If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
DFARS 252.204-7019, 7020 and 7021 arrived together, sit next to each other in solicitations, and get treated as one requirement. They aren’t. They do three different jobs, they bind different parties, and after the CMMC Phase 2 suspension they sit in three different states. For how these fit with 7012 and FAR 52.204-21, start with DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.
One line each:
- 7019 — you must have posted a score to be eligible for award
- 7020 — the government can come check, and you must verify your subs
- 7021 — you must hold a CMMC status and affirm it annually
DFARS 252.204-7019: the eligibility gate
This is a notice clause, which is why it’s easy to skim past. It tells offerors that to be considered for award, they must have a current NIST SP 800-171 DoD Assessment on record in the Supplier Performance Risk System.
Current means not more than three years old. That’s the trigger nobody diaries. A score posted in year one quietly expires in year four, and contractors discover it when a proposal is found ineligible — not while doing compliance work. Score expiry belongs on your list of trigger events alongside contract award and prime changes.
The score comes from the DoD Assessment Methodology: start at 110, deduct 5, 3, or 1 point per unimplemented requirement, floor at -203. Negative scores are normal early on and not disqualifying by themselves.
What matters is that a score exists, that it’s current, and — increasingly — that it’s defensible. A contracting officer can see your score before award. So can a prime evaluating you as a supplier. A score you can’t substantiate is worse than a low score you can, because the low score is a starting position and the unsupportable one is a representation.
DFARS 252.204-7020: the government’s right to check
7020 does two distinct things, and most contractors only know the first.
It preserves the government’s assessment authority. DoD may conduct a Medium or High assessment of your environment. In practice that’s DIBCAC, and a High assessment is an on-site review of evidence against all 320 objectives. This authority is entirely unaffected by the CMMC suspension.
It makes you responsible for your subcontractors’ scores. Before awarding a subcontract to a supplier that will handle CUI, you must ensure that supplier has its own current assessment posted in SPRS.
That second obligation is an active verification duty, not a paperwork one. Flowing the clause down does not satisfy it — you have to confirm the score is actually there. Primes who assume the clause does the work carry a gap they don’t know about. Flowdown: which clauses you must pass to your subcontractors covers how to run that check, and vendor and partner selection covers what to do when a supplier’s score is a problem.
DFARS 252.204-7021: the CMMC clause, and where it stands
7021 attaches a CMMC level to a specific contract. Where DoD designates a level, you must hold that status or higher at award, maintain it for the duration, and complete an annual affirmation of continuing compliance through a named affirming official.
On July 13, 2026, DoD suspended CMMC Phase 2, including the November 10, 2026 milestone that would have made third-party C3PAO assessments mandatory for most Level 2 contracts.
What that did and did not do:
The clause was not repealed. The CMMC program rule at 32 CFR Part 170 and the acquisition rule creating 7021 both went through full notice-and-comment rulemaking and remain on the books. Unwinding them would require new rulemaking. What was suspended is the department’s exercise of discretion in designating levels and requiring certification assessments. As of the suspension, 7021 was listed as “TBD” on DoD CIO’s CMMC resources page.
The clause can still appear in solicitations. If you hold a contract with a 7021 certification condition, expect a modification. If you’re mid-proposal on a solicitation that required certification, expect an amendment. Neither is automatic — see a clause in a contract you already signed for how to handle the first case.
Existing certifications still count. 7021 permits a higher certification level to satisfy a lesser designation, so a completed Level 2 certification remains valid and remains a differentiator with primes and in M&A diligence.
Phase 1 self-assessments continue. Level 1 and Level 2 self-assessment requirements were never suspended, and neither were the annual affirmations attached to them.
The part that catches subcontractors
The suspension binds DoD. It does not bind your prime.
7021 requires primes to flow down the substance of CMMC requirements. A prime managing its own liability may well keep certification language in subcontract terms regardless of what DoD paused — and it is entirely within its rights to do so.
Relief does not flow downhill automatically. If a prime has told you verbally that requirements are relaxed, get it in writing before you change anything about your assessment plans. A verbal assurance from a program manager is not a contract modification.
How the three interact
The clauses stack rather than substitute. What DFARS 252.204-7012 requires creates the substantive obligation — protect the data, report incidents. 7019 makes a posted score a condition of eligibility. 7020 lets the government verify independently and makes you verify suppliers. 7021 layers a certification status on top where DoD designates one.
Remove 7021 entirely, as the suspension effectively has for new designations, and you still have every obligation that mattered: implement 800-171, post a defensible score, keep it current, be ready for a government assessment, manage your supply chain. That’s the whole meaning of “suspended is not repealed.”
What to check
- When was your SPRS score last posted? Approaching three years means it expires whether you’re thinking about it or not.
- Could you survive a DIBCAC High assessment tomorrow? Not “are we compliant” — could you produce evidence for 320 objectives.
- Do your CUI-handling subcontractors have current SPRS scores? Have you actually looked?
- If 7021 is in a live contract, has your CO issued a modification? If not, the clause is still in your contract.
- Have any primes changed their flowdown in writing? Verbal doesn’t count.
Frequently asked
Questions about this topic
What is the difference between DFARS 252.204-7019 and 7020?
How current must a SPRS score be under DFARS 252.204-7019?
Is DFARS 252.204-7021 still in effect after the CMMC suspension?
Does the CMMC suspension apply to prime contractor flowdown requirements?
Can DIBCAC still assess us during the CMMC suspension?
Keep reading
More in Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires →
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors →
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements →
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements →
- Flowdown: Which Clauses You Must Pass to Your Subcontractors →
- What DFARS 252.204-7012 Requires, in Plain English →
- What to Do When a DFARS Clause Appears in a Contract You Already Signed →
- Who Is Exempt from CMMC, and Why “We Only Make Parts” Usually Isn’t →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5