HomeArticles › Defense
Defense

How Subcontractors Work on US Military Shipbuilding Programs: Process, Contract Types and Standard Terms

Share
How Subcontractors Work on US Military Shipbuilding Programs: Process, Contract Types and Standard Terms

How US Navy shipbuilding subcontractors qualify, contract, and manage flow-down clauses, cybersecurity and supplier terms.

Becoming a subcontractor on a U.S. military shipbuilding program is not simply a matter of registering as a vendor and responding to a purchase order. A supplier normally passes through several layers of commercial, technical, quality, cybersecurity, security and contractual qualification before it can perform controlled work for a major shipbuilder.

The important distinction is between being legally eligible to do business with the U.S. Government and being qualified and approved by a particular shipbuilding prime contractor. A company can satisfy the first requirement and still have a long way to go before a prime such as General Dynamics Electric Boat or HII will approve it for a particular product or service. (For how the prime's own contract with the Navy is typically structured, see our article on Standard Contracts in Ship Newbuilding and Repair: commercial forms like BIMCO NEWBUILDCON have no real equivalent on the defense side; government contracts run on FAR/DFARS instead.)

Becoming an Eligible Supplier

The federal starting point is normally the company's identity and registration information. A company seeking to participate directly in federal contracting generally establishes an entity registration in SAM.gov, receiving a Unique Entity ID (UEI): a 12-character code that replaced the old DUNS number in April 2022. SAM registration contains information including the company's NAICS classifications and business-size information. CAGE identification is also important in the defense environment; DCSA specifically identifies the CAGE code as part of the facility-clearance process. SAM registration itself is renewed annually.

There is an important practical qualification here: a company that is only going to work as a subcontractor to a prime does not necessarily have exactly the same federal-registration obligations as a company receiving a prime federal award. Nevertheless, major defense primes commonly require extensive corporate information in their own supplier-registration systems, and having the appropriate SAM, UEI and CAGE information is an important part of entering the U.S. defense supply chain.

The next layer is the prime contractor's supplier qualification process. This normally covers company history, financial and operational capability, relevant experience, manufacturing capacity, quality system, key personnel, insurance, safety performance, cybersecurity, export-control status and the company's ability to meet the technical specification.

Quality requirements are particularly important in naval shipbuilding. ISO 9001 is a common baseline quality-management certification, but it should not be treated as a universal Navy subcontractor requirement. A prime can impose additional quality requirements through its purchase order, specification, supplier-quality manual or program-specific requirements. For aerospace-related work, AS9100 may be relevant, but it is not automatically required merely because a supplier is working on a Navy ship.

Naval shipbuilding can add another layer of control. NAVSEA's SUPSHIP organizations provide government oversight of shipbuilding contracts, including quality assurance, engineering and contract administration. NAVSEA material also describes government source inspection, factory acceptance testing and first-article testing for appropriate equipment.

In practice, therefore, a supplier's quality system may be only the starting point. The purchase order can contain specific inspection points, material traceability, welding or nondestructive-testing requirements, configuration-control requirements, records-retention rules, corrective-action procedures and requirements for government or prime-contractor inspection.

General Dynamics Electric Boat provides a useful, publicly visible example of how detailed this supplier layer can become. Its supplier website publishes supplier registration forms, a supplier quality questionnaire, supplier corrective-action procedures, a quality specification (EB Spec 2678, covering requirements beyond baseline standards like ISO 9001:2015), and a full set of numbered purchase-order standard clauses. It also states that awards are generally made through competitive bidding where practical, and that suppliers are required to transmit applicable requirements down to their own sub-tier suppliers in turn.

Cybersecurity Is Now Part of Supplier Qualification

Cybersecurity should be treated as a contractual qualification issue rather than simply an IT certification exercise.

The Department of Defense's Cybersecurity Maturity Model Certification (CMMC) framework uses three levels, with the required level depending on the information involved in contract performance. The CMMC final rule took effect in December 2024, and the related DFARS rule enabling contracting officers to insert CMMC clauses into solicitations took effect in November 2025. Under DFARS 252.204-7021, the contract identifies the required level, and the contractor must maintain the required CMMC status for information systems processing, storing or transmitting Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The clause also requires the prime to flow the appropriate CMMC requirement to qualifying subcontractors.

