CMMC & DFARS CMMC & DFARS Prime questionnaire
Prime questionnaire guide

Your prime asked for your security posture — what they're actually requesting

When a prime sends you a security questionnaire, the request is rarely just a compliance checkbox. Here's what they're looking for and how to respond defensibly.

Defense prime contractors are required by DFARS 252.204-7012 to flow cybersecurity obligations down to subcontractors that handle covered defense information (CDI). The questionnaire in your inbox — whether it's a SIG Lite, a CAIQ, or a custom spreadsheet — is how your prime fulfills that obligation. Understanding what they're actually evaluating changes how you respond.

What triggers the request

Primes typically send security questionnaires at three points: during subcontract award, on an annual renewal cycle, and whenever a new system or program scope is added that touches CDI or controlled unclassified information (CUI). For many defense programs, these reviews have become mandatory due diligence — not optional.

The DFARS 252.204-7012 clause, which appears in most DoD prime contracts, requires primes to include the clause in subcontracts where subcontractors will process, store, or transmit CDI. That requirement creates a direct obligation for the prime to verify your security posture — and your questionnaire response is the primary evidence they collect.

What they're actually looking for

Most primes are not trying to determine whether you're certified to any specific standard. They're trying to establish three things:

  • Documentation exists. Do you have a System Security Plan? An incident response runbook? Written access control policies? Undocumented practices provide no assurance.
  • Your answers are traceable. Can every claim in the questionnaire be tied back to a specific policy, procedure, or prior assessment? Primes who get audited by their contracting officers need to be able to show the chain from their subcontractor's response to the underlying documentation.
  • A human reviewed and approved the responses. Questionnaire answers that clearly came from an automated tool without human review raise flags. Primes want to see that your security team is the accountable party, not a software system.

The DFARS flow-down obligation. Under DFARS 252.204-7012, prime contractors must ensure their subcontractors provide "adequate security" for covered defense information. Adequate security is defined by reference to NIST SP 800-171. When a prime sends you a questionnaire, they are documenting that they have verified your posture — and that documentation becomes part of their own compliance record.

Why "we're SOC 2 Type II" often isn't enough

SOC 2 is a meaningful certification for commercial software and cloud services, but it addresses a different control framework than NIST SP 800-171. A SOC 2 report tells your prime that an auditor reviewed your internal controls at a point in time. It does not tell them whether you have a System Security Plan, whether you have a plan of action and milestones (POA&M) for unmet controls, or how you handle DFARS-specific obligations like the 72-hour incident reporting requirement.

Primes who understand the DFARS landscape will ask about these specifically, often alongside or instead of standard framework questionnaires. Responding to DFARS-specific questions requires you to draw on different documentation than what your SOC 2 auditor reviewed.

How to respond defensibly

The most important principle: every answer in a DFARS questionnaire should trace back to a specific document your security team has approved. This means:

  • Answers about encryption practices should reference your data handling or security policy — the specific version and section.
  • Answers about incident response should reference your incident response runbook and the specific timeline commitment you've documented.
  • Answers about access controls should reference your access control policy or the relevant section of your System Security Plan.
  • Answers about your NIST SP 800-171 posture should reference your self-assessment results and your SPRS submission.

Responses that say "yes" without a source to back it up create two problems: they're difficult to defend if audited, and they may not accurately reflect what your documentation actually says. If your IR runbook commits to a 24-hour internal escalation and 72-hour prime notification, that's what your questionnaire response should say — not a vaguer "timely notification" answer from memory.

Before your response leaves, it should be reviewed by the person on your team who owns the documentation it cites. That person is best positioned to catch discrepancies and to stand behind the answer if your prime follows up with questions.

Reply Engine drafts from your documentation — every answer cited.

Upload your SSP, IR runbook, policies, and prior questionnaire responses. Reply Engine drafts answers to your prime's questionnaire from that corpus, cites the exact source for every response, and routes everything through your security team's approval queue before export. You send it; Reply Engine never submits on your behalf.

Get started