The New DoW CIO FAQ Just Dropped – What it means for you.

Posted November 28, 2025 by Philip Duplisey

The Office of the Chief Information Officer at the Department of War (DoW) has released a new FAQ that strengthens expectations around safeguarding CUI and maintaining compliance across the defense supply chain. For organizations working within the DIB, the message is simple: your subcontractors’ cybersecurity posture now matters as much as your own.

The FAQ clarifies that any subcontractor who stores, transmits, or processes CUI must meet the same NIST 800-171 standards as the prime. DoW also emphasizes the importance of audit-ready documentation—meaning SSPs, POA&Ms, MFA enforcement, logging, and evidence of control implementation must be current and defensible. Verbal assurances or outdated paperwork are no longer sufficient.

For our customers, this matters because the risks now extend beyond internal systems. A subcontractor with weak controls can jeopardize contract eligibility, delay awards, or trigger increased scrutiny. The FAQ makes it clear that primes are responsible for monitoring and validating subcontractor readiness, not simply trusting that vendors “should be compliant.”

As a subcontractor who handles CUI, now is the time to:

  • Confirm they understand the new DoW expectations

  • Request updated SSP and POA&M documentation

  • Ensure they can produce evidence for implemented controls

  • Verify that CUI is only flowing to entities prepared to safeguard it

Our team can help you assess subcontractor readiness, streamline due-diligence requests, and ensure both you and your vendors remain aligned with DoW and CMMC requirements. If you need support reviewing the FAQ or determining next steps, we’re here to help.