If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
The DFARS cybersecurity clauses show up in defense contracts in a predictable way: someone in contracts forwards a solicitation with a highlighted paragraph and asks whether it’s a problem. This pillar explains what each clause requires, which ones apply to you, and which ones you have to pass down to your own suppliers.
The short version: the clauses are not interchangeable and they do not all do the same job. One tells you to protect data. One tells you to post a score. One gives the government the right to check. One ties a certification level to your contract. And one covers a different category of information entirely. Confusing them is how contractors end up either over-buying or quietly non-compliant.
The five DFARS cybersecurity clauses at a glance
| Clause | What it does | Applies when |
|---|---|---|
| FAR 52.204-21 | 15 basic safeguarding requirements | You handle Federal Contract Information (FCI) |
| DFARS 252.204-7012 | Safeguard covered defense information, report incidents in 72 hours | You handle Covered Defense Information / CUI on a DoD contract |
| DFARS 252.204-7019 | Post a current NIST SP 800-171 self-assessment score in SPRS | Condition of award on solicitations containing 7012 |
| DFARS 252.204-7020 | Government right to assess; subcontractor score verification | Contracts containing 7012 |
| DFARS 252.204-7021 | Maintain a CMMC status for the life of the contract; annual affirmation | Where DoD designates a CMMC level |
Start with the data, not the clause
Every one of these clauses is triggered by a type of information — not by your size, your NAICS code, or whether you consider yourself a “cyber” company. So the first question is never “which clause applies to me.” It’s what kind of government information do we actually touch.
Federal Contract Information (FCI) is information provided by or generated for the government under a contract that isn’t intended for public release. Delivery schedules. Statements of work. Correspondence about performance. Almost every federal contractor has FCI, and FCI triggers FAR 52.204-21 and the 15 basic safeguarding requirements.
Covered Defense Information (CDI) is the DoD term used in 7012, and in practice it means Controlled Unclassified Information — engineering drawings, technical data with military application, specifications, test reports, source code, and the rest of what sits in the CUI Registry.
The distinction matters because the requirement sets are wildly different in size. FCI gets you fifteen basic practices. CUI gets you 110 NIST SP 800-171 requirements and 320 assessment objectives. Contractors who guess wrong in either direction pay for it — one by failing an assessment, the other by buying a government cloud they never needed. If you’re selling outside DoD, note that the FAR CUI rule extends CUI handling government-wide on a different track.
What each clause actually requires
FAR 52.204-21 — basic safeguarding
Fifteen requirements. Limit system access to authorized users, control who can execute what, sanitize media before disposal, limit physical access, monitor communications at the boundary, use encrypted or authenticated remote sessions, run antivirus and keep it current. They map closely to CMMC Level 1.
None of it requires a government cloud, an enclave, or an assessor. It’s the floor, and it applies government-wide — not just DoD.
DFARS 252.204-7012 — safeguarding and incident reporting
This clause does the heavy lifting, and it carries four distinct obligations people tend to collapse into one: implement NIST SP 800-171, report cyber incidents to DIBNet within 72 hours of discovery, preserve media for 90 days and submit malicious software to DC3, and ensure any cloud handling covered defense information meets FedRAMP Moderate or equivalent.
Each of those is a separate failure point. What DFARS 252.204-7012 requires walks all four, including the medium assurance certificate you need before an incident rather than during one.
DFARS 252.204-7019, 7020 and 7021 — score, assessment, certification
7019 makes a current SPRS score a condition of award — current meaning not more than three years old. 7020 preserves the government’s right to conduct its own assessment and obliges you to verify your subcontractors’ scores. 7021 attaches a CMMC status to the contract where DoD designates one.
These three arrived together and get treated as one requirement. They aren’t, and after the July 2026 CMMC Phase 2 suspension they’re in three different states. DFARS 252.204-7019 vs 7020 vs 7021 covers what each one triggers and what the suspension did and did not change.
Flowdown: what you have to pass to your suppliers
Flowdown is where most of the real exposure sits, because the obligation runs both directions — you inherit requirements from your prime and you owe them to your suppliers. A gap anywhere in that chain lands on whoever the government is contracting with.
7012, 7020, and 7021 all flow down, as does FAR 52.204-21 where FCI is involved. But flowdown isn’t automatic and it isn’t universal: you pass the clause to subcontractors whose performance involves the covered information. A supplier who never touches CUI doesn’t need the CUI clause, and papering every vendor creates work without reducing risk.
7020 also creates an active verification duty most primes miss — you must confirm the subcontractor’s score is actually posted, not merely require it in the terms. Flowdown: which clauses you must pass to your subcontractors includes a decision tree for making that call supplier by supplier. Getting the supplier side right also feeds directly into vendor and partner selection.
Edge cases worth knowing
Three situations that come up constantly and have their own answers:
You’re mid-proposal and don’t know if the requirements are manageable. The clause numbers are only part of it — requirements hide in the SOW, the CDRLs, and program security attachments too. How to read a solicitation for cybersecurity requirements is built as a bid/no-bid tool.
You’ve found a clause in something you already signed. Common, fixable, and the sequence matters. See a clause in a contract you already signed.
You sell a commercial product. There is a real carve-out and it is routinely over-read — see commercial-item and COTS contracts. If your position is that none of this applies to you, who is exempt from CMMC and DFARS cybersecurity clauses tests that honestly, including the four arguments that don’t hold.
What to do this week
Pull your three largest active contracts and search them for these five clause numbers. Write down which appear and on which contract. Most contractors have never done this and are surprised by at least one result — either a clause they didn’t know they’d accepted, or one they assumed was there that isn’t.
Then check the other direction: which of your suppliers touch that same information, and what did you actually flow down? A contract award, a new prime relationship, or a modification are all trigger events that should start this review rather than a calendar reminder.
Frequently asked
Questions about this topic
Which DFARS clause requires NIST SP 800-171?
Did the CMMC suspension remove the DFARS cybersecurity clauses?
What is the difference between FCI and CUI?
Which DFARS clauses must I flow down to subcontractors?
How current does my SPRS score have to be?
Keep reading
More in Contract Clauses & Flowdown
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers →
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors →
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements →
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements →
- Flowdown: Which Clauses You Must Pass to Your Subcontractors →
- What DFARS 252.204-7012 Requires, in Plain English →
- What to Do When a DFARS Clause Appears in a Contract You Already Signed →
- Who Is Exempt from CMMC, and Why “We Only Make Parts” Usually Isn’t →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5