The important practical point for a supplier is that CMMC level is driven by the information handled by the supplier, not simply by the fact that the supplier works for the Navy. A supplier manufacturing a physical component with no FCI/CUI environment may face a very different cybersecurity requirement from an engineering subcontractor receiving controlled technical information.

Level 1 generally concerns protection of FCI, and can be self-assessed. Level 2 addresses the more substantial CUI protection requirements and may require third-party assessment. Level 3 is associated with the highest-risk CUI environments and additional government assessment through the Defense Industrial Base Cybersecurity Assessment Center. The exact requirement must be determined from the applicable solicitation, contract and information flow, and it's worth noting this is a genuinely moving target: in July 2026 the Department suspended the rollout of Phase 2 and later CMMC milestones, though the underlying rule and DFARS 252.204-7021 itself remain in force. A supplier should check the current implementation status rather than assume a fixed timeline.

Even below CMMC-specific requirements, FAR 52.204-21 establishes basic safeguarding requirements for covered contractor information systems handling Federal Contract Information, and expressly requires the substance of the clause to be included in qualifying subcontracts. Separately, DFARS 252.204-7012 addresses safeguarding of Controlled Unclassified Information specifically and requires reporting any cyber incident to the DoD within 72 hours of discovery.

Classified Work: FCL and PCL Are a Separate System

Cybersecurity certification should not be confused with a security clearance.

If a subcontractor needs access to classified information, it may require a Facility Clearance (FCL), while employees who need access normally require appropriate Personnel Security Clearances (PCLs).

The FCL concerns the organization and facility. DCSA describes it as an administrative determination that a facility is eligible to access classified information at a specified level. The process involves sponsorship, security agreements, business-structure information, key management personnel and consideration of Foreign Ownership, Control or Influence (FOCI): assessed in part through a company's SF-328 disclosure. A CAGE code is required early in the FCL process; DCSA notes that not having one on hand can delay or even stall the process.

A company does not normally obtain an FCL simply because it wants one. There must be a legitimate need connected with classified work. In the industrial-security system, the government ultimately controls the clearance decision. A contractor's Facility Security Officer (FSO) manages the company's security program and coordinates personnel-clearance processing, but the contractor does not itself grant or revoke PCLs.

This is one reason defense subcontracting differs substantially from ordinary commercial vendor qualification. A supplier may be commercially approved by a shipbuilder while still being unable to receive particular classified drawings, data or work until the necessary security arrangements are in place. (For a deeper look at exactly why a prime sponsoring an uncleared subcontractor still doesn't shortcut this timeline, see our article on Flow-Down and Firewall.)

How a Company Actually Gets Selected

Registration does not normally cause a Navy shipbuilder to start sending RFQs. Supplier selection is driven by the prime contractor's procurement organization and program requirements, typically following a route like this:

  1. The prime identifies a required component, service or work package.
  2. Procurement identifies potential qualified sources, often from the prime's existing supplier database.
  3. Prospective suppliers register through the prime's own supplier portal.
  4. The prime issues an RFQ or e-sourcing event.
  5. Suppliers submit technical and commercial proposals.
  6. Procurement, engineering, quality and sometimes program/security personnel evaluate the supplier.
  7. The selected supplier is onboarded and receives a purchase order or subcontract.

Electric Boat, for example, operates a dedicated supplier environment covering prospective suppliers, its enterprise supplier-management portal, RFQ/bidding information, quality, security, forms and standard clauses: all published for suppliers to review before they bid.

Small-business participation is another route into the supply chain. FAR 52.219-8 establishes the federal policy of providing small businesses and designated socioeconomic categories the maximum practicable opportunity to participate in federal contracts and subcontracts. For qualifying larger prime contracts with subcontracting possibilities above set dollar thresholds, FAR 52.219-9 requires the prime to maintain a formal Small Business Subcontracting Plan, and to flow the same utilization obligation down to its own larger subcontractors in turn.

Mentor-protégé arrangements can also create structured opportunities for smaller companies. The important distinction is that these programs facilitate access and development; they do not automatically guarantee a subcontract award.

