Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

What to Do When a DFARS Clause Appears in a Contract You Already Signed

Finding a DFARS clause in an already signed contract is one of the more uncomfortable discoveries in government contracting, and it is far more common than anyone admits. Somebody runs a search, finds 252.204-7012 in an award from eighteen months ago, and realizes nothing was ever done about it. For what the clauses actually require, see DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.

Two things worth saying immediately. This is fixable, and it is fixable more often than not. But the order you do things in matters a great deal, and the instinct most people have — call the contracting officer right away — is the wrong first move.

What not to do first

Do not call your contracting officer before you know your own position. Not because you should hide anything — you shouldn’t, and you can’t — but because a conversation where you cannot answer basic questions about your own environment goes badly and is hard to un-have.

Your CO’s first questions will be some version of: what data do you actually handle, what’s your current state against the requirement, and what’s your plan. Walking in without those answers turns a manageable disclosure into an open-ended problem.

Do not post a SPRS score to look responsive. A score you haven’t earned is worse than no score. See the section on False Claims Act exposure below — this is the single most consequential mistake available in this situation.

Do not backdate anything. Not a policy, not a training record, not a system security plan. Assessors are experienced at spotting documents created in a batch the week before, and the consequence of being caught shifts the matter from a compliance gap to something considerably worse.

Step 1: Determine whether the clause actually bites

Before assuming the worst, establish whether you handle the data the clause is about. The presence of a clause in a contract is not the same as the obligation being triggered.

DFARS 252.204-7012 attaches where you process, store, or transmit covered defense information. Contracting officers sometimes include the clause on contracts where no CUI ever flows — it happens, particularly on services contracts and IDIQ vehicles where the clause is applied at the vehicle level.

So the first question is: has any CUI actually reached us under this contract? Check the deliverables, the technical data you’ve received, the drawings, the specifications, and anything marked. If you’re genuinely unsure, that ambiguity is itself worth resolving with your CO — but resolve it as a scoping question, not as a confession.

If no covered defense information has ever come to you under that contract, your position is significantly better than you think. Document how you reached that conclusion.

Step 2: Establish your actual position

Assuming the clause does bite, you need an honest picture before you talk to anyone.

Score yourself against NIST SP 800-171 at the objective level, not the requirement level. The DoD Assessment Methodology breaks 110 requirements into 320 objectives, and a requirement counts as implemented only when every objective under it is met. Most contractors who self-score quickly overstate by a wide margin — see what DFARS 252.204-7012 requires for the detail.

You will likely land on a negative number. That is normal and it is not disqualifying. Contractors early in this work routinely score below zero; the methodology allows down to -203. A defensible negative score is a legitimate starting position. An indefensible positive one is a liability.

Step 3: Build the SSP and POA&M before you post anything

A System Security Plan describes your environment and how each requirement is met. A Plan of Action and Milestones lists what isn’t met, who owns it, and when it will be.

These two documents are what turn “we’re non-compliant” into “we have a compliance program in progress,” and that distinction is the entire difference in how your situation reads to a contracting officer, a prime, or an assessor.

The POA&M has to be real. Dates that have already passed, no named owners, and no movement between versions reads as a decision not to comply rather than a plan to comply. That is the specific failure mode that turns a gap into a finding.

Step 4: Post a defensible score

Now post to SPRS. The score reflects your genuine current state, with the SSP and POA&M standing behind it.

If your contract also contains DFARS 252.204-7019, note that a current score was a condition of eligibility for award — meaning it should have been posted before, not after. That’s a real gap and worth understanding before the conversation. DFARS 252.204-7019 vs 7020 vs 7021 covers what each of the three triggers.

Step 5: Now have the conversation

With a scoped boundary, an honest score, an SSP, and a real POA&M, you can go to your contracting officer with something workable: here is what we handle, here is where we stand, here is our remediation plan and timeline.

That conversation usually goes better than people expect. COs deal with this regularly, and a contractor arriving with a plan is a considerably easier problem than one arriving with a question.

