Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires

The DFARS cybersecurity clauses show up in defense contracts in a predictable way: someone in contracts forwards a solicitation with a highlighted paragraph and asks whether it’s a problem. This pillar explains what each clause requires, which ones apply to you, and which ones you have to pass down to your own suppliers.

The short version: the clauses are not interchangeable and they do not all do the same job. One tells you to protect data. One tells you to post a score. One gives the government the right to check. One ties a certification level to your contract. And one covers a different category of information entirely. Confusing them is how contractors end up either over-buying or quietly non-compliant.

The five DFARS cybersecurity clauses at a glance

ClauseWhat it doesApplies when
FAR 52.204-2115 basic safeguarding requirementsYou handle Federal Contract Information (FCI)
DFARS 252.204-7012Safeguard covered defense information, report incidents in 72 hoursYou handle Covered Defense Information / CUI on a DoD contract
DFARS 252.204-7019Post a current NIST SP 800-171 self-assessment score in SPRSCondition of award on solicitations containing 7012
DFARS 252.204-7020Government right to assess; subcontractor score verificationContracts containing 7012
DFARS 252.204-7021Maintain a CMMC status for the life of the contract; annual affirmationWhere DoD designates a CMMC level

Start with the data, not the clause

Every one of these clauses is triggered by a type of information — not by your size, your NAICS code, or whether you consider yourself a “cyber” company. So the first question is never “which clause applies to me.” It’s what kind of government information do we actually touch.

Federal Contract Information (FCI) is information provided by or generated for the government under a contract that isn’t intended for public release. Delivery schedules. Statements of work. Correspondence about performance. Almost every federal contractor has FCI, and FCI triggers FAR 52.204-21 and the 15 basic safeguarding requirements.

Covered Defense Information (CDI) is the DoD term used in 7012, and in practice it means Controlled Unclassified Information — engineering drawings, technical data with military application, specifications, test reports, source code, and the rest of what sits in the CUI Registry.

The distinction matters because the requirement sets are wildly different in size. FCI gets you fifteen basic practices. CUI gets you 110 NIST SP 800-171 requirements and 320 assessment objectives. Contractors who guess wrong in either direction pay for it — one by failing an assessment, the other by buying a government cloud they never needed. If you’re selling outside DoD, note that the FAR CUI rule extends CUI handling government-wide on a different track.

What each clause actually requires

FAR 52.204-21 — basic safeguarding

Fifteen requirements. Limit system access to authorized users, control who can execute what, sanitize media before disposal, limit physical access, monitor communications at the boundary, use encrypted or authenticated remote sessions, run antivirus and keep it current. They map closely to CMMC Level 1.

None of it requires a government cloud, an enclave, or an assessor. It’s the floor, and it applies government-wide — not just DoD.

DFARS 252.204-7012 — safeguarding and incident reporting

This clause does the heavy lifting, and it carries four distinct obligations people tend to collapse into one: implement NIST SP 800-171, report cyber incidents to DIBNet within 72 hours of discovery, preserve media for 90 days and submit malicious software to DC3, and ensure any cloud handling covered defense information meets FedRAMP Moderate or equivalent.

Each of those is a separate failure point. What DFARS 252.204-7012 requires walks all four, including the medium assurance certificate you need before an incident rather than during one.

DFARS 252.204-7019, 7020 and 7021 — score, assessment, certification

7019 makes a current SPRS score a condition of award — current meaning not more than three years old. 7020 preserves the government’s right to conduct its own assessment and obliges you to verify your subcontractors’ scores. 7021 attaches a CMMC status to the contract where DoD designates one.

These three arrived together and get treated as one requirement. They aren’t, and after the July 2026 CMMC Phase 2 suspension they’re in three different states. DFARS 252.204-7019 vs 7020 vs 7021 covers what each one triggers and what the suspension did and did not change.

