while showing what each supplier still has to do.

  3. 03

    Accept a common evidence record where possible instead of imposing another proprietary questionnaire.

Challenge the model

What does this role page miss?

Bring a real or synthetic handoff, conflict, responsibility boundary, or decision this model needs to handle.

Start a technical discussion