If the contract contains DFARS 252.204-7021 with a CMMC level designated, ask specifically whether a modification is coming in light of the July 2026 Phase 2 suspension. The clause was not repealed — existing contracts containing it need a modification to change, and that is your CO’s action, not yours.

The part people are actually worried about

Let’s name it directly, because the anxiety is usually about this even when the question isn’t.

When a contractor certifies compliance as a condition of award or payment and that certification is false, that is a False Claims Act theory. The Department of Justice’s Civil Cyber-Fraud Initiative exists specifically to pursue contractors who misrepresent their cybersecurity posture in federal contracting, and procurement fraud was named a critical enforcement priority in August 2026.

Here is the useful distinction. Having a gap is not fraud. Representing that you don’t have one is.

Which means an unremediated gap you’ve documented honestly and are working through is a compliance matter. An inflated SPRS score sitting in a government system attached to a signed contract is a different category of problem — and it is one that gets meaningfully worse the longer it sits, not better.

If you have posted a score you cannot defend, correcting it is the move. That is uncomfortable and it is still by far the best available option. This is also the point at which involving counsel is genuinely warranted rather than cautious boilerplate — a False Claims Act question is a legal question, not a technical one.

What about the other direction — your suppliers?

If you’ve just discovered a clause you missed, check whether you flowed it down. Most contractors who missed a clause on the way in also missed it on the way out.

Under DFARS 252.204-7020 you’re also required to verify that CUI-handling subcontractors have current SPRS scores posted — an active check, not a contract term. Flowdown: which clauses you must pass to your subcontractors has a decision tree for running that supplier by supplier, and vendor and partner selection covers what to do when a supplier can’t meet the requirement.

How to stop this happening again

The root cause is almost always that nobody reads solicitations for cybersecurity requirements before bid. How to read a solicitation for cybersecurity requirements is a fifteen-minute process that prevents this entirely.

Build it into your bid/no-bid step rather than your post-award step. Contract award, contract modification, and a new prime relationship are all trigger events that should prompt a clause review — the goal is to find these before signature, when your options are still open.

Common questions about finding a DFARS clause after signing

What should I do if I find DFARS 252.204-7012 in a contract I already signed?

Establish your own position before contacting your contracting officer. Confirm whether covered defense information has actually reached you under that contract, score yourself honestly against NIST SP 800-171 at the objective level, build a System Security Plan and a Plan of Action and Milestones, post a defensible SPRS score, and then have the conversation with a remediation plan in hand.

Can I be penalized for not complying with a DFARS clause I did not notice?

Not noticing is not a defense, but an unremediated gap that is honestly documented and actively being worked is a compliance matter rather than a fraud matter. The serious exposure comes from representing compliance you do not have — for example an inflated SPRS score — which is a False Claims Act theory pursued by the Civil Cyber-Fraud Initiative.

Should I post a SPRS score immediately to show good faith?

Only if it is defensible. A score you cannot substantiate is worse than a late one, because it becomes a representation rather than a gap. Score yourself at the objective level first, document your position in a System Security Plan and Plan of Action and Milestones, and post the number those support.

Does the CMMC suspension help if 252.204-7021 is in my signed contract?

Not automatically. The clause was not repealed — the program rule at 32 CFR Part 170 and the acquisition rule creating it remain on the books. An existing contract containing 7021 needs a modification from your contracting officer to change. Ask specifically whether one is coming.

Is a negative SPRS score a problem?

No. The DoD Assessment Methodology allows scores down to -203, and negative scores are normal for contractors early in implementation. A defensible negative score is a legitimate starting position. An indefensible positive one is a liability.


Next step: Step two is where most people stall, because scoring honestly requires knowing what’s actually in scope. If you want a person to walk it with you, a scoping session maps what you handle, where you stand, and what closing the gap involves. No obligation, no charge, and we will tell you if the honest answer is that you can handle it yourself.

Last reviewed: August 2026. This is general information, not legal advice. Where False Claims Act exposure is a live question, involve counsel.

Table of Contents