The Subcontract Itself: What Form Does the Relationship Take?

The commercial instrument depends on what is being purchased and how well the requirement can be defined.

Fixed-price subcontracts

For a defined hardware item, fabrication package or clearly specified service, fixed-price contracting is common. Under a firm-fixed-price arrangement, the agreed price generally does not change merely because the supplier's actual cost is higher than expected: that transfers substantial cost and productivity risk to the subcontractor. For the supplier, the attraction is commercial certainty if the scope is stable; the downside is exposure to estimating errors, material-price changes, rework and productivity problems unless the contract provides appropriate adjustment mechanisms.

Cost-reimbursement subcontracts

Cost-reimbursement arrangements pay allowable incurred costs under the contractual rules, normally subject to an estimated cost and applicable ceiling. They are used when the requirement cannot reasonably be defined or priced with sufficient certainty for fixed-price contracting. In shipbuilding, this structure is more naturally associated with uncertain engineering, development or technical-support work than with a mature, repeatable manufactured component: it places more cost risk on the customer but creates considerably more accounting, audit and cost-control administration.

Time-and-materials

Time-and-materials arrangements pay specified labor categories at fixed hourly rates plus actual allowable material costs. FAR 16.601 specifically describes this structure and limits its use to situations where the extent or duration of the work cannot be estimated accurately enough for another contract type. For a subcontractor, T&M can reduce the risk of unknown labor quantities, but it also brings requirements for timekeeping, labor-category control, supporting records and customer approval.

Purchase orders versus formal subcontracts

The distinction is partly commercial rather than simply one of document length. A purchase order (PO) is commonly used for a defined purchase of goods or services, and may incorporate extensive standard terms, specifications, drawings and flow-down clauses by reference. A formal subcontract agreement is more likely where the relationship involves substantial engineering, services, continuing obligations, complex intellectual-property provisions, milestones, changes, government-furnished property or significant contractual risk.

In defense shipbuilding, the practical reality can matter more than the title on the document: a PO can contain a substantial body of contractual obligations. Electric Boat, again, publishes extensive PO standard clauses and terms and conditions for its suppliers rather than treating a purchase order as a one-page form.

BOAs and BPAs

A Basic Ordering Agreement (BOA) establishes terms and mechanisms for future orders when recurring requirements are expected but exact quantities or prices may not yet be known: FAR 16.703 explicitly states that a BOA is not itself a contract; individual orders create the contractual commitment. A Blanket Purchase Agreement (BPA) is a simplified mechanism for repetitive purchases from qualified sources. These structures reduce repetitive commercial negotiation, but they do not remove the need to comply with the terms applicable to each individual order.

Flow-Down Clauses: How Government Requirements Reach the Subcontractor

A flow-down clause is the contractual mechanism by which an obligation contained in the prime contract is incorporated into a subcontract. The logic is straightforward: the Navy contracts with the prime shipbuilder, the shipbuilder buys equipment and services from suppliers, and some government requirements must continue down the supply chain. The prime therefore incorporates applicable requirements into its purchase orders and subcontracts.

Flow-down is not unlimited. FAR 44.402 specifically states that subcontractors supplying commercial products and services should not generally be burdened with every clause in the prime contract, only clauses required by law, executive order, or consistent with customary commercial practice are to be flowed down, and FAR 52.244-6 is the actual clause that implements this limitation in practice.

Examples of clauses that commonly appear in a defense supply chain include:

  • FAR 52.204-21: Basic Safeguarding of Covered Contractor Information Systems. Flows down whenever a subcontractor may have Federal Contract Information residing in or transiting through its information system.
  • DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting.
  • DFARS 252.204-7021: Contractor Compliance With the CMMC Level Requirements, including subcontractor/supplier flow-down where applicable.
  • FAR 52.219-8, Utilization of Small Business Concerns.
  • FAR 52.222-50, Combating Trafficking in Persons, which flows down to all subcontracts, with additional compliance-plan obligations above certain dollar thresholds for work performed outside the United States.
  • DFARS 252.225-7001: Buy American and Balance of Payments Program. Whether this applies depends on the specific procurement; it is not a universal requirement for every shipbuilding purchase.
  • DFARS 252.225-7048: Export-Controlled Items, covering items subject to the EAR or ITAR, with its own explicit subcontract flow-down requirement.