Flowdown: what you have to pass to your suppliers

Flowdown is where most of the real exposure sits, because the obligation runs both directions — you inherit requirements from your prime and you owe them to your suppliers. A gap anywhere in that chain lands on whoever the government is contracting with.

7012, 7020, and 7021 all flow down, as does FAR 52.204-21 where FCI is involved. But flowdown isn’t automatic and it isn’t universal: you pass the clause to subcontractors whose performance involves the covered information. A supplier who never touches CUI doesn’t need the CUI clause, and papering every vendor creates work without reducing risk.

7020 also creates an active verification duty most primes miss — you must confirm the subcontractor’s score is actually posted, not merely require it in the terms. Flowdown: which clauses you must pass to your subcontractors includes a decision tree for making that call supplier by supplier. Getting the supplier side right also feeds directly into vendor and partner selection.

Edge cases worth knowing

Three situations that come up constantly and have their own answers:

You’re mid-proposal and don’t know if the requirements are manageable. The clause numbers are only part of it — requirements hide in the SOW, the CDRLs, and program security attachments too. How to read a solicitation for cybersecurity requirements is built as a bid/no-bid tool.

You’ve found a clause in something you already signed. Common, fixable, and the sequence matters. See a clause in a contract you already signed.

You sell a commercial product. There is a real carve-out and it is routinely over-read — see commercial-item and COTS contracts. If your position is that none of this applies to you, who is exempt from CMMC and DFARS cybersecurity clauses tests that honestly, including the four arguments that don’t hold.

What to do this week

Pull your three largest active contracts and search them for these five clause numbers. Write down which appear and on which contract. Most contractors have never done this and are surprised by at least one result — either a clause they didn’t know they’d accepted, or one they assumed was there that isn’t.

Then check the other direction: which of your suppliers touch that same information, and what did you actually flow down? A contract award, a new prime relationship, or a modification are all trigger events that should start this review rather than a calendar reminder.

Common questions about DFARS cybersecurity clauses

Which DFARS clause requires NIST SP 800-171?

DFARS 252.204-7012. It requires “adequate security” on any system handling covered defense information, which in practice means implementing all 110 NIST SP 800-171 requirements, with gaps documented in a System Security Plan and tracked in a Plan of Action and Milestones.

Did the CMMC suspension remove the DFARS cybersecurity clauses?

No. The July 13, 2026 suspension paused CMMC Phase 2 third-party certification assessments. DFARS 252.204-7012, 7019, and 7020 were unaffected and remain fully in force. DFARS 252.204-7021 was not repealed either — the program rule at 32 CFR Part 170 and the acquisition rule creating the clause both remain on the books.

What is the difference between FCI and CUI?

Federal Contract Information is information generated for or provided by the government under a contract that is not intended for public release. Controlled Unclassified Information is a defined category requiring specific safeguarding — engineering drawings, technical data with military application, and similar. FCI triggers 15 basic requirements under FAR 52.204-21. CUI triggers 110 requirements under NIST SP 800-171.

Which DFARS clauses must I flow down to subcontractors?

DFARS 252.204-7012, 7020, and 7021 flow down, as does FAR 52.204-21 where FCI is involved. Flowdown applies to subcontractors whose performance involves the covered information — not to every supplier. Under 7020 you must also verify that CUI-handling subcontractors have a current SPRS score posted, which is an active check rather than a contract term.

How current does my SPRS score have to be?

Not more than three years old. Under DFARS 252.204-7019, a current assessment posted in the Supplier Performance Risk System is a condition of eligibility for award. A score posted in year one expires in year four, which contractors typically discover when a proposal is found ineligible.


Next step: If you’re not sure which of your systems and suppliers fall inside the boundary, that’s the scoping problem, and it comes before everything else. Our CUI Scoping Workbook is a fillable 15-page workbook for defining the smallest defensible boundary. Free, no email required.

Last reviewed: August 2026. CMMC program status is under review; verify current requirements against official sources before acting.

Table of Contents