The exact flow-down list must be taken from the actual prime contract, purchase order and applicable prime-contractor terms. A supplier should never assume a clause applies merely because it is commonly seen elsewhere in defense contracting. It is also more accurate to say that the prime remains contractually responsible to the Government for performance of its prime contract, rather than to say the prime is automatically liable for every subcontractor violation: the prime must actively manage and enforce applicable subcontract requirements, while the subcontractor carries its own contractual obligations to the prime.

What Is Inside a Typical Defense Supplier Terms Document?

A defense shipbuilding supplier document is usually much more than a simple purchasing page. A typical composite structure, not a claim that any one named shipbuilder uses these exact headings, will contain provisions covering:

  • definitions and interpretation;
  • order acceptance and precedence of documents;
  • incorporation of specifications and technical requirements;
  • applicable FAR/DFARS and prime-contract flow-down clauses;
  • quality-management and inspection requirements;
  • source inspection, testing and government/prime access rights;
  • configuration management and engineering changes;
  • delivery dates, milestones and notification of delay;
  • packaging, shipping and marking;
  • acceptance and rejection, and nonconforming material/corrective action;
  • warranties;
  • changes and equitable adjustments;
  • payment, invoicing, and records retention/audit rights;
  • intellectual property, technical data and data rights;
  • confidentiality, cybersecurity and controlled information;
  • export-control requirements;
  • government-furnished property, where applicable;
  • subcontracting and restrictions on further subcontracting;
  • compliance with law and ethical-conduct requirements;
  • indemnification and insurance;
  • termination for convenience, termination for default, and suspension/stop-work;
  • dispute resolution, governing law, and miscellaneous legal provisions.

There are, however, public examples demonstrating the underlying structure in practice. General Dynamics Electric Boat publishes separate commercial and non-commercial terms, additional addenda, numbered standard purchase-order clauses and supplier-quality material on its public supplier site. That page explicitly tells suppliers that exceptions to terms and conditions must be submitted with the bid: illustrating how the contractual terms are part of the RFQ process itself, not something negotiated only after delivery begins. Electric Boat also publishes supplier-registration forms, quality questionnaires and corrective-action forms, showing how commercial qualification, quality qualification and contractual compliance operate together in one place.

Other major shipbuilders maintain their own supplier-management and compliance programs, but the exact contents and availability of their current standard terms should be verified against each company's current supplier portal before attributing particular clauses or headings to that company. It would be unsafe to assume that a generic list of defense-industry clauses is an exact reproduction of the current standard terms used by HII, Austal USA, Fincantieri Marinette Marine or Bath Iron Works. (For how prime-level procurement of major equipment fits into the wider schedule, see our article on Procurement and Supply Chain for Major Ship Equipment.)

The practical lesson for a prospective supplier is that qualification and contracting are two different gates. A company may have the necessary registration, ISO certification, manufacturing capability and commercial references and still fail to qualify for a particular naval component because of cybersecurity, security-clearance, technical-data, export-control, quality or program-specific requirements.

For project managers and planners, this has a direct operational consequence: the subcontract is part of the project's execution architecture. Its delivery milestones, inspection points, documentation requirements, approval cycles, change procedures and acceptance criteria can all affect the shipbuilder's integrated schedule. A supplier that appears to have a simple "delivery date" in its commercial quotation may in reality be subject to a much larger contractual chain of engineering approvals, quality records, testing, source inspection and government/prime acceptance before the item can be released for installation.

The contract-type choices discussed throughout this article - fixed-price, cost-reimbursement, and everything in between - are not arbitrary; they follow a deliberate risk-allocation logic explained in our article on Why the US Navy Doesn't Use Fixed-Price Contracts the Way Commercial Shipowners Do.

Written and maintained by the Project2me team — practicing planning and project management professionals with hands-on experience on shipyard new-build and repair contracts. This article reflects that practical experience and is meant as a planning-oriented view, not a classification-society rule or contractual standard. More about our background →